{"title":"SmartRetro: Blockchain-Based Incentives for Distributed IoT Retrospective Detection","authors":"Bo Wu, Qi Li, Ke Xu, Ruoyu Li, Zhuotao Liu","doi":"10.1109/MASS.2018.00053","DOIUrl":null,"url":null,"abstract":"Internet of Things (IoT) has already been in the period of rapid development and widespread deployment, while it is still vulnerable to various malicious attacks. Security detection before system installation is not enough to ensure that IoT devices are always secure, because newly emerging vulnerabilities can still be exploited to launch attacks. To address this issue, retrospective detection is often required to trace the security status of IoT systems. Unfortunately, existing centralized detection mechanisms cannot easily provide a comprehensive security analysis. In particular, consumers cannot automatically receive security notification whenever a new vulnerability is uncovered. In this paper, we propose a novel blockchain-powered incentive platform, called SmartRetro, that can incentivize and attract more distributed detectors to participate in retrospective vulnerability detection and contribute their detection results. Leveraging smart contracts, consumers in SmartRetro receive automatic security feedback about their installed IoT systems. We perform the security and theoretical analysis to demonstrate that SmartRetro achieves our desirable security goals.We further implement SmartRetro prototype on Ethereum to evaluate its performance. Our experimental results show SmartRetro is technically feasible and economically beneficial.","PeriodicalId":146214,"journal":{"name":"2018 IEEE 15th International Conference on Mobile Ad Hoc and Sensor Systems (MASS)","volume":"555 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE 15th International Conference on Mobile Ad Hoc and Sensor Systems (MASS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MASS.2018.00053","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10
Abstract
Internet of Things (IoT) has already been in the period of rapid development and widespread deployment, while it is still vulnerable to various malicious attacks. Security detection before system installation is not enough to ensure that IoT devices are always secure, because newly emerging vulnerabilities can still be exploited to launch attacks. To address this issue, retrospective detection is often required to trace the security status of IoT systems. Unfortunately, existing centralized detection mechanisms cannot easily provide a comprehensive security analysis. In particular, consumers cannot automatically receive security notification whenever a new vulnerability is uncovered. In this paper, we propose a novel blockchain-powered incentive platform, called SmartRetro, that can incentivize and attract more distributed detectors to participate in retrospective vulnerability detection and contribute their detection results. Leveraging smart contracts, consumers in SmartRetro receive automatic security feedback about their installed IoT systems. We perform the security and theoretical analysis to demonstrate that SmartRetro achieves our desirable security goals.We further implement SmartRetro prototype on Ethereum to evaluate its performance. Our experimental results show SmartRetro is technically feasible and economically beneficial.
物联网(Internet of Things, IoT)已经处于快速发展和广泛部署的时期,但它仍然容易受到各种恶意攻击。系统安装前的安全检测不足以确保物联网设备始终安全,因为新出现的漏洞仍然可以被利用来发动攻击。为了解决这个问题,通常需要回顾性检测来跟踪物联网系统的安全状态。不幸的是,现有的集中式检测机制不能轻易地提供全面的安全分析。特别是,消费者无法在发现新漏洞时自动收到安全通知。在本文中,我们提出了一个新的区块链驱动的激励平台,称为SmartRetro,可以激励和吸引更多的分布式检测器参与回顾性漏洞检测并贡献其检测结果。利用智能合约,SmartRetro的消费者可以收到有关其安装的物联网系统的自动安全反馈。我们执行安全性和理论分析,以证明SmartRetro实现了我们期望的安全目标。我们进一步在以太坊上实现SmartRetro原型,以评估其性能。实验结果表明,SmartRetro在技术上是可行的,经济上是有益的。