RuleChain: A Novel Intrusion Rules Distribution Method Based on Blockchain
Fan Zhang, Wenshan Li, Tao Li, Yunpeng Wang, Zhiyong Li · 2019
Intrusion detection systems (IDSs) have been widely employed to deal with cyber threats and attacks. In order to detect a new type of intrusion, traditional IDSs need either operators to add rules manually or IDS itself to periodically obtain the latest intrusion feature information (rules) from a central online server. However, these two methods are difficult to distribute new intrusion rules on a large scale quickly. It causes IDS to lag in response to new intrusion threats, leaving the network into intrusion risks. In addition, the traditional centralized rules distribution method is also vulnerable to advanced cyber-attacks or nature disasters. This paper proposes a new private blockchain-based intrusion rules distribution method: RuleChain. The management nodes are employed to pack the new rules into a new RuleBlock, and broadcasting it to the entire network. All nodes received the broadcast message will update the local RuleChain with the new RuleBlock to obtain the latest intrusion rules. In this way, the newly released intrusion rules can be quickly transmitted to all nodes of the entire network, thus the proposed method ensures the rapid detection capability of IDS for new intrusion threats. Moreover, the proposed method can accomplish almost all functions of traditional centralized paradigm at very low hardware cost. Theories and experiments show that the proposed method supports fast and efficient distribution of rules across the entire network anywhere.