Architecture of a Secure and Decentralized Domain Classification System using Blockchain and IPFS for DNS Sinkhole and Threat Intelligence Applications

Aryan Pandey, Rishikesh Bharadwaj, S Krishnaveni, B Jothi · 2025

The escalating sophistication of cyber threats demands innovative approaches to threat intelligence sharing and DNS security mechanisms. Traditional centralized domain reputation services and DNS sinkhole implementations suffer from scalability limitations, single points of failure, and susceptibility to tampering. This paper introduces a novel architecture for secure, verifiable, and decentralized domain classification and distribution specifically designed for DNS sinkhole and threat intelligence applications. Our system leverages blockchain technology for immutable record-keeping, the InterPlanetary File System (IPFS) for distributed content storage, and public key cryptography to maintain a chain of trust from security researchers to end consumers. By combining these technologies, we establish a framework that ensures authenticity, integrity, and timeliness of domain threat intelligence without reliance on centralized authorities. The architecture allows security researchers to publish categorized domain lists (malware, phishing, adware, etc.) with cryptographic verification while enabling DNS sinkhole operators and threat intelligence consumers to confidently retrieve and implement this intelligence. Performance evaluation demonstrates that our solution provides significant advantages in terms of resilience, tamper resistance, and trustworthiness compared to conventional distribution methods, with minimal overhead for verification processes. This research addresses critical gaps in current threat intelligence sharing mechanisms and DNS sinkhole implementations, offering a practical architecture for enhancing cybersecurity defenses against domain-based threats.

Read the paper · More papers on PaperTik