SmartWitness: A Proactive Software Transparency System using Smart Contracts


연구 분야: Infrastructure



학회: BSCI '20: Proceedings of the 2nd ACM International Symposium on Blockchain and Secure Critical Infrastructure


초록

Package managers have become essential for software distribution and management. Their goal is to allow users to install programs, drivers, or updates in their systems in a secure, quick, and often, unattended way. However, in recent years, attackers have found severe flaws in software distribution systems and used them as a stealthy launch pad for malicious software. Moreover, it was proved that actors of the software supply-chain are ineffective in detecting and stopping attacks on user devices. In this paper, we present a design for software distribution systems based on distributed ledgers. By replacing traditional code signing certificates with smart contracts, named SmartWitness, we propose a novel system that provides properties of binary transparency, useful and granular package revocation, and dynamic and proactive security assessment improving risk awareness of end users. SmartWitness keeps all actors transparent and accountable, and it enables security providers to participate earlier in the software distribution process, directly influencing package installations on user devices. We show how SmartWitness is integrated into an existing package manager system, and we present results from conducted experiments indicating that the system is practical as for today.


Author Profile
Juan David Guarnizo

Singapore University of Technology and Design Singapore Singapore

Andorra
Author Profile
Bithin Alangot

Amrita Vishwa Vidyapeetham Amritapuri India

India
Author Profile
Paweł Szałachowski

Singapore University of Technology and Design Singapore Singapore

Andorra

📄 논문 정보

발행 연도 2020년
인용수 3
출판 국가 Andorra, India
사이트 ACM
좋아요 수 0

연관 논문 목록 (298건)