blockchain and applications in information security bahou...blockchain and applications in...

48
Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 [email protected] InfoSec Nashville September 2018 © 2018 Waller Lansden Dortch & Davis, LLP

Upload: others

Post on 22-Apr-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

Blockchain and Applications in Information Security

A.J. Bahou, Esq., LLM, MsECE615‐850‐[email protected]

InfoSec NashvilleSeptember 2018

© 2018 Waller Lansden Dortch & Davis, LLP

Page 2: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

2

Page 3: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

3

Page 4: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

4

Page 5: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

5

Agenda

• Introduction− What is Blockchain?

− Why does it matter?

• Components− Cryptography

− Terms ‐ Blocks, Tokens, Hashes, Immutable

• Blockchain Applications in Information Security− Use Cases and Examples for Discussion

− Prior Hacks

Page 6: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

6

Attorney Disclaimer

• This is merely an introduction & terminology is used in various ways…(focus on concepts as we begin).

• My apologies in advance, but if I say I can’t answer ….

− It might be because we haveo Clients with Patent Applications

o Clients with Business Models 

− that are not ready for disclosure yet.

Page 7: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

7

What is Blockchain?

• Cryptographic Distributed Ledger− A Blockchain is a distributed public database that keeps a permanent record of digital transactions.

− Promise to consider…

Page 8: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

8

Why does Blockchain matter?

• This technology could change everything…like− Electricity

− Transistor

− Internet

• No central authority (in theory) − Is consensus good enough?

− Will the consensus always make the ‘right’ decision?

Page 9: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

9

Cryptography & Security Basics

Alice Charlie Bob

Eve

Page 10: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

10

Cryptography

• Process of converting ordinary information (plaintext) into encrypted unintelligible text (ciphertext).

• Encryption− 𝑒 𝑑 , 𝑤ℎ𝑒𝑟𝑒 ′𝑘′ 𝑖𝑠 𝑡ℎ𝑒 𝑘𝑒𝑦

Page 11: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

11

PKI

• Public Key Infrastructure

https://en.wikipedia.org/wiki/Public‐key_cryptography 

Page 12: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

12

PKI

Alice Charlie Bob

Eve

https://en.wikipedia.org/wiki/Public‐key_cryptography 

Page 13: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

13

PKI

https://en.wikipedia.org/wiki/Public‐key_cryptography 

• Public Key Infrastructure

Page 14: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

14

PKI

• Advanced Variation – Diffie‐Hellman Key Exchange

https://en.wikipedia.org/wiki/Public‐key_cryptography 

Page 15: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

15

Hashing

• Hashing is a mathematical algorithm that maps data of arbitrary size to a bit string of a fixed size (a hash function) which is designed to also be a one‐way function, that is, a function which is infeasibleto invert. 

https://en.wikipedia.org/wiki/Cryptographic_hash_function

Page 16: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

16

Hashing

https://www.youtube.com/watch?v=_160oMzblY8

Page 17: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

17

Creating the Chain

https://www.youtube.com/watch?v=_160oMzblY8

Page 18: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

18

Blockchain

• Satoshi Nakamoto Whitepaper, Oct. 31, 2008

Page 19: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

19

Example

https://hackernoon.com/bitcoin‐ethereum‐blockchain‐tokens‐icos‐why‐should‐anyone‐care‐890b868cec06

Page 20: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

20

Terms

• Blocks – files that contain permanently recorded transaction data

• Hashes – algorithm that maps data to a fixed size

• Tokens – can represent any fungible tradable good• Nonce – an arbitrary number that may only be used once

Page 21: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

21

Terms

• Immutable – unchanging over time or unable to change

• Distributed – copied on various nodes throughout the network

• Ledger – collection of transactions• Nodes – computer connected to the network that performs the task of validating and relaying transactions

Page 22: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

22

Applications of Blockchain in 

Information Security

Page 23: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

23

Growth of Blockchain in Cyber Security

• Cyber security is one of the most important use‐cases for blockchain. 

• A 2017 IBM Study of 3,000 global C‐suite executives found that 33 percent of organizations− are considering or already using blockchain for

o security against fraud and 

o protecting against cybercrime being the main reason organizations are interested.

https://medium.com/polyswarm/5‐important‐use‐cases‐for‐blockchain‐92aeea35484d

Page 24: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

24

Blockchain Use Cases in Information Security

• Identity and Access Management 

• Data Management ‐Improved Confidentiality and Data Integrity

• Securing Edge Devices with Authentication• Secure Private Messaging

• Next Generation PKI• Safer DNS• Reduce DDos Attacks

Page 25: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

25

Identity Management Using Blockchain

Page 26: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

26

Identity Management

Page 27: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

27

Data Management

• Government Agencies (Public information with integrity)− birth and death dates − marital status − business licensing − property transfers, or − criminal activity.

https://www.mckinsey.com/business‐functions/digital‐mckinsey/our‐insights/using‐blockchain‐to‐improve‐data‐management‐in‐the‐public‐sector

Page 28: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

28

Data Management

• Example nation of Estonia− Keyless Signature Infrastructure (KSI) to safeguard all public‐sector data

− KSI creates hash values

− Hash values can be used to identify records 

− But hash values cannot be used to reconstruct the information in the file itself

− KSI allows government officials to monitor changes within various databases

− Electronic health records of all Estonian citizens are managed using KSI technology

• Delaware – Smart Incorporation on the Blockchain 

Page 29: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

29

Data Management

Page 30: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

30

Securing Edge Devices with Blockchain

• IoT devices host the ledger and is capable of participating in blockchain transactions, including mining.

• Each device is provisioned with a private key(Cloud Security Alliance, Using Blockchain to Secure the IoT, 2018) 

Page 31: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

31

Securing Edge Devices with Blockchain

• Cloud‐Enabled IoT Blockchain Network (BC, M2M, API)

− Whitelist devices

− Two‐way authentication

Page 32: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

32

Securing Edge Devices with Blockchain

• Smart Cities, Trusted Communications 

Page 33: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

33

Secure Private Messaging 

• Status Ethereum‐based messenger app (https://status.im) 

− Uses Ethereum node on smartphone, such as a cryptocurrency wallet as an interface for decentralized applications 

− Whisper Protocol – multicast, peer‐to‐peer, end‐to‐end encrypted gossip protocol 

Page 34: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

34

Next Generation PKI ‐ Estonian Government Example

• Since 2013, Estonian Government have used Keyless Signature Infrastructure (KSI) pairs of cryptographic ‘hash functions’ with a distributed ledger to

− Guarantee a record of the state of any component within the network

− Guarantee data stores

• Citizens use ID cards to:− Order prescriptions

− Vote

− Bank online

− Review kid’s school records

− Apply for state benefits

− File tax returns

− Upload their will

− Serve in armed forces, etc.

Page 35: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

35

Securing Cryptocurrency

Page 36: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

36

Securing Cryptocurrency ‐ HackerOne

Page 37: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

37

Securing Cryptocurrency – HackerOne Bug Bounty

Page 38: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

38

Securing Cryptocurrency – HackerOne Bug Bounty

Page 39: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

39

How do we —as InfoSec professionals—

need to protect information on the Blockchain?

Page 40: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

40

Prior Hacks Related to Blockchain

• Mt. Gox − June 2011 ‐ $8 million stolen (admin pw)

− Feb. 2014 ‐ $460 million stolen (attack on the hot wallet)

• Issues− No version control

o Bug fixes delayed

o Untested code deployed

https://www.rsaconference.com/writable/presentations/file_upload/fon4‐t11_hacking_blockchain.pdf

Page 41: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

41

Hacks Related to Blockchain

• The DAO (Distributed Autonomous Organization)− $50 million hack

− DAO smart contract flaw known since May 2016

− Hacker used flaw that allowed splits inside splits, moving Ether repeatedly without checking the ‘balance’

− Hard fork resulted

https://www.rsaconference.com/writable/presentations/file_upload/fon4‐t11_hacking_blockchain.pdf https://www.deepdotweb.com/2016/10/06/cryptocurrency‐hacks‐biggest‐heists‐blockchain‐history/

Page 42: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

42

Compare to Traditional Banking

• Deposit made, balance updated, but can’t always use funds.

• What is comparison with exchanging cryptocurrency?− No FDIC

Page 43: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

43

Industries to Consider

Banking & Finance Cybersecurity

Supply Chain Management Government

Networking and IoT Insurance

Voting Charity

Health Care Energy Management

Online Music Real Estate

Crowd Funding Forecasting

Page 44: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

44

Resources

• Webpages− CoinDesk.com

− Bitcoin.com 

− Blockchain.info

− Insight.Bitpay.com

− Ethereum.org/

Page 45: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

45https://blockchain.info/tree/155502176

Page 46: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

46https://blockchain.info/tree/155502176

Page 47: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

47

Conclusions

• Blockchain will disrupt many industries, including cybersecurity.

• Potential Applications in Information Security may allow the use of Blockchains to manage digital identities, protect large amounts of data, and secure edge devices.

• Cybersecurity jobs are safe – just be ready to protect the Blockchain.  

Page 48: Blockchain and Applications in Information Security Bahou...Blockchain and Applications in Information Security A.J. Bahou, Esq., LLM, MsECE 615‐850‐8542 AJ.Bahou@wallerlaw.com

48

Questions?

A.J. Bahou, Esq.615‐850‐[email protected]