信息通信技术与政策

信息通信技术与政策

信息通信技术与政策 ›› 2019, Vol. 45 ›› Issue (2): 45-51.

上一篇    下一篇

区块链安全分析及针对强制挖矿的安全防护建议*

Blockchain security analysis and security protection suggestions for cryptojacking

  

  • 出版日期:2019-02-15 发布日期:2020-12-04
  • 作者简介:
    程叶霞:中国科学院大学网络空间安全学院博士研究生
    付俊:中国移动通信研究院安全技术研究所副主任研究员
    彭晋:中国移动通信研究院安全技术研究所所长
    杜跃进:阿里巴巴集团安全部副总裁

  • Online:2019-02-15 Published:2020-12-04

摘要: 目前,世界各国高度重视区块链技术并积极开展研究与应用。随着大量区块链技术漏洞的披露,区块链安全引发业界高度关注。本文对区块链安全进行了分析,提出区块链安全问题主要包括区块链技术本身的漏洞以及恶意占用现网的算力进行挖矿的强制挖矿问题;并针对强制挖矿详细介绍与分析了其概念及攻击形势、攻击技术手段及流程、检测方法、攻击案例、安全防护建议等;最后,从企业层面提出了区块链应用及安全建议。

关键词: 区块链, 强制挖矿, 区块链安全, 安全防护

Abstract: At present, many countries around the world attach great importance to blockchain technology and carry out research and application of blockchain actively. With the disclosure of a large number of blockchain vulnerabilities, blockchain security has caused great concern in the industry. The paper carries out the security analysis of blockchain, the security problem of which mainly focuses on blockchain vulnerabilities and the cryptojacking problem using current network maliciously. Besides, concerning to the cryptojacking, the paper introduces and analyzes its concept and attack situation, attack technology and process, detection methods, attack cases and security protection suggestions, etc. Finally, the blockchain application and security recommendations are proposed from the enterprise level.

Key words: blockchain, cryptojacking, blockchain security, security protection