<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Mubashar Iqbal[</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>A Reference Model for Security Risk Management of the Blockchain-based Applications</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Security Risk Management</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Institute of Computer Science, University of Tartu</institution>
          ,
          <addr-line>Tartu</addr-line>
          ,
          <country country="EE">Estonia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>0000</year>
      </pub-date>
      <volume>0003</volume>
      <abstract>
        <p>In order to realise the true potential of blockchain-based applications, the rst step is to understand the associated risks and vulnerabilities. Blockchain-based applications are considered to be less vulnerable but there are certain security risks (e.g., Sybil and Doublespending, etc) within the blockchain-based applications that are debatable. There exists no comprehensive blockchain-based security reference model to systematically evaluate the security of blockchain-based applications. In this study, we illustrate the PhD thesis research work to build an ontology-based reference model for security risk management of blockchain-based applications. A reference model would establish a common ground and systematic understanding for professionals and researchers regarding the security of the blockchain-based application.</p>
      </abstract>
      <kwd-group>
        <kwd>Blockchain</kwd>
        <kwd>Security Risks</kwd>
        <kwd>Blockchain-based Security Reference Model</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        A rst cryptocurrency bitcoin introduced a concept of blockchain technology.
Blockchain is a distributed immutable ledger technology [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] and over the past
few years, blockchain technology is emerging in various elds and so
blockchainbased applications. The security of blockchain-based applications is an important
aspect of its acceptability. However, the involvement of the monetary assets
raises security concerns, mainly when the attackers stole the monetary assets
or damages the system. For example, the reentrancy attack on the Ethereum
based decentralised autonomous organization (DAO) smart contracts when an
adversary gained control of over $60 million Ethers [
        <xref ref-type="bibr" rid="ref12 ref2">2, 12</xref>
        ].
      </p>
      <p>
        In order to realise the true potential of blockchain-based applications, the
rst step is to understand the associated risks and vulnerabilities. These risks
and vulnerabilities could be exploited by an attacker and a ect valuable assets
and services. Mostly, the security issues arise by the wrong security decisions,
incomplete knowledge, or misunderstanding the security needs of the software.
In [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], the security risks that appear (e.g., Sybil and Double-spending, etc) within
Copyright © 2020 for this paper by its authors. Use permitted under
Creative Commons License Attribution 4.0 International (CC BY 4.0).
the blockchain-based applications are debatable. However, there exists no
comprehensive (or standardised) blockchain-based security reference model to
systematically evaluate the security of blockchain-based applications. There exist
few studies reporting on security challenges in the blockchain platforms [
        <xref ref-type="bibr" rid="ref17 ref6">6, 17</xref>
        ],
but do not focus on the security of the blockchain-based applications.
      </p>
      <p>The main research objective is formulated as follows: How to assist the
development of a reference model for security risk management of blockchain-based
applications? The blockchain-based security reference model would help to
overcome the problems that are discussed above by enabling the systematic
evaluation, understanding the main components and their relationships within the
blockchain-based applications. A reference model would establish a common
ground and systematic understanding for professionals and researchers
regarding the security of the blockchain-based applications. It would also communicate
security requirements to technical experts more e ectively and e ciently.</p>
      <p>Hence, the blockchain-based security reference model is required for security
risk management of blockchain-based applications to identify security risks and
their impacts timely. Ultimately, the reference model would lead to reducing the
possible security risks to the blockchain-based applications.</p>
      <p>This paper introduces the research work for the PhD thesis. The paper is
structured as follows: Section 2 describes the research questions and foreseen
outcome. Section 3 presents the research method. Section 4 discusses the
preliminary results. Sections 5 presents the work in progress. Section 6 presents the
background and related Work. Section 7 discusses the concluding remarks.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Research Questions and Foreseen Outcome</title>
      <p>The aim of this research is to build a blockchain-based security reference model
as a blockchain-based security risk management tool to systematically evaluate
the security needs of blockchain-based applications. In order to achieve the aim,
this research establishes the four main research questions. The research questions
represent the step-by-step approach to reach the desired outcome. The research
questions are:
[RQ1]: What is the state-of-the-art in the security of the
blockchainbased applications?
In the RQ1, our research objectives were two-fold. First, we identify a list of
security risks that are mitigated by the blockchain-based application. Second,
the security risks that appear within the blockchain-based application after
incorporating the blockchain technology.
[RQ2]: What are the means to analyse the security risks within the
blockchain-based applications?
In the RQ2, we performed an analysis of security risks that are mitigated and
appear within the blockchain-based applications to build conceptual models. Also,
what assets to secure from the security risks, the potential vulnerabilities of
security risks and countermeasures to mitigate the vulnerabilities.
[RQ3]: How to transform the conceptual models to a reference model
for security risks management of the blockchain-based applications?
In the RQ3, we identify the common components (e.g., concepts alignment)
of blockchain-based applications from the conceptual models (knowledge from
RQ2) and feasible modelling language to build the reference model.
[RQ4]: How could the reference model be validated?
In the RQ4, we validate the reference model to answer "Will the use of a
reference model improve the security of the blockchain-based application?"
The outcome of this research is an ontology-based reference model for security risk
management of the blockchain-based applications. This reference model would
evaluate the security needs of blockchain-based applications and help to explore
the protected assets, security risks, and potential countermeasures. The reference
model would not be dependent on the speci c blockchain type or blockchain
platform. It would be generic enough to perform a security risk management of
di erent blockchain platforms-based applications.
3</p>
    </sec>
    <sec id="sec-3">
      <title>Research Method</title>
      <p>
        This research work follows four distinct research method approaches (Fig. 1),
where each research approach represent the one research question respectively.
State-of-the-Art Technique: We follow the state-of-the-art technique to
answer RQ1. In this stage, we conducted a systematic literature review (SLR) [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] to
identify and understand the security risks related to the blockchain-based
applications. The SLR approach led us to explore the security eld of blockchain-based
applications from two di erent perspectives. Firstly, we explain what security
risks of the centralised applications are mitigated by introducing the
blockchainbased applications. Secondly, we report the security risks of the blockchain-based
applications which appear after introducing the blockchain technology.
Analytic Methodology: In the second stage, we analyse [
        <xref ref-type="bibr" rid="ref10 ref8 ref9">8, 10, 9</xref>
        ] the results
of the SLR and built conceptual models of Ethereum and Hyperledger Fabric
platforms-based applications. The analysis follows the security risk management
(SRM) domain model [
        <xref ref-type="bibr" rid="ref13 ref3">3, 13</xref>
        ]. The analysis helps to identify the assets to
secure, vulnerabilities, and how the vulnerabilities a ect di erent assets within
the blockchain-based applications. The analysis results show the
countermeasures to mitigate the identi ed vulnerabilities.
      </p>
      <p>Proposal of Solution: The proposal of solution brings the concept of building
the blockchain-based security reference model by using the ontology, and
knowledge reasoning (from stage 1 &amp; 2). The conceptual models that are built in a
stage 2 transform into a blockchain-based security reference model by identifying
the common components and their relationships.
Proof of Concept: In the nal stage, the validation of the reference model will
be performed. The validation stage includes three di erent phases: In the rst
phase, we automate the reference model to analyse the security of a
blockchainbased application by a prede ned set of rules in a controlled environment. In
the second phase, we develop a blockchain-based application by implementing
the newly built reference model analysis. In the third phase, we evaluate the
e ectiveness of the reference model. The e ectiveness will be measured by
using the requirements engineering techniques(e.g., meetings, questionnaires, and
interviews). The experts will be approached who develop the blockchain-based
application using the reference model.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Preliminary Results</title>
      <p>
        The rst year of the PhD focuses on the state-of-the-art of security risks on
the blockchain-based applications. Firstly, we perform the SLR [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] by
following the SLR settings [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] and identify 68 research papers that were further
analysed. The main contributions of this study are: 1) a list of security risks
in the blockchain-based applications which are mitigated by incorporating the
blockchain technology (see Table 1), 2) a list of security risks in the
blockchainbased applications which are appeared within blockchain-based applications by
incorporating the blockchain technology (see Table 1), 3) aggregate a list of
possible countermeasures, and 4) an overview of the prominent research domains
(see Table 1) which are nourishing by the blockchain. The results of this study
could be seen as a preliminary checklist of security risks when implementing
blockchain-based applications.
      </p>
      <p>
        Next, the results of SLR are analysed by the SRM domain model in two
di erent phases. Firstly, the analysis represents the discussion on a comparison
of blockchain-based applications (e.g., Ethereum- and Hyperledger Fabric-based
applications) [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] to identify how blockchain-based applications mitigate data
tampering risks. Secondly, we conducted a similar study to analyse Sybil and
Double-spending risks [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] that appeared within blockchain-based applications
after introducing the blockchain technology. The main contributions of both
studies are as follows: 1) assets to be secured from the security risks 2)
conceptual model of security risks for Ethereum-based applications 3) conceptual
model of countermeasures for Ethereum-based applications 4) conceptual model
of security risks for Hyperledger Fabric-based applications 5) conceptual model
of countermeasures for Hyperledger Fabric-based applications 6) the comparison
of countermeasures. The models were constructed by an ArchiMate1 modelling
language. The ArchiMate o ers a uniform structure to model di erent
components of software applications [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. The architectures modelling support us in the
analysis of blockchain-based applications. The visual representation leads to a
clear understanding and categorisation of the assets in di erent layers.
      </p>
      <p>
        In order to validate the e ectiveness of conceptual models and results so far
(the above mentioned preliminary results), we analysed the case of "capital
markets post-trade matching and con rmation" [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. The study has been performed
by using the blockchain-based Corda platform. The reason to use Corda was
to investigate the di erent emerging blockchain platforms to understand what
are the similarities, di erences, and approach as compared to Ethereum and
Hyperledger Fabric to build blockchain-based applications.
5
      </p>
    </sec>
    <sec id="sec-5">
      <title>Work in Progress</title>
      <p>Currently, we are working on transforming the conceptual models to build an
ontology-based reference model for security risk management of the
blockchainbased applications. The work is in an initial phase where we are organising
the components of the model and the processes. Figure 2 presents the abstract
representation of the reference model. The reference model would include three
main components: 1) de ne the settings 2) analysis based on the de ned settings
and risks assessment 3) guidelines of security risks and countermeasures. The
analysis and risk assessment component include a repository of security risks
and countermeasures.</p>
    </sec>
    <sec id="sec-6">
      <title>Background and Related Work</title>
      <p>
        There already exist software security risk management frameworks (e.g., NIST
cybersecurity framework [
        <xref ref-type="bibr" rid="ref14 ref4">4, 14</xref>
        ], ISO 27001 International information security
1 https://www.archimatetool.com/
standard [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], etc.) to assess and improve their ability to prevent, detect, and
respond to cyberattacks. The study [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] discusses to customise the NIST framework
when developing the cybersecurity programs for the permissioned blockchain
networks. The report states, "the NIST framework as it is not a one-size- ts-all
approach to managing cybersecurity risk because organizations will continue to
have unique risks, di erent threats, di erent vulnerabilities, di erent risk
tolerances, and how they implement the practices in the framework will vary". In
addition to this, there are di erent blockchain platforms and their settings that
also play an important role in the security of the blockchain-based applications.
      </p>
      <p>
        Similarly, the OWASP is planning to build the blockchain security framework
[
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. The project is aiming to create a comprehensive framework that would cover
blockchain security from the ideation stage to the production stage. According
to the OWASP project, "it would help to de ne security requirements, selecting
programming language, consensus protocols, functional security review, security
testing requirements, audit and logging requirements, forensic readiness". The
OWASP project is relevant to this PhD thesis research but currently, it is in a
very initial phase as compared to our progress on this topic.
      </p>
      <p>
        Our aim is to build a blockchain-speci c security reference model for
evaluating the security of blockchain-based applications. One relevant research [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]
that presents the stacked hierarchy of various threats and threat-risk
assessment using ISO/IEC 15408. In [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], the authors discussed the security and
privacy of blockchain by following the survey approach. The research discussed
the blockchain security and privacy properties by presenting the architecture of
blockchain systems. Similar to a previous study [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], this study also explains the
security of blockchain systems. The study illustrates the consensus algorithms,
hash chained storage, mixing protocols, anonymous signatures, non-interactive
zero-knowledge proof to gain an in-depth understanding of the security and
privacy of blockchain systems. Both research studies focus on a security reference
architecture for blockchain systems (frameworks) that is di erent from our
research focus. For example, we are focusing on the security of the blockchain-based
applications, not the blockchain systems.
7
      </p>
    </sec>
    <sec id="sec-7">
      <title>Concluding Remarks</title>
      <p>In this paper, we discussed the PhD thesis research work to build an
ontologybased reference model for security risk management of the blockchain-based
applications. We have completed the rst two research questions (RQ1 &amp; RQ2)
and currently, working on a RQ3 that relates to building the reference model. A
reference model would systematically evaluate the security of blockchain-based
applications. The reference model would establish a common ground and
systematic understanding for professionals and researchers regarding the security of
the blockchain-based applications. The reference model will be validated by the
proof of concept (Section 3) that includes automating the reference model and
implementing it to build a real-time blockchain-based application. In order to
evaluate the e ectiveness of the reference model, the experts will be approached
to participate in the validation process.</p>
    </sec>
    <sec id="sec-8">
      <title>Acknowledgement</title>
      <p>This PhD thesis is supervised by Prof. Raimundas Matulevicius at the Institute
of Computer Science, University of Tartu, Estonia.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Aldea</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Franken</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Iacob</surname>
            ,
            <given-names>M.E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Quartel</surname>
            ,
            <given-names>D.:</given-names>
          </string-name>
          <article-title>Strategy on a Page : An ArchiMate - based tool for visualizing and designing strategy (</article-title>
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Atzei</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bartoletti</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cimoli</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>A survey of attacks on Ethereum smart contracts (SoK) (</article-title>
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Dubois</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mayer</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Heymans</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Matulevicius</surname>
          </string-name>
          , R.:
          <source>Intentional perspectives on information systems engineering</source>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>English</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kim</surname>
            ,
            <given-names>A.D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nonaka</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Advancing Blockchain Cybersecurity : Technical and Policy Considerations for the Financial Services Industry</article-title>
          . In:
          <article-title>Cybersecurity policy and resilience (</article-title>
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Governance</surname>
            ,
            <given-names>I.: ISO</given-names>
          </string-name>
          27001 Risk Assessments https://bit.ly/3aaAbW1
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Homoliak</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Venugopalan</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hum</surname>
            ,
            <given-names>Q.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Szalachowski</surname>
            ,
            <given-names>P.:</given-names>
          </string-name>
          <article-title>A security reference architecture for blockchains</article-title>
          .
          <source>In: 2019 2nd IEEE International Conference on Blockchain, Blockchain</source>
          <year>2019</year>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Iqbal</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Matulevicius</surname>
          </string-name>
          , R.:
          <article-title>Blockchain-Based Application Security Risks: A Systematic Literature Review</article-title>
          . In: CAiSE 2019 Workshop
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Iqbal</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Matulevicius</surname>
          </string-name>
          , R.:
          <article-title>Comparison of Blockchain-Based Solutions to Mitigate Data Tampering Security Risk</article-title>
          . In: BPM 2019 Blockchain Forum
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Iqbal</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Matulevicius</surname>
          </string-name>
          , R.:
          <article-title>Exploring Sybil and Double-spending Risks in the Blockchain-based Applications</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Iqbal</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Matulevicius</surname>
          </string-name>
          , R.:
          <article-title>Managing Security Risks in Post-Trade Matching and Con rmation using CorDapp</article-title>
          .
          <source>In: 14th International Baltic Conference on Databases and Information Systems</source>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Kitchenham</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Charters</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Guidelines for performing Systematic Literature reviews in Software Engineering Version 2.3</article-title>
          . In: Engineering
          <volume>45</volume>
          (
          <year>4ve</year>
          ) (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cao</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Roscoe</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>ReGuard: Finding reentrancy bugs in smart contracts</article-title>
          .
          <source>In: International Conference on Software Engineering</source>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Matulevicius</surname>
          </string-name>
          , R.:
          <source>Fundamentals of Secure System Modelling</source>
          . Springer International Publishing,
          <volume>1</volume>
          <fpage>edn</fpage>
          . (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14. NIST: Cybersecurity Framework:
          <article-title>Helping organizations to better understand and improve their management of cybersecurity risk</article-title>
          , https://bit.ly/2XHm9Zh
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Pahl</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          : OWASP Blockchain Security Framework, https://bit.ly/2VwZGM2
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Sato</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Himura</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          :
          <article-title>Smart-Contract Based System Operations for Permissioned Blockchain</article-title>
          .
          <source>In: 9th IFIP International Conference on New Technologies, Mobility and Security</source>
          ,
          <string-name>
            <surname>NTMS</surname>
          </string-name>
          <year>2018</year>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Zhang</surname>
          </string-name>
          , R.,
          <string-name>
            <surname>Xue</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , Liu,
          <string-name>
            <surname>L.</surname>
          </string-name>
          :
          <article-title>Security and privacy on blockchain</article-title>
          .
          <source>ACM Computing Surveys</source>
          <volume>52</volume>
          (
          <issue>3</issue>
          ) (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>