{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T16:46:43Z","timestamp":1783097203497,"version":"3.54.6"},"reference-count":45,"publisher":"MDPI AG","issue":"18","license":[{"start":{"date-parts":[[2020,9,16]],"date-time":"2020-09-16T00:00:00Z","timestamp":1600214400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Integrated Planning Project of China Academy of Engineering Physics","award":["TCGH1203"],"award-info":[{"award-number":["TCGH1203"]}]},{"name":"Institute of Computer Application, China Academy of Engineering Physics","award":["SJ2019A05, SJ2020A08"],"award-info":[{"award-number":["SJ2019A05, SJ2020A08"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U19A2066);"],"award-info":[{"award-number":["U19A2066);"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Defense Innovation Special Zone Program of Science and Technology","award":["JG2019055"],"award-info":[{"award-number":["JG2019055"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The insider threats have always been one of the most severe challenges to cybersecurity. It can lead to the destruction of the organisation\u2019s internal network system and information leakage, which seriously threaten the confidentiality, integrity and availability of data. To make matters worse, since the attacker has authorized access to the internal network, they can launch the attack from the inside and erase their attack trace, which makes it challenging to track and forensics. A blockchain traceability system for insider threats is proposed in this paper to mitigate the issue. First, this paper constructs an insider threat model of the internal network from a different perspective: insider attack forensics and prevent insider attacker from escaping. Then, we analyze why it is difficult to track attackers and obtain evidence when an insider threat has occurred. After that, the blockchain traceability system is designed in terms of data structure, transaction structure, block structure, consensus algorithm, data storage algorithm, and query algorithm, while using differential privacy to protect user privacy. We deployed this blockchain traceability system and conducted experiments, and the results show that it can achieve the goal of mitigating insider threats.<\/jats:p>","DOI":"10.3390\/s20185297","type":"journal-article","created":{"date-parts":[[2020,9,16]],"date-time":"2020-09-16T10:30:12Z","timestamp":1600252212000},"page":"5297","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["Tracking the Insider Attacker: A Blockchain Traceability System for Insider Threats"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8624-0210","authenticated-orcid":false,"given":"Teng","family":"Hu","sequence":"first","affiliation":[{"name":"Institute for Cyber Security, School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu 611731, China"},{"name":"Institute of Computer Application, China Academy of Engineering Physics, Mianyang 621900, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bangzhou","family":"Xin","sequence":"additional","affiliation":[{"name":"Institute of Computer Application, China Academy of Engineering Physics, Mianyang 621900, China"},{"name":"School of CyberScience, University of Science and Technology of China, Hefei 230027, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8510-4025","authenticated-orcid":false,"given":"Xiaolei","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Computer Application, China Academy of Engineering Physics, Mianyang 621900, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ting","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute for Cyber Security, School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kangyi","family":"Ding","sequence":"additional","affiliation":[{"name":"Institute for Cyber Security, School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaosong","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute for Cyber Security, School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,9,16]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"471","DOI":"10.1109\/JSYST.2016.2558507","article-title":"Detecting insider threats using radish: A system for real-time anomaly detection in heterogeneous data streams","volume":"11","author":"Avasarala","year":"2017","journal-title":"IEEE Syst. J."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3303771","article-title":"Insight into insiders and it: A survey of insider threat taxonomies, analysis, modeling, and countermeasures","volume":"52","author":"Homoliak","year":"2019","journal-title":"ACM Comput. Surv."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Hu, T., Niu, W., Zhang, X., Liu, X., Lu, J., and Liu, Y. (2019). An Insider Threat Detection Approach Based on Mouse Dynamics and Deep Learning. Secur. Commun. Netw., 2019.","DOI":"10.1155\/2019\/3898951"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1109\/MCE.2017.2776459","article-title":"The blockchain as a decentralized security framework [future directions]","volume":"7","author":"Puthal","year":"2018","journal-title":"IEEE Consum. Electron. Mag."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"269","DOI":"10.1007\/s10207-012-0165-6","article-title":"Insider threat mitigation: Preventing unauthorized knowledge acquisition","volume":"11","author":"Yaseen","year":"2012","journal-title":"Int. J. Inf. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Tukur, Y.M., Thakker, D., and Awan, I.U. (2019, January 4\u20137). Ethereum Blockchain-Based Solution to Insider Threats on Perception Layer of IoT Systems. Proceedings of the 2019 IEEE Global Conference on Internet of Things (GCIoT), Abu Dubai, UAE.","DOI":"10.1109\/GCIoT47977.2019.9058395"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Spooner, D., Silowash, G., Costa, D., and Albrethsen, M. (2018, January 24). Navigating the Insider Threat Tool Landscape: Low Cost Technical Solutions to Jump Start an Insider Threat Program. Proceedings of the 2018 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA.","DOI":"10.1109\/SPW.2018.00040"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"75","DOI":"10.1016\/j.ijcip.2008.08.001","article-title":"Game-theoretic modeling and analysis of insider threats","volume":"1","author":"Liu","year":"2008","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1397","DOI":"10.1109\/COMST.2018.2800740","article-title":"Detecting and preventing cyber insider threats: A survey","volume":"20","author":"Liu","year":"2018","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1109\/TIFS.2009.2039591","article-title":"Insiders behaving badly: Addressing bad actors and their actions","volume":"5","author":"Pfleeger","year":"2009","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Mylrea, M., Gourisetti, S.N.G., Larimer, C., and Noonan, C. (2018, January 24). Insider threat cybersecurity framework webtool & methodology: Defending against complex cyber-physical threats. Proceedings of the 2018 IEEE Security and PrivacyWorkshops (SPW), San Francisco, CA, USA.","DOI":"10.1109\/SPW.2018.00036"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Mavroeidis, V., Vishi, K., and J\u00f8sang, A. (2018, January 28\u201331). A framework for data-driven physical security and insider threat detection. Proceedings of the 2018 IEEE\/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM), Barcelona, Spain.","DOI":"10.1109\/ASONAM.2018.8508599"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Park, W., You, Y., and Lee, K. (2018). Detecting potential insider threat: Analyzing insiders\u2019 sentiment exposed in social media. Secur. Commun. Netw., 2018.","DOI":"10.1155\/2018\/7243296"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Bin Ahmad, M., Akram, A., Asif, M., and Ur-Rehman, S. (2014). Using genetic algorithm to minimize false alarms in insider threats detection of information misuse in windows environment. Math. Probl. Eng., 2014.","DOI":"10.1155\/2014\/179109"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Lo, O., Buchanan, W.J., Griffiths, P., and Macfarlane, R. (2018). Distance measurement methods for improved insider threat detection. Secur. Commun. Netw., 2018.","DOI":"10.1155\/2018\/5906368"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Meng, W., Li, W., and Zhu, L. (2019). Enhancing medical smartphone networks via blockchain-based trust management against insider attacks. IEEE Trans. Eng. Manag.","DOI":"10.1109\/TEM.2019.2921736"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"14757","DOI":"10.1109\/ACCESS.2017.2730843","article-title":"MeDShare: Trust-less medical data sharing among cloud service providers via blockchain","volume":"5","author":"Xia","year":"2017","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Liu, J., Li, X., Ye, L., Zhang, H., Du, X., and Guizani, M. (2018, January 9\u201313). BPDS: A blockchain based privacy-preserving data sharing for electronic medical records. Proceedings of the 2018 IEEE Global Communications Conference (GLOBECOM), Abu Dhabi, UAE.","DOI":"10.1109\/GLOCOM.2018.8647713"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Ferdous, M.S., Margheri, A., Paci, F., Yang, M., and Sassone, V. (2017, January 5\u20138). Decentralised runtime monitoring for access control systems in cloud federations. Proceedings of the 2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), Atlanta, GA, USA.","DOI":"10.1109\/ICDCS.2017.178"},{"key":"ref_20","unstructured":"Hassan, M.U., Rehmani, M.H., and Chen, J. (2019). Differential Privacy in Blockhain Technology: A Futuristic Approach. arXiv."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"512","DOI":"10.1016\/j.future.2019.02.060","article-title":"Privacy preservation in blockchain based IoT systems: Integration issues, prospects, challenges, and future research directions","volume":"97","author":"Hassan","year":"2019","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"536","DOI":"10.1126\/science.1256297","article-title":"Unique in the shopping mall: On the reidentifiability of credit card metadata","volume":"347","author":"Radaelli","year":"2015","journal-title":"Science"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Hassan, M.U., Rehmani, M.H., and Chen, J. (2019). Differential privacy techniques for cyber physical systems: A survey. IEEE Commun. Surv. Tutor.","DOI":"10.1109\/COMST.2019.2944748"},{"key":"ref_24","unstructured":"Dwork, C. (2006, January 10\u201314). Automata, Languages and Programming. Proceedings of the International Colloquium on Automata, Languages, and Programming, Venice, Italy."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"557","DOI":"10.1142\/S0218488502001648","article-title":"k-anonymity: A model for protecting privacy","volume":"10","author":"Sweeney","year":"2002","journal-title":"Int. J. Uncertain. Fuzziness Knowl. Based Syst."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"3-es","DOI":"10.1145\/1217299.1217302","article-title":"l-diversity: Privacy beyond k-anonymity","volume":"1","author":"Machanavajjhala","year":"2007","journal-title":"ACM Trans. Knowl. Discov. Data (TKDD)"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Li, N., Li, T., and Venkatasubramanian, S. (2007, January 15\u201320). t-closeness: Privacy beyond k-anonymity and l-diversity. Proceedings of the 2007 IEEE 23rd International Conference on Data Engineering, Istanbul, Turkey.","DOI":"10.1109\/ICDE.2007.367856"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Dwork, C. (2008). Differential privacy: A survey of results. International Conference on Theory and Applications of Models Of Computation, Springer.","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"793","DOI":"10.1137\/090756090","article-title":"What can we learn privately?","volume":"40","author":"Kasiviswanathan","year":"2011","journal-title":"SIAM J. Comput."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Nurse, J.R., Buckley, O., Legg, P.A., Goldsmith, M., Creese, S., Wright, G.R., and Whitty, M. (2014, January 17\u201318). Understanding insider threat: A framework for characterising attacks. Proceedings of the 2014 IEEE Security and Privacy Workshops, San Jose, CA, USA.","DOI":"10.1109\/SPW.2014.38"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Maasberg, M., Warren, J., and Beebe, N.L. (2015, January 5\u20138). The dark side of the insider: Detecting the insider threat through examination of dark triad personality traits. Proceedings of the 2015 48th Hawaii International Conference on System Sciences, Kauai, HI, USA.","DOI":"10.1109\/HICSS.2015.423"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Moore, A.P., Cappelli, D.M., and Trzeciak, R.F. (2008). The \u201cbig picture\u201d of insider IT sabotage across US critical infrastructures. Insider Attack and Cyber Security, Springer.","DOI":"10.21236\/ADA482452"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Moore, A.P., Cappelli, D.M., Caron, T.C., Shaw, E., Spooner, D., and Trzeciak, R.F. (2011). A Preliminary Model of Insider Theft of Intellectual Property, Carnegie-Mellon Univ Pittsburgh Pa Software Engineering Inst.. Technical Report.","DOI":"10.21236\/ADA589594"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Chen, T., Kamm\u00fcller, F., Nemli, I., and Probst, C.W. (2015). A probabilistic analysis framework for malicious insider threats. International Conference on Human Aspects of Information Security, Privacy, and Trust, Springer.","DOI":"10.1007\/978-3-319-20376-8_16"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Kamm\u00fcller, F., Nurse, J.R., and Probst, C.W. (2016). Attack tree analysis for insider threats on the IoT using Isabelle. International Conference on Human Aspects of Information Security, Privacy, and Trust, Springer.","DOI":"10.1007\/978-3-319-39381-0_21"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Axelrad, E.T., Sticha, P.J., Brdiczka, O., and Shen, J. (2013, January 23\u201324). A Bayesian network model for predicting insider threats. Proceedings of the 2013 IEEE Security and Privacy Workshops, San Francisco, CA, USA.","DOI":"10.1109\/SPW.2013.35"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"597","DOI":"10.1109\/TSMCB.2009.2033564","article-title":"Maintaining defender\u2019s reputation in anomaly detection against insider attacks","volume":"40","author":"Zhang","year":"2009","journal-title":"IEEE Trans. Syst. Man Cybern. Part B"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"859","DOI":"10.1016\/j.cose.2010.06.002","article-title":"A game-based intrusion detection mechanism to confront internal attackers","volume":"29","author":"Kantzavelou","year":"2010","journal-title":"Comput. Secur."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Chagarlamudi, M., Panda, B., and Hu, Y. (2009, January 27\u201329). Insider threat in database systems: Preventing malicious users\u2019 activities in databases. Proceedings of the 2009 Sixth International Conference on Information Technology: New Generations, Las Vegas, NV, USA.","DOI":"10.1109\/ITNG.2009.67"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Kandias, M., Mylonas, A., Virvilis, N., Theoharidou, M., and Gritzalis, D. (2010). An insider threat prediction model. International Conference on Trust, Privacy and Security in Digital Business, Springer.","DOI":"10.1007\/978-3-642-15152-1_3"},{"key":"ref_41","unstructured":"Liu, Y., Corbett, C., Chiang, K., Archibald, R., Mukherjee, B., and Ghosal, D. (2009, January 5\u20138). SIDD: A framework for detecting sensitive data exfiltration by an insider attack. Proceedings of the 2009 42nd Hawaii international conference on system sciences, Big Island, HI, USA."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Salem, M.B., and Stolfo, S.J. (2011). Modeling user search behavior for masquerade detection. International Workshop on Recent Advances in Intrusion Detection, Springer.","DOI":"10.1007\/978-3-642-23644-0_10"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1504\/IJSN.2008.017224","article-title":"Using PLSI-U to detect insider threats by datamining e-mail","volume":"3","author":"Okolica","year":"2008","journal-title":"Int. J. Secur. Netw."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Yu, L., Liu, L., Pu, C., Gursoy, M.E., and Truex, S. (2019, January 19\u201323). Differentially private model publishing for deep learning. Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00019"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1561\/0400000042","article-title":"The algorithmic foundations of differential privacy","volume":"9","author":"Dwork","year":"2014","journal-title":"Found. Trends Theor. Comput. Sci."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/18\/5297\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T10:10:31Z","timestamp":1760177431000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/18\/5297"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,9,16]]},"references-count":45,"journal-issue":{"issue":"18","published-online":{"date-parts":[[2020,9]]}},"alternative-id":["s20185297"],"URL":"https:\/\/doi.org\/10.3390\/s20185297","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,9,16]]}}}