logo SBA

ETD

Digital archive of theses discussed at the University of Pisa

 

Thesis etd-06132025-212728


Thesis type
Tesi di laurea magistrale
Author
BRACCINI, GIOVANNI
URN
etd-06132025-212728
Thesis title
Using BlockChains to Generate and Distribute Deny Lists
Department
INFORMATICA
Course of study
INFORMATICA
Supervisors
relatore Prof. Baiardi, Fabrizio
Keywords
  • blacklist automation
  • blockchain
  • botnet detection
  • decentralized security
  • denylist
  • distributed c2
  • honeypots
  • intrusion prevention
  • kex hashes
  • kex-filtering
  • orb botnets
  • proactive defense
  • secure blacklist distribution
  • ssh fingerprinting
  • threat intelligence
  • trust model
Graduation session start date
18/07/2025
Availability
Withheld
Release date
18/07/2028
Summary
Kex-Filtering proactively detects SSH botnets by fingerprinting client configurations via KEX hashes, overcoming IP blacklist limits. Tested on Azure/AWS honeypots, it blocked 98.5% of attacks using tens of hashes (<2% false positives). Blacklists are dynamically updated via distributed C2 servers using trust, expiration, and thresholds. Multiple blockchain-based architectures are proposed to ensure secure, tamper-proof, and decentralized blacklist distribution. Analyses are conducted on the implementation feasibility of the method, and performance metrics are explored.
File