NORMA eResearch @NCI Library

A Blockchain-Integrated Detection System with Hash-Based Validation and AI under Zero Trust Security for APTs

Cherian Roy, Ryan (2025) A Blockchain-Integrated Detection System with Hash-Based Validation and AI under Zero Trust Security for APTs. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (1MB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (713kB) | Preview

Abstract

Intrusion Detection Systems (IDS) play a critical role for enterprises for monitoring and detecting unauthorized entry points or malicious attacks. However, the current IDS systems with signature-based detection engine raise an alarm whenever network traffic matches any signature. This process results in significant challenges when dealing with the modern zero-day attacks and other fileless and insider attack threats. They often bypass conventional detection methods by finding ways to avoid the known pattern of detection and thus exploiting system vulnerabilities in novel ways. So, to address this issue, this paper introduces a Blockchain-Enabled Intrusion Detection System which is designed to enhance detection capabilities through the integration of blockchain-based file integrity verification system and anomaly detection using a Random Forest model within a Zero Trust security framework. This system makes use of blockchain technology to store verified endpoint data in the form of SHA256 hashes on its blocks which is then used to verify the system integrity in comparison to the hashes collected from real-time processes and files from the endpoint agent. If a file hash is absent or altered, it is flagged for further analysis. Subsequently, the flagged program’s behavioral patterns are assessed using machine learning techniques to identify potential advanced threats or any persistent activities by making use of Sysmon operational logs. This dual-layer approach enables real-time detection, tamper-proof logging, and enhanced threat response. The use of blockchain ensures immutable and verifiable integrity records, while the Random Forest model effectively distinguishes between benign and malicious activity. BIDPS’s modular design supports distributed deployment, making it adaptable to varied environments, including SMEs, enterprise networks, and resource-constrained IoT systems.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Mahajan, Kamil
UNSPECIFIED
Uncontrolled Keywords: IDS; Blockchain; Hash Verification; Zero Trust; Anomaly Detection
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
Q Science > QH Natural history > QH301 Biology > Methods of research. Technique. Experimental biology > Data processing. Bioinformatics > Artificial intelligence
Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Artificial intelligence
Q Science > QA Mathematics > Computer software > Computer Security > Database security > Blockchains (Databases)
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security > Database security > Blockchains (Databases)
Z Bibliography. Library Science. Information Resources > ZA Information resources > ZA4050 Electronic information resources > Databases > Distributed databases > Blockchains (Databases)
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 24 Aug 2026 11:29
Last Modified: 24 Aug 2026 11:29
URI: https://norma.ncirl.ie/id/eprint/9596

Actions (login required)

View Item View Item