Decentralized Vulnerability Disclosure Using Permissioned Blockchain: A Secure and Transparent Alternative to Centralized CVE Management

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This study introduces a decentralized, blockchaindriven framework for publishing Common Vulnerabilities and Exposures (CVEs) as an alternative to the predominantly centralized model managed by MITRE. The proposed solution employs a permissioned blockchain that restricts write privileges to authenticated CVE Numbering Authorities (CNAs) while maintaining public transparency. Through the integration of smart contracts, the framework enables essential functions such as embargoed vulnerability disclosures and decentralized governance. We assess the proposed approach against current practices, demonstrating its improvements in transparency, trust distribution, and auditability. Furthermore, we present a prototype built on Hyperledger Fabric to validate the feasibility of the model and discuss its potential impact on the evolution of vulnerability disclosure mechanisms.

Original languageEnglish
Title of host publication2025 18th International Conference on Information Security and Cryptology, ISCTurkiye 2025 - Proceedings
EditorsAli Aydin Selcuk, Seref Sagiroglu, Oguz Yayla, Cihangir Tezcan
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798331557102
DOIs
Publication statusPublished - 2025
Event18th International Conference on Information Security and Cryptology, ISCTurkiye 2025 - Ankara, Turkey
Duration: 22 Oct 202523 Oct 2025

Publication series

Name2025 18th International Conference on Information Security and Cryptology, ISCTurkiye 2025 - Proceedings

Conference

Conference18th International Conference on Information Security and Cryptology, ISCTurkiye 2025
Country/TerritoryTurkey
CityAnkara
Period22/10/2523/10/25

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

Keywords

  • Common Vulnerabilities and Exposures (CVE)
  • Decentralized Vulnerability Disclosure
  • Hyperledger Fabric
  • Permissioned Blockchain
  • Smart Contracts
  • Trust Distribution

Fingerprint

Dive into the research topics of 'Decentralized Vulnerability Disclosure Using Permissioned Blockchain: A Secure and Transparent Alternative to Centralized CVE Management'. Together they form a unique fingerprint.

Cite this