PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 20, 2026Big Data and Cognitive Computing0 citationsOpen Access

A Hybrid PoS–PoW Blockchain Framework for Secure Cyber Threat Intelligence Sharing: Design, Implementation, and Evaluation

View Full Paper
AEAhmed El-KosairyHAHeba K. Aslan

Key Points

  • This research aims to develop and evaluate a hybrid blockchain framework for secure cyber threat intelligence sharing.
  • Designed a proof-of-concept hybrid Proof-of-Stake and Proof-of-Work framework (CTIB) for CTI publication.
  • Evaluated prototype in a controlled Hardhat environment measuring throughput, latency, and success rates.
  • Conducted security analysis using analytical modeling, committee capture probability, and Monte Carlo simulations.
  • CTIB achieved an average throughput of 141.13 to 166.14 feeds/min across ten runs.
  • Measured p50 latency ranged from 326.18 to 403.09 ms, and p95 latency from 553.22 to 700.82 ms under various PoW difficulty levels.
  • Security analysis showed that compromising both validation and anchoring layers of the system increases the cost of manipulation.

Abstract

Many blockchain-based cyber threat intelligence (CTI) sharing systems emphasize immutability and auditability, but often treat CTI submissions as ordinary blockchain transactions without explicitly separating content validation from publication anchoring. This paper presents CTIB, a proof-of-concept hybrid Proof-of-Stake (PoS) and Proof-of-Work (PoW) framework for CTI publication. CTIB uses a sequential workflow in which a PoS committee first evaluates CTI submissions, and an accepted feed hash is then anchored through a PoW step to provide verifiable temporal binding. The prototype is evaluated in a controlled local Hardhat environment; therefore, the results should be interpreted as prototype-level feasibility evidence rather than production-scale deployment results. CTI content is represented using STIX 2.1, canonicalized, and hashed using SHA-256; only integrity-critical evidence is stored on-chain, while full CTI content remains off-chain. Experimental results demonstrate prototype-level feasibility, with measured throughput, latency, and success rate metrics under different PoW difficulty profiles. Across ten independent local runs, CTIB achieved an average throughput between 141.13 and 166.14 feeds/min, average p50 latency between 326.18 and 403.09 ms, and average p95 latency between 553.22 and 700.82 ms under the tested difficulty profiles. Security analysis uses analytical modeling, committee capture probability, and Monte Carlo simulation to evaluate majority-attack feasibility under stated assumptions. The results indicate that sequential compromise of both validation and anchoring layers increases the cost of coordinated manipulation.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

El-Kosairy et al. (2026) studied this question.

synapsesocial.com/papers/6a0d4f62f03e14405aa9ab86https://doi.org/10.3390/bdcc10050158
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 3 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Statistical detection of selfish mining in proof-of-work blockchain systems2024 · 24 citations
  2. 2BlockIntelChain: a blockchain-based cyber threat intelligence sharing architecture2025 · 3 citations
  3. 3Mining temporal attack patterns from cyberthreat intelligence reports2025 · 8 citations