Blockchain-Based Security Framework for OSI Model Network Interaction in Critical Infrastructure Systems

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1303

Keywords:

cybersecurity, critical infrastructure, OSI model, blockchain, PBFT consensus, smart contracts, intrusion detection systems

Abstract

The article develops and experimentally evaluates a cybersecurity framework for network interaction in critical infrastructure systems by combining cross-layer OSI monitoring, permissioned blockchain, PBFT consensus, smart-contract-based detection and automated response. The relevance of the study is determined by the growing exposure of energy, water supply, transport, telecommunications and other critical infrastructure sectors to multi-stage cyberattacks that affect several layers of network communication and may include traffic manipulation, false command injection, denial-of-service actions and tampering with security logs. Conventional centralized intrusion detection architectures remain vulnerable to the compromise of event repositories and create a single point of failure, which limits the evidentiary value and operational reliability of collected security events. The aim of the article is to propose an integrated architecture in which monitoring agents collect metadata of protocol data units from OSI layers L2-L7, hashes and compressed event features are recorded in an immutable distributed ledger, and smart contracts perform cross-layer correlation and initiate response scenarios. The paper formalizes the threat model, describes the structure of the blockchain registry, introduces an adaptive trust assessment mechanism for event sources, defines an integral anomaly score and presents the operational algorithm of the framework. Experimental evaluation on an emulation testbed demonstrates that the proposed approach achieves a higher F1 score than a signature-based IDS, an RF-IDS and a centralized event-storage variant while preserving acceptable end-to-end detection latency for critical infrastructure monitoring scenarios. The results confirm the feasibility of using permissioned blockchain networks as a trusted layer for logging, verification and response coordination in distributed cyber-physical environments where the integrity and traceability of security evidence are essential.

Downloads

Download data is not yet available.

References

Kim, K., Alshenaifi, I. M., Ramachandran, S., Kim, J., Zia, T., & Almorjan, A. (2023). Cybersecurity and cyber forensics for smart cities: A comprehensive literature review and survey. Sensors, 23(7), 3681. https://doi.org/10.3390/s23073681

National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29

European Union Agency for Cybersecurity. (2025). ENISA threat landscape 2025. ENISA. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025

International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection-Information security management systems-Requirements. ISO. https://www.iso.org/standard/27001

Sharafaldin, I., Habibi Lashkari, A., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018) (pp. 108-116). SciTePress. https://doi.org/10.5220/0006639801080116

Nakamoto, S. (2008). Bitcoin: A peer-to-peer electronic cash system. https://bitcoin.org/bitcoin.pdf

Androulaki, E., Barger, A., Bortnikov, V., et al. (2018). Hyperledger Fabric: A distributed operating system for permissioned blockchains. In Proceedings of the 13th EuroSys Conference (EuroSys 2018) (Article 30, pp. 1-15). ACM. https://doi.org/10.1145/3190508.3190538

Castro, M., & Liskov, B. (2002). Practical Byzantine fault tolerance and proactive recovery. ACM Transactions on Computer Systems, 20(4), 398–461. https://doi.org/10.1145/571637.571640

Wang, W., Mosse, D., Sun, Y., & Zhang, L. (2021). Industrial control malicious traffic anomaly detection system based on improved deep autoencoder. Frontiers in Energy Research, 8, 555145. https://doi.org/10.3389/fenrg.2020.555145

Supeno, B. A., Mohamed Radzi, N. A. B., & Al-Haiqi, A. (2025). Machine learning-based anomaly detection for Modbus and DNP3 protocols in industrial control systems. In 2025 International Conference on Technology and Policy in Energy and Electric Power (ICT-PEP). IEEE. https://doi.org/10.1109/ICT-PEP67281.2025.11232367

Azhar, M., Perveen, S., Iqbal, A., & Lee, B. (2024). IDRandom-Forest: Advanced Random Forest for real-time intrusion detection. IEEE Access, 12, 113842-113854. https://doi.org/10.1109/ACCESS.2024.3443408

Wood, G. (2014). Ethereum: A secure decentralised generalised transaction ledger. Ethereum Yellow Paper. https://ethereum.github.io/yellowpaper/paper.pdf

Rathee, G., Ahmad, F., Jaglan, N., & Konstantinou, C. (2023). A secure and trusted mechanism for Industrial IoT network using blockchain. IEEE Transactions on Industrial Informatics, 19(2), 1894–1902. https://doi.org/10.1109/TII.2022.3182121

Ghadi, Y. Y., et al. (2025). A hybrid AI-blockchain security framework for smart grids. Scientific Reports, 15, 05257. https://doi.org/10.1038/s41598-025-05257-w

Georgiades, M., et al. (2025). An explainable AI approach for interpretable cross-layer intrusion detection. Electronics, 14(16), 3218. https://doi.org/10.3390/electronics14163218

Maosa, H., et al. (2024). A hierarchical security event correlation model for real-time intrusion detection. Cybersecurity, 4(1), 4. https://doi.org/10.3390/cyber4010004

Karlzén, H., & Sommestad, T. (2023). Automatic incident response solutions: A review of proposed solutions’ input and output. In Proceedings of the 18th International Conference on Availability, Reliability and Security (ARES 2023) (Article 37, pp. 1–9). ACM. https://doi.org/10.1145/3600160.3605066

Chu, H., Zhang, P., Dong, H., Xiao, Y., Ji, S., & Li, W. (2023). A survey on smart contract vulnerabilities: Data sources, detection and repair. Information and Software Technology, 159, 107221. https://doi.org/10.1016/j.infsof.2023.107221

MITRE Corporation. (2026). MITRE ATT&CK® knowledge base. https://attack.mitre.org/

Al-Sada, B., Sadighian, A., & Oligeri, G. (2024). MITRE ATT&CK: State of the art and way forward. ACM Computing Surveys, 57(2), Article 39. https://doi.org/10.1145/3687300

Guggenberger, T., Sedlmeir, J., Fridgen, G., & Luckow, A. (2022). An in-depth investigation of the performance characteristics of Hyperledger Fabric. Computers & Industrial Engineering, 173, 108716. https://doi.org/10.1016/j.cie.2022.108716

Liu, W., Zhang, X., Feng, W., Huang, M., & Xu, Y. (2022). Optimization of PBFT algorithm based on QoS-aware trust service evaluation. Sensors, 22(12), 4590. https://doi.org/10.3390/s22124590

Ahakonye, L. A. C., Nwakanma, C. I., & Kim, D.-S. (2024). Tides of blockchain in IoT cybersecurity. Sensors, 24(10), 3111. https://doi.org/10.3390/s24103111

Ortmann, M., et al. (2024). Zero trust architectures for interconnected industry. Fraunhofer Institute for Production Technology IPT. https://doi.org/10.24406/publica-3778

Barreto, N. E. M., et al. (2025). Cyber-physical power system digital twins – A study on resilience, flexibility and cybersecurity. Energies, 18(22), 5960. https://doi.org/10.3390/en18225960

Novikova, E., Doynikova, E., & Golubev, S. (2022). Federated learning for intrusion detection in the critical infrastructures: Vertically partitioned data use case. Algorithms, 15(4), 104. https://doi.org/10.3390/a15040104

Castiglione, A., Esposito, J. G., Loia, V., Nappi, M., Pero, C., & Polsinelli, M. (2025). Integrating post-quantum cryptography and blockchain to secure low-cost IoT devices. IEEE Transactions on Industrial Informatics, 21(2), 1674–1683. https://doi.org/10.1109/TII.2024.3485796

Downloads


Abstract views: 7

Published

2026-09-24

How to Cite

Prokopovych-Tkachenko, D., Khrushkov, B., Babenko, K., Kozachenko, I., & Cherkaskyi, D. (2026). Blockchain-Based Security Framework for OSI Model Network Interaction in Critical Infrastructure Systems. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 480–492. https://doi.org/10.28925/2663-4023.2026.34.1303

Most read articles by the same author(s)