Uppsats
Byzantine Fault-Tolerant SIEM : A Two-Tier Consensus Architecture for Distributed Security Monitoring
Yrkesexamen på avancerad nivå
Blekinge Tekniska Högskola/Institutionen för datavetenskap
Publicerad: 2026
Språk: Engelska
Sammanfattning
Security Information and Event Management systems are a cornerstone of modern security monitoring, yet their centralized architecture introduces a fundamental vulnerability: a single node whose compromise silences the system designed to detect it. This thesis investigates whether Byzantine fault-tolerant consensus can be integrated into a SIEM pipeline to address this vulnerability, and at what performance cost. A prototype system is designed and implemented following the Design Science Research methodology. The architecture distributes the SIEM analytical pipeline --- scoring, correlation, hypothesis generation, and judgment --- across four Byzantine fault-tolerant subgroups coordinated by a committee tier, forming a two-tier PBFT-based architecture. A hybrid consensus mechanism decouples computation from coordination: every node independently computes the correct result before the leader's proposal arrives, providing a natural Byzantine check on the leader without additional verification rounds. A dual Quorum Certificate mechanism is designed to provide accountability for both subgroup and committee consensus rounds, enabling cryptographic attribution of Byzantine behavior provided nodes vote. The system is evaluated against a centralized baseline using synthetic alert data across 124 nodes. The consensus layer introduces a mean end-to-end latency of 9.95 ms compared to 0.706 ms for the centralized baseline. The two-tier architecture reduces message complexity by approximately 33x relative to a flat PBFT deployment at equivalent scale. An optimized two-path view change mechanism achieves O(n) message complexity in the common case, with a measured mean of 1.28 ms at 31 nodes per subgroup. Byzantine fault injection confirms that the consensus layer converges correctly under adversarial voting conditions within the theoretical fault bound. The results demonstrate that Byzantine fault-tolerant consensus can be integrated into a SIEM pipeline at an operationally negligible absolute cost. The 9.95 ms overhead is negligible for any security monitoring use case where detection timescales are measured in seconds or minutes, and the relative overhead decreases toward 1x as analytical complexity increases. The trade-off is operationally acceptable in any environment where node compromise is a realistic threat and availability under node failure is a requirement --- conditions that characterize the IoT, industrial control, and distributed infrastructure deployments for which this architecture is most relevant.
Information
- Författare
- Wigren, Kevin
- Lärosäte / institution
- Blekinge Tekniska Högskola/Institutionen för datavetenskap
- Publiceringsdatum
- 2026
- Uppsatstyp
- Yrkesexamen på avancerad nivå
- Språk
- Engelska