Computer Science > Cryptography and Security
[Submitted on 19 Aug 2017 (this version), latest version 7 Feb 2019 (v3)]
Title:NIZKCTF: A Non-Interactive Zero-Knowledge Capture the Flag Platform
View PDFAbstract:Capture the Flag (CTF) competitions are educational and professional tools for the cybersecurity community. Unfortunately, CTF platforms suffer from the same security issues as other software components, what may give advantage to competitors who target the actual platform instead of the challenges. While it is arguable that successful attacks against the platform demonstrate relevant skills, the organizers may be interested into enforcing rules and rewarding solutions of the contest problems, due to sponsorship duties or focused recruiting efforts. To mitigate this, we present NIZKCTF, the first open-audit CTF platform based on non-interactive zero-knowledge proofs. NIZKCTF is publicly available for anyone who wants to run a CTF competition and provides strong transparency guarantees through the protocol, allowing any entity to verify the contest progression and outcome by employing a Git-based transaction log, a continuous integration service and zero-knowledge proofs. Using NIZKCTF, we conducted a competition for 10 invited teams. This competition had a bug bounty program, with cash prizes for teams able to exploit and compromise the CTF result. In this experiment, we observed that attacks carried by the teams against the platform were unsuccessful.
Submission history
From: Paulo Matias [view email][v1] Sat, 19 Aug 2017 13:55:01 UTC (137 KB)
[v2] Mon, 12 Mar 2018 03:09:37 UTC (179 KB)
[v3] Thu, 7 Feb 2019 10:27:00 UTC (423 KB)
Bibliographic and Citation Tools
Bibliographic Explorer (What is the Explorer?)
Litmaps (What is Litmaps?)
scite Smart Citations (What are Smart Citations?)
Code, Data and Media Associated with this Article
CatalyzeX Code Finder for Papers (What is CatalyzeX?)
DagsHub (What is DagsHub?)
Gotit.pub (What is GotitPub?)
Papers with Code (What is Papers with Code?)
ScienceCast (What is ScienceCast?)
Demos
Recommenders and Search Tools
Influence Flower (What are Influence Flowers?)
Connected Papers (What is Connected Papers?)
CORE Recommender (What is CORE?)
arXivLabs: experimental projects with community collaborators
arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.
Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.
Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs.