Present work explores the transformative potential of blockchain technology in cybersecurity.It begins with a fundamental introduction to blockchain's workings, then focuses on its current trends in bolstering cybersecurity, such as identity management and tamper-proof data storage.Real-world examples are used to guide practical implementations in industries like healthcare, finance, and voting.The paper also explores potential developments in the future, such as quantumresistant cryptography, decentralized autonomous organizations, and artificial intelligence integration.The paper concludes by assessing the lasting impact of blockchain on the broader cybersecurity landscape, highlighting its ability to reshape trust paradigms and empower individuals to control their digital identities.
Samson Kahsay Gebresilassie, Joseph Rafferty, Mamun Abu-Tair, Aftab Ali · 6 authors
The Internet of Things (IoT) is a technology paradigm that has transformed several domains including manufacturing, agriculture, healthcare, power grids, travel, and retail. Despite the enormous advantages that IoT offers to organizations and transforming individuals’ everyday lives in a wide range of domains, it comes with potential cyber risks that can negatively impact, harm, or damage them. Security is the most challenging issue in IoT systems due to insecure devices, inadequate IDMS, lack of data security and privacy, lack of trust, lack of risk analysis on network traffic, various vulnerabilities and attacks, lack of physical security, and many other risk factors. Although several security architectures have been developed, they fail to properly and fully address these IoT security challenges and an urgent demand awaits for a robust IoT security architecture. Thus, this work investigates state-of-the-art solutions and proposes a holistic novel IoT security architecture called SHIELD: Secure Holistic IoT Environment with Ledger-based Defense with core security capabilities of decentralized Identity Management System (IDMS), Network Traffic Monitoring, Analysis, and dataset generation, deep learning-based Intrusion Detection System (IDS), and Distributed Ledger Technology (DLT)-based Trust Management System (TMS). The proposed architecture is qualitatively compared with existing solutions using key features like a single point of failure, risk/attack-aware, trust, real-time traffic behavior monitoring, up-to-date dataset, cross-platform functionality, and availability among others. As a result of this comparison, SHIELD architecture provides a holistic and robust solution with multiple core security features to overcome some of the key security challenges IoT environment.
Uzma Jafar, Mohd Juzaiddin Ab Aziz, Zarina Shukur, Hafiz Adnan Hussain
As electronic voting systems become increasingly prevalent, the urgent need for robust security measures to combat evolving cyber threats has never been more critical. This paper introduces a ground-breaking architectural framework Secure-Tech Triad that synergistically combines Blockchain technology with Machine Learning (ML) algorithms and Internet of Things (IoT) capabilities to enhance the security and efficiency of electronic voting systems. This architectural framework utilizes a modified Proof-of-Stake (PoS) Blockchain algorithm, a Random Forest ML model for real-time anomaly detection, and an MQTT protocol for IoT-based data collection to create a more secure, efficient, and responsive voting environment. Rigorous testing and evaluation show that the integrated framework significantly outperforms existing Blockchain-only solutions in key performance indicators, such as security breach detection rate, system latency, and cost efficiency. This integrated approach is the best-performing model, achieving a 97% security breach detection rate, a 30% reduction in system latency (down to 2.3 seconds), and a 25% decrease in operational costs. These results underscore the combined effectiveness of Blockchain, AI, and IoT in enhancing security, speed, and cost-effectiveness. Specifically, the Random Forest algorithm has been instrumental in achieving an exceptional security breach detection rate, while IoT data collection has played a pivotal role in enabling real-time anomaly detection and proactive threat mitigation.
Njoku ThankGod Anthony, Mahmoud Shafik, Hany F. Atlam
With the proliferation of blockchain technology, ensuring the security and integrity of permissionless Proof-of-Stake (PoS) blockchain networks has become imperative. This paper addresses the persistent need for an effective system to detect and mitigate malicious nodes in such environments. Leveraging Deep Learning (DL) techniques, specifically Multi-Layer Perceptron (MLP), a novel model is proposed for real-time identification and detection of malicious nodes in PoS blockchain networks. The model integrates components for data collection, feature extraction, and model training using MLP. The proposed model is trained on labelled data representing both benign and malicious node activities, utilising transaction volumes, frequencies, timestamps, and node reputation scores to identify anomalous behaviour indicative of malicious activity. The experimental results validate the efficacy of the proposed model in distinguishing between normal and malicious nodes within blockchain networks. The model demonstrates exceptional performance in classification tasks with an accuracy of 99%, precision, recall, and F1-score values hovering around 0.99 for both classes. The experimental results verify the proposed model as a dependable tool for enhancing the security and integrity of PoS blockchain networks, offering superior performance in real-time detection and mitigation of malicious activities.
We explore how cybersecurity should be incorporated into corporate governance and develop a specific framework for implementing it. We consider different types of cybersecurity incidents, such as ransomware and data leaks, and their impacts on companies. We then discuss how cybersecurity situates in the current corporate governance theoretical framework. Based on the Resource Dependency Theory (RDT), we develop a specific governance framework with a focus on the role of chief cybersecurity officer, the audit committee, the regulatory powers, and market enforcement mechanisms. As more companies are becoming digital native and more services provided are digital in the Web3 space, this chapter is policy relevant as it provides a theoretical basis for implementing cybersecurity within companies in the digital space and a specific framework for the implementation.
Daniele Granata, Massimiliano Rak, Paolo Palmiero, Adele Pastena
Despite the growing role of information and communication technology (ICT) in public administration, paper ballots still dominate elections, especially in Italy. Electronic voting has had limited success worldwide, largely due to security and manipulation concerns. The COVID-19 pandemic has reignited interest in remote e-voting for safe participation while social distancing, though security remains a critical issue. Embracing electronic voting is essential to safeguard rights, improve resource efficiency, and promote digital citizenship. Accordingly, to address security concerns in e-voting, this research emphasizes the importance of security and legal measures. The study is based on ISO15408 (Common Criteria) certification process, a framework for independent security evaluations. The paper proposes a methodology that combines legal and technical requirements for e-voting security assessments, focusing on BPMN processes to model scenarios. The methodology has been applied to a common Ethereum smart contract, focusing on the e-voting process. A detailed analysis of a Solidity e-voting smart contract reveals its vulnerabilities and limitations. The research also produces a BPMN representation of an e-voting scenario, aligning logical behaviour with smart contract implementation. The aim is to bridge the gap between legal and technical aspects of e-voting, enhancing security and transparency.
Blockchain has emerged as a groundbreaking security technology, playing a vital role in various industries such as banking, the Internet of Things (IoT), healthcare, education, and voting. However, the widespread adoption of this technology has introduced certain vulnerabilities, particularly in the form of exploitation by malicious entities. While existing research primarily focuses on identifying anomalous actor behavior, there has been limited exploration of precisely identifying hostile actors within the Ethereum network. This study aims to uncover malevolent actors operating on the Ethereum network and categorize attacks based on their actions. To achieve this research goal, a new dataset was constructed by consolidating data on malicious actors involved in illicit Ethereum activities. Key features were extracted from this dataset using advanced feature selection techniques, including Principal Component Analysis (PCA), Information Gain, and Ridge Regression. Machine learning classifiers such as LGBM, XGBoost, Random Forest, Extra Tree, Bagging, and K-Nearest Neighbors were applied to identify and classify malicious actors effectively. The results, achieving an impressive accuracy rate of 98%, underscore the effectiveness of Information Gain when coupled with LGBM and XGBoost. Notably, XGBoost demonstrates efficiency by completing the analysis in a mere 13.72 seconds. In addition to identifying fraudulent activities, this research classifies them into distinct categories, enhancing blockchain security and addressing trust concerns. This study’s outcomes fortify the Ethereum network’s resilience and contribute to the broader discourse on bolstering reliability in blockchain systems.
The Internet of Healthcare Things (IoHT) is an emerging critical technology for managing patients’ health. They are prone to cybersecurity vulnerabilities because they are connected to the internet, primarily by wireless connections. This is a major concern, considering data privacy and security. Artificial intelligence (AI) models are excellent methods to detect and mitigate cybersecurity vulnerabilities. Since medical Information Technology (IT) is evolving and data privacy is a major concern with sensors generally, in healthcare IoT. The TON_IOT, Edge_IIoT, and UNSW-NB15 datasets were used in this study for assessment and implementation to solve the challenge using the chosen benchmark AI models with the integration of IPFS blockchain technology in order to decentralize and secure the data. Justifiable parameters were used to determine how efficient each technique is in predicting the best outcome. The results show the efficiency of the utilized models, particularly the Support Vector Machines (SVM). The TON_IoT dataset obtained 100% accuracy, the Edge_IIoT dataset obtained 98% accuracy, and the UNSW-NB15 dataset obtained 89% accuracy. The integrated blockchain technology in this model is applied for security purposes. Utilizing these techniques will proffer a secure and safe transmission of medical data. This study will generally provide important insight to other researchers in the healthcare field.
Bitcoin is widely used as the most classic electronic currency for various electronic services such as exchanges, gambling, marketplaces, and also scams such as high-yield investment projects. Identifying the services operated by a Bitcoin address can help determine the risk level of that address and build an alert model accordingly. Feature engineering can also be used to flesh out labeled addresses and to analyze the current state of Bitcoin in a small way. In this paper, we address the problem of identifying multiple classes of Bitcoin services, and for the poor classification of individual addresses that do not have significant features, we propose a Bitcoin address identification scheme based on joint multi-model prediction using the mapping relationship between addresses and entities. The innovation of the method is to (1) Extract as many valuable features as possible when an address is given to facilitate the multi-class service identification task. (2) Unlike the general supervised model approach, this paper proposes a joint prediction scheme for multiple learners based on address-entity mapping relationships. Specifically, after obtaining the overall features, the address classification and entity clustering tasks are performed separately, and the results are subjected to graph-based maximization consensus. The final result is made to baseline the individual address classification results while satisfying the constraint of having similarly behaving entities as far as possible. By testing and evaluating over 26,000 Bitcoin addresses, our feature extraction method captures more useful features. In addition, the combined multi-learner model obtained results that exceeded the baseline classifier reaching an accuracy of 77.4%.
Kainat Ansar, Mansoor Ahmed, Markus Helfert, Jungsuk Kim
In cybersecurity, personal data breaches have become one of the significant issues. This fact indicates that data breaches require unique detection systems, techniques, and solutions, which necessitate the potential to facilitate precise and quick data breach detection. Various research works on data breach detection and related areas in dealing with this problem have been proposed. Several survey studies have been conducted to comprehend insider data breaches better. However, these works did not examine techniques related to blockchain and innovative smart contract technologies to detect data breaches. In this survey, we examine blockchain-based data breach detection mechanisms developed so far to deal with data breach detection. We compare blockchain-based data breach detection techniques based on type, platform, smart contracts, consensus algorithm language/tool, and evaluation measures. We also present a taxonomy of contemporary data breach types. We conclude our study by outlining existing methodologies’ issues, offering ideas for overcoming those challenges, and pointing the way forward.
Stephen Kirkman, Steven Fulton, Jeffrey Hemmes, Christopher Garcia · 5 authors
The motivation of this research (and also one of the nation’s cyber goals) is enhancing the resilience of Industrial Control Systems (ICS)/Supervisory Control and Data Acquisition (SCADA) systems against ransomware attacks. ICS and SCADA systems run some of the most important networks in the country: our critical infrastructure (i.e., water flow, power grids, etc.). Disruption of these systems causes confusion, panic, and in some cases loss of life. We propose a SCADA architecture that uses blockchain to help protect ICS data from ransomware. We focus on the historian. In a SCADA system, the historian collects events from devices in the control network for real-time and future analysis. We choose to use Ethereum and its Proof of Stake (PoS) consensus protocol. The other goal of this research focuses on the resilience of blockchain. There is very little research in protecting the blockchain itself. By performing encryption testing on an Ethereum private network, we explore how vulnerable blockchain is and discuss potential ways to make a blockchain client more resilient.
Jannik Lucas Sommer, Magnus Mølgaard Lund, Nicola Cibin, Michele Albano
The frequency of software supply chain attacks has reached unprecedented levels, primarily due to the increasing reliance on huge numbers of software and hardware dependencies, and the inherent vulnerabilities they harbor. Currently, vendors providing these software and hardware components share security advisories to centralized databases or post them on proprietary websites, which security engineers have to search manually to find vulnerabilities relevant for their systems. Furthermore, the security advisories often do not follow a standard machine-readable format, which results in the engineers having to manually analyze the documents. In this paper, SENTINEL, a novel solution for automating dissemination and discovery of security advisories leveraging Web3 technologies, is presented. In particular, the Ethereum blockchain is used by vendors to notify asset owners of novel vulnerabilities in their systems in a reliable and accountable manner. Evaluation tests conducted on the Ethereum Sepolia Testnet confirm that our proposal is a functional and functioning solution for securely disseminating and discovering security advisories utilizing a fully decentralized infrastructure. SENTINEL’s source code is released as open source software on GitHub.
Blockchain technologies have gained widespread use in security-sensitive applications due to their robust data protection. However, as blockchains are increasingly integrated into critical data management systems, they have become attractive targets for attackers. Among the various attacks on blockchain systems, distributed denial of service (DDoS) attacks are one of the most significant and potentially devastating. These attacks render the systems incapable of processing transactions, causing the blockchain to come to a halt. To address the challenge of detecting DDoS attacks on blockchains, existing visualization schemes have been developed. However, these schemes often fail to provide early DDoS detection since they typically display only past and current system status. In this paper, we present a novel visualization scheme that not only portrays past and current values but also forecasts future expected system statuses. We achieve these future predictions by utilizing polynomial regression with blockchain data. Additionally, we offer an alternative DDoS detection method employing statistical analysis, specifically the coefficient of determination, to enhance accuracy. Through our experiments, we demonstrate that our proposed scheme excels at predicting future blockchain statuses and anticipating DDoS attacks with minimal error. Our work empowers system managers of blockchain-based applications to identify and mitigate DDoS attacks at an earlier stage.
Low-speed internet can negatively impact incident response by causing delayed detection, ineffective response, poor collaboration, inaccurate analysis, and increased risk. Slow internet speeds can delay the receipt and analysis of data, making it difficult for security teams to access the relevant information and take action, leading to a fragmented and inadequate response. All of these factors can increase the risk of data breaches and other security incidents and their impact on IoT-enabled communication. This study combines virtual network function (VNF) technology with software -defined networking (SDN) called virtual network function software-defined networking (VNFSDN). The adoption of the VNFSDN approach has the potential to enhance network security and efficiency while reducing the risk of cyberattacks. This approach supports IoT devices that can analyze large volumes of data in real time. The proposed VNFSDN can dynamically adapt to changing security requirements and network conditions for IoT devices. VNFSDN uses threat filtration and threat-capturing and decision-driven algorithms to minimize cyber risks for IoT devices and enhance network performance. Additionally, the integrity of IoT devices is safeguarded by addressing the three risk categories of data manipulation, insertion, and deletion. Furthermore, the prioritized delegated proof of stake (PDPoS) consensus variant is integrated with VNFSDN to combat attacks. This variant addresses the scalability issue of blockchain technology by providing a safe and adaptable environment for IoT devices that can quickly be scaled up and down to pull together the changing demands of the organization, allowing IoT devices to efficiently utilize resources. The PDPoS variant provides flexibility to IoT devices to proactively respond to potential security threats, preventing or mitigating the impact of cyberattacks. The proposed VNFSDN dynamically adapts to the changing security requirements and network conditions, improving network resiliency and enabling proactive threat detection. Finally, we compare the proposed VNFSDN to existing state-of-the-art approaches. According to the results, the proposed VNFSDN has a 0.08 ms minimum response time, a 2% packet loss rate, 99.5% network availability, a 99.36% threat detection rate, and a 99.77% detection accuracy with 1% malicious nodes.
In blockchains, mempool controls transaction flow before consensus, denial of whose service hurts the health and security of blockchain networks. This paper presents MPFUZZ, the first mempool fuzzer to find asymmetric DoS bugs by exploring the space of symbolized mempool states and optimistically estimating the promisingness of an intermediate state in reaching bug oracles. Compared to the baseline blockchain fuzzers, MPFUZZ achieves a > 100x speedup in finding known DETER exploits. Running MPFUZZ on major Ethereum clients leads to discovering new mempool vulnerabilities, which exhibit a wide variety of sophisticated patterns, including stealthy mempool eviction and mempool locking. Rule-based mitigation schemes are proposed against all newly discovered vulnerabilities.
The industrial Internet of Things (IIoT) involves the integration of Internet of Things (IoT) technologies into industrial settings. However, given the high sensitivity of the industry to the security of industrial control system networks and IIoT, the use of software-defined networking (SDN) technology can provide improved security and automation of communication processes. Despite this, the architecture of SDN can give rise to various security threats. Therefore, it is of paramount importance to consider the impact of these threats on SDN-based IIoT environments. Unlike previous research, which focused on security in IIoT and SDN architectures separately, we propose an integrated method including two components that work together seamlessly for better detecting and preventing security threats associated with SDN-based IIoT architectures. The two components consist in a convolutional neural network-based Intrusion Detection System (IDS) implemented as an SDN application and a Blockchain-based system (BS) to empower application layer and network layer security, respectively. A significant advantage of the proposed method lies in jointly minimizing the impact of attacks such as command injection and rule injection on SDN-based IIoT architecture layers. The proposed IDS exhibits superior classification accuracy in both binary and multiclass categories.
Phishing scams have become the most serious type of crime involved in Ethereum. However, existing methods ignore the natural camouflage and sparse distribution of phishing scams in Ethereum leading to unsatisfactory performance, and they are also limited by the data scale which cannot be applied to real-world dynamic scenarios. In this paper, we propose a Transaction Graph Contrast network (TGC) to enhance phishing scam detection performance on Ethereum. TGC inputs subgraphs instead of the entire graph for training, which eases the model’s requirements for machine configuration and data connectivity. Motivated by phishing nodes are surrounded by normal nodes, we design the comparison between node-level to help phishing nodes learn the unique properties of themselves different from their neighbors. Observing the small number and sparse distribution of phishing nodes, we narrow the distance between phishing nodes by comparing node context-level structures, so as to learn universal transaction patterns. We further combine the obtained features with common statistics to identify phishing addresses. Evaluated on real-world Ethereum phishing scams datasets, our TGC outperforms the state-of-the-art methods in detecting phishing addresses and has obvious advantages in large-scale and dynamic scenarios.
Shereen Ismail, Muhammad Nouman, Diana W. Dawoud, Hassan Reza
Cyber-attacks pose a significant challenge to the security of Internet of Things (IoT) sensor networks, necessitating the development of robust countermeasures tailored to their unique characteristics and limitations. Various prevention and detection techniques have been proposed to mitigate these attacks. In this paper, we propose an integrated security framework using Blockchain (BC) and Machine Learning (ML) to protect IoT sensor networks. The framework consists of two modules: a BC prevention module and a ML detection module. The BC prevention module has two lightweight mechanisms: identity management and trust management. Identity management employs a lightweight Smart Contract (SC) to manage the node registration and authentication, ensuring that unauthorized entities are prohibited from engaging in any tasks, while trust management uses a lightweight SC that is responsible for maintaining trust and credibility between sensor nodes throughout the network's lifetime and tracking historical node behaviors. Consensus and transaction validation are achieved through a Verifiable Byzantine Fault Tolerance (VBFT) mechanism to ensure network reliability and integrity. The ML detection module utilizes LightGBM algorithm to classify malicious nodes and notify the BC network if it must make decisions to mitigate their impacts. We investigate the performance of several off-the-shelf ML algorithms, including Logistic Regression, Complement Naive Bayes, Nearest Centroid, and Stacking, using the WSN-DS dataset. LightGBM is selected following a detailed comparative analysis conducted using accuracy, precision, recall, F1-score, processing time, training time, prediction time, computational complexity, and Matthews Correlation Coefficient (MCC) evaluation metrics.
Yuheng Zhang, Liu Pin, Guojun Wang, Peiqiang Li · 8 authors
With the evolution of blockchain technology, the issue of transaction security, particularly on platforms like Ethereum, has become increasingly critical. Front-running attacks, a unique form of security threat, pose significant challenges to the integrity of blockchain transactions. In these attack scenarios, malicious actors monitor other users' transaction activities, then strategically submit their own transactions with higher fees. This ensures their transactions are executed before the monitored transactions are included in the block. The primary objective of this paper is to delve into a comprehensive classification of transactions associated with front-running attacks, which aims to equip developers with specific strategies to counter each type of attack. To achieve this, we introduce a novel detection method named FRAD (Front-Running Attacks Detection on Ethereum using Ternary Classification Model). This method is specifically tailored for transactions within decentralized applications (DApps) on Ethereum, enabling accurate classification of front-running attacks involving transaction displacement, insertion, and suppression. Our experimental validation reveals that the Multilayer Perceptron (MLP) classifier offers the best performance in detecting front-running attacks, achieving an impressive accuracy rate of 84.59% and F1-score of 84.60%.
The increasing reliance on cyber-physical systems (CPSs) in critical domains such as healthcare, smart grids, and intelligent transportation systems necessitates robust security measures to protect against cyber threats. Among these threats, blackhole and greyhole attacks pose significant risks to the availability and integrity of CPSs. The current detection and mitigation approaches often struggle to accurately differentiate between legitimate and malicious behavior, leading to ineffective protection. This paper introduces Gini-index and blockchain-based Blackhole/Greyhole RPL (GBG-RPL), a novel technique designed for efficient detection and mitigation of blackhole and greyhole attacks in smart health monitoring CPSs. GBG-RPL leverages the analytical prowess of the Gini index and the security advantages of blockchain technology to protect these systems against sophisticated threats. This research not only focuses on identifying anomalous activities but also proposes a resilient framework that ensures the integrity and reliability of the monitored data. GBG-RPL achieves notable improvements as compared to another state-of-the-art technique referred to as BCPS-RPL, including a 7.18% reduction in packet loss ratio, an 11.97% enhancement in residual energy utilization, and a 19.27% decrease in energy consumption. Its security features are also very effective, boasting a 10.65% improvement in attack-detection rate and an 18.88% faster average attack-detection time. GBG-RPL optimizes network management by exhibiting a 21.65% reduction in message overhead and a 28.34% decrease in end-to-end delay, thus showing its potential for enhanced reliability, efficiency, and security.
Bitcoin has been launched for over a decade and made an increasing impact on the world’s financial order, which attracted extensive attention of researchers. Bitcoin system runs on a dynamic P2P network, containing tens of thousands of nodes including reachable nodes and unreachable nodes. In this article, a detection system BNS (Bitcoin Network Sniffer) was prososed, which could collect as many Bitcoin nodes as possible. For reachable nodes, the authors designed an algorithm BRF (Bitcoin Reachable-nodes Finding) based on node activity evaluation, which reduced the nodes to be detected and greatly shortened the detection time. For unreachable nodes, the authors trained a dicision tree model BUF(Bitcoin Unreachable-nodes Finding) to identify unreachable nodes based on attribute features from massive node addresses. Experiments showed that BNS performed better than the website "Bitnodes" in total number and efficiency. Based on the experimental results, the authors analyzed the real network size, node "churn" and geographical distribution.
Leandro Cunha, Miguel A. Brito, Domingos F. Oliveira, Ana Paula Martins
The cryptocurrency market has grown significantly, and this quick growth has given rise to scams. It is necessary to put fraud detection mechanisms in place. The challenge of inadequate labeling is addressed in this work, which is a barrier to the training of high-performance supervised classifiers. It aims to lessen the necessity for laborious and time-consuming manual labeling. Some unlabeled data points have labels that are more pertinent and informative for the supervised model to learn from. The viability of utilizing unsupervised anomaly detection algorithms and active learning strategies to build an iterative process of acquiring labeled transactions in a cold start scenario, where there are no initial-labeled transactions, is being investigated. Investigating anomaly detection capabilities for a subset of data that maximizes supervised models’ learning potential is the goal. The anomaly detection algorithms under performed, according to the results. The findings underscore the need that anomaly detection algorithms be reserved for situations involving cold starts. As a result, using active learning techniques would produce better outcomes and supervised machine learning model performance.
Advances in blockchain technology have attracted significant attention across the world. The practical blockchain applications emerging in various domains, ranging from finance, healthcare, and entertainment, have quickly become attractive targets for adversaries. The novelty of the technology coupled with the high degree of anonymity it provides made malicious activities even less visible in the blockchain environment. This made their robust detection challenging. This article presents EtherShield, a novel approach for identifying malicious activity on the Ethereum blockchain. By combining temporal transaction information and contract code characteristics, EtherShield can detect various types of threats and provide insight into the behavior of contracts. The time-interval-based analysis used by EtherShield enables expedited detection, achieving comparable accuracy to other approaches with significantly less data. Our validation analysis, which involved over 15,000 Ethereum accounts, demonstrated that EtherShield can significantly expedite the detection of malicious activity while maintaining high accuracy levels (86.52% accuracy with 1 hour of transaction history data and 91.33% accuracy with 1 year of transaction history data).