Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

824 papersLast indexed Aug 31, 2026
Search papers

Paper index

824 results · page 12 of 35

Clear filters
Jun 23, 2023·JUCS - Journal of Universal Computer Science
3 cites
Aggregating Users’ Online Opinions Attributes and News Influence for Cryptocurrencies Reputation Generation

Achraf Boumhidi, Abdessamad Benlahbib, El Habib Nfaoui

Reputation generation systems are decision-making tools used in different domains including e-commerce, tourism, social media events, etc. Such systems generate a numerical reputation score by analyzing and mining massive amounts of various types of user data, including textual opinions, social interactions, shared images, etc. Over the past few years, users have been sharing millions of tweets related to cryptocurrencies. Yet, no system in the literature was designed to handle the unique features of this domain with the goal of automatically generating reputation and supporting investors’ and users’ decision-making. Therefore, we propose the first financially oriented reputation system that generates a single numerical value from user-generated content on Twitter toward cryptocurrencies. The system processes the textual opinions by applying a sentiment polarity extractor based on the fine-tuned auto-regressive language model named XLNet. Also, the system proposes a technique to enhance sentiment identification by detecting sarcastic opinions through examining the contrast of sentiment between the textual content, images, and emojis. Furthermore, other features are considered, such as the popularity of the opinions based on the social network interactions (likes and shares), the intensity of the entity’s demand within the opinions, and news influence on the entity. A survey experiment has been conducted by gathering numerical scores from 827 Twitter users interested in cryptocurrencies. Each selected user assigns 3 numerical assessment scores toward three cryptocurrencies. The average of those scores is considered ground truth. The experiment results show the efficacy of our model in generating a reliable numerical reputation value compared with the ground truth, which proves that the proposed system may be applied in practice as a trusted decision-making tool.

Open access
Sentiment Analysis and Opinion Mining
Spam and Phishing Detection
Digital Marketing and Social Media
Original source
Jun 22, 2023·Journal of Cloud Computing Advances Systems and Applications
29 cites
HGAT: smart contract vulnerability detection method based on hierarchical graph attention network

Chuang Ma, Shuaiwu Liu, Guangxia Xu

Abstract With the widespread use of blockchain, more and more smart contracts are being deployed, and their internal logic is getting more and more sophisticated. Due to the large false positive rate and low detection accuracy of most current detection methods, which heavily rely on already established detection criteria, certain smart contracts additionally call for human secondary detection, resulting in low detection efficiency. In this study, we propose HGAT, a hierarchical graph attention network-based detection model, in order to address the aforementioned issues as well as the shortcomings of current smart contract vulnerability detection approaches. First, using Abstract Syntax Tree (AST) and Control Flow Graph, the functions in the smart contract are abstracted into code graphs (CFG). Then abstract each node in the code subgraph, extract the node features, utilize the graph attention mechanism GAT, splice the obtained vectors to form the features of each line of statements and use these features to detect smart contracts. To create test data and assess HGAT, we leverage the open-source smart contract vulnerability sample dataset. The findings of the experiment indicate that this method can identify smart contract vulnerabilities more quickly and precisely than other detection techniques.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Jun 18, 2023·arXiv (Cornell University)
9 cites
Understanding the Cryptocurrency Free Giveaway Scam Disseminated on Twitter Lists

Kai Li, Darren Lee, Shixuan Guan

This paper presents a comprehensive analysis of the cryptocurrency free giveaway scam disseminated in a new distribution channel, Twitter lists. To collect and detect the scam in this channel, unlike existing scam detection systems that rely on manual effort, this paper develops a fully automated scam detection system, \textit{GiveawayScamHunter}, to continuously collect lists from Twitter and utilize a Nature-Language-Processing (NLP) model to automatically detect the free giveaway scam and extract the scam cryptocurrency address. By running \textit{GiveawayScamHunter} from June 2022 to June 2023, we detected 95,111 free giveaway scam lists on Twitter that were created by thousands of Twitter accounts. Through analyzing the list creator accounts, our work reveals that scammers have combined different strategies to spread the scam, including compromising popular accounts and creating spam accounts on Twitter. Our analysis result shows that 43.9\% of spam accounts still remain active as of this writing. Furthermore, we collected 327 free giveaway domains and 121 new scam cryptocurrency addresses. By tracking the transactions of the scam cryptocurrency addresses, this work uncovers that over 365 victims have been attacked by the scam, resulting in an estimated financial loss of 872K USD. Overall, this work sheds light on the tactics, scale, and impact of free giveaway scams disseminated on Twitter lists, emphasizing the urgent need for effective detection and prevention mechanisms to protect social media users from such fraudulent activity.

Open access
3 source records
Spam and Phishing Detection
FinTech, Crowdfunding, Digital Finance
Blockchain Technology Applications and Security
Original source
Jun 15, 2023·Journal of Cloud Computing Advances Systems and Applications
8 cites
Ensuring security in edge computing through effective blockchain node detection

Shenqiang Wang, Zhaowei Liu, Haiyang Wang, Jianping Wang

Abstract The rapid development of blockchain technology has garnered increasing attention, particularly in the field of edge computing. It has become a significant subject of research in this area due to its ability to protect the privacy of data. Despite the advantages that blockchain technology offers, there are also security threats that must be addressed. Attackers may manipulate certain nodes in the blockchain network, which can result in tampering with transaction records or other malicious activities. Moreover, the creation of a large number of false nodes can be utilized to gain control and manipulate transaction records of the blockchain network, which can compromise the reliability and security of edge computing. This paper proposes a blockchain node detection method named $$T^2A2vec$$ T 2 A 2 v e c that provides a more secure, credible, and reliable solution to address these challenges. In order to achieve $$T^2A2vec$$ T 2 A 2 v e c , a transaction dataset that is evenly distributed in both space and time was collected. The transaction dataset is constructed as a transaction graph, where nodes represent accounts and edges describe transactions. BP neural network is used to extract account features, and a random walk strategy based on transaction time, type, and amount is used to extract transaction features. The obtained account features and transaction features are fused to obtain account representation. Finally, the obtained node representation is fed into different classifiers to identify malicious nodes.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Graph Neural Networks
Original source
Jun 6, 2023·arXiv
4 cites
Russo-Ukrainian War: Prediction and explanation of Twitter suspension

Alexander Shevtsov, Despoina Antonakaki, Ioannis Lamprou, Ioannis Kontogiorgakis · 6 authors

On 24 February 2022, Russia invaded Ukraine, starting what is now known as the Russo-Ukrainian War, initiating an online discourse on social media. Twitter as one of the most popular SNs, with an open and democratic character, enables a transparent discussion among its large user base. Unfortunately, this often leads to Twitter's policy violations, propaganda, abusive actions, civil integrity violation, and consequently to user accounts' suspension and deletion. This study focuses on the Twitter suspension mechanism and the analysis of shared content and features of the user accounts that may lead to this. Toward this goal, we have obtained a dataset containing 107.7M tweets, originating from 9.8 million users, using Twitter API. We extract the categories of shared content of the suspended accounts and explain their characteristics, through the extraction of text embeddings in junction with cosine similarity clustering. Our results reveal scam campaigns taking advantage of trending topics regarding the Russia-Ukrainian conflict for Bitcoin and Ethereum fraud, spam, and advertisement campaigns. Additionally, we apply a machine learning methodology including a SHapley Additive explainability model to understand and explain how user accounts get suspended.

Open access
2 source records
cs.SI
cs.AI
cs.LG
Original source
Jun 3, 2023·Journal of Information Technology and Digital World
2 cites
Blockchain based Transparent Donating System

J. Karthika, S Keerthana, A. Shali

Blockchain is a promising technology that is quickly gaining traction in the realm of security that is regulated by both governmental and commercial organizations. Donors are unable to know whether their donations are being used effectively due to a complete lack of transparency in donation-related transactions, which has prompted many to stop believing in charities. The immutability, traceability, and reliability properties of blockchain technology make it a viable solution for enhancing efficiency and transparency for charity. This research work is based on the Ethereum Blockchain, the decentralized donation tracking system that will permit transparent accountability, openness, and direct communication with the intended targets. The blockchain network would be made up of well-known, reliable, and esteemed companies.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Organizational and Employee Performance
Original source
Jun 2, 2023·arXiv (Cornell University)
14 cites
SourceP: Detecting Ponzi Schemes on Ethereum with Source Code

Pengcheng Lu, Liang Cai, Keting Yin

As blockchain technology becomes more and more popular, a typical financial scam, the Ponzi scheme, has also emerged in the blockchain platform Ethereum. This Ponzi scheme deployed through smart contracts, also known as the smart Ponzi scheme, has caused a lot of economic losses and negative impacts. Existing methods for detecting smart Ponzi schemes on Ethereum mainly rely on bytecode features, opcode features, account features, and transaction behavior features of smart contracts, which are unable to truly characterize the behavioral features of Ponzi schemes, and thus generally perform poorly in terms of detection accuracy and false alarm rates. In this paper, we propose SourceP, a method to detect smart Ponzi schemes on the Ethereum platform using pre-trained models and data flow, which only requires using the source code of smart contracts as features. SourceP reduces the difficulty of data acquisition and feature extraction of existing detection methods. Specifically, we first convert the source code of a smart contract into a data flow graph and then introduce a pre-trained model based on learning code representations to build a classification model to identify Ponzi schemes in smart contracts. The experimental results show that SourceP achieves 87.2% recall and 90.7% F-score for detecting smart Ponzi schemes within Ethereum's smart contract dataset, outperforming state-of-the-art methods in terms of performance and sustainability. We also demonstrate through additional experiments that pre-trained models and data flow play an important contribution to SourceP, as well as proving that SourceP has a good generalization ability.

Open access
4 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
FinTech, Crowdfunding, Digital Finance
Original source
May 31, 2023·Telecom
18 cites
Phishing Detection in Blockchain Transaction Networks Using Ensemble Learning

Roseline Oluwaseun Ogundokun, Micheal Olaolu Arowolo, Robertas Damaševičius, Sanjay Misra

The recent progress in blockchain and wireless communication infrastructures has paved the way for creating blockchain-based systems that protect data integrity and enable secure information sharing. Despite these advancements, concerns regarding security and privacy continue to impede the widespread adoption of blockchain technology, especially when sharing sensitive data. Specific security attacks against blockchains, such as data poisoning attacks, privacy leaks, and a single point of failure, must be addressed to develop efficient blockchain-supported IT infrastructures. This study proposes the use of deep learning methods, including Long Short-Term Memory (LSTM), Bi-directional LSTM (Bi-LSTM), and convolutional neural network LSTM (CNN-LSTM), to detect phishing attacks in a blockchain transaction network. These methods were evaluated on a dataset comprising malicious and benign addresses from the Ethereum blockchain dark list and whitelist dataset, and the results showed an accuracy of 99.72%.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Original source
May 31, 2023·IET Blockchain
15 cites
Ethereum phishing detection based on graph neural networks

Ao Xiong, Yuanzheng Tong, Chengling Jiang, Shaoyong Guo · 8 authors

Abstract With the development of blockchain, cryptocurrencies are also showing a boom. However, due to the decentralized and anonymous nature of blockchain, cryptocurrencies have inevitably become a hotbed for fraudulent crimes. For example, phishing scams are frequent, which not only jeopardize the financial security of blockchain, but also hinder the promotion of blockchain technology. To solve this problem, this paper proposes a graph neural network‐based phishing detection method for Ethereum, and validates it using Ethereum datasets. Specifically, this paper proposes a feature learning algorithm named TransWalk, which consists of a random walk strategy for transaction networks and a multi‐scale feature extraction method for Ethereum. Then, an Ethereum phishing fraud detection framework is built based on TransWalk, and conduct extensive experiments on the Ethereum dataset to verify the effectiveness of this scheme in identifying Ethereum phishing detection.

Open access
2 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Imbalanced Data Classification Techniques
Original source
May 26, 2023·International Research Journal of Modernization in Engineering Technology and Science
0 cites
ETHEREUM-BASED DECENTRALISED TOKEN EXCHANGE

Authors unavailable

In the world of modern technology, ensuring security is a top priority. To address this issue, blockchain technology has emerged as a promising solution by eliminating intermediaries and enhancing security. Cryptocurrencies are the first type of digital assets that have been successfully managed using blockchain technology. In recent years, financial institutions have been increasingly adding cryptocurrencies to their portfolios, leading to widespread adoption and interest among various stakeholders, including the banking sector, government, and individual investors. Cryptocurrency has the potential to become the future global currency, replacing fiat currency. This research project provides a comprehensive overview of the cryptocurrency market, including its origins, key features, price dynamics, market capitalization, and trading volumes. The project also explores important concepts such as Ethereum, smart contracts, tokens, and consensus algorithms that are critical to the functioning of the cryptocurrency market.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
May 25, 2023·Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis, Seattle, WA, USA, Jul. 2023, pp. 373-384
36 cites
Definition and Detection of Defects in NFT Smart Contracts

Shuo Yang, Jiachi Chen, Zibin Zheng

Recently, the birth of non-fungible tokens (NFTs) has attracted great attention. NFTs are capable of representing users’ ownership on the blockchain and have experienced tremendous market sales due to their popularity. Unfortunately, the high value of NFTs also makes them a target for attackers. The defects in NFT smart contracts could be exploited by attackers to harm the security and reliability of the NFT ecosystem. Despite the significance of this issue, there is a lack of systematic work that focuses on analyzing NFT smart contracts, which may raise worries about the security of users’ NFTs. To address this gap, in this paper, we introduce 5 defects in NFT smart contracts. Each defect is defined and illustrated with a code example highlighting its features and consequences, paired with possible solutions to fix it. Furthermore, we propose a tool named NFTGuard to detect our defined defects based on a symbolic execution framework. Specifically, NFTGuard extracts the information of the state variables from the contract abstract syntax tree (AST), which is critical for identifying variable-loading and storing operations during symbolic execution. Furthermore, NFTGuard recovers source-code-level features from the bytecode to effectively locate defects and report them based on predefined detection patterns. We run NFTGuard on 16,527 real-world smart contracts and perform an evaluation based on the manually labeled results. We find that 1,331 contracts contain at least one of the 5 defects, and the overall precision achieved by our tool is 92.6%.

Open access
3 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
May 24, 2023·Applied Sciences
8 cites
Phishing Node Detection in Ethereum Transaction Network Using Graph Convolutional Networks

Zhen Zhang, Tao He, Kai Chen, Boshen Zhang · 6 authors

As the use of digital currencies, such as cryptocurrencies, increases in popularity, phishing scams and other cybercriminal activities on blockchain platforms (e.g., Ethereum) have also risen. Current methods of detecting phishing in Ethereum focus mainly on the transaction features and local network structure. However, these methods fail to account for the complexity of interactions between edges and the handling of large graphs. Additionally, these methods face significant issues due to the limited number of positive labels available. Given this, we propose a scheme that we refer to as the Bagging Multiedge Graph Convolutional Network to detect phishing scams on Ethereum. First, we extract the features from transactions and transform the complex Ethereum transaction network into three simple inter-node graphs. Then, we use graph convolution to generate node embeddings that leverage the global structural information of the inter-node graphs. Further, we apply the bagging strategy to overcome the issues of data imbalance and the Positive Unlabeled (PU) problem in transaction data. Finally, to evaluate our approach’s effectiveness, we conduct experiments using actual transaction data. The results demonstrate that our Bagging Multiedge Graph Convolutional Network (0.877 AUC) outperforms all of the baseline classification methods in detecting phishing scams on Ethereum.

Open access
2 source records
Spam and Phishing Detection
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Original source
May 21, 2023·arXiv (Cornell University)
1 cites
Streaming phishing scam detection method on Ethereum

Wenjia Yu, Yijun Xia, Jieli Liu, Jiajing Wu

Phishing is a widespread scam activity on Ethereum, causing huge financial losses to victims. Most existing phishing scam detection methods abstract accounts on Ethereum as nodes and transactions as edges, then use manual statistics of static node features to obtain node embedding and finally identify phishing scams through classification models. However, these methods can not dynamically learn new Ethereum transactions. Since the phishing scams finished in a short time, a method that can detect phishing scams in real-time is needed. In this paper, we propose a streaming phishing scam detection method. To achieve streaming detection and capture the dynamic changes of Ethereum transactions, we first abstract transactions into edge features instead of node features, and then design a broadcast mechanism and a storage module, which integrate historical transaction information and neighbor transaction information to strengthen the node embedding. Finally, the node embedding can be learned from the storage module and the previous node embedding. Experimental results show that our method achieves decent performance on the Ethereum phishing scam detection task.

Open access
3 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Imbalanced Data Classification Techniques
Original source
May 18, 2023·International Conference on Recent Academic Studies
13 cites
A Systematic Review of Blockchain-based Identity Management Solutions

Huda Seyam, Adib Habbal

The involvement of digital identity in almost all online services contributes to the growing reliance on Identity Management Systems (IDMS) that establish, verify, and manage digital identities. However, digital identities are still kept in central repositories. Which are controlled by a single authority that may have many vulnerabilities due to low security, leading attackers to exploit these vulnerabilities and causing various security breaches such as identity theft or disclosure of sensitive information. Additionally, powerful entities who have access to these repositories, could gather and abuse users' information without their knowledge or consent. The concept of Self-sovereign Identity (SSI) allows users to exert ownership of their identity and gain insight into how their data is being used. The development of Blockchain technology has made a breakthrough in achieving SSI by giving individuals the ability to be the final arbiter of who can access and use their own identity. This paper overviews the traditional identity management (IdM) models and presents the next generation of distributed IDMS using Blockchain technology that targets user-centricity and eliminates the identity provider as a trusted third party. Furthermore, It gives an analysis of the recent Blockchain-based IdM solutions, discussing their architecture, components, and features. It also, reveals their weaknesses to identify the gaps between these solutions for future secure IDMS.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Cryptography and Data Security
Original source
May 17, 2023·ACM Computing Surveys
55 cites
Security Aspects of Cryptocurrency Wallets—A Systematic Literature Review

Sabine Houy, Philipp Schmid, Alexandre Bartel

Cryptocurrencies are gaining prominence among individuals and companies alike, resulting in the growing adoption of so-called cryptocurrency wallet applications, as these simplify transactions. These wallets are available in a myriad of different forms and specifications. All of them are susceptible to various ways the attacker can exploit the vulnerabilities and steal money from victims. Cryptocurrency wallets create a unique field as they combine features of password managers, banking applications, and the need to keep their users and their transactions anonymous. We collect the findings from previous literature to provide an overview of the different attack surfaces, possible countermeasures, and further research. Existing literature focused on one of the features mentioned before, while we considered all of them. Our systematic study shows that there is a considerable variety of attack vectors, which we have divided into six subcategories, (i) Memory and Storage, (ii) Operating Systems, (iii) Software Layer, (iv) Network Layer, (v) Blockchain Protocol, and (vi) Others. We have found a large gap between the possible countermeasures and their actual adoption. Therefore, we provide a list of possible directions for future research to tackle this gap.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Spam and Phishing Detection
Original source
May 17, 2023·International Journal on Recent and Innovation Trends in Computing and Communication
7 cites
Web3 Chain Authentication and Authorization Security Standard (CAA)

Nilesh P. Sable, Rahul Ganpatrao Sonkamble, Vijay U. Rathod, Swati Shirke · 6 authors

Web3 is the next evolution of the internet, which uses blockchains, cryptocurrencies, and NFTs to return ownership and authority to the consumers. The potential of Web3 is highlighted by the creation of decentralized applications (dApps), which are more secure, transparent, and tamper-proof than their centralized counterparts, allowing for new business models that were previously impossible on the traditional internet.Web3 also focuses on user privacy, where users have more control over their personal data and can choose to share only what they want. The emergence of Web3 represents an exciting new frontier in blockchain technology, and its focus on decentralization, user privacy, and trustless systems has the potential to transform the way we interact with the internet.Web3 authentication is required for enhanced security, increased privacy, and simplified user interface. Traditional login procedures and an authorization flow using web3 authentication work together seamlessly. However, there are several challenges associated with Web3, including scalability and regulatory issues. Chain Authentication and Authorization (CAA) is a multi-layer security mechanism that allows users to choose the security layer that suits them, just like a heavy iron chain, where the user and CAA developers act as blacksmith and form their security protocol that suits them. CAA is a solution to the challenges associated with Web3 authentication and authorization, and it focuses on creating a secure and decentralized authentication and authorization system that is scalable, flexible, and user-friendly.

Open access
Privacy, Security, and Data Protection
Spam and Phishing Detection
Access Control and Trust
Original source
May 16, 2023·Applied Sciences
31 cites
Blockchain-Based Platform to Fight Disinformation Using Crowd Wisdom and Artificial Intelligence

Cristian Nicolae Buţincu, Adrian Alexandrescu

Disinformation and fake news are used by multiple actors to manipulate and influence the public with the purpose of gaining a series of advantages. This paper describes a promising solution to the increased spread of disinformation on the Internet. Our approach leverages blockchain technology combined with both crowd intelligence and federated artificial intelligence to develop efficient capabilities that address the disinformation phenomenon. The blockchain-based architecture of the platform creates a decentralized ecosystem that ensures transparency and trust, enabling the users to make correctly informed decisions in the face of disinformation. The key differentiating factor of the platform is the incorporation of both crowd and artificial intelligence in a system that can identify and respond to disinformation quickly and efficiently. The presented architecture can be used to build reactive and proactive platforms to effectively challenge disinformation.

Open access
Blockchain Technology Applications and Security
Misinformation and Its Impacts
Spam and Phishing Detection
Original source
May 13, 2023·Journal of risk and financial management
7 cites
Phishing Attacks on Cryptocurrency Investors in the Arab States of the Gulf

Marzooq Hadi Marzooq Alyami, Reem Alhotaylah, Sawsan Alshehri, Abdullah Alghamdi

With the rapid development of technology in all fields, including the financial field, people have flocked to invest in cryptocurrencies, sometimes without prior knowledge or experience. This has prompted hackers to prey on inexperienced investors through many types of fraud and attacks, especially phishing attacks. Cryptocurrency investment transactions take place without intermediaries such as banks and monetary institutions. Investing in cryptocurrencies is a form of peer-to-peer transaction and takes place without the involvement of physical wallets. This study addresses cases where people may become victims of phishing attacks due to the nature of cryptocurrency investments. The aim of this study was to understand the concepts of various phishing attacks on cryptocurrencies and to measure the awareness of cryptocurrency investors in the Arab Gulf countries regarding the security risks associated with cryptocurrency investments. This research was conducted by distributing a questionnaire among cryptocurrency investors and collecting and analyzing all the survey responses. The results reveal a lack of awareness about how to deal with the security risks associated with cryptocurrency investments. The research concludes that the majority of cryptocurrency investors are unaware of how to deal with phishing attacks. Finally, we address future research directions and recommend actions that can be taken to increase investors’ awareness of this issue.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
May 12, 2023·International Journal of Information Security
8 cites
Malicious uses of blockchains by malware: from the analysis to Smart-Zephyrus

Mar Gimenez-Aguilar, José M. de Fuentes, Lorena González‐Manzano

Abstract The permanent availability and relative obscurity of blockchains is the perfect ground for using them for malicious purposes. However, the use of blockchains by malwares has not been characterized yet. This paper analyses the current state of the art in this area. One of the lessons learned is that covert communications for malware have received little attention. To foster further defence-oriented research, a novel mechanism (dubbed Smart-Zephyrus) is built leveraging smart contracts written in Solidity. Our results show that it is possible to hide 4 Kb of secret in 41 s. While being expensive (around USD 1.82 per bit), the provided stealthiness might be worth the price for attackers.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Malware Detection Techniques
Original source
May 11, 2023·Research Square
2 cites
SSH-DAuth: Secret Sharing based Decentralized OAuth using Decentralized Identifier

Danda Prudhvi Krishna, R. Ramaguru, K. Praveen, M. Sethumadhavan · 7 authors

OAuth2.0 is a Single Sign-On approach that helps to authorize users to log into multiple applications without re-entering the credentials. Here, the OAuth service provider controls the central repository where data is stored, which may lead to third-party fraud and identity theft. To circumvent this problem, we need a distributed framework to authenticate and authorize the user without third-party involvement. This paper proposes a distributed authentication and authorization framework using a secret-sharing mechanism that comprises a blockchain-based decentralized identifier and a private distributed storage via an interplanetary file system. We implemented our proposed framework in Hyperledger Fabric (permissioned blockchain) and Ethereum TestNet (permissionless blockchain). Our performance analysis indicates that secret sharing-based authentication takes negligible time for generation and a combination of shares for verification. Moreover, security analysis shows that our model is robust, end-to-end secure, and compliant with the Universal Composability Framework.

Open access
2 source records
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Spam and Phishing Detection
Original source
May 10, 2023·Applied Sciences
4 cites
Non-Face-to-Face P2P (Peer-to-Peer) Real-Time Token Payment Blockchain System

Hyug-Jun Ko, Seong-Soo Han, Chang‐Sung Jeong

With the increase of intelligent voice phishing and the increasing reliance on open banking systems, there has been a rise in cases where individuals' personal information has been exposed, resulting in significant financial losses for the victims. Non-face-to-face transactions in the financial sector face challenges such as customer identification, ensuring transaction integrity, and preventing transaction rejection. Blockchain-based distributed ledgers have been proposed as a solution, but their adoption is limited due to the difficulty of managing private keys and the burden of gas fees management. This paper proposes a non-face-to-face P2P real-time token payment system that minimizes the risk of key loss by storing private keys in a keystore file and database through a server-based key management module. The proposed system simplifies token creation and management through a server-based token management module and implements an automatic gas charging function for smooth token transactions. Transaction integrity and non-repudiation are ensured through a transaction confirmation module that uses transaction IDs without exposing personal information. Furthermore, advanced security measures such as blocking foreign IP access and DDoS defense are implemented to securely protect user data. The proposed system aims to provide a convenient, secure, and accessible online payment solution to the public by implementing a self-authentication function using a web application that is not limited to smart phones or application platforms.

Open access
3 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Caching and Content Delivery
Original source
May 7, 2023·arXiv (Cornell University)
0 cites
Which Games are Unaffected by Absolute Commitments?

Daji Landis, Nikolaj I. Schwartzbach

We identify a subtle security issue that impacts mechanism design in scenarios in which agents can absolutely commit to strategies. Absolute commitments allow the strategy of an agent to depend on the commitments made by the other agents. This changes fundamental game-theoretic assumptions by inducing a meta-game in which agents choose which strategies they commit to. We say that a game that is unaffected by such commitments is Stackelberg resilient and show that computing it is intractible in general, although it can be computed efficiently for two-player games of perfect information. We show the intuitive, but technically non-trivial result, that, if a game is resilient when some number of players have the capacity to make commitments, it is also resilient when these commitments are available to fewer players. We demonstrate the non-triviality of Stackelberg resilience by analyzing two escrow mechanisms from the literature. These mechanisms have the same intended functionality, but we show that only one is Stackelberg resilient. Our model is particularly relevant in Web3 scenarios, where these absolute commitments can be realized by the automated and irrevocable nature of smart contracts. Our work highlights an important issue in ensuring the secure design of Web3. In particular, our work suggests that smart contracts already deployed on major blockchains may be susceptible to these attacks.

Open access
3 source records
cs.GT
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source
May 4, 2023·Iraqi Journal for Computer Science and Mathematics
8 cites
Security Attacks on E-Voting System Using Blockchain

Saba Abdulbaqi Salman, Sufyan Al-Janabi, Ali Makki Sagheer

Electronic voting has become popular in democratic countries, and thus the cyber security of this system is demanded. In this paper, some attacks were made on a proposed electronic election model based on blockchain technology, where the impact of each attack (Sybil, DDoS, Eclipse, Selfish mining, 51% attack) was calculated, and the time in which it achieved 51% of the attack was calculated. In this study, we investigate of Blockchain technology’s attack surface, focusing on general blockchains. The following factors show how these attacks have an impact on the proposed model: 1) The cryptographic architecture of the Blockchain. 2) The distributed architecture of systems using Blockchain. 3) The Blockchain application context. For each of these factors, we identify several attacks, including selfish mining, 51% attack, sybil attacks, eclipse attacks, distributed denial-of-service (DDos) attacks, consensus delay (due to selfish behavior or distributed denial-of-service attacks), blockchain forks, orphan blocks, block swallowing, wallet theft, smart contract attacks, and privacy attacks.

Open access
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Network Security and Intrusion Detection
Original source
May 4, 2023·Drones
22 cites
BCDAIoD: An Efficient Blockchain-Based Cross-Domain Authentication Scheme for Internet of Drones

Gongzhe Qiao, Yi Zhuang, Tong Ye, Qiao Yuan

During long-distance flight, unmanned aerial vehicles (UAVs) need to perform cross-domain authentication to prove their identity and receive information from the ground control station (GCS). However, the GCS needs to verify all drones arriving at the area it is responsible for, which leads to the GCS being unable to complete authentication in time when facing cross-domain requests from a large number of drones. Additionally, due to potential threats from attackers, drones and GCSs are likely to be deceived. To improve the efficiency and security of cross-domain authentication, we propose an efficient blockchain-based cross-domain authentication scheme for the Internet of Drones (BCDAIoD). By using a consortium chain with a multi-chain architecture, the proposed method can query and update different types of data efficiently. By mutual authentication before cross-domain authentication, drones can compose drone groups to lighten the authentication workload of domain management nodes. BCDAIoD uses the notification mechanism between domains to enable path planning for drones in advance, which can further improve the efficiency of cross-domain authentication. The performance of BCDAIoD was evaluated through experiments. The results show that the cross-domain authentication time cost and computational overhead of BCDAIoD are significantly lower those of than existing methods when the number of drones is large.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Spam and Phishing Detection
Original source