Latifah Almuqren, Khalid Mahmood, Sumayh S. Aljameel, Ahmed S. Salama · 6 authors
The Internet of Things (IoT) refers to a technology enabler to enhance the urban physical architecture and render public services. But, public access to accumulated heterogeneous IoT urban information is prone to hackers attacking connected devices to the internet intellectual property as well. IoT security serves a dynamic part in the smart city. Some IoT devices are connected in smart homes, and these connections were centred on gateways. In smart homes, the gateways gain a lot of significance; but their centralized structure causes many security vulnerabilities like availability, integrity, and certification. Unified “cloud-like” computing networks and Blockchain (BC) type systems should be used to sort out these problems. Therefore, this article develops a Blockchain-Assisted Secure Smart Home Network using Gradient Based Optimizer with Hybrid Deep Learning (BSSHN-GBOHDL) model. The presented BSSHN-GBOHDL technique employs BC technology to improve the confidentiality of the data in the smart home environment. In addition, the BSSHN-GBOHDL technique identifies malicious activities in the smart home environment via three sub-processes namely data preprocessing, hybrid deep learning (HDL)-based malicious activity classification, and GBO-based hyperparameter tuning. The GBO algorithm assists in the proficient hyperparameter selection of the HDL model, which aids in accomplishing increased detection efficiency. The experimental validation of the BSSHN-GBOHDL approach is tested on a benchmark NSL-KDD dataset with 65495 normal and 60743 attack samples. The results highlight the betterment of the BSSHN-GBOHDL approach over other recent methods with maximum accuracy of 98.29%.
S Sheela, S. Shalini, D Sai Harsha, Vani Chandrashekar · 5 authors
This research introduces an approach to detect malware attacks using blockchain technology that integrates signature-based and behavioralbased methods. The proposed system uses a decentralized blockchain network to share and store malware signatures and behavioral patterns. This enables faster and more efficient detection of new malware files. The signature-based method involves storing the signatures in the blockchain and the sharing of the signature of malware files among the user nodes of the p2p blockchain network, while the behavioral-based approach analyzes the behavior and actions of files in a separate virtualized environment to identify suspicious patterns. This system addresses the limitations of conventional signature-based methods, which can be evaded by polymorphic malware, and behavioral-based methods, which may generate false positives. The results of the evaluation indicate that the proposed system achieves high detection rates while maintaining low false positives. Overall, the proposed system offers an effective and efficient approach to malware detection by utilizing the strengths of both signature-based and behavioral-based methods and utilizing the security and transparency benefits of blockchain technology.
Ahmed A. M. Sharadqh, Hazem Hatamleh, As’ad Mahmoud As’ad Alnaser, Said S. Saloum · 5 authors
Internet of Things (IoT) is an emerging technology and its applications are flattering amidst many users, as it makes everything easier. As a consequence of its massive growth, security and privacy are becoming crucial issues where the IoT devices are perpetually vulnerable to cyber-attacks. To overcome this issue, intrusion detection and mitigation is accomplished which enhances the security in IoT networks. In this paper, we proposed Blockchain entrenched Bi-level intrusion detection and graph based mitigation framework named as HybridChain-IDS. The proposed work embrace four sequential processes includes time-based authentication, user scheduling and access control, bi-level intrusion detection and attack graph generation. Initially, we perform time-based authentication to authenticate the legitimate users using NIK-512 hashing algorithm, password and registered time are stored in Hybridchain which is an assimilation of blockchain and Trusted Execution Environment (TEE) which enhances data privacy and security. After that, we perform user scheduling using Cheetah Optimization Algorithm (COA) which reduces the complexity and then the access control is provided to authorized users by smart contract by considering their trust and permission level. Then, we accomplish bi-level intrusion detection using ResCapsNet which extracts sufficient features and classified effectively. Finally, risk of the attack is evaluated, and then the attacks graphs are generated by employing Enhanced k-nearest neighbor (KNN) algorithm to identify the attack path. Furthermore, the countermeasures are taken based on the attack risk level and the attack graph is stored in Hybridchain for eventual attack prediction. The implementation of this proposed work is directed by network simulator of NS-3.26 and the performance of the proposed HybridChain-IDS is enumerated based on various performance metrics.
Metaverse is expected to rely on massive Internet of Things (IoT) connections so it inherits various security threats from the IoT network and also faces other sophisticated attacks related to virtual reality technology. As traditional security approaches show various limitations in the large-scale distributed metaverse, this paper proposes MetaCIDS, a novel collaborative intrusion detection (CID) framework that leverages metaverse devices to collaboratively protect the metaverse. In MetaCIDS, a federated learning (FL) scheme based on unsupervised au-toencoder and an attention-based supervised classifier enables metaverse users to train a CID model using their local network data, while the blockchain network allows metaverse users to train a machine learning (ML) model to detect intrusion network flows over their monitored local network traffic, then submit verifiable intrusion alerts to the blockchain to earn metaverse tokens. Security analysis shows that MetaCIDS can efficiently detect zero-day attacks, while the training process is resistant to SPoF, data tampering, and up to 33% poisoning nodes. Performance evaluation illustrates the efficiency of MetaCIDS with 96% to 99% detection accuracy on four different network intrusion datasets, supporting both multi-class detection using labeled data and anomaly detection trained on unlabeled data.
An IoT healthcare system refers to the use of Internet of Things (IoT) devices and technologies in the healthcare industry. It involves the integration of various interconnected devices, sensors, and systems to collect, monitor, and transmit health-related data for medical purposes. Blockchain-assisted intrusion detection on IoT healthcare systems is an innovative approach to enhancing the security and privacy of sensitive medical data. By combining the decentralized and immutable nature of blockchain technology with intrusion detection systems (IDS), it is possible to create a more robust and trustworthy security framework for IoT healthcare systems. With this motivation, this study presents Blockchain Assisted IoT Healthcare System using Ant Lion Optimizer with Hybrid Deep Learning (BHS-ALOHDL) technique. The presented BHS-ALOHDL technique enables IoT devices in the healthcare sector to transmit medical data securely and detects intrusions in the system. To accomplish this, the BHS-ALOHDL technique performs ALO based feature subset selection (ALO-FSS) system to produce a series of feature vectors. The HDL model integrates convolutional neural network (CNN) features and long short-term memory (LSTM) model for intrusion detection. Lastly, the flower pollination algorithm (FPA) is exploited for the optimal hyperparameter tuning of the HDL approach, which results in an enhanced detection rate. The experimental outcome of the BHS-ALOHDL system was tested on two benchmark datasets and the outcomes indicate the promising performance of the BHS-ALOHDL technique over other models.
Zahoor Ali Khan, Sana Amjad, Farwa Ahmed, Abdullah M. Almasoud · 6 authors
Over the past few years, great importance has been given to wireless sensor networks (WSNs) as they play a significant role in facilitating the world with daily life services like healthcare, military, social products, etc. However, heterogeneous nature of WSNs makes them prone to various attacks, which results in low throughput, and high network delay and high energy consumption. In the WSNs, routing is performed using different routing protocols like low-energy adaptive clustering hierarchy (LEACH), heterogeneous gateway-based energy-aware multi-hop routing (HMGEAR), etc. In such protocols, some nodes in the network may perform malicious activities. Therefore, four deep learning (DL) techniques and a real-time message content validation (RMCV) scheme based on blockchain are used in the proposed network for the detection of malicious nodes (MNs). Moreover, to analyse the routing data in the WSN, DL models are trained on a state-of-the-art dataset generated from LEACH, known as WSN-DS 2016. The WSN contains three types of nodes: sensor nodes, cluster heads (CHs) and the base station (BS). The CHs after aggregating the data received from the sensor nodes, send it towards the BS. Furthermore, to overcome the single point of failure issue, a decentralized blockchain is deployed on CHs and BS. Additionally, MNs are removed from the network using RMCV and DL techniques. Moreover, legitimate nodes (LNs) are registered in the blockchain network using proof-of-authority consensus protocol. The protocol outperforms proof-of-work in terms of computational cost. Later, routing is performed between the LNs using different routing protocols and the results are compared with original LEACH and HMGEAR protocols. The results show that the accuracy of GRU is 97%, LSTM is 96%, CNN is 92% and ANN is 90%. Throughput, delay and the death of the first node are computed for LEACH, LEACH with DL, LEACH with RMCV, HMGEAR, HMGEAR with DL and HMGEAR with RMCV. Moreover, Oyente is used to perform the formal security analysis of the designed smart contract. The analysis shows that blockchain network is resilient against vulnerabilities.
Blockchain technology has gained significant attention as a secure and decentralized platform for various applications. However, the immutable and distributed nature of blockchain also presents unique challenges for detecting anomalies and suspicious activities within the network. This research paper proposes a novel approach to anomaly detection in blockchain using machine learning techniques. The goal of this study is to develop an effective and scalable anomaly detection framework that can analyze the vast amount of data generated within a blockchain network and identify irregularities or potential security threats. The proposed framework leverages the power of machine learning algorithms to learn patterns, relationships, and behaviours from historical blockchain data, enabling the detection of anomalous activities in real time.The research paper first focuses on feature extraction techniques tailored specifically for blockchain data. These techniques consider key characteristics of blockchain transactions, such as transaction size, timestamp, and involved addresses, to construct meaningful features that capture the underlying patterns and trends. Various dimensionality reduction techniques are also explored to handle the high-dimensional nature of blockchain data.Subsequently, several machine learning algorithms, including clustering, classification, and anomaly detection methods, are employed to train models using the extracted features. The performance of different algorithms is evaluated using benchmark datasets and real-world blockchain data to assess their accuracy, precision, and recall in detecting anomalies. Additionally, the scalability of the proposed framework is investigated to ensure its effectiveness in large-scale blockchain networks.Furthermore, the research paper investigates the integration of domain-specific knowledge, such as known attack patterns and regulatory compliance rules, into the anomaly detection framework. This hybrid approach combines the strengths of machine learning algorithms with expert knowledge to enhance the accuracy and interpretability of anomaly detection results.The experimental results demonstrate that the proposed anomaly detection framework achieves promising performance in identifying various types of anomalies in blockchain data. It exhibits high detection rates while minimizing false positives, thereby providing valuable insights for blockchain network administrators and regulators to mitigate security risks and safeguard the integrity of blockchain systems. In conclusion, this research paper presents an innovative approach to anomaly detection in blockchain using machine learning. The proposed framework addresses the unique challenges posed by blockchain's decentralized and immutable nature, offering an effective solution for detecting suspicious activities and ensuring the security of blockchain networks. The findings of this study contribute to the growing field of blockchain analytics and have significant implications for real-world blockchain applications in domains such as finance, supply chain management, and healthcare.
Muhammad Nouman, U. Qasim, Hina Nasir, Abdullah M. Almasoud · 6 authors
In the proposed work, blockchain is implemented on the Base Stations (BSs) and Cluster Heads (CHs) to register the nodes using their credentials and also to tackle various security issues. Moreover, a Machine Learning (ML) classifier, termed as Histogram Gradient Boost (HGB), is employed on the BSs to classify the nodes as malicious or legitimate. In case, the node is found to be malicious, its registration is revoked from the network. Whereas, if a node is found to be legitimate, then its data is stored in an Interplanetary File System (IPFS). IPFS stores the data in the form of chunks and generates hash for the data, which is then stored in blockchain. In addition, Verifiable Byzantine Fault Tolerance (VBFT) is used instead of Proof of Work (PoW) to perform consensus and validate transactions. Also, extensive simulations are performed using the Wireless Sensor Network (WSN) dataset, referred as WSN-DS. The proposed model is evaluated both on the original dataset and the balanced dataset. Furthermore, HGB is compared with other existing classifiers, Adaptive Boost (AdaBoost), Gradient Boost (GB), Linear Discriminant Analysis (LDA), Extreme Gradient Boost (XGB) and ridge, using different performance metrics like accuracy, precision, recall, micro-F1 score and macro-F1 score. The performance evaluation of HGB shows that it outperforms GB, AdaBoost, LDA, XGB and Ridge by 2-4%, 8-10%, 12-14%, 3-5% and 14-16%, respectively. Moreover, the results with balanced dataset are better than those with original dataset. Also, VBFT performs 20-30% better than PoW. Overall, the proposed model performs efficiently in terms of malicious node detection and secure data storage.
Stephen W. Turner, Murat Karakuş, Evrim Güler, Suleyman Uludag
The state of computer network technologies has continually advanced at a rapid pace. Software Defined Networking (SDN) and Blockchain (BC) have emerged as complementary technologies providing support that facilitates greater security and greater network performance for many domains of application, including the Internet of Things (IoT) ecosystem, ideally resulting in an improvement in our collective quality of life. The proliferation of IoT devices, driven by a wide variety of use cases and its ubiquitous availability, combined with the emergence of SDN and BC, presents rich opportunities for various emerging research efforts. This paper presents a comprehensive survey of the studies in which BC and SDN have been integrated into the IoT ecosystem, referred to hereafter as BC-enabled Software- Defined IoT (BC-SDIoT). First, we discuss the motivations and drivers for integrating BC-enabled SDN and BC-SDIoT, as well as the benefits and drawbacks. Second, we categorize the relevant studies according to six key implementation objectives and ideas that combine BC, SDN, and IoT technologies to create smart, secure, and effective frameworks: Security, computing paradigms (edge and fog computing), trust management, access control & authentication, privacy, and networking. In the corresponding sections, we present the categories (i.e., problem domains) of the aforementioned novel taxonomy and discuss related studies (i.e., solutions) in depth. Finally, we outline potential major challenges, open issues, and future prospects that require further research attention and intensive endeavors for complete and ground-breaking frameworks to broaden newer research domains in BC-SDIoT. This survey paper may be a fruitful primer for a reader investigating the exploitation of BC in SDN and IoT ecosystems.
The year 2020 saw remarkable domination of Android devices. Android’s large share of the global market (85%) places it first in the list of preferred targets for mobile cybercrime. Computer attacks try to control and access confidential user information by exploiting the various vulnerabilities present in the various components of the Android ecosystem. This thesis aims to propose a new Framework named ANDROSCANREG (Android Permissions Scan Registry) which incorporates an extensible approach for analyzing Android applications initially based on permissions and deployed in a decentralized and distributed system. The mentioned framework is based on the emerging technology called "Blockchain" whose potential is approved for transparency, availability, security, and reliability without resorting to a central trusted entity. Furthermore, in our efforts to improve the implementation of this Framework, we have proposed a new consensus algorithm called "Proof of Conformity -PoC-" in order to improve the reliability of consensus algorithms whose node weight calculation is based on one (or more) distinctive measurable criterion (stake, power, etc.). This improvement relates to the addition of a new impact factor called "Node Security Metric (NSM)" in the calculation of the node weight. NSM is primarily based on the weight recalculation of each network node based on the security and stability of its respective software and hardware environment. PoC weight recalculation is based on Common Vulnerability Scoring System (CVSS) vulnerabilities, our new approach aims to strengthen the node security index and encourage participants, respecting the recommended security requirements, to take advantage of their proactivity, vigilance, and compliance by increasing their chance of being selected as a Leader (validator) and winning rewards corresponding to the effort deployed. Besides, PoC has been theoretically evaluated via simulation scenarios through which significant results have been obtained showing that our approach ensures more likelihood for the more secure participating nodes to be designated as a validator based on their compliance rates represented by their NSM scores. Moreover, we thought as part of our research axis to equitably reward active participants. Indeed, we have presented a new approach for calculating rewards and penalties for systems based on Blockchain technology. The objective of our proposal is to ensure a new source of income in order to retain participants by guaranteeing them permanent profitability in exchange for their active participation in the stability and security of the Blockchain network to which they belong. We have studied and analyzed existing systems that, in general, favor the monopoly of rewards by attributing them either only to the Leader node (elected by a consensus algorithm) or benefit the Leader from a large part of the rewards and distributing the rest to a shortlist of participants. The result of our study shows that our approach offers more benefits by ensuring permanent, dynamic, and proportional rewards for all participating nodes according to their scores and compliance rate, the latter impacts the gradual penalty system put in place, which verifies the compliance of each node to the Blockchain protocol rules. A new innovative concept of operations execution in a Blockchain network was also proposed in this thesis. Indeed, the new approach improves the traditional data validation processes opted by Blockchain-based systems by allowing their nodes to adopt different and modifiable environments at any time in order to reduce the false positive rate and help identify polymorphic treatments and thus improve the reliability of the final results.
T. Sathya, N Keertika, Sirikonda Shwetha, Deepti Upodhyay · 5 authors
In recent years, ransomware attacks have become a more significant source of computer penetration. Only general-purpose computing systems with sufficient resources have been harmed by ransomware so far. Numerous ransomware prediction strategies have been published, but more practical machine learning ransomware prediction techniques still need to be developed. In order to anticipate ransomware assaults, this study provides a method for obtaining data from artificial intelligence and machine learning systems. A more accurate model for outcome prediction is produced by using the data science methodology. Understanding the data and identifying the variables are essential elements of a successful model. A variety of machine learning algorithms are applied to the pre-processed data, and the accuracy of each technique is compared to determine which approach performed better. Additional performance indicators including recall, accuracy, and f1-score are also taken into account while evaluating the model. It uses machine learning to predict how the ransomware attack would pan out.
A. Gómez Ramírez, Loui Al Sardy, Francis Gomez Ramirez
Blockchain security is becoming increasingly relevant in today's cyberspace as it extends its influence in many industries. This paper focuses on protecting the lowest level layer in the blockchain, particularly the P2P network that allows the nodes to communicate and share information. The P2P network layer may be vulnerable to several families of attacks, such as Distributed Denial of Service (DDoS), eclipse attacks, or Sybil attacks. This layer is prone to threats inherited from traditional P2P networks, and it must be analyzed and understood by collecting data and extracting insights from the network behavior to reduce those risks. We introduce Tikuna, an open-source tool for monitoring and detecting potential attacks on the Ethereum blockchain P2P network, at an early stage. Tikuna employs an unsupervised Long Short-Term Memory (LSTM) method based on Recurrent Neural Network (RNN) to detect attacks and alert users. Empirical results indicate that the proposed approach significantly improves detection performance, with the ability to detect and classify attacks, including eclipse attacks, Covert Flash attacks, and others that target the Ethereum blockchain P2P network layer, with high accuracy. Our research findings demonstrate that Tikuna is a valuable security tool for assisting operators to efficiently monitor and safeguard the status of Ethereum validators and the wider P2P network
The rapid evolution of the Internet, particularly the emergence of Web3, has transformed the ways people interact and share data. Web3, although still not well defined, is thought to be a return to the decentralization of corporations' power over user data. Despite the obsolescence of the idea of building systems to detect and prevent cyber intrusions, this is still a topic of interest. This paper proposes a novel conceptual approach for implementing decentralized collaborative intrusion detection networks (CIDN) through a proof-of-concept. The study employs an analytical and comparative methodology, examining the synergy between cutting-edge Web3 technologies and information security. The proposed model incorporates blockchain concepts, cyber non-fungible token (cyberNFT) rewards, machine learning algorithms, and publish/subscribe architectures. Finally, the paper discusses the strengths and limitations of the proposed system, offering insights into the potential of decentralized cybersecurity models.
Traditional techniques for smart contract vulnerability detection rely on fixed expert criteria to discover vulnerabilities, which are less generalizable, scalable, and accurate. Deep learning algorithms help to address these issues, but most fail to encode true expert knowledge and remain interpretable. In this paper, we present a smart contract vulnerability detection mechanism that operates in phases with graph neural networks and expert patterns in deep learning to mutually address the deficiencies of the two detection approaches and improve smart contract vulnerability detection capabilities. Experiments show that our vulnerability detection mechanism outperforms the original deep learning model by an average of 6 points in detecting vulnerabilities and that the second stage of the checking mechanism can also block contract transactions containing dangerous actions at the Ethernet Virtual Machine (EVM) level and generate error reports for submission. This strategy helps to construct more stable smart contracts and to create a secure environment for smart contracts.
DeFi, a decentralized financial service based on blockchain, not only provides innovative financial services, but also poses various risks, such as the Terra Luna crash. Therefore, anomaly detection in DeFi is necessary to ensure the safety and reliability of the DeFi ecosystem. However, this is very difficult because of the complex protocol, interaction among smart contracts, and high market volatility. In this study, we propose a novel method to effectively detect anomalies in DeFi. To the best of our knowledge, this is the first study that utilizes deep learning to detect anomalies in DeFi. We propose a deep learning model, anomaly VAE-Transformer, which combines the variational autoencoder to extract local information in the short term, and the transformer, to identify dependencies between data in the long term. Based on a deep understanding of DeFi protocols, the proposed model collects and analyzes various on-chain data of Olympus DAO, a representative DeFi protocol, for extracting features suitable for anomaly detection. Then, we demonstrate the superiority of the proposed model by analyzing four anomaly cases detected successfully by the proposed model in Olympus DAO. A malicious attack attempt and structural changes in DeFi protocols can be identified quickly using the proposed method; this is expected to help protect the assets of DeFi users and improve the safety, reliability, and transparency of the DeFi market. The dataset and codes are available athttps://github.com/fialle/Anomaly-VAE-Transformer
Numerous abnormal transactions have been exposed as a result of targeted attacks on Ethereum, such as the Ethereum Decentralized Autonomous Organization attack. Exploiting vulnerabilities in smart contracts, malicious users can pursue their own illicit objectives through abnormal transactions. Consequently, identifying these malevolent users, implicated in fraudulent activities and their attribution, becomes exceedingly complex. Cryptocurrency transactions used for malicious purposes, employing pseudo-anonymous accounts to send and receive ransom payments and accumulating funds under various identities, further highlight the need to control and detect these abnormal transactions for maintaining a high level of security within the Ethereum network. Although existing Intrusion Detection Systems (IDSs) help mitigate abnormal transaction occurrences, their performance necessitates improvement. To address this issue, this study presents a novel approach, named Abnormal Transactions Detection Using a Semi-Supervised Generative Adversarial Network (ATD-SGAN), which efficiently detects abnormal attacks within the Ethereum network. ATD-SGAN leverages a semi-supervised generative adversarial network for this purpose. The results demonstrate that ATD-SGAN significantly enhances the performance of state-of-the-art IDSs. It achieves an increase in detection accuracy from 3.78% to 11.05% and reduces the false alarm rate from 42.29% to 0.15%. Moreover, ATD-SGAN notably improves the F1-measure, ranging from 10.39% to 3.79%, compared to the current IDSs.
Abstract Intelligent and networked vehicles help build an efficient vehicular network's infrastructure. The widespread use of electronic software exposes these networks to cyber‐attacks. Intrusion detection systems (IDS) are useful for preventing vehicle network assaults. IDS have been customized using machine and deep learning networks for greater real‐time performance. Current learning‐based intrusion detection systems demand substantial processing capabilities to train and update intricate training models in vehicular devices, resulting in decreased efficiency and ability to defend against assaults. This study presents Blockchain‐based Multi‐Layer Federated Extreme Learning Machines (MLFEM) enabled IDS (BEF‐IDS) for safe data transfers. The proposed IDS leverages federated learning to generate Multi‐Layered Extreme Learning Machines, which are offloaded to dispersed vehicular edge devices such as Road‐Side Units (RSU) and connected vehicles. This federated strategy decreases resource use without sacrificing security. Blockchain technology records and shares training models, assuring network security. Using real‐time data sets, the suggested algorithm's performance under different attack scenarios were extensively tested. The suggested method obtained 98% accuracy and Recall, 97.9% Precision, and 97.9% F1 Score performance, which suggests it's incredibly secure and costs very little to transmit.
The issue of creating an information security system is very relevant in the world today. One of the urgent tasks is to solve the issues of effective protection of information from both external and internal threats through the creation and implementation of information security management systems in automated systems of enterprises, which, among other things, requires the formalization of the task of protecting information for its subsequent implementation by software and other means. Now there are security analysis systems, for example, that examine the security elements settings of workstations and servers operating systems, analyze the network topology, look for unprotected network connections, examine the settings of firewalls. The disadvantage of these systems is that they are not suitable for monitoring large volumes of network traffic. The solution to this problem is the use of monitoring tools capable of analyzing large amounts of data in real time. Therefore, a significant place in the article is given to the review of developments based on artificial intelligence technologies, namely multi-agent systems, review of information security models, threat risk assessment in automated systems.
 The functional architecture of the information security management system based on a multi-agent system has been proposed to search in real time for information security optimal solutions through the selection of such coalitions of protection mechanisms agents that will allow to build the optimal protection of the automated system according to the selected criteria. The model with complete overlapping of threats has been substantiated and adopted as a basis, which allows to analyze the overall situation and choose strategically important decisions directly during the organization of information security. The essence of of multi-agent systems functioning that implement a decentralized control system based on the work of autonomous agents that can be implemented programmatically has been revealed. The role of threat agents, resource agents, agents of protection mechanisms and their functional purpose have been defined. The problem of searching a set of protection mechanisms agents coalition for the current state of the automated system as a problem of optimal search by the criterion of protection cost, taking into account the value of information, has been generalized. Due to the modularity of the multi-agent system, the further work will be aimed at detailing its components and perfection.
Ran Guo, Weijie Chen, Lejun Zhang, Guopeng Wang · 5 authors
Blockchain technology is currently evolving rapidly, and smart contracts are the hallmark of the second generation of blockchains. Currently, smart contracts are gradually being used in power system networks to build a decentralized energy system. Security is very important to power systems and attacks launched against smart contract vulnerabilities occur frequently, seriously affecting the development of the smart contract ecosystem. Current smart contract vulnerability detection tools suffer from low correct rates and high false positive rates, which cannot meet current needs. Therefore, we propose a smart contract vulnerability detection system based on the Siamese network in this paper. We improved the original Siamese network model to perform smart contract vulnerability detection by comparing the similarity of two sub networks with the same structure and shared parameters. We also demonstrate, through extensive experiments, that the model has better vulnerability detection performance and lower false alarm rate compared with previous research results.
We study security-latency bounds for Nakamoto consensus, i.e., how secure a block is after it becomes k-deep in the chain. We improve the state-of-the-art bounds by analyzing the race between adversarial and honest chains in three different phases. We find the probability distribution of the growth of the adversarial chains under models similar to those in Guo and Ren (2022) when a target block becomes k-deep in the chain. We analyze certain properties of this race to model each phase with random walks that provide tighter bounds than the existing results. Combining all three phases provides novel upper and lower bounds for blockchains with small$\lambda \Delta $.
Due to the surging popularity of various cryptocurrencies in recent years, a large number of browser extensions have been developed as portals to access relevant services, such as cryptocurrency exchanges and wallets. This has stimulated a wild growth of cryptocurrency themed malicious extensions that cause heavy financial losses to the users and legitimate service providers. They have shown their capability of evading the stringent vetting processes of the extension stores, highlighting a lack of understanding of this emerging type of malware in our community. In this work, we conduct the first systematic study to identify and characterize cryptocurrency-themed malicious extensions. We monitor seven official and third-party extension distribution venues for 18 months (December 2020 to June 2022) and have collected around 3600 unique cryptocurrency-themed extensions. Leveraging a hybrid analysis, we have identified 186 malicious extensions that belong to five categories. We then characterize those extensions from various perspectives including their distribution channels, life cycles, developers, illicit behaviors, and illegal gains. Our work unveils the status quo of the cryptocurrency-themed malicious extensions and reveals their disguises and programmatic features on which detection techniques can be based. Our work serves as a warning to extension users, and an appeal to extension store operators to enact dedicated countermeasures. To facilitate future research in this area, we release our dataset of the identified malicious extensions and open-source our analyzer.
Recently, the Internet of Things (IoT) has gained tremendous popularity in several realms such as smart cities, healthcare, industrial automation, etc. IoT networks are increasing rapidly, containing heterogeneous devices that offer easy and user-friendly services via the internet. With the big shift to IoT technology, the security of IoT networks has become a primary concern, especially with the lack of intrinsic security mechanisms regarding the limited capabilities of IoT devices. Therefore, many studies have been interested in enhancing the security of IoT networks. IoT networks need a scalable, decentralized, and adaptive defense system. Although the area of development provides advanced security solutions using AI and Blockchain, there is no systematic and comprehensive study talking about the convergence between AI and Blockchain to secure IoT networks. In this paper, we focus on reviewing and comparing recent studies that have been proposed for detecting cybersecurity attacks in IoT environments. This paper address three research questions and highlights the research gaps and future directions. This paper aims to increase the knowledge base for enhancing IoT security, recommend future research, and suggest directions for future research.