Abebe Diro, Lu Lu Zhou, Akanksha Saini, Shahriar Kaisar · 5 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
824 results · page 15 of 35
Abebe Diro, Lu Lu Zhou, Akanksha Saini, Shahriar Kaisar · 5 authors
No abstract is available for this record.
Sulyab Thottungal Valapu, Tamoghna Sarkar, Jared Coleman, Anusha Avyukt · 8 authors
We introduce DARSAN, a decentralized review system designed for Non-Fungible Token (NFT) marketplaces, to address the challenge of verifying the quality of highly resalable products with few verified buyers by incentivizing unbiased reviews. DARSAN works by iteratively selecting a group of reviewers (called ``experts'') who are likely to both accurately predict the objective popularity and assess some subjective quality of the assets uniquely associated with NFTs. The system consists of a two-phased review process: a ``pre-listing'' phase where only experts can review the product, and a ``pre-sale'' phase where any reviewer on the system can review the product. Upon completion of the sale, DARSAN distributes incentives to the participants and selects the next generation of experts based on the performance of both experts and non-expert reviewers. We evaluate DARSAN through simulation and show that, once bootstrapped with an initial set of appropriately chosen experts, DARSAN favors honest reviewers and improves the quality of the expert pool over time without any external intervention even in the presence of potentially malicious participants.
Myles Lewis
As time progresses, the need for more secure applications grows exponentially. The different types of sensitive information that is being transferred virtually has sparked a rise in systems that leverage blockchain. Different sectors are beginning to use this disruptive technology to evaluate the risks and benefits. Sectors like finance, medicine, higher education, and wireless communication have research regarding blockchain. Futhermore, the need for security standards in this area of research is pivotal. In recent past, several attacks on blockchain infrastructures have resulted in hundreds of millions dollars lost and sensitive information compromised. Some of these attacks include DAO attacks, bZx attacks, and Parity Multisignature Wallet Double Attacks which targeted vulnerabilities within smart contracts on the Ethereum network. These attacks exposed the weaknesses of current smart contract development practices which has led to the increase in distrust and adoption of systems that leverage blockchain for its functionality. In this paper, I identify common software vulnerabilities and attacks on blockchain infrastructures, thoroughly detail the smart contract development process and propose a model for ensuring a stronger security standard for future systems leveraging smart contracts. The purpose for proposing a model is to promote trust among end users in the system which is a foundational element for blockchain adoption in the future.
Jing Wang, Senkai Wu, Hai Liang, Yong Ding · 5 authors
Aim: A blockchain provides data consistency and builds a fair mining environment for a network by using a consensus mechanism such as proof of work (PoW) and proof of stake. However, selfish mining is a well-known mining attack. It can reduce the fairness and destabilize the network, especially for a PoW-based blockchain. Therefore, in this paper, we propose a new approach, named the adaptive mining difficulty adjustment protocol, which can deter a selfish attack. Methods: We propose using the unit profit as an improved version of the relative revenue, because it is more flexible for calculating the miners’ profits in different periods and can be used to analyze repeated mining games. Based on the unit profit, we propose using the adaptive mining-difficulty adjustment protocol to reduce an attacker’s profit. Our protocol evaluates the effective hash power in a network more accurately and corrects the mining difficulty. Moreover, we introduce the discount factor and model the long-term profit to analyze the impact of a miner’s patience on its future profit. Results: We used an open-source simulator to simulate the competition between a selfish miner and an honest miner and determined their profits under different protocols. Our experimental results show that our protocol can effectively raise the attack threshold, but it reduces the total network profit if the attacker still attacks. However, the long-term profit model shows that a more patient attacker needs to invest more hash power and pay increased mining costs to maintain its attack. Conclusion: We conclude that, under our protocol, selfish attackers will tend to become honest miners if their hash power does not exceed the threshold, which means that our protocol can effectively deter selfish attacks and some variants of selfish attacks. Briefly, our protocol can correct the mining difficulty and leads to a more stable and fairer mining environment for a PoW-based blockchain.
Suparat Srifa, Yury Yanovich, Ahmad Salehi Shahraki, Robert Vasilyev · 6 authors
No abstract is available for this record.
Yousra Belfaik, Yassine Sadqi, Yassine Maleh, Safi Said · 6 authors
OpenID Connect (OIDC) is one of the most widely used delegated authentication protocols in web and mobile applications providing a single sign-on experience. It allows third-party applications, called Relying Parties (RP), to securely request and receive information about authenticated sessions and end-users from an identity provider. The OIDC specification defines several parameters, including the client_id, client_secret, authorization code, access token, id token, state, and redirect_uri, as keys to the protocol operation, with significant security and privacy implications. Therefore, securing these parameters is critical to prevent attackers from impersonating legitimate entities, gaining unauthorized access, having complete control over users’ accounts, and/or violating their privacy. To enhance OIDC security and preserve its users’ privacy, we propose a novel model for OIDC based on the Ethereum Blockchain and the non-fungible token (ERC721) standard. To prove the robustness and safety of the proposed system, we perform a detailed security analysis formally using the most widely accepted protocols security verification tools, AVISPA and Scyther, and informally by discussing various attacks. The analysis results show that the proposed system is resilient against well-known attacks. Furthermore, we evaluate the cost and performance of the proposed solution, confirming its affordability and assuring that our approach does not impact the user experience and performance of existing OIDC-based systems. Finally, we conduct a security and privacy comparative analysis with similar existing systems, proving the superiority and efficiency of our proposed Blockchain-based OIDC system.
Chidimma Opara, Yingke Chen, Bo Wei
No abstract is available for this record.
A. Gómez Ramírez, Loui Al Sardy, Francis Gomez Ramirez
Blockchain security is becoming increasingly relevant in today's cyberspace as it extends its influence in many industries. This paper focuses on protecting the lowest level layer in the blockchain, particularly the P2P network that allows the nodes to communicate and share information. The P2P network layer may be vulnerable to several families of attacks, such as Distributed Denial of Service (DDoS), eclipse attacks, or Sybil attacks. This layer is prone to threats inherited from traditional P2P networks, and it must be analyzed and understood by collecting data and extracting insights from the network behavior to reduce those risks. We introduce Tikuna, an open-source tool for monitoring and detecting potential attacks on the Ethereum blockchain P2P network, at an early stage. Tikuna employs an unsupervised Long Short-Term Memory (LSTM) method based on Recurrent Neural Network (RNN) to detect attacks and alert users. Empirical results indicate that the proposed approach significantly improves detection performance, with the ability to detect and classify attacks, including eclipse attacks, Covert Flash attacks, and others that target the Ethereum blockchain P2P network layer, with high accuracy. Our research findings demonstrate that Tikuna is a valuable security tool for assisting operators to efficiently monitor and safeguard the status of Ethereum validators and the wider P2P network
T. M. Nithya, A. Amrita Varsheni, S. Brindha
The volume of information on the internet is currently rising dramatically. Social media platforms/e-commerce market place is producing a lot of data, including reviews, comments, and opinions, every day. As there are a number of fake reviews should incorporate Spam detection to produce a genuine opinion. Fake reviews are growing problem in online shopping, and they have a significant impact on consumer’s decision-making. Many people today base their decisions when choosing a product or service on social media opinions. Because so many false or phoney evaluations have been written by businesses or individuals for a variety of reasons, detecting opinion spam is a difficult and time-consuming task. They produce fictitious reviews to deceive users or automated detection systems by elevating or degrading the reputations of their target products in order to elevate or lower them. In this article, we’ll regulate it by leveraging blockchain technology to make the review system more authentic by allowing only legitimate product purchasers to submit evaluations using their account credentials. We use the Ethereum blockchain to authenticate user credentials, and we only permit verified users to purchase things. Also, we only permit customers to leave reviews or comments on products, ensuring that the reviews are accurate.
Georgia Osborn, Nathan Alan
Blockchain, or Web3 technology has the potential to disrupt the everyday use of the Internet. The polarised discussion around blockchain technology is notoriously difficult to navigate between the opposing narratives of blockchain evangelists and skeptics. This article focuses on blockchain domain names, a rapidly growing trend using blockchain technology that is currently non-interoperable with the Domain Name System (DNS) and therefore, out of scope of traditional Internet governance. Alternative DNS roots are not new and have previously not become popular due to the lack of supporting browsers. On one view, blockchain domain names are nothing more than another alternative root, insignificant and undeserving of attention. Other narratives regard them as offering an exciting prospect of a decentralised and novel way for managing online naming and addressing. This study explores the burgeoning growth, assesses the challenges of blockchain domain names and provides five recommendations to address them. Although many in traditional Internet communities may be hostile or ignore the blockchain alternative for naming and addressing, we argue that a pragmatic response should be adopted. Even if it is not clear that blockchain domain names solve any problems not currently solved by the DNS, the increase in registrations continues to rise and diverse Internet communities must keep ahead of the trends to understand them and integrate policy implications. Furthermore, the technologies will continue to advance and due to the decentralised nature of the blockchain, developments or changes can be more rapidly implemented than within the DNS.
Martijn de Vos, Georgy Ishmaev, Johan Pouwelse
The popularity of blockchain technology has bootstrapped many “Web3” applications, e.g., Ethereum and IPFS, that apply distributed ledger technology to store transactions. The amount of transactions generated and stored in such Web3 applications is significant and, in its raw form, usually not searchable by users. Existing Web3 transaction indexing and search engines are predominantly centralized and, therefore, can manipulate search results or censor particular queries. With the proliferation of Web3 transactions and applications, a decentralized and censorship-resistant search primitive is becoming essential. We present DeScan, a decentralized and censorship-resistant indexing and search engine for Web3. Users index their local Web3 transactions using custom rules that output triplets. Generated triplets are bundled in a distributed transaction graph that is searchable by other users. To coordinate search and distribute the storage of the transaction graph over peers in the network, we build upon a Skip Graph (SG) data structure. Since the Skip Graph does not provide any resilience against adversarial peers that censor searches, we propose four modifications to improve its robustness. We implement DeScan and conduct experiments with up to 12 800 peers and 10 million Ethereum transactions. Our experiments show that DeScan with our modifications enabled can tolerate 20% adversarial peers and 35% unresponsive peers without disruption. Moreover, we find that searches in DeScan are usually completed well within a second, even when the network grows. Finally, we show that storage and network costs are evenly distributed amongst peers as the network grows.
Rohit Saxena, Deepak Arora, Vishal Nagar
Ethereum is a digital asset whose transactions are kept on a decentralized, globally accessible ledger. An Ethereum Blockchain owner's real identity is concealed behind a pseudonym termed an address. Because of this, Ethereum is frequently used in illegal activities like gambling and ransomware attacks because it is popularly believed to offer the highest level of anonymity. As a result, it is necessary to categorize the various malicious cybercriminal users' activities and addresses in the Ethereum Blockchain. The Blockchain's public data enables an in-depth analysis. Using supervised machine learning models including linear, non-linear, and ensemble learning models based on malicious and non-malicious activities, the classification of Ethereum Blockchain addresses is carried out in this paper. In this research work, cross-validation accuracy, recall, precision, and f1-score have been employed for the assessment. Findings indicate that linear and non-linear machine learning approaches are superior to ensemble learning for classifying Ethereum Blockchain addresses. The results also show that it is possible to discover the Ethereum Blockchain addresses of malicious users.
Vaishali Ravindranath, M. K. Nallakaruppan, M. Lawanya Shri, Balamurugan Balusamy · 5 authors
No abstract is available for this record.
Faiqah Hafidzah Halim, Nor Aimuni Md Rashid, Nur Farahin Mohd Johari, Muhammad Amirul Hazim Abdul Rahman
In Malaysia, private healthcare providers keep computerized records of vaccination data, including personal information, diagnostic results, and vaccine prescriptions. However, such sensitive information is commonly stored using a centralized storage paradigm which subsequently brings about the issue of maintaining user privacy. Concerning this, unauthorized access to crucial information such as identity details and ailments that a patient is suffering from, as well as the misuse of patients' data and medical reports, are common threats to user's (patient) privacy. To overcome this problem, the researchers suggest leveraging IPFS (Interplanetary File System) and blockchain technology to create a decentralized children's immunization record management system. While respecting patient privacy, the proposed system also allows authorized entities, such as healthcare professionals, and provides easy access to medical data (e.g., doctors and nurses). The proposed decentralized system integrates IPFS, blockchain, and AES cryptography to ensure consistency, integrity, and accessibility. A permission Ethereum blockchain allows hospitals and patients within private healthcare providers to connect. We utilized a combination of symmetric and asymmetric key encryption to provide secure storage and selective records access. The proposed system was analyzed using Wireshark to evaluate the overall system's performance in terms of integrity and accessibility while sharing patient records. This project aims to provide automated system keeper using autonomous agents collaboratively with the role of blockchain for further enhancement.
Kangrui Huang, Weili Chen, Zibin Zheng
Blockchain technology has created a new cryptocurrency world and attracted a lot of attention. It also attracts scams, for example, phishing scam, a typical fraud, has been found making a notable amount of money in the blockchain ecosystem, which has a very negative impact. Considering the whole life cycle of a phishing scam, this paper proposes the concept of a phishing gang, that is, a set of accounts that serve for phishing activity and belong to the same entity on the blockchain. As phishers often use multiple accounts to commit phishing scams and money laundering, detecting phishing gangs in the blockchain ecosystem is a real and critical problem. To help deal with this issue, this paper proposes a method of detecting phishing gangs on the Ethereum blockchain. Specifically, we first construct a transaction network with a graph structure by mining the transaction record and the account labels of the Ethereum blockchain. Next, we propose the base and improvement methods of taint analysis, aiming to evaluate the taint score of each account by tracking the fund flow of phishing accounts. Then, with the results of taint analysis and some heuristic means, all accounts in the transaction network are divided into five categories. Based on this, we propose a heuristics algorithm for phishing gang detection. And we also summarize gang patterns and reveal money laundering in phishing activities. Experimental results indicate that the proposed framework can be used to build a uniform platform to monitor every account on the Ethereum blockchain for early warning of phishing scams and detection of the phishers' money laundering and cashing process.
Zainab Ali Kamal, Rana Fareed Ghani
The primary concerns with manual transactions include corruption, lack of transparency, fraud, and mismanagement of distribution operations, all of which are created by traditional centralized applications, necessitating the migration to blockchain technology. In this work, a system is presented to secure and monitor correspondence between several nodes and store it in a decentralized database in order to secure distributed ledger transactions and safeguard against fraud and tampering when transactions are shared by multiple parties. The hashing that blockchain technology delivers in each transaction ensures a high level of security. The hashing associated with each transaction confirms all sending and receiving transactions. When a transaction is sent from one node to another, the other node checks the hash accompanying the transaction to see if it came from a registered node or an external node. Within the blockchain system, the nodes will check transaction correspondences. The system has demonstrated its effectiveness by delivering a more secure messaging system with high credibility and tamper resistance. In addition, the time it takes to authenticate will be in real time. Index Terms— Blockchain, Consensus procedure, Hashing, Blockchain in Governance.
Ebru Aydoğan, Muhammed Fatih Aydemir
The e-commerce sector has grown beyond predictions with the help of the most recent technological developments, changes in consumer preferences, and the COVID-19 pandemic. E-commerce activities assume a subsidiary role of brick-and-mortar shops with the benefits it offers to all parties, which have also resulted in new problems such as privacy, security, transparency, and costs, unlike traditional businesses. Blockchain technology is among the promising technologies in solving the problems of the e-commerce sector with its decentralized structure that does not require third-party intermediaries, and its features (such as privacy, immutability, security, transparency, and auditability). In this study—which examines, under five titles, the benefits that blockchain can offer to e-commerce—it is concluded that blockchain can reshape e-commerce activities by enabling integrated e-commerce systems that include all parties and offering low transaction costs, high transaction speed, traceability of transactions, strong security standards, and low risks. In this direction, blockchain-based e-commerce platforms can push existing e-commerce platforms into the background.
Wuqi Zhang, Lili Wei, Shing-Chi Cheung, Yepang Liu · 7 authors
Front-running attacks have been a major concern on the blockchain. Attackers launch front-running attacks by inserting additional transactions before upcoming victim transactions to manipulate victim transaction executions and make profits. Recent studies have shown that front-running attacks are prevalent on the Ethereum blockchain and have caused millions of US dollars loss. It is the vulnerabilities in smart contracts, which are blockchain programs invoked by transactions, that enable the front-running attack opportunities. Although techniques to detect front-running vulnerabilities have been proposed, their performance on real-world vulnerable contracts is unclear. There is no large-scale benchmark based on real attacks to evaluate their capabilities. We make four contributions in this paper. First, we design an effective algorithm to mine real-world attacks in the blockchain history. The evaluation shows that our mining algorithm is more effective and comprehensive, achieving higher recall in finding real attacks than the previous study. Second, we propose an automated and scalable vulnerability localization approach to localize code snippets in smart contracts that enable front-running attacks. The evaluation also shows that our localization approaches are effective in achieving higher precision in pinpointing vulnerabilities compared to the baseline technique. Third, we build a benchmark consisting of 513 real-world attacks with vulnerable code labeled in 235 distinct smart contracts, which is useful to help understand the nature of front-running attacks, vulnerabilities in smart contracts, and evaluate vulnerability detection techniques. Last but not least, we conduct an empirical evaluation of seven state-of-the-art vulnerability detection techniques on our benchmark. The evaluation experiment reveals the inadequacy of existing techniques in detecting front-running vulnerabilities, with a low recall of$\leq$6.04%. Our further analysis identifies four common limitations in existing techniques: lack of support for inter-contract analysis, inefficient constraint solving for cryptographic operations, improper vulnerability patterns, and lack of token support.
Zhiju Yang, Gaoyuan Man, Songqing Yue
Hacks on blockchains are prevalent nowadays because a wide range of vulnerabilities exists in smart contracts. To deal with the vulnerabilities, security auditing has been emerging and widely adopted for manual code inspection. However, little is known about how manual security auditing impacts the blockchain community. In this work, we investigated security audits on blockchain by answering three research questions covering the type, severity, and resolve status of issues in the audit reports. We in total collected 2,421 security audit reports consisting of the details of 28,782 security issues. We found that manual security auditing has superior merit over static analysis tools in identifying logic-related issues, considering 27.65% of all findings are logical issues. We also found that 87.28% of 2,421 projects have at least one centralization issue that breaks the decentralization primitive of blockchain. Moreover, while 21.17% of issues are of major or critical severity, we surprisingly found that 61.83% of all issues were unresolved or partially resolved. We concluded that while manual security auditing can help identify security vulnerabilities uniquely, project developers need to take serious actions to address and secure their smart contracts.
Fares Ghazzawi, Yury Yanovich
The data from decentralized finance services is openly available once they operate in public blockchains. Although data encryption techniques for transaction exist, they are challenging, increase costs and decrease trust. Therefore, everyone can use the DeFi data. Natively, the data is stored as a transaction log, where we have a byte code of contracts and history of their method calls with parameters. So the problem is to represent it conveniently for analysis. In the paper, we consider a decentralized exchange called UniSwap, overview its operation principles, create a database with the related data and share scripts with the elementary examples. The results help overcome the entering threshold for further data analysis.
Yihang Fu, Zesen Zhuang, Luyao Zhang
Blockchain has empowered computer systems to be more secure using a distributed network. However, the current blockchain design suffers from fairness issues in transaction ordering. Miners are able to reorder transactions to generate profits, the so-called miner extractable value (MEV). Existing research recognizes MEV as a severe security issue and proposes potential solutions, including prominent Flashbots. However, previous studies have mostly analyzed blockchain data, which might not capture the impacts of MEV in a much broader AI society. Thus, in this research, we applied natural language processing (NLP) methods to comprehensively analyze topics in tweets on MEV. We collected more than 20000 tweets with #MEV and #Flashbots hashtags and analyzed their topics. Our results show that the tweets discussed profound topics of ethical concern, including security, equity, emotional sentiments, and the desire for solutions to MEV. We also identify the co-movements of MEV activities on blockchain and social media platforms. Our study contributes to the literature at the interface of blockchain security, MEV solutions, and AI ethics.
Ruijie Luo, Luo Feng, Bingsen Wang, Ting Chen
The smart contracts of Ethereum have brought an essential contribution to the development of blockchain. Nowadays, an increasing number of smart contracts are being deployed on Ethereum, which brings prosperity to Ethereum while also bringing many security risks. According to reports, several attacks due to the smart contract vulnerability have caused huge losses to Ethereum. Therefore, detecting smart contract security vulnerabilities is of great importance. However, the existing work is not sufficient to fully perform this task. For this reason, we propose a variant of the LSTM model to detect smart contract vulnerabilities at the bytecode level. In our variant LSTM model, we interact hidden state of the model with the input sequence multiple times. In this way, the variant model is able to capture more potential features in the bytecode for learning. We used a dataset of 34822 unique smart contracts for training and testing. The results show that the variant LSTM model outperforms the general LSTM model and improves in most metrics.
Sudeep Krishnan
eCommerce merchants anticipate adoption of cryptocurrencies in a vast scale in the coming years. While the concepts of Web3 are being adopted, business leaders and decision makers need to understand key the elements of Web3 and technological constructs behind the evolution of Web3. This study focuses on defining these constructs of Web3 and explain technological differences as compared to Web 2.0. Using extensive academic, industry, and online information, the study defines major characteristics of Web3, show cases early adopters, use cases, and opportunities in the area. Web3 is still evolving and there are many challenges which needs to be addressed. eCommerce businesses who are going to sustainably change the business models or disrupt with a new Web3 business is likely to succeed in the coming years. The findings of this study are also validated with an expert interview.
Kailong Wang, Yuxi Ling, Yanjun Zhang, Zhou Yu · 8 authors
Due to the surging popularity of various cryptocurrencies in recent years, a large number of browser extensions have been developed as portals to access relevant services, such as cryptocurrency exchanges and wallets. This has stimulated a wild growth of cryptocurrency themed malicious extensions that cause heavy financial losses to the users and legitimate service providers. They have shown their capability of evading the stringent vetting processes of the extension stores, highlighting a lack of understanding of this emerging type of malware in our community. In this work, we conduct the first systematic study to identify and characterize cryptocurrency-themed malicious extensions. We monitor seven official and third-party extension distribution venues for 18 months (December 2020 to June 2022) and have collected around 3600 unique cryptocurrency-themed extensions. Leveraging a hybrid analysis, we have identified 186 malicious extensions that belong to five categories. We then characterize those extensions from various perspectives including their distribution channels, life cycles, developers, illicit behaviors, and illegal gains. Our work unveils the status quo of the cryptocurrency-themed malicious extensions and reveals their disguises and programmatic features on which detection techniques can be based. Our work serves as a warning to extension users, and an appeal to extension store operators to enact dedicated countermeasures. To facilitate future research in this area, we release our dataset of the identified malicious extensions and open-source our analyzer.