With countless devices connected to the Internet of Things, trust mechanisms are especially important. IoT devices are more deeply embedded in the privacy of people's lives, and their security issues cannot be ignored. Smart contracts backed by blockchain technology have the potential to solve these problems. Therefore, the security of smart contracts cannot be ignored. We propose a flexible and systematic hybrid model, which we call the Serial-Parallel Convolutional Bidirectional Gated Recurrent Network Model incorporating Ensemble Classifiers (SPCBIG-EC). The model showed excellent performance benefits in smart contract vulnerability detection. In addition, we propose a serial-parallel convolution (SPCNN) suitable for our hybrid model. It can extract features from the input sequence for multivariate combinations while retaining temporal structure and location information. The Ensemble Classifier is used in the classification phase of the model to enhance its robustness. In addition, we focused on six typical smart contract vulnerabilities and constructed two datasets, CESC and UCESC, for multi-task vulnerability detection in our experiments. Numerous experiments showed that SPCBIG-EC is better than most existing methods. It is worth mentioning that SPCBIG-EC can achieve F1-scores of 96.74%, 91.62%, and 95.00% for reentrancy, timestamp dependency, and infinite loop vulnerability detection.
Newton Chinyamunjiko, Forbes Makudza, Lucia Mandongwe
Abstract: Purpose: The study sought to uncover the effect of blockchain digital ledger technology (BCDLT) on financial crimes. The study was driven by the need to promote blockchain technology in a bid to enhance financial sanity through elimination of financial delinquency. Research methodology: The study followed a quantitative paradigm using an explanatory research design. The study targeted financial executives, senior staff members at the Zimbabwe stock exchange, bankers and officials from the financial regulators. Data was collected using a structured questionnaire. Results: The study found out that of the four independent BCDLT antecedents, manual audit costs were insignificant, whereas the other three had strong positive associations with financial crime reduction. Limitations: The study targeted a specific group of financiers; hence the results may not be universal to other excluded categories Contribution: The study significantly guides policy formulation and laws in line with the adoption of the blockchain technology in the global financial system to guard against the possibility of new forms of financial crimes that could emanate from the use of technology. Keywords: 1. Blockchain digital ledger technology 2. Financial crime 3. Financial performance
Abstract In shaping the Internet of Money, the application of blockchain and distributed ledger technologies (DLTs) to the financial sector triggered regulatory concerns. Notably, while the user anonymity enabled in this field may safeguard privacy and data protection, the lack of identifiability hinders accountability and challenges the fight against money laundering and the financing of terrorism and proliferation (AML/CFT). As law enforcement agencies and the private sector apply forensics to track crypto transfers across ecosystems that are socio-technical in nature, this paper focuses on the growing relevance of these techniques in a domain where their deployment impacts the traits and evolution of the sphere. In particular, this work offers contextualized insights into the application of methods of machine learning and transaction graph analysis. Namely, it analyzes a real-world dataset of Bitcoin transactions represented as a directed graph network through various techniques. The modeling of blockchain transactions as a complex network suggests that the use of graph-based data analysis methods can help classify transactions and identify illicit ones. Indeed, this work shows that the neural network types known as Graph Convolutional Networks (GCN) and Graph Attention Networks (GAT) are a promising AML/CFT solution. Notably, in this scenario GCN outperform other classic approaches and GAT are applied for the first time to detect anomalies in Bitcoin. Ultimately, the paper upholds the value of public–private synergies to devise forensic strategies conscious of the spirit of explainability and data openness.
<p>Cybersecurity is an inherent characteristic that should be addressed before the large deployment of smart city applications. Recently, Blockchain appears as a promising technology to provide several cybersecurity aspects of smart city applications. This paper provides a comprehensive review of the existing blockchain-based solutions for the cybersecurity of the main smart city applications, namely smart healthcare, smart transportation, smart agriculture, supply chain management, smart grid, and smart homes. We describe the existing solutions and we discuss their merits and limits. Moreover, we define the security requirements of each smart city application and we give a mapping of the studied solutions to these defined requirements. Additionally, future directions are given. We believe that the present survey is a good starting point for every researcher in the fields of cybersecurity, blockchain, and smart cities.</p>
A service can be an intangible commodity in which no physical goods are transferred from the seller to the buyer. However, traditional trading platforms have many limitations in trading services due to dishonest buyers and brokers. In this paper, we propose a service trading ecosystem based on blockchain, named STEB, which combines blockchain, smart contract, encryption, and digital authentication techniques for service trading. In addition, a dual-chain architecture, which contains two types of blockchains, namely TraChain and SerChain, and a hierarchical encryption scheme of the data on the chain, are proposed to ensure the integrity of transaction data and fine-grained privacy protection of users. Furthermore, we describe a new set of smart contracts to ensure safe transactions for the entire service trading. Security analysis and simulation results confirm that the proposed STEB can achieve more efficient contract execution and enhance service transaction privacy.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Due to its significant global impact, both domestic and international efforts are underway to cure the infection and stop the COVID-19 virus from spreading further. In resource-limited environments, overwhelmed healthcare institutions and surveillance systems are struggling to cope with this epidemic, necessitating a specific strategic response. In this study, we looked into the COVID-19 situation and to establish trust, accountability, and transparency, we employed blockchain's immutable and tamper-proof properties. We offered a smart contract (SC)-based solution (Block-HPCT) that has been successfully tested to preserve a digital health passport (DHP) for vaccine recipients; also, for contact tracing (CT) we employed proof of location concept, which aids in a swift and credible response directly from the appropriate healthcare authorities. To connect on-chain and off-chain data, trusted and registered oracles were integrated and to provide a double layer of security along with symmetric key encryption; both Interplanetary File System (IPFS) and Hyperledger Fabric were merged as storage center. We also provided a full description of the suggested solution's system design, implementation, experiment results, and evaluation (privacy and cost analysis). As per the findings, the suggested approach performed satisfactorily across all significant assessment criteria, implying that it can lead the way for practical implementations and also can be used for similar types of situations where contact tracing of infectious can be crucial.
Gibran Gómez, Pedro Moreno-Sánchez, Juan Antonio Caballero-Hernández
Cybercriminals often leverage Bitcoin for their illicit activities. In this work, we propose back-and-forth exploration, a novel automated Bitcoin transaction tracing technique to identify cybercrime financial relationships. Given seed addresses belonging to a cybercrime campaign, it outputs a transaction graph, and identifies paths corresponding to relationships between the campaign under study and external services and other cybercrime campaigns. Back-and-forth exploration provides two key contributions. First, it explores both forward and backwards, instead of only forward as done by prior work, enabling the discovery of relationships that cannot be found by only exploring forward (e.g., deposits from clients of a mixer). Second, it prevents graph explosion by combining a tagging database with a machine learning classifier for identifying addresses belonging to exchanges. We evaluate back-and-forth exploration on 30 malware families. We build oracles for 4 families using Bitcoin for C&C and use them to demonstrate that back-and-forth exploration identifies 13 C&C signaling addresses missed by prior work, 8 of which are fundamentally missed by forward-only explorations. Our approach uncovers a wealth of services used by the malware including 44 exchanges, 11 gambling sites, 5 payment service providers, 4 underground markets, 4 mining pools, and 2 mixers. In 4 families, the relations include new attribution points missed by forward-only explorations. It also identifies relationships between the malware families and other cybercrime campaigns, highlighting how some malware operators participate in a variety of cybercriminal activities.
Mohammad Monirujjaman Khan, Nesat Tasneem RoJa, Faris A. Almalki, Maha Aljohani
The days of storing data manually are behind us. We are opting for the online form of data storage and transfer. The new era of data digitization comes with its own perks and detriments. Cybersecurity is still a crucial concern today. As more data transfer occurs through an online medium, the risks of a breach and cyberattacks are inevitable. The whole foundation of e-commerce is based on the online transfer of goods and transactions without the need to travel. Transferring transactional data and transactions in e-commerce are prone to cyber threats. Our research’s major objective is to develop a system that protects against such mishaps, especially during the transfer of transactional data, and also implement an automated system that ensures these transactions occur without any errors. To implement this, we are taking advantage of new emerging technologies called blockchain and smart contract. Blockchain allows a decentralized, immutable digital ledger to safely store and transfer data across the network. Blockchain technology is used in e-commerce to transfer transactions in a safe, secure, and faster way. Blockchain enables a peer-to-peer transaction system and data encryption that enables the safe transfer of transactional data. Blockchain is used to transfer transactional data. A smart contract is a special program that enables, verifies, and enforces the terms of a contract digitally. It provides transactional security as the contact is in place. The blockchain, coupled with smart contracts, will revolutionize the future of e-commerce. We have combined blockchain technology to ensure data security and user privacy with smart contracts to ensure that the protocol for the transaction is maintained. The results are presented by building and implementing the proposed system that provides the solution for transactional data privacy.
Eugene B. Chang, Paul J. Darcy, Kim‐Kwang Raymond Choo, Nhien‐An Le‐Khac
Cryptocurrency has been (ab)used to purchase illicit goods and services such as drugs, weapons and child pornography (also referred to as child sexual abuse materials), and thus mobile devices (where cryptocurrency wallet applications are installed) are a potential source of evidence in a criminal investigation. Not surprisingly, there has been increased focus on the security of cryptocurrency wallets, although forensic extraction and attribution of forensic artefacts from such wallets is understudied. In this paper, we examine Bitcoin and Dogecoin. The latter is increasingly popular partly due to endorsements from celebrities and being positioned as an introductory path to cryptocurrency for newcomers. Specifically, we demonstrate how one can acquire forensic artefacts from Android Bitcoin and Dogecoin cryptocurrency wallets, such as wallet IDs, transaction IDs, timestamp information, email addresses, cookies, and OAuth tokens.
This paper investigates the cryptocurrency giveaway scam with the YouTube live stream carried out on 5/15/2022 and 5/16/2022. In this scam scheme, the scammer plays a recorded video of a famous person in a YouTube live stream annotated with a cryptocurrency giveaway announcement. In the annotated announcement, the victims are directed to the scammer's webpage. The scammer's webpage is designed intelligently to deceive victims such that they believe the legitimacy of the giveaway. The scammer claims that whatever donation the victim sends to a cryptocurrency wallet address, the giveaway scheme will double the donated amount and immediately send it back to the victim. By analyzing the scammers' wallet addresses, it can be seen that scammers could steal a significant amount of money in a short time. After analyzing the attackers' techniques, tactics, and procedures, this paper discusses the countermeasures that can be applied to mitigate such a fraudulent activity in the future.
Security and privacy are two conditions that are closely linked to current trends in cryptocurrency, and this study offers a similar comprehensive review. Cryptocurrency adds security to transactions and controls the formation of additional currency units. Great growth for cryptocurrency market testing leads to the misuse of failures to benefit enemies. In this study, the review was designed to focus on safety and security standards of cryptocurrencies especially in Bitcoin. This study explains cryptocurrency agreements, their benefits, and communications within the framework
In the context of the rapid development of blockchain technology, smart contracts have also been widely used in the Internet of Things, finance, healthcare, and other fields. There has been an explosion in the number of smart contracts, and at the same time, the security of smart contracts has received widespread attention because of the financial losses caused by smart contract vulnerabilities. Existing analysis tools can detect many smart contract security vulnerabilities, but because they rely too heavily on hard rules defined by experts when detecting smart contract vulnerabilities, the time to perform the detection increases significantly as the complexity of the smart contract increases. In the present study, we propose a novel hybrid deep learning model named CBGRU that strategically combines different word embedding (Word2Vec, FastText) with different deep learning methods (LSTM, GRU, BiLSTM, CNN, BiGRU). The model extracts features through different deep learning models and combine these features for smart contract vulnerability detection. On the currently publicly available dataset SmartBugs Dataset-Wild, we demonstrate that the CBGRU hybrid model has great smart contract vulnerability detection performance through a series of experiments. By comparing the performance of the proposed model with that of past studies, the CBGRU model has better smart contract vulnerability detection performance.
Since the Industrial era, women are playing a significant role in the workforce to move the world forward. Their increasing contribution in various fields has earned a fortune for the global economy. Despite that, women constantly face more obstacles than men in the workplace. When half of the population are mistreated because of gender inequality, the economy of any nation is supposed to collapse. One of the biggest barriers for women in their careers is workplace harassment. Workplace harassment may include physical, verbal or nonverbal harassment that not only have an adverse effect on a woman's career, mental health and physical health but also organizational reputation. A common way to make a complaint in most organizations is to fill up a complaint form, email or go directly to the competent authority and complain. But victims often hesitate to complain because their identity might get revealed or their documentary evidence might be tampered. As a result, most of the harassers get through very easily. To resolve this problem, this paper presents a blockchain-based anonymous, transparent and secure platform where women can easily complain against their harassers. To keep the platform secure and reliable, a two-level hierarchical model is introduced, where level-1 is the Human Resources (HR) and level-2 is the Higher Authority. In level-1, victims can anonymously complain to HR and in Level-2, victims can complain with their identity revealed to higher authority. This way, the proposed platform ensures women of a healthy work environment and provides all necessary support to stand up against injustice in the workplace.
While blockchain technology triggers new industrial and technological revolutions, it also brings new challenges. Recently, a large number of new scams with a "blockchain" sock-puppet continue to emerge, such as Ponzi schemes, money laundering, etc., seriously threatening financial security. Existing fraud detection methods in blockchain mainly concentrate on manual feature and graph analytics, which first construct a homogeneous transaction graph using partial blockchain data and then use graph analytics to detect anomaly, resulting in a loss of pattern information. In this paper, we mainly focus on Ponzi scheme detection and propose HFAug, a generic Heterogeneous Feature Augmentation module that can capture the heterogeneous information associated with account behavior patterns and can be combined with existing Ponzi detection methods. HFAug learns the metapath-based behavior characteristics in an auxiliary heterogeneous interaction graph, and aggregates the heterogeneous features to corresponding account nodes in the homogeneous one where the Ponzi detection methods are performed. Comprehensive experimental results demonstrate that our HFAug can help existing Ponzi detection methods achieve significant performance improvement on Ethereum datasets, suggesting the effectiveness of heterogeneous information on detecting Ponzi schemes.
ASIC Kings (Company name: Boðeind EHF | Identification number: 6907871569) is based in Reykjavik - Iceland, we are an experienced supplier dedicated to providing our customers with the best cryptocurrency mining equipment.
Cryptocurrencies have dramatically increased adoption in mainstream applications in various fields such as financial and online services, however, there are still a few amounts of cryptocurrency transactions that involve illicit or criminal activities. It is essential to identify and monitor addresses associated with illegal behaviors to ensure the security and stability of the cryptocurrency ecosystem. In this paper, we propose a framework to build a dataset comprising Bitcoin transactions between 12 July 2019 and 26 May 2021. This dataset (hereafter referred to as BABD-13) contains 13 types of Bitcoin addresses, 5 categories of indicators with 148 features, and 544,462 labeled data, which is the largest labeled Bitcoin address behavior dataset publicly available to our knowledge. We also propose a novel and efficient subgraph generation algorithm called BTC-SubGen to extract a${k}$-hop subgraph from the entire Bitcoin transaction graph constructed by the directed heterogeneous multigraph starting from a specific Bitcoin address node. We then conduct 13-class classification tasks on BABD-13 by five machine learning models namely${k}$-nearest neighbors algorithm, decision tree, random forest, multilayer perceptron, and XGBoost, the results show that the accuracy rates are between 93.24% and 97.13%. In addition, we study the relations and importance of the proposed features and analyze how they affect the effect of machine learning models. Finally, we conduct a preliminary analysis of the behavior patterns of different types of Bitcoin addresses using concrete features and find several meaningful and explainable modes.
Ardeshir Shojaeinasab, Amir Pasha Motamed, Behnam Bahrak
Abstract Cryptocurrencies, particularly Bitcoin, have garnered attention for their potential in anonymous transactions. However, their anonymity has often been compromised by deanonymization attacks. To counter this, mixing services have been introduced. While they enhance privacy, they obscure fund traceability. This study seeks to demystify transactions linked to these services, shedding light on pathways of concealed and laundered money. We propose a method to identify and classify transactions and addresses of major mixing services in Bitcoin. Unlike previous research focusing on older techniques like CoinJoin, we emphasize modern mixing services. We gathered labelled data by transacting with three prominent mixers (MixTum, Blemder, and CryptoMixer) and identified recurring patterns. Using these patterns, an algorithm was created to pinpoint mixing transactions and distinguish mixer‐related addresses. The algorithm achieved a remarkable recall rate of 100%. Given the lack of clear ground truth and the vast number of unlabelled transactions, ensuring accuracy was a challenge. However, by analyzing a set of non‐mixing transactions with our model, it was confirmed that the high recall rate was not misleading. This work provides a significant advancement in monitoring mixing transactions, presenting a valuable tool against fraud and money laundering in cryptocurrency networks.
This paper examines the relationship between events reported in international news via categorical discourses and Bitcoin price. Natural language processing was adopted in this study to model data-driven discourses in the crypto-economy, specifically the Bitcoin market. Using topic modelling, namely Latent Dirichlet Allocation, a text analysis of cryptocurrency articles ( N = 4218) published from 60 countries in international news media identified key topics associated with cryptocurrency in the international news media from 2018 to 2020. This study provides empirical evidence that across the corpora of international news articles, 18 key topics were framed around the following categorical macro discourses: crypto-related crime, financial governance, and economy and markets. Analysis shows that the identified discourses may have had a ‘social signal’ effect on movements in the crypto-financial markets, particularly on Bitcoin's price volatility. Results show these specific discourses proved to have a negative effect on Bitcoin's market price, within 24 h of when the crypto news articles were published. Further, the study found that in some cases, the source of the news may have amplified the volatility effect, particularly in terms of geographical region, relative to broader market conditions.
Jinho Choi, Taehwa LEE, Kwanwoo KIM, Min-Jae Seo · 6 authors
Bitcoin is currently a hot issue worldwide, and it is expected to become a new legal tender that replaces the current currency started with El Salvador. Due to the nature of cryptocurrency, however, difficulties in tracking led to the arising of misuses and abuses. Consequently, the pain of innocent victims by exploiting these bitcoins abuse is also increasing. We propose a way to detect new signatures by applying two-fold NLP-based clustering techniques to text data of Bitcoin abuse reports received from actual victims. By clustering the reports of text data, we were able to cluster the message templates as the same campaigns. The new approach using the abuse massage template representing clustering as a signature for identifying abusers is much efficacious.
This thesis presents techniques to investigate transactions in uncharted cryptocurrencies and services. Cryptocurrencies are used to securely send payments online. Payments via the first cryptocurrency, Bitcoin, use pseudonymous addresses that have limited privacy and anonymity guarantees. Research has shown that this pseudonymity can be broken, allowing users to be tracked using clustering and tagging heuristics. Such tracking allows crimes to be investigated. If a user has coins stolen, investigators can track addresses to identify the destination of the coins. This, combined with an explosion in the popularity of blockchain, has led to a vast increase in new coins and services. These offer new features ranging from coins focused on increased anonymity to scams shrouded as smart contracts. In this study, we investigated the extent to which transaction privacy has improved and whether users can still be tracked in these new ecosystems. We began by analysing the privacy-focused coin Zcash, a Bitcoin-forked cryptocurrency, that is considered to have strong anonymity properties due to its background in cryptographic research. We revealed that the user anonymity set can be considerably reduced using heuristics based on usage patterns. Next, we analysed cross-chain transactions collected from the exchange ShapeShift, revealing that users can be tracked as they move across different ledgers. Finally, we present a measurement study on the smart-contract pyramid scheme Forsage, a scam that cycled $267 million USD (of Ethereum) within its first year, showing that at least 88% of the participants in the scheme suffered a loss. The significance of this study is the revelation that users can be tracked in newer cryptocurrencies and services by using our new heuristics, which informs those conducting investigations and developing these technologies.
Criminals have become increasingly experienced in using cryptocurrencies, such as Bitcoin, for money laundering. The use of cryptocurrencies can hide criminal identities and transfer hundreds of millions of dollars of dirty funds through their criminal digital wallets. However, this is considered a paradox because cryptocurrencies are goldmines for open-source intelligence, giving law enforcement agencies more power when conducting forensic analyses. This paper proposed Inspection-L, a graph neural network (GNN) framework based on a self-supervised Deep Graph Infomax (DGI) and Graph Isomorphism Network (GIN), with supervised learning algorithms, namely Random Forest (RF), to detect illicit transactions for anti-money laundering (AML). To the best of our knowledge, our proposal is the first to apply self-supervised GNNs to the problem of AML in Bitcoin. The proposed method was evaluated on the Elliptic dataset and shows that our approach outperforms the state-of-the-art in terms of key classification metrics, which demonstrates the potential of self-supervised GNN in the detection of illicit cryptocurrency transactions.
Security issues are increasing day by day all over the world. Cyber issues are one of the major issues that cause cyber-attacks involving Malware, Phishing, and Ransomware attack. Pakistan is also one of the major countries that are facing cybercrime issues. The most important firms are government agencies like NADRA, Law Firm, and Police Firm. Pakistan has still not made a refined structure to ensure its security from advanced risks. By, and by it has transformed into a national security hazard for Pakistan because the individual data of the government is not secured. Multiple attacks on the NADRA server have occurred in the past. The reason is the centralization server, and security flaws. With the coming of Technology in the 21st century, and security worries that happens due to cybercrimes. Individuals are currently pushing toward new advances, the main thing that comes in the mind to keep away from security hazards, is to circulate the information among various individuals, so the idea of decentralization comes in. A technology that recently has gathered a lot of attention is Blockchain technology. Its decentralized nature gives secure, secret, and basic intends to keep up the records without alteration. Blockchain provides immutability, Integrity, helps enhanced security, distributed ledger, and also provides consensuses. So for government organizations like NADRA data is the most important thing, if this data is compromised due to security flaws then it’s happened a national security hazard that causes leakages of the nation's personal information. So this thesis purpose how to secure data using Blockchain technology a private Blockchain technology. An architectural view is presented with the help of use cases for government organizations NADRA, Police Firm, and Law Firm using HLF Blockchain technology. This thesis also presents the design, and architecture of how organizations work, and interact with one another. Using this design, and architecture we will be able to provide forensic to government organization data which makes it more secure from cyber threats.