Lingyu Bian, Linlin Zhang, Kai Zhao, Hao Wang · 5 authors
In recent years, the rapid development of blockchain technology has attracted much attention from people around the world. Scammers take advantage of the pseudo-anonymity of blockchain to implement financial fraud. The Ponzi scheme, one of the main scam methods, has defrauded investors of large amounts of money, thereby harming their interests and hindering the application of blockchain. Unfortunately, the current detection technology typically largely relies on the source code of the contract or uses a single feature which does not fully represent the contract characteristics. In such a case, the detection of Ponzi schemes with high efficiency becomes urgent. In this paper, we propose an image-based scam detection method using an attention capsule network (SE-CapsNet) focused on Ethereum. The sequence of bytecode, the opcode frequency, and the application binary interface (ABI) call are extracted as features from the contract bytecode and ABI, further converted into grayscale images, and then mapped into three color channels to generate RGB images, which are used as the input of the model for detecting the Ponzi scheme contract. In addition, we employ fancy PCA for data augmentation to reduce the impact of imbalanced data on the detection results. Experimental results show that the image-based detection method using deep learning models can effectively detect contracts before transactions occur. Among them, our proposed SE-CapsNet obtains great detection results, with an F1 score of 98.38%.
Open access
Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
A blockchain is a distributed ledger in which participants who do not fully trust each other agree on the ledger’s content by running a consensus algorithm. It has been more popular and mature in recent years. Smart contracts on the blockchain system are usually redundantly executed by a large number of nodes for the purpose of verification, which can result in a large waste of computation. The waste is especially significant when the smart contracts are heavy-duty. The problem of reducing the computation has attracted a lot of interest from both the research community and the industry. In this creative component, we present a game theoretic design for efficient execution of heavy-duty smart contracts, and develop a simulator to implement the design and evaluate its performance in a large-scale blockchain system that simulates Ethereum. The simulator is built based on BlockSim, an emerging general-purpose blockchain simulator, but has enhanced it with detailed simulation of the heavy-duty smart contract protocol. The simulation results demonstrate the efficacy and efficiency of our design.
Mohammad Saidur Rahman, Ibrahim Khalil, Mohammed Atiquzzaman
Drones, or unmanned aerial vehicles, can be used for commercial services such as short-distance delivery. In order to ensure quality services, multiple drone-based delivery service providers can be employed in delivery service systems. In this article, we address two very important and unexplored challenges of employing drones in delivery services. First, involving multiple drones from different service providers elevates the chance of collision during flights. Second, drones may hamper the privacy of citizens by unauthorized access to private and restricted areas. In order to solve the aforementioned issues, we propose a blockchain-based policy enforcement mechanism in the drone-based delivery service systems. At first, the mechanism will set policies to establish pre-allocated flight paths for different drones at different times to avoid collisions, and ensure the privacy of citizens by restricting their access to unauthorized areas. Later, the blockchain will enforce the policies to monitor compliance of the drone flights and identify non-compliant drone services to penalize corresponding service providers. We simulate a virtual drone-based delivery system with the Ethereum blockchain platform and examine the performance and feasibility of our proposed mechanism.
Health information exchange (HIE) refers to the integrated management and secure sharing of health information among healthcare entities. HIE improves healthcare quality and streamline healthcare administrative work. These advantages have propelled health-care stakeholders to implement HIE. However, challenged by issues such as security, privacy, and costs, HIE is not widespread. Recent studies have suggested blockchain-based HIE for solving security and privacy issues. Unfortunately, existing blockchain-based HIE studies do not consider the privacy issues caused by analyzing senders and receivers of transactions in the blockchain. In this work, we suggest MEXchange, a novel blockchain-based privacypreserving HIE that prevents the privacy issue by obscuring the sender and concealing receiver addresses. We propose smart contracts and workflow that use ring signature and stealth address for blockchainbased HIE. Software components and implementation of MEXchange on the Ethereum private network are discussed. We evaluate MEXchange quantitatively by measuring the transaction latency and throughput of exchanging. Also, we evaluate MEXchange qualitatively using the requirements of the Office of National Coordinator for Health Information Technology (ONC). Moreover, we proceed threat modeling based on STRIDE. Finally, we compare MEXchange with Ancile, FHIRChain, Integrating the Healthcare Enterprise Cross-Enterprise Document Sharing (IHE XDS), and MedRec. The MEXchange lowers barriers to the application of blockchain-based HIE systems by mitigating privacy and security issues among healthcare stakeholders.
With the mass expansion of Internet of Things (IoT) in industry and consumer life, IoT security has become a focal point of research and development. New technologies are enabling unprecedented methods of developing and securing IoT devices. This thesis focuses on studying and applying Web 3.0 technologies in an IoT device and service context while addressing IoT security vulnerabilities through the use of good security design practices. Through the application of Web 3.0 technologies this thesis illustrates the advantages and disadvantages that these technologies offer. The practi- cal implementation utilizes a custom Ethereum based security protocol that enables an IoT device to use a decentralized data network as its dedicated backend infrastructure. The results of the implementation will be analyzed through the lens of security and practicality.
Blockchain is a decentralized distributed ledger technology. The public chain represented by Bitcoin and Ethereum only realizes the limited anonymity of user identity, and the transaction amount is open to the whole network, resulting in user privacy leakage. Based on the existing anonymous technology, the concealment of the sender, receiver, amount of the transaction, and does not disclose any information, which makes the supervision difficult. Therefore, the design of blockchain scheme with privacy protection and supervision functions is of great significance. In this paper, a blockchain transaction model with both privacy and supervision function is proposed. It uses probability encryption to realize the hiding of the true identity of the blockchain transaction, and uses the commitment scheme and zero-knowledge proof technology to realize the privacy protection and guarantee legitimacy verification of the transaction. With the use of encryption technology, the regulators can supervise blockchain transactions without storing the users' information, which greatly reduces the pressure on storage, computing and key management. In addition, it does not rely on specific consensus mechanism and can be used as an independent module. The security performance analysis shows that the proposed scheme has great practicability and has potential application in many fields.
Blockchain is an emerging technology that has many uses and applications among many industries such as banking, education, and tourism. It has proven over time to be more cryptographically secure than traditional databases. Many people confuse Bitcoin with Blockchain. Because of the considerable value of Bitcoins, people have the perception that blockchain technology requires large computing infrastructure and power due to CPU bottleneck challenges. This paper presents the process used in testing blockchain technology performance on a virtual machine by focusing on benchmarking workloads like CPUHeavy using Ethereum blockchain and comparing two different algorithm sorts, Quick and bubble. The results of the testing indicate that blockchain workloads can be performed on smaller machines with very little CPU bottlenecks. In addition, performance test outcomes found that the CPUHeavy and Quicksort was more superior.
The automotive value chain comprises a complex manufacturing network, which encompasses several departments, companies, and even countries. In the age of electrification and autonomous driving, the quality and transparency requirements are rising, in particular for electric and electronic components, which contribute to safety-critical functionalities. In this research, we analyze the traceability requirements and liability implications for the automotive manufacturing network. A key component in preventing safety and quality deficiencies in manufacturing processes is a state-of-the-art traceability system. Accordingly, we propose a blockchain-based traceability architecture to achieve the aspired level of transparency and process security. The proposed blockchain architecture processes manufacturing data entries and defines blockchain nodes, access, as well as consensus algorithm and transaction logic. An Ethereum-based blockchain demonstrator validates the architecture by implementing the logic for automotive product configuration and process sequencing based on the semi-fungible ERC 1155 token, the proof of authority consensus, and an automotive product token smart contract.
Stable coins are not very stable. Cash collateralized coins are more stable, but the overall failure rate is similar to tokens that are not designed to be stable. USD Coin, Tether and Dai have the largest Ethereum market shares, and they have an average velocity nearly three times higher than M1. Centralized and decentralized exchanges are the most active nodes and largest holders on the blockchain. Four of the top ten tokens have Herfindahl indices higher than the U.S. banking system. Median gas fees for Tether rose more than twelve times over the last two years, and nearly twenty times for USD Coin. Transactions of under 50,000 USD can generally be done more cheaply offchain. 24 hour exchange turnover in Tether is nearly 60 billion USD. This is comparable to the daily volume at the NYSE and eight times the daily flow in money market mutual funds. Narrow bid-ask spreads and depth have attracted HFT participation approaching 50%
Blockchain gets its name from being a series of blocks that are linked together to form a chain. Once the information has been added to the chain, it cannot be changed. There are several consensus protocols, and each of them is chosen based on the type of blockchain and the system requirements. With the rapid urbanization of the world, several economic, social, and environment-related issues have been raised. Smart cities are an emerging concept that holds the solution to these urban problems. Blockchain is such an innovation that can promote the development of smart cities. Along with its application in the internet of things, smart cities, and logistics, blockchain truly is state-of-the-art technology. Here, the authors aim to provide an in-depth look into this relatively new technology, beginning with blockchain's fundamentals and then covering the applications, issues, and future scope.
With the popularity of blockchain technology, the financial security issues of blockchain transaction networks have become increasingly serious. Phishing scam detection methods will protect possible victims and build a healthier blockchain ecosystem. Usually, the existing works define phishing scam detection as a node classification task by learning the potential features of users through graph embedding methods such as random walk or graph neural network (GNN). However, these detection methods are suffered from high complexity due to the large scale of the blockchain transaction network, ignoring temporal information of the transaction. Addressing this problem, we defined the transaction pattern graphs for users and transformed the phishing scam detection into a graph classification task. To extract richer information from the input graph, we proposed a multi-channel graph classification model (MCGC) with multiple feature extraction channels for GNN. The transaction pattern graphs and MCGC are more able to detect potential phishing scammers by extracting the transaction pattern features of the target users. Extensive experiments on seven benchmark and Ethereum datasets demonstrate that the proposed MCGC can not only achieve state-of-the-art performance in the graph classification task but also achieve effective phishing scam detection based on the target users' transaction pattern graphs.
The developers of Ethereum smart contracts often implement administrating patterns, such as censoring certain users, creating or destroying balances on demand, destroying smart contracts, or injecting arbitrary code. These routines turn an ERC20 token into an administrated token - the type of Ethereum smart contract that we scrutinize in this research. We discover that many smart contracts are administrated, and the owners of these tokens carry lesser social and legal responsibilities compared to the traditional centralized actors that those tokens intend to disrupt. This entails two major problems: a) the owners of the tokens have the ability to quickly steal all the funds and disappear from the market; and b) if the private key of the owner's account is stolen, all the assets might immediately turn into the property of the attacker. We develop a pattern recognition framework based on 9 syntactic features characterizing administrated ERC20 tokens, which we use to analyze existing smart contracts deployed on Ethereum Mainnet. Our analysis of 84,062 unique Ethereum smart contracts reveals that nearly 58% of them are administrated ERC20 tokens, which accounts for almost 90% of all ERC20 tokens deployed on Ethereum. To protect users from the frivolousness of unregulated token owners without depriving the ability of these owners to properly manage their tokens, we introduce SafelyAdministrated - a library that enforces a responsible ownership and management of ERC20 tokens. The library introduces three mechanisms: deferred maintenance, board of trustees and safe pause. We implement and test SafelyAdministrated in the form of Solidity abstract contract, which is ready to be used by the next generation of safely administrated ERC20 tokens.
We propose OmniLytics, a blockchain-based secure data trading marketplace for machine learning applications. Utilizing OmniLytics, many distributed data owners can contribute their private data to collectively train an ML model requested by some model owners, and receive compensation for data contribution. OmniLytics enables such model training while simultaneously providing 1) model security against curious data owners; 2) data security against the curious model and data owners; 3) resilience to malicious data owners who provide faulty results to poison model training; and 4) resilience to malicious model owners who intend to evade payment. OmniLytics is implemented as a blockchain smart contract to guarantee the atomicity of payment. In OmniLytics, a model owner splits its model into the private and public parts and publishes the public part on the contract. Through the execution of the contract, the participating data owners securely aggregate their locally trained models to update the model owner's public model and receive reimbursement through the contract. We implement a working prototype of OmniLytics on Ethereum blockchain and perform extensive experiments to measure its gas cost, execution time, and model quality under various parameter combinations. For training a CNN on the MNIST dataset, the MO is able to boost its model accuracy from 62% to 83% within 500ms in blockchain processing time.This demonstrates the effectiveness of OmniLytics for practical deployment.
Neta Elad, Sophie Rain, Neil Immerman, Laura Kovács · 5 authors
Abstract Some of the most significant high-level properties of currencies are the sums of certain account balances. Properties of such sums can ensure the integrity of currencies and transactions. For example, the sum of balances should not be changed by a transfer operation. Currencies manipulated by code present a verification challenge to mathematically prove their integrity by reasoning about computer programs that operate over them, e.g., in Solidity. The ability to reason about sums is essential: even the simplest ERC-20 token standard of the Ethereum community provides a way to access the total supply of balances. Unfortunately, reasoning about code written against this interface is non-trivial: the number of addresses is unbounded, and establishing global invariants like the preservation of the sum of the balances by operations like transfer requires higher-order reasoning. In particular, automated reasoners do not provide ways to specify summations of arbitrary length. In this paper, we present a generalization of first-order logic which can express the unbounded sum of balances. We prove the decidablity of one of our extensions and the undecidability of a slightly richer one. We introduce first-order encodings to automate reasoning over software transitions with summations. We demonstrate the applicability of our results by using SMT solvers and first-order provers for validating the correctness of common transitions in smart contracts.
The Deposit Smart Contract (DSC) is an instrumental component of the Ethereum 2.0 Phase 0 infrastructure. We have developed the first machine-checkable version of the incremental Merkle tree algorithm used in the DSC. We present our new and original correctness proof of the algorithm along with the Dafny machine-checkable version. The main results are: 1) a new proof of total correctness; 2) a software artefact with the proof in the form of the complete Dafny code base and 3) new provably correct optimisations of the algorithm.
Ziaur Rahman, Xun Yi, Ibrahim Khalil, Andrei Kelarev
The world has been experiencing a mind-blowing expansion of blockchain technology since it was first introduced as an emerging means of cryptocurrency called bitcoin. Currently, it has been regarded as a pervasive frame of reference across almost all research domains, ranging from virtual cash to agriculture or even supply-chain to the Internet of Things. The ability to have a self-administering register with legitimate immutability makes blockchain appealing for the Internet of Things (IoT). As billions of IoT devices are now online in distributed fashion, the huge challenges and questions require to addressed in pursuit of urgently needed solutions. The present paper has been motivated by the aim of facilitating such efforts. The contribution of this work is to figure out those trade-offs the IoT ecosystem usually encounters because of the wrong choice of blockchain technology. Unlike a survey or review, the critical findings of this paper target sorting out specific security challenges of blockchain-IoT Infrastructure. The contribution includes how to direct developers and researchers in this domain to pick out the unblemished combinations of Blockchain enabled IoT applications. In addition, the paper promises to bring a deep insight on Ethereum, Hyperledger blockchain and IOTA technology to show their limitations and prospects in terms of performance and scalability.
We present positive evidence of price stability of cryptocurrencies as a medium of exchange. For the sample years from 2016 to 2020, the prices of major cryptocurrencies are found to be stable, relative to major financial assets. Specifically, after filtering out the less-than-one-month cycles, we investigate the daily returns in US dollars of the major cryptocurrencies (i.e., Bitcoin, Ethereum, and Ripple) as well as their comparators (i.e., major legal tenders, the Euro and Japanese yen, and the major stock indexes, S&P 500 and MSCI World Index). We examine the stability of the filtered daily returns using three different measures. First, the Pearson correlations increased in later years in our sample. Second, based on the dynamic time-warping method that allows lags and leads in relations, the similarities in the daily returns of cryptocurrencies with their comparators have been present even since 2016. Third, we check whether the cumulative sum of errors to predict cryptocurrency prices, assuming stable relations with comparators' daily returns, does not exceeds the bounds implied by the Black-Scholes model. This test, in other words, does not reject the efficient market hypothesis.
Ignacio Amores-Sesar, Christian Cachin, Anna Parker
Despite the tremendous interest in cryptocurrencies like Bitcoin and Ethereum today, many aspects of the underlying consensus protocols are poorly understood. Therefore, the search for protocols that improve either throughput or security (or both) continues. Bitcoin always selects the longest chain (i.e., the one with most work). Forks may occur when two miners extend the same block simultaneously, and the frequency of forks depends on how fast blocks are propagated in the network. In the GHOST protocol, used by Ethereum, all blocks involved in the fork contribute to the security. However, the greedy chain selection rule of GHOST does not consider the full information available in the block tree, which has led to some concerns about its security. This paper introduces a new family of protocols, called Medium, which takes the structure of the whole block tree into account, by weighting blocks differently according to their depths. Bitcoin and GHOST result as special cases. This protocol leads to new insights about the security of Bitcoin and GHOST and paves the way for developing network- and application-specific protocols, in which the influence of forks on the chain-selection process can be controlled. It is shown that almost all protocols in this family achieve strictly greater throughput than Bitcoin (at the same security level) and resist attacks that can be mounted against GHOST.
Peer-to-peer (p2p) content delivery is promising to provide benefits like cost-saving and scalable peak-demand handling in comparison with conventional content delivery networks (CDNs) and complement the decentralized storage networks such as Filecoin. However, reliable p2p delivery requires proper enforcement of delivery fairness, i.e., the deliverers should be rewarded according to their in-time delivery. Unfortunately, most existing studies on delivery fairness are based on non-cooperative game-theoretic assumptions that are arguably unrealistic in the ad-hoc p2p setting. We for the first time put forth the expressive yet still minimalist securities for p2p content delivery, and give two efficient solutions FairDownload and FairStream via the blockchain for p2p downloading and p2p streaming scenarios, respectively. Our designs not only guarantee delivery fairness to ensure deliverers be paid (nearly) proportional to his in-time delivery, but also ensure the content consumers and content providers to be fairly treated. The fairness of each party can be guaranteed when the other two parties collude to arbitrarily misbehave. Moreover, the systems are efficient in the sense of attaining asymptotically optimal on-chain costs and optimal deliverer communication. We implement the protocols to build the prototype systems atop the Ethereum Ropsten network. Extensive experiments done in LAN and WAN settings showcase their high practicality.
Victor von Wachter, Johannes Rude Jensen, Omri Ross
Decentralized financial (DeFi) applications on the Ethereum blockchain are highly interoperable because they share a single state in a deterministic computational environment. Stakeholders can deposit claims on assets, referred to as 'liquidity shares', across applications producing effects equivalent to rehypothecation in traditional financial systems. We seek to understand the degree to which this practice may contribute to financial integration on Ethereum by examining transactions in 'composed' derivatives for the assets DAI, USDC, USDT, ETH and tokenized BTC for the full set of 344.8 million Ethereum transactions computed in 2020. We identify a salient trend for 'composing' assets in multiple sequential generations of derivatives and comment on potential systemic implications for the Ethereum network.
In cryptocurrencies, the block reward is meant to serve as the incentive mechanism for miners to commit resources to create blocks and in effect secure the system. Existing systems primarily divide the reward in proportion to expended resources and follow one of two static models for total block reward: (i) a fixed reward for each block (e.g., Ethereum), or (ii) one where the block reward halves every set number of blocks (e.g., the Bitcoin model of halving roughly every 4 years) but otherwise remains fixed between halvings. In recent work, a game-theoretic analysis of the static model under asymmetric miner costs showed that an equilibrium always exists and is unique. Their analysis also reveals how asymmetric costs can lead to large-scale centralization in blockchain mining, a phenomenon that has been observed in Bitcoin and Ethereum and highlighted by other studies. In this work we introduce a novel family of mining reward functions, HaPPY-Mine (HAsh-Pegged Proportional Yield), which peg the value of the reward to the hashrate of the system, decreasing the reward as the hashrate increases. HaPPY-Mine distributes rewards in proportion to expended hashrate and inherits the safety properties of the generalized proportional reward function. We study HaPPY-Mine under a heterogeneous miner cost model and show that an equilibrium always exists with a unique set of miner participants and a unique total hashrate. Significantly, we prove that a HaPPY-Mine equilibrium is more decentralized than the static model equilibrium under a set of metrics including number of mining participants and hashrate distribution. Finally, we show that any HaPPY-Mine equilibrium is also safe against collusion and sybil attacks, and explore how the market value of the currency affects the equilibrium.
Vincenzo Botta, Daniele Friolo, Daniele Venturi, Ivan Visconti
In this work, we consider executions of smart contracts for implementing secure multi-party computation (MPC) protocols on forking blockchains (e.g., Ethereum), and we study security and delay issues due to forks. In this setting, the classical double-spending problem tells us that messages of the MPC protocol should be confirmed on-chain before playing the next ones, thus slowing down the entire execution. Our contributions are twofold: For the concrete case of fairly tossing multiple coins with penalties, we notice that the lottery protocol of Andrychowicz et al. (S&P ’14) becomes insecure if players do not wait for the confirmations of several transactions. In addition, we present a smart contract that instead retains security even when all honest players immediately answer to transactions appearing on-chain. We analyze the performance using Ethereum as testbed.We design a compiler that takes any “digital and universally composable” MPC protocol (with or without honest majority), and transforms it into another one (for the same task and same setup) which maintains security even if all messages are played on-chain without delays. The special requirements on the starting protocol mean that messages consist only of bits (e.g., no hardware token is sent) and security holds also in the presence of other protocols. We further show that our compiler satisfies fairness with penalties as long as honest players only wait for confirmations once. By reducing the number of confirmations, our protocols can be significantly faster than natural constructions.