Abstract With the wide application and development of blockchain technology in various fields such as finance, government affairs and medical care, security incidents occur frequently on it, which brings great threats to users’ assets and information. Many researchers have worked on blockchain abnormal behavior awareness in respond to these threats. We summarize respectively the existing public blockchain and consortium blockchain abnormal behavior awareness methods and ideas in detail as the difference between the two types of blockchain. At the same time, we summarize and analyze the existing data sets related to mainstream blockchain security, and finally discuss possible future research directions. Therefore, this work can provide a reference for blockchain security awareness research.
Finans, sağlık, sosyal medya vb ortamlardaki insanların ihtiyacı olan güven problemine blok zinciri teknolojisi, şifreli algoritmalar ile çözümler sunmaktadır. Güven problemini çözen ve verileri dağıtık olarak kayıt altına alan ve her şeyi şeffaf olarak bizlere sunan blok zinciri bir devrim niteliğindedir. Blok zinciri, akıllı sözleşmeler sayesinde kurumsal projelerde de kullanabilmektedir. Kurumların arasında yeni nesil bir ağ olarak da adlandırılan blok zinciri ile bir çok şeyin değişmesi beklenmektedir. İnternetin, mobile cihazların ve sensörlerin yaygınlaşmasıyla birlikte güven problemi her geçen gün daha da önem kazanmaktadır. Farklı amaçlara hizmet eden Ethereum, Cardano, EOS, Cosmos, Hyperledger gibi blok zincir platformları vardır. Altyapılarında Proof of Work (PoW), Proof of Stake (PoS), Delegated Proof of Stake (DPoS) ve Directed Acyclic Graph (DAG) gibi farklı fikir birliği mekanizmalarını kullanmaktadırlar. Bu çalışmada blok zinciri platformları, altyapılarında kullandıkları mutabakat mekanizmaları ve blok zinciri ağının güvenliği araştırılmıştır.
The key issue in the field of smart contract security is efficient and rapid vulnerability detection in smart contracts. Most of the existing detection methods can only detect the presence of vulnerabilities in the contract and can hardly identify their type. Furthermore, they have poor scalability. To resolve these issues, in this study, we developed a smart contract vulnerability detection model based on multi-task learning. By setting auxiliary tasks to learn more directional vulnerability features, the detection capability of the model was improved to realize the detection and recognition of vulnerabilities. The model is based on a hard-sharing design, which consists of two parts. First, the bottom sharing layer is mainly used to learn the semantic information of the input contract. The text representation is first transformed into a new vector by word and positional embedding, and then the neural network, based on an attention mechanism, is used to learn and extract the feature vector of the contract. Second, the task-specific layer is mainly employed to realize the functions of each task. A classical convolutional neural network was used to construct a classification model for each task that learns and extracts features from the shared layer for training to achieve their respective task objectives. The experimental results show that the model can better identify the types of vulnerabilities after adding the auxiliary vulnerability detection task. This model realizes the detection of vulnerabilities and recognizes three types of vulnerabilities. The multi-task model was observed to perform better and is less expensive than a single-task model in terms of time, computation, and storage.
Abstract Online markets in cryptocurrency represent a sprawling and eclectic alternative financial system, selling cutting edge techno-investment schemes that are complex and high risk. Crime control is almost entirely absent from this new crypto economy, and it is full of scams. This paper draws on an ethnography of crypto trading to review the main types of scam, suggesting that the grey economy of cryptocurrency trading is part of a wider evolution of society towards the technosocial, and beyond that perhaps towards the metaversal.
Following the rampant increase in Bitcoin prices, there has been a proliferation of cryptocurrencies, which have become a major way of doing business across national boundaries. This paper investigates the link between cryptocurrency markets and drug trafficking activities. More specifically, we explore the impact of the announcement of 24 major drug busts on the systematic risk and return of the world cryptocurrency market. We deploy an event study methodology to estimate the abnormal returns associated with drug trafficking activities in the cryptocurrency market. We find that the relationship between the two is quite strong in the case of some cryptocurrencies, albeit weaker in others. However, we show that drug bust news tends to create uncertainty, and accordingly impart risk into cryptocurrency markets. This study confirms the predictions of convenience theories of crime as to the relative attractiveness of cryptocurrencies to criminals, and the extent to which not only general, but also their own future interests, sacrificed readily on the altar of accessibility. We highlight how when social and regulatory foundations are weak, criminal behaviour may overwhelm virtual spaces, marginalizing more orthodox businesses, no matter how altruistic the intentions of their founders.
Cryptocurrencies have completely altered the digital transaction process all over the globe. Almost a decade after Satoshi Nakamoto generated the first Bitcoin block; many cryptocurrencies have been established. The Ransomware attack is a type of cybercrime and a class of malware that encrypts the files and prevents users from accessing their data or systems and demands payment for decrypting and retrieving access to their files. Ransomware data classification using present data mining and machine learning methods is difficult because predictions aren't always correct. We aim to build two models that effectively address these challenges and can diagnose and classify Ransomware attacks accurately, then compare the performance of the models. In this paper, we investigated the use of Rule-Based algorithms for mining Bitcoin Ransomware Data to classify Ransomware attacks in Bitcoin transactions. Employing Rule-Based techniques in detecting Bitcoin data is beneficial because the algorithms effectively classify non-linear datasets. The analysis was done on a Bitcoin dataset for 61,004 addresses selected from 29 Ransomware families and contained ten descriptive and decision attributes. Both Rule-Based algorithms were illustrated and compared on the dataset employing 10-fold cross-validation. Experimental results show that classification under partial decision tree (PART) algorithm performed better in different metrics than the Decision Table algorithm. It provides an accuracy of 96.01%, a recall of 96%, a precision of 95.9%, and an F-Measure of 95.6%. Experimental results propose that it is beneficial to further investigate the application of PART to predictive modelling tasks in Ransomware studies.
In this paper, we identify and review key challenges to bridge the knowledge-gap between SME's, companies, organisations, businesses, government institutions and the general public in adopting, promoting and utilising Blockchain technology. The challenges indicated are Cybersecurity and Data privacy in this instance. Additional challenges are set out supported by literature, in researching data security management systems and legal frameworks to ascertaining the types and varieties of valid encryption, data acquisition, policy and outcomes under ISO 27001 and the General Data Protection Regulations. Blockchain, a revolutionary method of storage and immutability, provides a robust storage strategy, and when coupled with a Smart Contract, gives users the ability to form partnerships, share information and consent via a legally-based system of carrying out business transactions in a secure digital domain. Globally, ethical and legal challenges significantly differ; consent and trust in the public and private sectors in deploying such defensive data management strategies, is directly related to the accountability and transparency systems in place to deliver certainty and justice. Therefore, investment and research in these areas is crucial to establishing a dialogue between nations to include health, finance and market strategies that should encompass all levels of society. A framework is proposed with elements to include Big Data, Machine Learning and Visualisation methods and techniques. Through the literature we identify a system necessary in carrying out experiments to detect, capture, process and store data. This includes isolating packet data to inform levels of Cybersecurity and privacy-related activities, and ensuring transparency demonstrated in a secure, smart and effective manner.
The purpose of this paper is to identify research that has been carried out about cryptocurrency regulation contributions and the current challenges that need to be addressed in future studies. The methodology used to conduct this research and report the findings was systematic mapping. We use this methodology to search, identify, and select all relevant primary studies on cryptocurrency regulation. The findings reveal that the key cryptocurrency regulation research topics are distributed governance, central bank digital currency, monetary policy, cryptocurrency adoption, security, regulation, cryptocurrency market, cybercrime economy and money laundering. The research proposals for cryptocurrency regulation comprise tools, protocols, methods, models, frameworks and, knowledge. The cryptocurrency regulatory challenges are cryptocurrency adoption, central bank digital currency regulation, accounting for cryptocurrencies and risk for cryptocurrencies. This systematic mapping provides an overview of the solutions proposed to regulate cryptocurrency as well as the current research challenges.
BACKGROUND: Cryptocurrency fraud has become a growing global concern, with various governments reporting an increase in the frequency of and losses from cryptocurrency scams. Despite increasing fraudulent activity involving cryptocurrencies, research on the potential of cryptocurrencies for fraud has not been examined in a systematic study. This review examines the current state of knowledge about what kinds of cryptocurrency fraud currently exist, or are expected to exist in the future, and provides comprehensive definitions of the frauds identified. METHODS: The study involved a scoping review of academic research and grey literature on cryptocurrency fraud and a 1.5-day expert consensus exercise. The review followed the PRISMA-ScR protocol, with eligibility criteria based on language, publication type, relevance to cryptocurrency fraud, and evidence provided. Researchers screened 391 academic records, 106 of which went on to the eligibility phase, and 63 of which were ultimately analysed. We screened 394 grey literature sources, 128 of which passed on to the eligibility phase, and 53 of which were included in our review. The expert consensus exercise was attended by high-profile participants from the private sector, government, and academia. It involved problem planning and analysis activities and discussion about the future of cryptocurrency crime. RESULTS: The academic literature identified 29 different types of cryptocurrency fraud; the grey literature discussed 32 types, 14 of which were not identified in the academic literature (i.e., 47 unique types in total). Ponzi schemes and (synonymous) high yield investment programmes were most discussed across all literature. Participants in the expert consensus exercise ranked pump-and-dump schemes and ransomware as the most profitable and feasible threats, though pump-and-dumps were, notably, perceived as the least harmful type of fraud. CONCLUSIONS: The findings of this scoping review suggest cryptocurrency fraud research is rapidly developing in volume and breadth, though we remain at an early stage of thinking about future problems and scenarios involving cryptocurrencies. The findings of this work emphasise the need for better collaboration across sectors and consensus on definitions surrounding cryptocurrency fraud to address the problems identified.
Jan 1, 2022·Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences
Over 3,739 apps on average are published per day on the Google Play store [1]. A handful of the applications contain advertisement malware referred to as malvertising. As a result, Android advertisement malware has been a growing multi-billion-dollar problem. It constantly assaults many of the major advertising libraries such as the Google, Facebook, and Amazon. This paper presents an effective strategy for countering advertising malware using dynamic and static analysis techniques and the Soot compiler framework. Our research aims to detect malvertising click fraud in Android applications using the Soot compiler framework and blockchain technology. But the approach and the framework can be used to counter mobile malware families.
Digital assets are changing the way businesses think about equity, labor, business models, and business organization. Digital assets, like Bitcoin or Ethereum, provide incredible opportunities to further align shareholders with the objectives of the entity. Each time humanity advances its technology for ledgers, markets explode, and we witness immense wealth creation. Digital assets like Bitcoin and Ethereum are the next great step forward for ledger technology. While there are incredible opportunities to leverage this new technology, there are also incredible risks. There are many public examples of “hacks” of prominent blockchains like Ethereum and Solana. Blockchain technology has captured the imagination of the public. Blockchain, therefore, must develop a robust security system and intelligently distribute and limit liability for institutional and retail investors to reap the rewards of public attention. Part of the risk that comes from digital assets is its newness. Blockchains that run smart contracts have many incredible uses that could eliminate middlemen in many industries. But courts are yet to develop case law surrounding smart contracts. The way that smart contracts self-execute presents a new question which courts must address: how should a court allocate risk between two smart-contracting parties? No matter how the courts decide, the market needs an answer. This article attempts to explore some of the opportunities in digital assets and how these opportunities are fundamentally different from their traditional equivalents.
A smart Ponzi scheme (SPS) is a financial Ponzi scheme that is implemented and deployed in blockchain through smart contract technology. It is built on treachery and lies, by which, the organizers and speculators jointly deceive innocent investors by fostering a belief in obtaining the expected benefits. The occurrence of SPSs is originated from the vulnerability of the supervision mechanism on the blockchain. Although there are many excellent studies, these contributions overemphasized the methods themselves, did not describe the characteristics of the SPS well, and had certain limitations in practice. We made a thorough study on the characteristics of an SPS and brought out the vital features to identify an SPS for an investor. Based on the analysis of the contributions of predecessors, we propose an approach to test whether a contract is an SPS. This approach could deal with two situations, the contracts to be deployed and the long-run contracts respectively. Of the approach, the priori method can be exploited to distinguish whether the contract to be deployed is an SPS for the runner of a blockchain; the posterior method could protect an investor from being trapped in a fraud. At the same time, the posterior method can also be extended to monitor some contracts dynamically to alert users with the probability to be fallen into SPSs.
Know Your Customer (KYC) process plays a vital role for all banks in authenticating the identity of their customers. KYC verification is crucial to prevent banks from being used by illegal elements for money laundering activities such as drug trafficking, terrorism and other crimes. Manual KYC process in mainstream at present is less secure, time consuming and outdated. Since Blockchain offers features like decentralization, immutability and security, these limitations can be eliminated by using Blockchain based KYC verification. In this paper, we have proposed decentralized KYC verification process using Ethereum Blockchain platform. It would allow all the banks in the Blockchain network to verify and vote for legitimacy of the data provided by the customer. Depending on number of votes KYC status of customer gets stored on the Blockchain. Major enhancement in our proposed method is, banks can also vote for other banks if any bank is tampering with the KYC data and it will get removed from the network based on this voting. In this way, Blockchain can be used to improve the efficiency of KYC process with its distinctive features.
Cross-border financial transactions increasingly require robust, secure, and efficient mechanisms for customer identity verification. Regulatory compliance, particularly with Know Your Customer (KYC) standards, Anti-Money Laundering (AML) obligations, and counter-terrorist financing regulations, imposes significant operational and procedural burdens on financial institutions engaged in international finance. Traditional KYC processes rely heavily on manual verification, centralized databases, and fragmented identity documentation, often resulting in inefficiencies, duplications, and heightened exposure to fraud. In response, blockchain technology has emerged as a promising solution, offering decentralized, tamper-proof, and verifiable identity frameworks that can streamline KYC operations, reduce duplication, and enhance cross-border compliance. This paper proposes a conceptual blockchain-based framework for digital identity verification in cross-border financial contexts. The framework leverages distributed ledger technology to securely manage identity credentials, facilitate interoperability among financial institutions, and maintain compliance with international financial regulations. The study synthesizes prior research on blockchain applications in financial services, digital identity management, and KYC automation, highlighting challenges such as privacy, scalability, interoperability, and regulatory integration. By integrating blockchain with secure digital identity protocols, the proposed framework aims to enhance efficiency, trust, and compliance in international financial operations. The paper concludes with a discussion of implementation considerations, potential limitations, and future research directions to enable secure, scalable, and regulatory-compliant digital identity verification in cross-border financial ecosystems.
Purpose The purpose of this paper is to examine the currently known techniques to tackle money laundering in Bitcoin mixers, and examine what gaps exist that would allow a criminal to get away with laundering Bitcoin obtained through illicit activities. Design/methodology/approach This paper first establishes the relevant properties of Bitcoin, how transactions occur over the Bitcoin network and then introduces the Bitcoin transaction graph as an important data structure for any analysis of Bitcoin transactions. Next, the paper outlines how Bitcoin mixing works, along with the relevant properties of mixers that would be relevant for money laundering. The paper then assesses the known methods for identifying mixed transactions within the Bitcoin network, followed by an assessment on identifying money laundering activities on known mixed transactions. Findings This paper argues that there remains a gap for criminals to launder money through Bitcoin mixing services as known methods would unlikely be able to trace a tainted transaction that goes through a decentralized mixer that uses off-chain communication techniques to coordinate the mixing and charges randomized mixing fees. Research limitations/implications The study of known methods is restricted to literature published in the public domain. There are private organizations that are tackling similar problems, but their methods are not published and therefore cannot be included in this paper. Originality/value To best of the author’s knowledge, this is the first paper that performs a contemporaneous review on anti-money laundering in the context of Bitcoin mixing. This paper could assist regulators and policymakers in their understanding of Bitcoin mixers and provide guidance on where they should focus their resources to address the money laundering problem of Bitcoin mixing.
Oumaima Fadi, Karim Zkik, El Ghazi Abdellatif, Mohammed Boulmalf
Smart environments consist of a collection of sensors, actuators, and numerous computing units that improve human life. With the booming of smart environments, data generation has been notably increasing in recent years, which must be managed in a smart and optimal manner. The components (i.e., workstations and cloud) used for data processing are not the best to recommend since it is risky and resource costing. For that matter, enterprises, firms and companies are deploying blockchain technologies (BT) as a more suitable alternative. In fact, blockchain is a distributed transaction ledger ensuring the reliability and transparency of data. However, BT faces some inherent security challenges such as DoS, eclipse and double spending attacks as well as Advanced Persistent Threat (APT) and malware. Thus, advanced anomaly detection and mitigation approaches, especially the ones using artificial intelligence (AI) techniques (e. g. Machine Learning, Deep Learning, Federated Learning) are required to address the aforementioned issues. In combination, AI and BT are capable of detecting anomalies within blockchain networks with high accuracy. In this paper, with a focus on cyber security issues, we explore the challenges of blockchain deployment in smart environments. Additionally, we explore the use of anomaly detection AI-based techniques as a ledger of blockchain technologies to address the security issues in smart environments. Thus, we propose a framework that emphasizes the challenges of BT, values and capabilities of BT-AI integration. We also present research trends to highlight potential research paths for improving the security of blockchain networks using artificial intelligence.
The interest in cryptocurrency investing is constantly growing. Cryptocurrency may be the currency of the future, but it is also the heaven for con artists to scam investors from their money. Crypto transactions are irreversible. If the underlying blockchain technology has privacy or mixer capabilities it can be virtually untraceable, which creates a new avenue for criminals to scam victims with ease. Social media impersonation is one of the top scams currently performed by criminals. This study presents an example of a social media impersonation scam and the characteristics of the scam. The qualitative data is gathered from communication between the scammer and the potential victim. This study also indicates that cryptocurrency awareness should be included in cyber security training curriculums.
Bitcoin is the most widely used cryptocurrency for illegal trade in current darknet markets. Owing to the anonymity of its addresses, even though transaction flows are globally visible, Bitcoin clustering remains one of the most challenging and open problems in illegal Bitcoin transaction analysis. In this article, to resolve this problem, we propose a novelmulti-layer heuristicalgorithm for Bitcoin clustering, which leverages on-chain transactions as well as off-chain application data in the real world. For this purpose, we first explored the unique characteristics of darknet market ecosystems including their trading systems. By conducting an in-depth analysis of the data manually collected for 11 months, we found that some darknet market review data disclosed transactions containing Bitcoin value and item delivery information. We then identified unique Bitcoin addresses associated with the disclosed information, owned by the same darknet providers. Based on address ownership, more accurate market clusters could be created, which have not previously been identified by other clustering algorithms. According to our experimental results, approximately 31.68% of the darknet market review data matched real Bitcoin transactions, and 122 hidden clusters associated with Silk Road 4 were found. This indicates that the proposed algorithm can complement existing clustering methods and significantly reduce the false negative rate by up to 91.7%.
With the proliferation of the blockchain technology ecosystems such as mining pools, crypto exchanges, full Bitcoin nodes, wallets, and pool protocol servers in recent years, the denial of service (DoS) attack vector has become more prevalent, and the attacks are targeted to the peer-to-peer networks and blockchain users. Despite blockchain enhancing security with decentralized design, secured distributed storage, and privacy, it is still vulnerable to new attack threats. If an attempted DoS is successful on blockchain, the impact is most likely massive given the fact that it is predominantly used for finance applications. An extensive account of the current state-of-the-art for possible DoS and corresponding mitigation techniques is not discussed in the existing research. This paper analyzes and categorizes the existing state-of-the-art DoS attack methods, detection techniques, and mitigation solutions targeting blockchain peer-to-peer networks as well as conventional network crypto exchanges. The review of the prior research shows that the blockchain ecosystem can be a target to successfully perform DoS attacks in the future, and technological advancements in blockchain are needed to mitigate potential attacks.