Juan Velandia Botello, Andrés Pardo Mesa, Fabián Ardila Rodríguez, Daniel Díaz López · 6 authors
The Internet of Things (IoT) paradigm has revolutionized several industries (e.g., manufacturing, health, transport, education, among others) by allowing objects to connect to the Internet and, thus, enabling a variety of novel applications. In this sense, IoT devices have become an essential component of smart cities, allowing many novel and useful services, but, at the same time, bringing numerous cybersecurity threats. The paper at hand proposes BlockSIEM, a blockchain-based and distributed Security Information and Event Management (SIEM) solution framework for the protection of the aforementioned smart city services. The proposed SIEM relies on blockchain technology to securely store and access security events. Such security events are generated by IoT sentinels that are in charge of shielding groups of IoT devices. The IoT sentinels may be deployed in smart city scenarios, such as smart hospitals, smart transport systems, smart airports, among others, ensuring a satisfactory level of protection. The blockchain guarantees the non-repudiation and traceability of the registry of security events due to its features. To demonstrate the feasibility of the proposed approach, our proposal is implemented using Ethereum and validated through different use cases and experiments.
The statistical concept of Gambler's Ruin suggests that gambling has a large amount of risk. Nevertheless, gambling at casinos and gambling on the Internet are both hugely popular activities. In recent years, both prospect theory and lab-controlled experiments have been used to improve our understanding of risk attitudes associated with gambling. Despite theoretical progress, collecting real-life gambling data, which is essential to validate predictions and experimental findings, remains a challenge. To address this issue, we collect publicly available betting data from a \emph{DApp} (decentralized application) on the Ethereum Blockchain, which instantly publishes the outcome of every single bet (consisting of each bet's timestamp, wager, probability of winning, userID, and profit). This online casino is a simple dice game that allows gamblers to tune their own winning probabilities. Thus the dataset is well suited for studying gambling strategies and the complex dynamic of risk attitudes involved in betting decisions. We analyze the dataset through the lens of current probability-theoretic models and discover empirical examples of gambling systems. Our results shed light on understanding the role of risk preferences in human financial behavior and decision-makings beyond gambling.
In this paper, we present Zecale, a general purpose SNARK proof aggregator that uses recursive composition of SNARKs. We start by introducing the notion of recursive composition of SNARKs, before introducing Zecale as a privacy preserving scalability solution. Then, we list application types that can emerge and be built with Zecale. Finally, we argue that such scalability solutions for privacy preserving state transitions are paramount to emulate "cash" on blockchain systems.
Gerardo Canfora, Andrea Di Sorbo, Sonia Laudanna, Anna Vacca · 5 authors
Nowadays, blockchain technologies are increasingly adopted for different purposes and in different application domains. Accordingly, more and more applications are developed for running on a distributed ledger technology (i.e., \textit{dApps}). The business logic of a dApp (or part of it) is usually implemented within one (or more) smart contract(s) developed through Solidity, an object-oriented programming language for writing smart contracts on different blockchain platforms, including the popular Ethereum. In Ethereum, once compiled, the smart contracts run on the machines of miners who can earn Ethers (a cryptographic currency like Bitcoin) by contributing their computing resources and the \textit{gas} (in Ether) corresponds to the execution fee compensating such computing resources. However, the deployment and execution costs of a smart contract strictly depend on the choices done by developers while implementing it. Unappropriated design choices -- e.g., in the data structures and the specific instructions used -- could lead to higher gas consumption than necessary. In this paper, we systematically identify a set of 20 Solidity code smells that could affect the deployment and transaction costs of a smart contract, i.e., \textit{cost smells}. On top of these smells, we propose GasMet, a suite of metrics for statically evaluating the code quality of a smart contract, from the gas consumption perspective. In an experiment involving 2,186 real-world smart contracts, we demonstrate that the proposed metrics (i) have direct associations with deployment costs, and (ii) they could be used to properly identify the level of gas consumption of a smart contract without the need for deploying it.
Gerardo Canfora, Andrea Di Sorbo, Sonia Laudanna, Anna Vacca · 5 authors
Nowadays, more and more applications are developed for running on a distributed ledger technology, namely dApps. The business logic of dApps is usually implemented within smart contracts developed through Solidity, a programming language for writing smart contracts on different blockchain platforms, including the popular Ethereum. In Ethereum, the smart contracts run on the machines of miners and the gas corresponds to the execution fee compensating such computing resources. However, the deployment and execution costs of a smart contract depend on the implementation choices done by developers. Unappropriated design choices could lead to higher gas consumption than necessary. In this paper, we (i) identify a set of 19 Solidity code smells affecting the deployment and transaction costs of a smart contract, and (ii) assess the relevance of such smells through a survey involving 34 participants. On top of these smells, we propose GasMet, a suite of metrics for statically evaluating the code quality of a smart contract from the gas consumption perspective. An experiment involving 2,186 smart contracts demonstrates that the proposed metrics have direct associations with deployment costs. The metrics in our suite can be used for more easily identifying source code segments that need optimizations.
Andrea Di Sorbo, Sonia Laudanna, Anna Vacca, Corrado Aaron Visaggio · 5 authors
Nowadays, more and more applications are developed for running on a distributed ledger technology, namely dApps. The business logic of dApps is usually implemented within smart contracts developed through Solidity, a programming language for writing smart contracts on different blockchain platforms, including the popular Ethereum. In Ethereum, the smart contracts run on the machines of miners and the gas corresponds to the execution fee compensating such computing resources. However, the deployment and execution costs of a smart contract depend on the implementation choices done by developers. Unappropriated design choices could lead to higher gas consumption than necessary. In this paper, we (i) identify a set of 19 Solidity code smells affecting the deployment and transaction costs of a smart contract, and (ii) assess the relevance of such smells through a survey involving 34 participants. On top of these smells, we propose GasMet, a suite of metrics for statically evaluating the code quality of a smart contract from the gas consumption perspective. An experiment involving 2,186 smart contracts demonstrates that the proposed metrics have direct associations with deployment costs. The metrics in our suite can be used for more easily identifying source code segments that need optimizations.
Lukas Mastilak, Marek Galinski, Pavol Helebrandt, Ivan Kotuliak · 5 authors
Communication on the Internet consisting of a massive number of Autonomous Systems (AS) depends on routing based on Border Gateway Protocol (BGP). Routers generally trust the veracity of information in BGP updates from their neighbors, as with many other routing protocols. However, this trust leaves the whole system vulnerable to multiple attacks, such as BGP hijacking. Several solutions have been proposed to increase the security of BGP routing protocol, most based on centralized Public Key Infrastructure, but their adoption has been relatively slow. Additionally, these solutions are open to attack on this centralized system. Decentralized alternatives utilizing blockchain to validate BGP updates have recently been proposed. The distributed nature of blockchain and its trustless environment increase the overall system security and conform to the distributed character of the BGP. All of the techniques based on blockchain concentrate on inspecting incoming BGP updates only. In this paper, we improve on these by modifying an existing architecture for the management of network devices. The original architecture adopted a private blockchain implementation of HyperLedger. On the other hand, we use the public blockchain Ethereum, more specifically the Ropsten testing environment. Our solution provides a module design for the management of AS border routers. It enables verification of the prefixes even before any router sends BGP updates announcing them. Thus, we eliminate fraudulent BGP origin announcements from the AS deploying our solution. Furthermore, blockchain provides storage options for configurations of edge routers and keeps the irrefutable history of all changes. We can analyze router settings history to detect whether the router advertised incorrect information, when and for how long.
<sec> <title>BACKGROUND</title> An electronic consent management system can improve the care service significantly by balancing the risks to patient privacy with the benefits of health information exchange and interoperability. Patients leave their health information on multiple providers’ silo. A holistic report and privacy-preserved analysis can help to expedite several medical services including both personal- and community-care. Furthermore, access to consent-based, anonymous health records can accelerate innovation in health services and researches. </sec> <sec> <title>OBJECTIVE</title> We propose BlockMed, a proof-of-concept (POC) for a novel, cost-effective e-consent management system. Given proper consent, BlockMed can query the patient’s information fractured over multiple healthcare-providers’ silo make it available to the patient. At the same time, BlockMed also enables privacy-preserved data analysis by third-party service providers in the same system. Leveraging the unique and anonymous Ethereum id, BlockMed masks out the patient’s original identification in the provider’s secured local silo and abstract away any complication caused by changes in the identification information on multiple silos. </sec> <sec> <title>METHODS</title> The core functionalities of BlockMed are developed with a set of smart contracts on Ethereum blockchain. To develop those smart contracts, we have divided the potential users into three different groups such as, patient, provider, and third-party analyzer. Users are identified by their anonymous Ethereum id and need to sign the consent to access healthcare data. After signing, BlockMed can automatically initiate the queries to fetch data from providers’ data warehouse, enables analysis on any third-party service provider’s infrastructure if required, and finally, presents a report to the intended users including the patient. The signed consents stay on Ethereum forever leaving a permanent audit trail to uphold the integrity of the system. </sec> <sec> <title>RESULTS</title> We evaluated our system in terms of its functionality and cost. Our decentralized application (DApp) can not only query the data from multiple providers' silo but also enable third-party report generation with proper consent and privacy. Masking out the actual patient identification information under anonymous Ethereum ID our DApp can operate irrespective of geographical boundaries. Our cost analysis shows that the adoption of decentralized blockchain-based technology can avoid huge amount of capital investment required for similar services using centralized infrastructure such as AWS cloud. </sec> <sec> <title>CONCLUSIONS</title> Many prior studies have already confirmed that blockchain can improve and expedite data sharing among different providers. Our POC, BlockMed takes it to one step ahead where the data analysis is also integrated. We prove the efficacy of BlockMed by evaluating its functionalities qualitatively as well as its comparing its cost with an alternative cloud-based architecture. </sec>
Pramod Abichandani, Deepan Lobo, Smit Kabrawala, William A. McIntyre
Ethereum blockchain is a powerful, open-source technology for creating decentralized and secure information sharing systems. The main contribution of this article is the experimental validation of an Ethereum blockchain-based software and hardware architecture that enables secure communication for multiple small unmanned aerial vehicles (sUAVs). The experiments involved three DJI M100 quadrotors that shared images captured during flight based on smart contracts created using Ethereum’s Turing complete programming language. The smart contract was designed so that only the intended recipient sUAV could access a specific image. The effect of image size, difficulty level, and consensus algorithms on image transfer times during flight are noted and point to the feasibility of this system in practical missions. The effects of wireless network disruptions on the Ethereum network are documented. The fully documented smart contract code is open sourced to assist readers in quick prototyping. As efforts for decentralization and security of multirobot systems continue to grow, the system architecture and implementation detailed here may serve as a guide for future research.
Context: Smart contracts and DApps are becoming increasingly important and widespread. DApps are often business-critical, and strong security guarantees must be ensured. However, developing safe and reliable smart contracts remains a challenging task. Despite growing literature, simple and actionable tools to address security issues are still lacking. Objective: This study identifies design patterns and best practices for DApp security. We categorize them into twelve critical areas based on their security goals and map them to the architecture of decentralized applications. For each item, we define concrete actions to support secure implementation. These are further structured into three security assurance checklists. Method: We analyze existing literature and manually review 224 security items, consolidating duplicates and harmonizing terminology. This process results in 84 unique items, divided into 36 design patterns and 48 best practices, further grouped into 12 categories. We also map the items into three checklists based on the development phase of DApp lifecycle. Finally, for each pattern and practice, we derive 374 actionable security tasks to guide secure development. Results: To the best of our knowledge, this is the most comprehensive and structured collection of DApp security items to date. The proposed framework and checklists help developers ensure the consistent and complete application of secure design principles. Conclusion: Focusing on Ethereum and Solidity, we present a comprehensive framework for improving DApp security. Our work supports ongoing efforts to reduce vulnerabilities in decentralized applications and provides developers with practical tools to build safer, more reliable systems.
In this paper, the importance of blockchain technology have been discussed and the generations of blockchain (Bitcoin and Ethereum) have been compared provided different aspects. The blockchain is a technology which allows direct transaction without involving third party. Also, it offers many facilities like high translucency, high safety and security, improved trace-ability, greater proficient and transactions' speed, and reduced costs. Moreover, the cryptocurrencies provide advance security level. The basic purpose of this study is to highlight different aspects of Blockchain, Bitcoin and Ethereum and to show which cryptocurrency is better approach. The research contributes to show the impact of this technology in different fields and a comparison of bitcoin and ethereum is presented to analyze and furnish a decision regarding the best among them.
Ethereum has become a widely used platform to enable secure, Blockchain-based financial and business transactions. However, many identified bugs and vulnerabilities in smart contracts have led to serious financial losses, which raises serious concerns about smart contract security. Thus, there is a significant need to better maintain smart contract code and ensure its high reliability. In this research: (1) Firstly, we propose an automated deep learning based approach to learn structural code embeddings of smart contracts in Solidity, which is useful for clone detection, bug detection and contract validation on smart contracts. We apply our approach to more than 22K solidity contracts collected from the Ethereum blockchain, results show that the clone ratio of solidity code is at around 90%, much higher than traditional software. We collect a list of 52 known buggy smart contracts belonging to 10 kinds of common vulnerabilities as our bug database. Our approach can identify more than 1000 clone related bugs based on our bug databases efficiently and accurately. (2) Secondly, according to developers' feedback, we have implemented the approach in a web-based tool, named SmartEmbed, to facilitate Solidity developers for using our approach. Our tool can assist Solidity developers to efficiently identify repetitive smart contracts in the existing Ethereum blockchain, as well as checking their contract against a known set of bugs, which can help to improve the users' confidence in the reliability of the contract. We optimize the implementations of SmartEmbed which is sufficient in supporting developers in real-time for practical uses. The Ethereum ecosystem as well as the individual Solidity developer can both benefit from our research.
Money is clearly a primary need of every human being that cannot be avoided, human needs can be realized by using money. Seeing from the lack of systematic literature review papers discussing cryptocurrency, this is a challenge as well as the main purpose of this paper. Along with the development of modernization and globalization which has now entered the industrial era 4.0 revolution there is a blockchain based technology, Cryptocurrency. Cryptocurrency is one of the developments of the blockchain that is often used as a decentralized digital currency. The word Cryptocurrency means a virtual currency that has no physical form, and Cryptocurrency also means that the transaction currency cannot be seen and is safe. This digital currency has many types such as Bitcoin, Ethereum, Litecoin, Monero, and many other types. Although it has no physical form, this currency functions the same as conventional currencies in general and has an exchange rate. Exchange rates on Cryptocurrency fluctuate which means unexpected, this is often exploited by traders. Cryptocurrency transactions in the form of forwarding from one individual to another individual online, therefore they deal directly without a third party. Every technology has advantages and disadvantages aside from efficiency and convenience, Cryptocurrency has the disadvantage of not having the authority responsible for dealing with all problems that occur in all transactions, and money laundering crimes also often occur, this is a challenge for how to utilize Cryptocurrency and blockchain technology in the current era of globalization.
The proliferation of IoT in various technological realms has resulted in the massive spurt of unsecured data. The use of complex security mechanisms for securing these data is highly restricted owing to the low-power and low-resource nature of most of the IoT devices, especially at the Edge. In this article, we propose to use blockchains for extending security to such IoT implementations. We deploy a Ethereum blockchain consisting of both regular and constrained devices connecting to the blockchain through wired and wireless heterogeneous networks. We additionally implement a secure and encrypted networked clock mechanism to synchronize the non-real-time IoT Edge nodes within the blockchain. Further, we experimentally study the feasibility of such a deployment and the bottlenecks associated with it by running necessary cryptographic operations for blockchains in IoT devices. We study the effects of network latency, increase in constrained blockchain nodes, data size, Ether, and blockchain node mobility during transaction and mining of data within our deployed blockchain. This study serves as a guideline for designing secured solutions for IoT implementations under various operating conditions such as those encountered for static IoT nodes and mobile IoT devices.
Time synchronization among IoT devices is a fundamental requirement for efficient and reliable communication on a global scale. Common synchronization schemes such as NTP operate on a trust-based client-server model, which does not scale well in a decentralized network because single server failures can lead to a severe downtime before re-establishing synchronization. Public blockchains such as Ethereum provide a trustless network and tamper-proof time-stamped data that is freely available. In this paper, we leverage the availability of time information in the block headers, which are very small (several hundreds of bytes) compared to the full blocks and can be validated without participation in the mining process. Our approach uses two estimators that are fed with the timestamps from block headers as well as the elapsed time between consecutive block receptions to estimate the true time to an accuracy of one second. We evaluate our approach by extensive validation on blockchain data from different geographical locations across the globe and show that global synchronization can be established despite the non-deterministic behavior of blockchains such as mining difficulty, network latencies and forks.
Evidence-based applications of resources remain one of the greatest challenges faced by governments, businesses, and policymakers. The United States Government Accountability Office (GAO) evaluated ten large programs, which together cost more than $10 billion/year, through randomised control trials – the highest standard of evidence-based practice (EBP). The evaluation found that nine of them had ‘weak or no positive effects’ on their participants. Many programs were not evaluated at all. In January 2019, U.S. President signed the ‘Foundations for Evidence-based Policy Making Act’ into law. A USAID (US Agency for International Development) study looked at 43 blockchain projects and companies claiming to have solved various problems using distributed ledgers. The study found that almost no company was willing to share their results and MERL (monitoring, evaluation, research and learning) processes. Other observational data revealed that 80–90% of blockchain-based token offering projects failed to deliver on their promises, a prediction also made by Vitalik Buterin, the founder of Ethereum blockchain, in 2017. The concept of evidence-based blockchain (EBB) was first introduced by Naqvi in 2018. We conducted an evaluation of 517 blockchain firms against PCIO framework of evidence-based practice: Problem – Comparison – Intervention and Outcomes. We define the fundamentals of EBB (Ask, Acquire, Appraise, Apply, Assess), provide a review of the literature on EBB, report findings of our study and propose an Assessment Framework of Evidence Based Blockchain.
Umut Uyar, Göksal Selahatdin Kelten, Tuncay MORALI
Bireysel ve kurumsal yatırımcıların finansal piyasalarda yatırım kararları alırken sıklıkla kullandıkları analizler temel analiz ve teknik analiz şeklinde ikiye ayrılmaktadır. Temel analiz; makroekonomik gidişatı, sektörel gelişmeleri ve spesifik olarak yatırım yapılacak varlığın finansal göstergelerini dikkate alırken, teknik analiz; finansal varlıkların geçmiş fiyat hareketlerinden yola çıkarak bu finansal varlığın gelecekteki fiyat hareketlerini tahminlemeye çalışmaktadır. Teorik altyapısı Dow Teorisine dayanan ve “finansal varlığın geçmiş fiyat hareketleri zamanla tekrarlanacaktır” gibi bir takım varsayımlar barındıran teknik analiz yöntemine göre yatırım kararı alınırken çeşitli indikatörler, osilatörler ve formasyonlar kullanılmaktadır. Bu göstergelerden Hareketli Ortalamaların Yakınsaması/Uzaklaşması (MACD), Bollinger Band (BBand), Göreceli Güç Endeksi (RSI) yatırımcıların sıklıkla kullandıkları göstergeler arasındadır. Bu çalışmada 2014-2018 Bitcoin (BTC) ve Ethereum (ETH) günlük fiyat verileri kullanılarak MACD, BBand ve RSI test edilmiş, BTC ve ETH Al/Sat kararları tahmin edilmeye çalışılmıştır. Çıkan sonuçlar neticesinde kripto paraların yatırımcılara sağlayacağı getiriler hesaplanmıştır. Finansal piyasalarda en fazla işlem gören kripto paraların analiz edildiği çalışmada, yatırım kararlarında teknik analizin ne derece etkili olduğu ve bu yatırımlardan teknik analiz kullanılarak herhangi bir getiri sağlanıp sağlanamayacağı irdelenmiştir. Elde edilen bulgulara göre BBand, RSI ve MACD yöntemleri birbirleri ile çelişkili sinyaller verebilmektedir. Bu nedenle yatırımcıların kullanacakları analiz yöntemine göre kazanç ve kayıplarının farklılaşabileceğini söylemek mümkündür
Many popular blockchain platforms are supporting smart contracts for building decentralized applications. However, the vulnerabilities within smart contracts have led to serious financial loss to their end users. For the EOSIO blockchain platform, effective vulnerability detectors are still limited. Furthermore, existing vulnerability detection tools can only support one blockchain platform. In this work, we present WANA, a cross-platform smart contract vulnerability detection tool based on the symbolic execution of WebAssembly bytecode. Furthermore, WANA proposes a set of test oracles to detect the vulnerabilities in EOSIO and Ethereum smart contracts based on WebAssembly bytecode analysis. Our experimental analysis shows that WANA can effectively detect vulnerabilities in both EOSIO and Ethereum smart contracts with high efficiency.
Smart contracts are programs, which are stored in a decentralized network i.e. Block chain. These are written by users to develop decentralized applications using different platform like Ethereum and bitcoin. In current scenario, even though blockchain support features like security and transparency. Because of solidity language vulnerability, there is a possibility of attacks on smart contracts in blockchain. So, to avoid those attacks like i.e. Locked Ether, Transaction order dependency and Time stamp dependency. We discussed, analyzed and tested these attacks in this paper. Further, in our project supply chain management for textile industry using block chain technology, we have developed smart contract using solidity language on Ethereum Platform. With the aim of protecting our project from these attacks, we are thoroughly and experimentally analyzed. And based on the experimental observations, we are going to protect our project from these attacks. All the above mentioned attacks are thoroughly studied and experimentally tested on Ganache, Ropston test network, Rinkeby test network using Remix IDE in JVM, injectedweb3and web3 provider environments. Finally, we have suggested security measures to protect from these attacks
This paper describes the Distributed Ledger Network Analyzer (DiLeNA), a new software tool for the analysis of the transactions network recorded in Distributed Ledger Technologies (DLTs). The set of transactions in a DLT forms a complex network. Studying its characteristics and peculiarities is of paramount importance, in order to understand how users interact in the distributed ledger system. The tool design and implementation is introduced and some results are provided. In particular, the Bitcoin and Ethereum blockchains, i.e. the most famous and used DLTs at the time of writing, have been analyzed and compared.
The increasing of digital technology today has helped many people to fulfill their needs. But the election system, still conventionally using paper in its implementation. Elections in general still use a centralized system, where there is an organization that manages it. Some of the problems that may occur in traditional electoral systems are that there are organizations that have full control over the database and system, so the possibility of hacking the database is quite a big opportunity.Blockchain innovation is one arrangement that can be utilized in light of the fact that it has a decentralized framework and the whole database is duplicated by all clients. Blockchain itself has been used by Bitcoin and Ethereum cryptocurrency which is known as a decentralized system. By using the blockchain in database recording on an e-voting system can reduce one source of fraud that is database manipulation. This study discusses the recording of voting data using blockchain technology. The implementation of Smart Contracts contained in the Ethereum Blockchain will be implemented to create this voting system
Sharding is a promising blockchain scaling solution. But it currently suffers from high latency and low throughput when it comes to cross-shard transactions, i.e., transactions that require coordination from multiple shards. The root cause of these limitations arise from the use of the classic two-phase commit protocol, which involves locking assets for extended periods of time. This paper presents Rivet, a new paradigm for blockchain sharding that achieves lower latency and higher throughput for cross-shard transactions. Rivet has a single reference shard running consensus, and multiple worker shards maintaining disjoint states and processing a subset of transactions in the system. Rivet obviates the need for consensus within each worker shard, and as a result, tolerates more failures within a shard and lowers communication overhead. We prove the correctness and security of Rivet. We also propose a more realistic framework for evaluating sharded blockchains by creating a benchmark based on real Ethereum transactions. An evaluation of our prototype implementation of Rivet and the baseline two-phase commit, atop 50+ AWS EC2 instances, using our evaluation framework demonstrates the latency and throughput improvements for cross-shard transactions.