As the pioneer of blockchain technology, Bitcoin is the most popular cryptocurrency to date. Given its dramatic price spikes (and crashes) along with the never-ending news from SEC regulations to security breaches, there seems to be a lack of understanding about the dynamics of cryptocurrencies. These dynamics are believed to be affected by various political, security, financial, and regulatory events. In this paper, we present an efficient framework for holistic analysis of cryptocurrency fluctuations by introducing the Impact-Score metric to distinguish event-induced changes from normal variations. We have applied our framework to 16 major worldwide events and the Bitcoin blockchain network (defined as Bitcoin transaction and users, blockchain data, and memory pool data) from 2016-2018. The results show that a majority of the events are correlated with substantial network changes. We observed roughly generalizable correlations between event types (e.g. financial events) and sub-structures of the Bitcoin blockchain network. Subgroups of these events have strongly consistent temporal impacts on specific facets (e.g. activity or fees) of the Bitcoin ecosystem. Furthermore, we demonstrate the robustness of our process by correlating a majority of spikes in network/subnetwork change with major events.
Marsha Chikita Intania Putri, Parman Sukarno, Aulia Arif Wardana
Authentication is a method for securing an account by verifying the user identity by inputting email with a password. Two factor authentications is an authentication system that combines the first-factor authentication with the second factor. General two factor authentication by entering an email or username with a password are similar. However, two factor authentication requires additional information that must be inputted by the user. Additional information can be in the form of tokens or one-time passwords (OTP). Two factor authentications generally still uses third-party services to generate token or OTP still have vulnerable because can attacked from tokens steal through MITM and found that the generated tokens with the same value. Therefore, we propose a two-factor authentication framework based on ethereum blockchain with dApp as token generation system. Firstly, outcome from the analysis of the system, next succeeded in creating a two-factor authentication system without using third-parties. Second, token system generate up to 3164 different tokens in one second and has been collisions tested. Third, security method to protect token from MITM attack. The attacker unable to get access caused all the checking are done by dApp user authentication.
The blockchain technology firstly presented by Haber and Stornetta in the year 1990, and first time blockchain technology used in Bitcoin by Satoshi Nakamoto in 2008. The blockchain technology is truly decentralized technology. In blockchain technology, every block has consisted three main parts that is data, hash block, and the previous hash block. Hash is controls the uniqueness of each block and it is unique for each block. Each block also contains the hash of the previous block; thus, the blocks are connected to each other. A blockchain can divided into three categories public blockchain, consortium blockchain and private blockchain. The proposed paper provided the comparative and analytical review on the blockchain consensus algorithms.
Self-sovereign identity is a new identity management paradigm that allows entities to really have the ownership of their identity data and control their use without involving any intermediary. Blockchain is an enabling technology for building self-sovereign identity systems by providing a neutral and trustable storage and computing infrastructure, and can be viewed as a component of the systems. Both blockchain and self-sovereign identity are emerging technologies which could present a steep learning curve for architects. We collect and propose 12 design patterns for blockchain-based self-sovereign identity systems to help the architects understand and easily apply the concepts in system design. Based on the lifecycles of three main objects involved in self-sovereign identity, we categorise the patterns into three groups: key management patterns, decentralised identifier management patterns, and credential design patterns. The proposed patterns provide a systematic and holistic guide for architects to design the architecture of blockchain-based self-sovereign identity systems.
Lei Wu, Siwei Wu, Yajin Zhou, Runhuai Li · 8 authors
As one of the representative blockchain platforms, Ethereum has attracted lots of attacks. Due to the existed financial loss, there is a pressing need to perform timely investigation and detect more attack instances. Though multiple systems have been proposed, they suffer from the scalability issue due to the following reasons. First, the tight coupling between malicious contract detection and blockchain data importing makes them infeasible to repeatedly detect different attacks. Second, the coarse-grained archive data makes them inefficient to replay transactions. Third, the separation between malicious contract detection and runtime state recovery consumes lots of storage. In this paper, we present the design of a scalable attack detection framework on Ethereum. It overcomes the scalability issue by saving the Ethereum state into a database and providing an efficient way to locate suspicious transactions. The saved state is fine-grained to support the replay of arbitrary transactions. The state is well-designed to avoid saving unnecessary state to optimize the storage consumption. We implement a prototype named EthScope and solve three technical challenges, i.e., incomplete Ethereum state, scalability, and extensibility. The performance evaluation shows that our system can solve the scalability issue, i.e., efficiently performing a large-scale analysis on billions of transactions, and a speedup of around 2,300x when replaying transactions. It also has lower storage consumption compared with existing systems. The result with three different types of information as inputs shows that our system can help an analyst understand attack behaviors and further detect more attacks. To engage the community, we will release our system and the dataset of detected attacks.
Lei Wu, Siwei Wu, Yajin Zhou, Runhuai Li · 8 authors
As one of the representative blockchain platforms, Ethereum has attracted
lots of attacks. Due to the potential financial loss, there is a pressing need
to detect malicious smart contracts and understand their behaviors. Though
there exist multiple systems for smart contract analysis, they cannot
efficiently analyze a large number of transactions and re-execute smart
contracts to introspect malicious behaviors. In this paper, we urge for a transaction-centric security analytics framework
for Ethereum, which provides an efficient way to quickly locate suspicious ones
from a large number of transactions and extensible way to detect malicious
smart contracts with analyst-provided scripts. We present the system design in
the paper, which solves three technical challenges, i.e., incomplete states,
scalability and extensibility. We have implemented a prototype system named
EthScope to solve these challenges. In particular, the first component Data
Aggregator collects and recovers critical blockchain states. The second
component Replay Engine is able to {replay} arbitrary and a large number of
transactions. The third component Instrumentation Framework exposes interfaces
for an analyst to dynamically instrument smart contracts and introspect the
execution of suspicious transactions. The comprehensive evaluation with six
types of attacks demonstrated the effectiveness of our system. The performance
evaluation shows that our system can perform a large-scale analysis on
suspicious transactions (more than 8 million ones) and has a speed up of around
2,300x compared with the JSTracer provided by Go-Ethereum. To engage the
community, we will release our system and a dataset of detected attacks on
https://github.com/zjuicsr/ethscope.
Paulo Silva, David Vavřička, João Barreto, Miguel Matos
Given the large adoption and economical impact of permissionless blockchains, the complexity of the underlying systems and the adversarial environment in which they operate, it is fundamental to properly study and understand the emergent behavior and properties of these systems. We describe our experience on a detailed, one-month study of the Ethereum network from several geographically dispersed observation points. We leverage multiple geographic vantage points to assess the key pillars of Ethereum, namely geographical dispersion, network efficiency, blockchain efficiency and security, and the impact of mining pools. Among other new findings, we identify previously undocumented forms of selfish behavior and show that the prevalence of powerful mining pools exacerbates the geographical impact on block propagation delays. Furthermore, we provide a set of open measurement and processing tools, as well as the data set of the collected measurements, in order to promote further research on understanding permissionless blockchains.
Cong T. Nguyen, Diep N. Nguyen, Hoang Thai Dinh, Hoang-Anh Pham · 7 authors
Mobile service providers (MSPs) are particularly vulnerable to roaming frauds, especially ones that exploit the long delay in the data exchange process of the contemporary roaming management systems, causing multi-billion dollars loss each year. In this paper, we introduce BlockRoam, a novel blockchain-based roaming management system that provides an efficient data exchange platform among MSPs and mobile subscribers. Utilizing the Proof-of-Stake (PoS) consensus mechanism and smart contracts, BlockRoam can significantly shorten the information exchanging delay, thereby addressing the roaming fraud problems. Through intensive analysis, we show that the security and performance of such PoS-based blockchain network can be further enhanced by incentivizing more users (e.g., subscribers) to participate in the network. Moreover, users in such networks often join stake pools (e.g., formed by MSPs) to increase their profits. Therefore, we develop an economic model based on Stackelberg game to jointly maximize the profits of the network users and the stake pool, thereby encouraging user participation. We also propose an effective method to guarantee the uniqueness of this game's equilibrium. The performance evaluations show that the proposed economic model helps the MSPs to earn additional profits, attracts more investment to the blockchain network, and enhances the network's security and performance.
To implement a blockchain, we need a blockchain protocol for all the nodes to follow. To design a blockchain protocol, we need a block publisher selection mechanism and a chain selection rule. In Proof-of-Stake (PoS) based blockchain protocols, block publisher selection mechanism selects the node to publish the next block based on the relative stake held by the node. However, PoS protocols, such as Ouroboros v1, may face vulnerability to fully adaptive corruptions. In this paper, we propose a novel PoS-based blockchain protocol, QuickSync, to achieve security against fully adaptive corruptions while improving on performance. We propose a metric called block power, a value defined for each block, derived from the output of the verifiable random function based on the digital signature of the block publisher. With this metric, we compute chain power, the sum of block powers of all the blocks comprising the chain, for all the valid chains. These metrics are a function of the block publisher's stake to enable the PoS aspect of the protocol. The chain selection rule selects the chain with the highest chain power as the one to extend. This chain selection rule hence determines the selected block publisher of the previous block. When we use metrics to define the chain selection rule, it may lead to vulnerabilities against Sybil attacks. QuickSync uses a Sybil attack resistant function implemented using histogram matching. We prove that QuickSync satisfies common prefix, chain growth, and chain quality properties and hence it is secure. We also show that it is resilient to different types of adversarial attack strategies. Our analysis demonstrates that QuickSync performs better than Bitcoin by an order of magnitude on both transactions per second and time to finality, and better than Ouroboros v1 by a factor of three on time to finality.
Over the past few years, there has been a growth in activity, public knowledge, and awareness of cryptocurrencies and related blockchain technology. As the industry has grown, there has also been an increase in scams looking to steal unsuspecting individuals' cryptocurrency. Many of the scams operate on visually similar but seemingly unconnected websites, advertised by malicious social media accounts, which either attempt an advance-fee scam or operate as phishing websites. This paper analyses public online and blockchain-based data to provide a deeper understanding of these cryptocurrency scams. The clustering technique DBSCAN is applied to the content of scam websites to discover a typology of advance-fee and phishing scams. It is found that the same entities are running multiple instances of similar scams, revealed by their online infrastructure and blockchain activity. The entities also manufacture public blockchain activity to create the appearance that their scams are genuine. Through source and destination of funds analysis, it is observed that victims usually send funds from fiat-accepting exchanges. The entities running these scams cash-out or launder their proceeds using a variety of avenues including exchanges, gambling sites, and mixers.
Bitcoin paper gave birth to a new era; cryptocurrencies aiming distributed trust model. Almost all the cryptocurrencies require their users individually manage their own cryptographic keys, provide or recommend use of cryptocurrency wallets. A wallet, which at least stores public-private keys and addresses, is one of the key points for end-users' security. Since the authentication of a transaction strictly depends on private keys, any adversary who gains access to a wallet may seize all the coins within. Hence, cryptocurrency wallet solutions should be carefully analyzed and better to be certified if possible. In this study, we aim to define the security problems and objectives necessary for the development of a certified product that can stand against the known attacks within the Framework of Common Criteria (CC). We believe this would be a brief source for cryptocurrency wallet Protection Profile (PP) and Security Target (ST) documents.
Ralph Holz, Diego Perino, Matteo Varvello, Johanna Amann · 9 authors
In late 2017, a sudden proliferation of malicious JavaScript was reported on the Web: browser-based mining exploited the CPU time of website visitors to mine the cryptocurrency Monero. Several studies measured the deployment of such code and developed defenses. However, previous work did not establish how many users were really exposed to the identified mining sites and whether there was a real risk given common user browsing behavior. In this paper, we present a retroactive analysis to close this research gap. We pool large-scale, longitudinal data from several vantage points, gathered during the prime time of illicit cryptomining, to measure the impact on web users. We leverage data from passive traffic monitoring of university networks and a large European ISP, with suspected mining sites identified in previous active scans. We corroborate our results with data from a browser extension with a large user base that tracks site visits. We also monitor open HTTP proxies and the Tor network for malicious injection of code. We find that the risk for most Web users was always very low, much lower than what deployment scans suggested. Any exposure period was also very brief. However, we also identify a previously unknown and exploited attack vector on mobile devices.
With the revolution and growth of the media industry, and development of new mediums to update citizens with the latest news, in recent years there has been a spurt in the production of articles spreading fake information. Many media channels leverage on the concept of spreading eye-catching malicious news that attracts readers which has been proven to be quite dangerous in most cases. These channels post an exaggerated version of the truth, thus leading to an emerging trend of spreading fake news. To tackle this problem, we propose a two-step solution involving machine learning and block chain. The proposed solution consists of a news verification portal using a two-fold approach, which first detects whether the news article is fake or real leveraging the accuracy of a machine learning algorithm and then verifies the source using human crowd auditors on a block chain platform based on proof-of-stake.
The limitation with smart contracts is that they cannot access external data which might be required to control the execution of business logic. Oracles can be used to provide external data to smart contracts. An oracle is an interface that delivers data from external data outside the blockchain to a smart contract to consume. Oracle can deliver different types of data depending on the industry and requirements. In this paper, we study and describe the widely used blockchain oracles. Then, we elaborate on his potential role, technical architecture, and design patterns. Finally, we discuss the human oracle and his key role in solving the truth problem by reaching a consensus about a certain inquiry and tasks.
As the indispensable trading platforms of the ecosystem, hundreds of cryptocurrency exchanges are emerging to facilitate the trading of digital assets. While, it also attracts the attentions of attackers. A number of scam attacks were reported targeting cryptocurrency exchanges, leading to a huge mount of financial loss. However, no previous work in our research community has systematically studied this problem. In this paper, we make the first effort to identify and characterize the cryptocurrency exchange scams. We first identify over 1,500 scam domains and over 300 fake apps, by collecting existing reports and using typosquatting generation techniques. Then we investigate the relationship between them, and identify 94 scam domain families and 30 fake app families. We further characterize the impacts of such scams, and reveal that these scams have incurred financial loss of 520k US dollars at least. We further observe that the fake apps have been sneaked to major app markets (including Google Play) to infect unsuspicious users. Our findings demonstrate the urgency to identify and prevent cryptocurrency exchange scams. To facilitate future research, we have publicly released all the identified scam domains and fake apps to the community.
Crowdfunding is an innovative way of financing projects that allows anyone to contribute money online and support various initiatives, such as businesses, causes, or solutions. However, traditional crowdfunding platforms face some challenges, such as lack of transparency and security, high fees, and limited control over the funds by the contributors and the project owners. Blockchain technology, which is a P2P, decentralized ledger, which is distributed can offer a more reliable, secure, and transparent solution for crowdfunding. Blockchain-based crowdfunding can leverage smart contracts, which are self-executing agreements that encode the rules and conditions of the funding process and ensure that the funds are released only when the predefined criteria are met. This paper aims to propose a concept for designing efficient smart contracts for crowdfunding, which can enable both the contributors and the project owners to have more control and influence over the funds and the project outcomes. Unlike the existing literature-based ideas, our proposed method not only allows the contributors to invest their own money, but also guarantees them that their token values will be preserved. This method can be integrated without disrupting the existing logic of the blockchain. The methodology provides higher control and transparency for all the parties involved in the crowdfunding process.
Son yıllarda, bloglar, tweet’ler, forumlar, e-postalar gibi Web 2.0 hizmetleri iletişim kanalı olarak yaygın bir şekilde kullanılmaktadır. Ayrıca sosyal medya; gerek bilgi paylaşımı gerekse istek, şikayet ve dilekler gibi görüşleri belirtmenin en kolay ve en güncel yolu olarak düşünülmektedir. Sosyal medyanın, birçok alana olduğu gibi Bitcoin fiyatlarına olan etkisi de son yıllarda tartışılmaktadır. Bitcoin yıllardır üzerinde durulan ve popülerliği her geçen gün artan bir yatırım aracıdır. Merkezi olmayan bir elektronik para birimi sistemi olan Bitcoin, çok sayıda kullanıcının ilgisini çeken, finansal sistemlerdeki köklü bir değişikliği ifade etmektedir. Bu çalışmada sosyal medyanın, özellikle Twitter kanalından elde edilen tweet’ler bazında, Bitcoin fiyatı ile etkileşimi ortaya konulmuştur. Bunun için 06.10.2018-19.05.2019 tarihleri arasında Twitter kullanıcıları tarafından atılan toplam 2.819.784 tweet üzerinden makine öğrenmesi yöntemlerinden sınıflandırma algoritmaları kullanılarak çeşitli analizler gerçekleştirilmiştir. Bulgular değerlendirildiğinde metin sınıflandırmada %90 ile en yüksek doğruluk oranına sahip olan Yapay Sinir Ağları kullanılmıştır. Ayrıca Bitcoin fiyatları ve sınıflandırılmış olumlu/olumsuz tweet oranları ile ikili korelasyon yapılmıştır. Elde edilen 0,681 korelasyon katsayısı ile pozitif yönde orta üstü kuvvetli ilişki tespit edilmiştir.
Currently, there are hundreds of Bitcoin exchanges on the market, so choosing a reliable exchange is a critical issue for users. We know that the amount of Bitcoin holdings is an essential indicator for evaluating an exchange, but people have very few ways to access this information. Besides, many reports indicate that the trading volumes of most Bitcoin exchanges do not match their real situations, and the fake volume has become an unspoken rule of the whole industry. It causes the public to doubt the actual amount of Bitcoin owned by each exchange. To solve the problem of information asymmetry between users and exchanges, we propose a method for tagging Bitcoin addresses of exchanges. Through vertical, forward, and backward address mining, the method can utilize only one or several addresses of an exchange to find out all its addresses and distinguish different address types: deposit wallet, hot wallet, and cold wallet. Then the balance and transfers of the exchange can be further obtained through these addresses, helping users understand the real Bitcoin holdings of the exchange. Several experiments are conducted to evaluate the effectiveness of the proposed Bitcoin address tagging method. Our method has very little dependence on off-chain information. Only one address is needed for each exchange as a seed to find out all the other addresses. Such a seed address can be easily obtained by depositing some Bitcoin into the exchange or withdrawing some from it, which makes our method feasible for all exchanges.
Ethereum Smart contracts use blockchain to transfer values among peers on networks without central agency. These programs are deployed on decentralized applications running on top of the blockchain consensus protocol to enable people to make agreements in a transparent and conflict-free environment. The security vulnerabilities within those smart contracts are a potential threat to the applications and have caused huge financial losses to their users. In this paper, we present a framework that combines static and dynamic analysis to detect Reentrancy vulnerabilities in Ethereum smart contracts. This framework generates an attacker contract based on the ABI specifications of smart contracts under test and analyzes the contract interaction to precisely report Reentrancy vulnerability. We conducted a preliminary evaluation of our proposed framework on 5 modified smart contracts from Etherscan and our framework was able to detect the Reentrancy vulnerability in all our modified contracts. Our framework analyzes smart contracts statically to identify potentially vulnerable functions and then uses dynamic analysis to precisely confirm Reentrancy vulnerability, thus achieving increased performance and reduced false positives.
Popular Blockchain-based cryptocurrencies, like Bitcoin, are increasingly being used maliciously for illegal trades. In order to trace and analyze suspected Bitcoin transactions and addresses, address clustering methods and Bitcoin flow analysis methods are gaining attention recently. However, existing methods only focus on Bitcoin addresses and flow, and neglect other important information, such as transaction structure and behavior features. In order to exploit all useful features of transactions, this paper proposes a Bitcoin transaction network analytic method for facilitating Blockchain forensic investigation based on an extended safe Petri Net. The structural features and dynamic semantics of Petri net are used in our proposed model to define the static and dynamic features of Bitcoin transactions. Nineteen features have been identified to define Bitcoin transaction patterns for analyzing and finding suspected addresses. Bitcoin gene has been embedded into the Petri net transitions to trace and analyze Bitcoin flow accurately. Finally, marginal distribution analysis of Bitcoin transaction features and data visualization techniques are used to eliminate some false positive samples further and to improve the accuracy of identifying suspected addresses. The proposed Bitcoin transaction network analytic method provides a reliable forensic investigation model along with a prototype platform which is beneficial for financial security. The efficiency of our proposed method is empirically verified based on a real-life case study analysis.
Blockchain technology gains more and more attention in the past decades and has been applied in many areas. The main bottleneck for the development and application of blockchain is its limited scalability. Blockchain with directed acyclic graph structure (BlockDAG) is proposed in order to alleviate the scalability problem. One of the key technical problems in BlockDAG is the identification of honest blocks which are very important for establishing a stable and invulnerable total order of all the blocks. The stability and security of BlockDAG largely depends on the precision of honest block identification. This paper presents a novel universal framework based on graph theory, called MaxCord, for identifying the honest blocks in BlockDAG. By introducing the concept of discord, the honest block identification is modelled as a generalized maximum independent set problem. Several algorithms are developed, including exact, greedy and iterative filtering algorithms. The extensive comparisons between proposed algorithms and the existing method were conducted on the simulated BlockDAG data to show that the proposed iterative filtering algorithm identifies the honest blocks both efficiently and effectively. The proposed MaxCord framework and algorithms can set the solid foundation for the BlockDAG technology.
In this competitive world, it is hard to get a job. It requires some specific qualifications and experience according to the post. If a person is not fulfilling these required entities, then not able to apply for that post. Therefore, some people, who are not eligible may use different forgery approaches like fake mark sheets, fake experience certificates, fake medical certificates, etc. However, despite being these fake certificates, some people may have a criminal background also. Therefore, large numbers of resources are required to verify the educational records, criminal background, and experience of a person. Therefore, the proposed system provides an efficient solution to these problems using blockchain technology. In the proposed work, we used three different modules like college, organisation, and police. The college is responsible for providing academic qualifications and the organisation is responsible for providing experience while police are responsible for proving and verification of the criminal record. The proposed system is implemented on the Ethereum blockchain platform and effectively can be used by the organisations for verifying the record of their employees.