Arkan Hammoodi Hasan Kabla, Mohammed Anbar, Selvakumar Manickam, Shankar Karupayah
Recently, the rapid flourish of blockchain technology in the financial field has attracted many cybercriminals’ attention to launch blockchain-based attacks such as Ponzi schemes, Scam wallets, and phishing scams. Currently, Ethereum is the most prominent blockchain-based platform and the first that supports smart contracts. However, the number of phishing scam accounts are reportedly more than 50% of all cybercrimes in Ethereum. In contrast, this paper proposes a detection mechanism called Ethereum Phishing Scam Detection (Eth-PSD) that attempts to detect phishing scam-related transactions using a novel machine learning-based approach. Eth-PSD tackles some of the limitations in the existing works, such as the use of imbalanced datasets, complex feature engineering, and lower detection accuracy. We also investigated the aspects of constructing a new updated and balanced dataset that can be used for evaluating Eth-PSD effectively. Our experimental results indicate that Eth-PSD could efficiently detect the phishing scam on Ethereum with a detection accuracy of 98.11%, with a very low False Positive Rate of 0.01. Taken together, Eth-PSD showed a superior advantage compared to the existing works in reducing the dimensionality of the dataset by feature engineering and achieved an overall detection accuracy with an improvement of at least 6% compared to other existing solutions from the related work.
Shahid Hussain Danwar, Javed Ahmed Mahar, Aneela Kiran
Election allows the voter of a country to select the most suitable group of candidates to run the government. Election in Pakistan is simply paper-based method but some certain political and socio-economic issues turn that simple process in complicated and disputes once. Solutions of such problems are consisting of many methods including the e-voting system. The e-voting system facilitates the voters to cast their votes by electronic means with very easy and convenient way. This also allows maintaining the security and secrecy of the voter along with election process. Electronic voting reduces the human-involvement throughout the process from start to the end. Such system is not established yet in Pakistan. Hence, every election is disputed always. In this paper we proposed the framework of an e-voting system and simulation with the use of blockchain ledger technology. The proposed framework owns the capacity to deal with ballots in Pakistan. The novelty of the framework is that the e-voting system is linked to National Database and Registration Authority (NADRA) database which assures voter's validation. The fundamental requirements were kept in consideration during the performance evaluation of the system. The results are processed and depicted specially with reference to the number of voters and voting stations, real time of vote casting, network bandwidth and controlling principles. The results support the decision makers and guide them in the foundation and customization of an e-voting system in Pakistan.
A smart public transport system is expected to be an integral part of our human lives to improve our mobility and reduce the effect of our carbon footprint. The safety and ongoing maintenance of the smart public transport system from cyberattacks are vitally important. To provide more comprehensive protection against potential cyberattacks, we propose a novel approach that combines blockchain technology and a deep learning method that can better protect the smart public transport system. By the creation of signed and verified blockchain blocks and chaining of hashed blocks, the blockchain in our proposal can withstand unauthorized integrity attack that tries to forge sensitive transport maintenance data and transactions associated with it. A hybrid deep learning-based method, which combines autoencoder (AE) and multi-layer perceptron (MLP), in our proposal can effectively detect distributed denial of service (DDoS) attempts that can halt or block the urgent and critical exchange of transport maintenance data across the stakeholders. The experimental results of the hybrid deep learning evaluated on three different datasets (i.e., CICDDoS2019, CIC-IDS2017, and BoT-IoT) show that our deep learning model is effective to detect a wide range of DDoS attacks achieving more than 95% F1-score across all three datasets in average. The comparison of our approach with other similar methods confirms that our approach covers a more comprehensive range of security properties for the smart public transport system.
Yourong Chen, Hao Chen, Yang Zhang, Meng Han · 6 authors
Owing to the incremental and diverse applications of cryptocurrencies and the continuous development of distributed system technology, blockchain has been broadly used in fintech, smart homes, public health, and intelligent transportation due to its properties of decentralization, collective maintenance, and immutability. Although the dynamism of blockchain abounds in various fields, concerns in terms of network communication interference and privacy leakage are gradually increasing. Because of the lack of reliable attack analysis systems, fully understanding some attacks on the blockchain, such as mining, network communication, smart contract, and privacy theft attacks, has remained challenging. Therefore, in this study, we examine the security and privacy of the blockchain and analyze possible solutions. We systematical classify the blockchain attack techniques into three categories, then discuss the corresponding attack and defense methods based on these categories. We focus on (1) the attack and defense methods of mining pool attacks for blockchain security issues, such as block withholding, 51%, pool hopping, selfish mining, and fork after withholding attacks, in the attack type of consensus excitation; (2) the attack and defense methods of network communication and smart contracts for blockchain security issues, such as distributed denial-of-service, Sybil, eclipse, and reentrancy attacks, in the attack type of middle protocol; and (3) the attack and defense methods of privacy thefts for blockchain privacy issues, such as identity privacy and transaction information attacks, in the attack type of application service. Finally, we discuss future research directions for blockchain security.
When building the large-scale distributed decision control system based on mobile terminal devices (MTDs), electronic voting (E-voting) is a necessary technique to settle the dispute among parties. Due to the inherent insecurity of Internet, it is difficult for E-voting to attain complete fairness and robustness. In this study, we argue that Bitcoin blockchain offers better options for a more practical E-voting. We first present a coin mixing-based E-voting system model, which can cut off the relationship between the voter’s real identity and its Bitcoin address to achieve strong anonymity. Moreover, we devise a secret sharing-based E-voting protocol, which can prevent voting number from being leaked ahead and further realize strong robustness. We establish the probable security theory to prove its security. In addition, we use the experimental evaluation to demonstrate its efficiency.
Covid-19 pandemisi ile birçok gereksinimler uzaktan ve sosyal mesafe kurallarına göre gerçekleştirmektedir. Bu kurallar, eğitim, iş, market alışverişi gibi birçok alanda uygulanmaktadır. Anket veya oy kullanmada bu süreçte zamanla zorunlu hale gelebilecektir. Günümüzde anketlerin çoğu elektronik sistemler üzerinden gerçekleştirilmektedir. Kullanıcılar, oluşturulan anketleri paylaşarak hiçbir temasta bulunmadan fikir alışverişi yapabilmektedir. Çalışmada bir anket sistemi oluşturulmuştur. Bu çalışmada asıl amaç ise anket kayıtları blok zincir altyapısı kullanan etheryum ağında oluşturulan akıllı kontrat üzerine kaydedilerek kayıtların ileri seviyede güvenliği sağlanmasıdır. Çalışmada kullanıcı verilerinin güvenliği ön planda tutulurken kullanım kolaylığı da sağlanmaktadır. Çalışmada, web ara yüzleri için Web3.js, Bootstrap ve MVC teknolojileri kullanılmıştır. Akışı sağlamak için veri kaydı iki alana yapılmaktadır. Bunlardan ilki etheryum tabanlı akıllı kontrat diğeri MySQL veri tabanıdır. Kullanıcı verileri ilk olarak blok ağına kayıt talebinde bulunmaktadır. Bu sürede, kullanıcının kaydı ağa kaydedilinceye kadar beklememesi için veriler MySQL veri tabanına da kaydedilmektedir. Böylelikle kullanıcı beklemek zorunda kalmamakta ve işlemlerine devam edebilmektedir. Kullanıcı sistemden verilerinin kontrolünü yapmak istediğinde kontrol modülünden etheryum test ağındaki veri ile MySQL verisini karşılaştırması istenmektedir. Karşılaştırma sonrası bir sorun olması durumunda profil anahtarı ile yöneticiye başvurulmakta ve tam güvenlik sağlayan blok zincir ağındaki kayıt doğru kabul edilmektedir. Çalışma, ankette bulunan kullanıcı verilerinin güvenliğini üst seviye de sağlaması ile literatüre katkı sağlamaktadır.
Due to the unique characteristics of blockchain, such as decentralization, anonymity, high credibility, and nontampering, blockchain technologies have become an integral part of public data platforms and public infrastructure. The communication between the stakeholders of a given blockchain can be used as a carrier for covert communication under cover of legal transactions, which has become a promising research direction of blockchain technology. Due to the special mechanism of blockchain, some traditional blockchain covert communication schemes are not mature enough. They suffer from various drawbacks, such as weak concealment of secret information, cumbersome identification and screening of special transactions, poor availability, and low comprehensive performance. Therefore, this paper designs a scheme of covert communication in the Bitcoin blockchain, which takes normal transactions as a mask and leverages the Bitcoin transaction mechanism to embed secret information in the public key hash field. Specifically, we propose a novel key update mechanism combined with the hash algorithm to construct a covert channel. It ensures security and can update the channel to prevent the related problems caused by address reuse. We are taking advantage of the feature of Bitcoin that cannot be double-spent to solve the problem of burning bitcoin when paying bitcoin to a fake public key hash. In our scheme, both parties to the communication are anonymous, and the attacker cannot detect the covert data or track the transaction and address. Our proposed scheme was tested in real Bitcoin blockchain network, and the experimental results were analyzed to verify its security, availability, and efficiency.
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Rihab Habeeb Sahib, Prof. Dr. Eman Salih Al-Shamery
Regular E-voting systems for elections may count the votes in less time,less cost,save the privacy of citizens,but still considered risky as votes can be tampered.E-voting systems based on a network distributed ledger show fast results,more trusted,save privacy,cannot be tampered,and distributed in which no central organization controls the system.This paper illustrate an e-voting system to solve the challenge of a massive ledger that is distributed among network-nodes using a data reduction technique as a security-matching-tool,singular value decomposition(SVD) that handle a copy of election results in another form and matched with the SQL-database results to announce a successful election-event representing a transparency-powerful-secured-system
In cryptocurrencies, privacy of users is preserved using pseudonymity . However, it has been shown that pseudonymity does not result in anonymity if a user's transactions are linkable. This makes cryptocurrencies vulnerable to deanonymization attacks. The current solutions proposed in the literature suffer from at least one of the following issues: (1) requiring a trusted third–party entity, (2) poor performance, and (3) incompatible with the standard structure of cryptocurrencies. In this article, we propose Unlinkable Coin (UCoin), a secure mix–based approach to address these issues. In UCoin, the link between the input (payer) and output (payee) addresses in a transaction is broken. This is done by mixing the transactions of multiple users into a single aggregated transaction in which the output addresses have been secretly shuffled. In our protocol design, we first develop HDC–net, a secure shuffling protocol that enables a group of users to anonymously publish their data. Then, we deploy the proposed HDC–net protocol in the UCoin architecture (as a mixing unit) to generate the aggregate transactions. We show that UCoin (1) does not rely on a trusted third–party, (2) can mix 50 transactions in 6.3 seconds that is 18% faster than the current solutions, and (3) is fully compatible with the architecture of cryptocurrencies.
Mingyu Liang, Ioanna Karantaidou, Foteini Baldimtsi, Steven Gordon · 5 authors
Abstract We propose a new theoretical approach for building anonymous mixing mechanisms for cryptocurrencies. Rather than requiring a fully uniform permutation during mixing, we relax the requirement, insisting only that neighboring permutations are similarly likely. This is defined formally by borrowing from the definition of differential privacy. This relaxed privacy definition allows us to greatly reduce the amount of interaction and computation in the mixing protocol. Our construction achieves O ( n· polylog( n )) computation time for mixing n addresses, whereas all other mixing schemes require O ( n 2 ) total computation across all parties. Additionally, we support a smooth tolerance of fail-stop adversaries and do not require any trusted setup. We analyze the security of our generic protocol under the UC framework, and under a stand-alone, game-based definition. We finally describe an instantiation using ring signatures and confidential transactions.
Jochen Schäfer, Christian Müller, Frederik Armknecht
Abstract Bitcoin and similar cryptocurrencies are becoming increasingly popular as a payment method in both legitimate and illegitimate online markets. Such markets usually deploy a review system that allows users to rate their purchases and help others to determine reliable vendors. Consequently, vendors are interested into accumulating as many positive reviews (likes) as possible and to make these public. However, we present an attack that exploits these publicly available information to identify cryptocurrency addresses potentially belonging to vendors. In its basic variant, it focuses on vendors that reuse their addresses. We also show an extended variant that copes with the case that addresses are used only once. We demonstrate the applicability of the attack by modeling Bitcoin transactions based on vendor reviews of two separate darknet markets and retrieve matching transactions from the blockchain. By doing so, we can identify Bitcoin addresses likely belonging to darknet market vendors.
Pedro Casas, Matteo Romiti, Peter Holzer, Sami Ben Mariem · 6 authors
Proposed in 2016 and launched in 2018, the Bitcoin (BTC) Lightning Network (LN) can scale-up the capacity of the BTC blockchain network to process a significantly higher amount of transactions, in a faster, cheaper, and more privacy preserving manner. The number of LN nodes has been significantly increasing since 2018, and today there are more than twelve thousand nodes actively participating of so-called LN payment channels. The upcoming Taproot upgrade to the Bitcoin protocol would further boost the development and adoption of the LN. Taproot is the most significant upgrade to the Bitcoin network since the block size increase of 2017, and it will make LN transactions cheaper, more flexible, and more private. We focus on the characterization of the LN network topology, using network active measurements. By crawling the underlying P2P network supporting the Bitcoin LN over a span of 10-months, we unveil the LN in terms of size and location of its nodes as well as connectivity protocols, comparing it to the P2P IP network supporting the BTC blockchain. Among our findings, we show that IP addresses exposed by LN nodes correspond mainly to customer networks, even if most BTC nodes are actually deployed at major cloud providers, and that LN nodes significantly rely on anonymized networks and protocols such as Onion, with more than 40% of LN nodes connect through Tor.
Abstract: A decentralised, Secure, Peer-to-Peer Multi-Voting System on Ethereum Blockchain is a distributed ledger technology (DLT) that permits virtual votes to be transacted in a peer-to-peer decentralized network. Those transactions are validated and registered through every node of the network, so creating a transparent and immutable series of registered events whose truthfulness is supplied through a consensus protocol. Smart contract automates the execution of agreement that runs routinely as soon as the conditions are satisfied. Smart contract would not need any third parties consequently prevents time loss. By Eliminating the requirement for third parties, consequently, allows numerous processes to be extra efficient and economical. The system is secure, reliable, and anonymous. Smart contract is enforced for the Ethereum network using the Ethereum wallets and also the Solidity language. Users are capable of submit their votes immediately from their Ethereum wallets, and those transaction requests is handled with the consensus of each single Ethereum node. This creates a transparent environment for evoting. A lot of concerning efficiency of the peer-to-peer decentralized electoral system on Ethereum network along with application and the outcomes of implementation are provided in this paper. Keywords: Blockchain, Distributed Ledger Technology (DLT), Consensus Protocol, Smart Contracts, Ethereum, Solidity
Recently, two attacks were presented against Proof-of-Stake (PoS) Ethereum: one where short-range reorganizations of the underlying consensus chain are used to increase individual validators' profits and delay consensus decisions, and one where adversarial network delay is leveraged to stall consensus decisions indefinitely. We provide refined variants of these attacks, considerably relaxing the requirements on adversarial stake and network timing, and thus rendering the attacks more severe. Combining techniques from both refined attacks, we obtain a third attack which allows an adversary with vanishingly small fraction of stake and no control over network message propagation (assuming instead probabilistic message propagation) to cause even long-range consensus chain reorganizations. Honest-but-rational or ideologically motivated validators could use this attack to increase their profits or stall the protocol, threatening incentive alignment and security of PoS Ethereum. The attack can also lead to destabilization of consensus from congestion in vote processing.
Patrick McCorry, Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti · 5 authors
This article discusses secure methods to conduct e-voting over a blockchain in three different settings: decentralized voting, centralized remote voting, and centralized polling station voting. These settings cover almost all voting scenarios that occur in practice. A proof-of-concept implementation for decentralized voting over Ethereum’s blockchain is presented. This work demonstrates the suitable use of a blockchain not just as a public bulletin board but, more importantly, as a trustworthy computing platform that enforces the correct execution of the voting protocol in a publicly verifiable manner. We also discuss scaling up a blockchain-based voting application for national elections. We show that for national-scale elections the major verifiability problems can be addressed without having to depend on any blockchain. However, a blockchain remains a viable option to realize a public bulletin board, which has the advantage of being a “preventive” measure to stop retrospective changes on previously published records as opposed to a “detective” measure like the use of mirror websites. CCS Concepts: • Security and privacy ;
The blockchain provides a reliable and scalable method for enabling source-tracing functionality in large-scale Internet of Things (IoT) systems. Traditional blockchain-based source tracing applications are generally based on the hypothesis that the raw data collected by each IoT node are credible and consistent, which however may not always be the truth. As no mechanism ensures the reliability of the original data collected from the IoT devices, these data may be accidently screwed up or maliciously tampered with before they are uploaded on-chain. To address this issue, we propose the Multi-dimensional Certificates of Origin (MCO) method to filter out the potentially incredible data-till all the data uploaded to the chain are credible. To achieve this, we devise the Multi-dimensional Information Cross-Verification (MICV) and Multi-source Data Matching Calculation (MDMC) methods. MICV verifies whether a to-be-uploaded datum is consistent or credible, and MDMC determines which data should be discarded and which data should be kept to retain the most likely credible/untampered ones in the circumstance when data inconsistency appears. Large-scale experiments show that our scheme ensures on the credibility of data and off the chain with an affordable overhead.
Mwrwan Abubakar, Zakwan Jaroucheh, Ahmed Al Dubai, Bill Buchanan
The Session Initiation Protocol (SIP) is the principal signalling protocol in Voice over IP (VoIP) systems, responsible for initialising, terminating, and maintaining sessions amongst call parties. However, the problem with the SIP protocol is that it was not designed to be secure by nature as the HTTP digest authentication used in SIP is insecure, making it vulnerable to a variety of attacks. The current solutions rely on several standardised encryption protocols, such as TLS and IPsec, to protect SIP registration messages. However, the current centralised solutions do not scale well and cause algorithm overload when encoding and decoding SIP messages. In trying to rectify this issue, we propose in this paper a blockchain-based lightweight authentication mechanism, which involves a decentralised identity model to authenticate the SIP client to the SIP server. Our mechanism uses a smart contract on the Ethereum blockchain to ensure trust, accountability and preserves user privacy. We provided a proof-of-concept implementation to demonstrate our work. Further analysis of this approach's usability, mainly CPU and memory usage, was conducted comparing to IPsec and TLS. Then we discussed our system's security and presented a security analysis. Our analysis proves that our approach satisfies the SIP protocol security requirements.
Peer-to-peer VoIP applications are exposed to threats in the Internet environment as they carry out conversations over the Internet, which is an electronic communication line, and its security has always been largely a matter of concern. Authentication of the caller is the first line of defense among the security principles and is an important principle to provide security in VoIP application. Authentication methods in VoIP applications are usually based on trusted third parties or through centralized architecture. This situation creates problems in terms of single point of failure and privacy in call security over IP based communications. However, blockchain technology with a distributed architecture offers an innovative solution to multimedia communication authentication model. In this paper, a blockchain-based mutual authentication scheme for VoIP applications is proposed. In addition, the model's having a comprehensive security structure against various threats is explained via security and communication cost analysis. The proposed schema shows better performance than the methods that make a verification through the centralized architecture in the literature. The proposed model has been formally verified using the AVISPA tool, and it has been proven that the model is safe against potential threats.
Tor hidden services are anonymous servers of unknown location and ownership who can be accessed through any Tor-enabled web browser. They have gained popularity over the years, but still suer from major usability challenges due to their cryptographicallygenerated non-memorable addresses. In response to this difficulty, in this work we introduce the Onion Name System (OnioNS), a privacy-enhanced distributed DNS that allows users to reference a hidden service by a meaningful globally-unique veriable domain name chosen by the hidden service operator. We introduce a new distributed self-healing public ledger and construct OnioNS as an optional backwards-compatible plugin for Tor on top of existing hidden service infrastructure. We simplify our design and threat model by embedding OnioNS within the Tor network and provide mechanisms for authenticated denial-of-existence with minimal networking costs. Our reference implementation demonstrates that OnioNS successfully addresses the major usability issue that has been with Tor hidden services since their introduction in 2002.
Open access
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Advanced Steganography and Watermarking Techniques
Cryptocurrencies based on decentralized systems, especially blockchain, are gaining popularity more than ever. Freedom advocates hail blockchain technology as a breakthrough in digital privacy and internet anonymity. Unfortunately, after recent studies conducted, it may come as a surprise that the transactions are, in fact, not always anonymous. In this short paper, the possibility of identifying a user's accounts in different cryptocurrencies given the user's portfolio of investment gained from social media is investigated. In this study, the generic elements of blockchain systems are briefly studied. In section \ref{sec:blocksim}, BlockSim which is a tool for simulating transactions, and an algorithm for answering this question is introduced.
Current advances in information technology have brought about significant changes, including ways to carry out elections using computer technology known as e-voting. Blockchain underlies the popularity of the digital currency Bitcoin and some other digital money, sparking the start of a new era of Internet use, including electronic voting (e-voting) system. In this work, we proposed designing and implementing an evoting system powered by the Ethereum blockchain. We used real-world data from the Indonesian Election Commission (KPU) with 26 candidates and 15,725 voters from the Jelupang sub-district. The testing and evaluation results using three miners in the blockchain show that the system could commit around 23 transactions per second. All 15,725 votes are committed to the blockchain successfully within 12.75 minutes. The total time required for creating all blockchain accounts is 13.4 hours.
The emergence of the current pandemic has led to a new reality in which bureaucratic formalities have been affected in terms of health security, procedures, resource management, among others. Specifically, in the electoral processes, where the difficulty of fulfilling the social distance and the mobility restrictions reopen the debate on the implementation of other more advanced and modern alternatives, such as electronic voting (e-voting). This article presents the design and implementation of a decentralized e-voting system that has the potential to provide a higher level of transparency, security, and cost-efficiency. Hyperledger Fabric blockchain and smart contracts are used to cast votes, which are then recorded in an immutable way, giving voters anonymity and trust in the fairness of the election process. In addition, promising results of the performance of the e-voting system in terms of latency and transaction load are presented.
Ballots are often hold for fair decisions such as party theme selecting, however, the existing traditional ballot has some problems involving amount of human resources, cost of places, equipment, time and traffic, and repeated procedures. In order to solve the issues aforementioned, a ballot blockchain system is designed and implemented based on the smart contract of Ethereum. It is designed on the core blockchain technologies of the decentralized ledger technology, using a secure hash algorithm, anonymous user, incorruptible data, and adopting a public blockchain. The ballot blockchain system is implemented based on the MetaMask verification and the Remix interface development environment. The smart contract plays the role of the decision-maker for controlling ballot activities instead of numerous human tasks. All ballot transactions are recorded in the ballot blockchain permanently when the ballot completed. The aim of the ballot blockchain system is to achieve a fair, less time-consuming, secured, and transparent environment.