After introducing key concepts and definitions in the field of digital identity, this paper will investigate the benefits and drawbacks of existing identity systems on the road towards achieving self-sovereign identity. It will explore, in particular, the use of blockchain technology and biometrics as a means to ensure the “unicity” and “singularity” of identities, and the associated challenges pertaining to the security and confidentiality of personal information. The paper will then propose a model of blockchain-based self-sovereign identity based on attestations, claims, credentials and permissions, which is globally portable across the life of an individual. Such a system is not dependent on any particular government or organization for administration or legitimacy, although it might include government issued identification and biometrics as one of many indicia of identity. Such a solution based on a recorded and signed digital history of actions is a system that best approximates the fluidity and granularity of identity, enabling individuals to express only specific facets of their identity, depending on the parties with whom they wish to interact. This paper focuses on two case studies to explain how such a credentials system could work in specific contexts: (1) Kiva’s identity protocol for building credit history in Sierra Leone, and (2) World Food Programme’s Building Blocks program for delivering cash aid to refugees in Jordan. Finally, the paper will explore what the future might look like when blockchain-based cryptocurrencies and self-sovereign identity intersect. With digital transactions functioning as identity claims within an ecosystem based on self-sovereign identity, new business models might emerge, such as identity insurance schemes, along with the emergence of value-stable cryptocurrencies (“stablecoins”) functioning as local currencies.
As the first decentralized peer-to-peer (P2P) cryptocurrency system allowing people to trade with pseudonymous addresses, Bitcoin has become increasingly popular in recent years. However, the P2P and pseudonymous nature of Bitcoin make transactions on this platform very difficult to track, thus triggering the emergence of various illegal activities in the Bitcoin ecosystem. Particularly,mixing servicesin Bitcoin, originally designed to enhance transaction anonymity, have been widely employed for money laundering to complicate the process of trailing illicit fund. In this article, we focus on the detection of the addresses belonging to mixing services, which is an important task for anti-money laundering in Bitcoin. Specifically, we provide a feature-based network analysis framework to identify statistical properties of mixing services from three levels, namely, network level, account level, and transaction level. To better characterize the transaction patterns of different types of addresses, we propose the concept of attributed temporal heterogeneous motifs (ATH motifs). Moreover, to deal with the issue of imperfect labeling, we tackle the mixing detection task as a positive and unlabeled learning (PU learning) problem and build a detection model by leveraging the considered features. Experiments on real Bitcoin datasets demonstrate the effectiveness of our detection model and the importance of hybrid motifs including ATH motifs in mixing detection.
Information security incident under-reporting is unambiguously a business problem, as identified by a variety of sources, such as ENISA (2012), Symantec (2016), Newman (2018) and more. This research project identified the underlying issues that cause this problem and proposed a solution, in the form of an innovative artefact, which confronts a number of these issues. This research project was conducted according to the requirements of the Design Science Research Methodology (DSRM) by Peffers et al (2007). The research question set at the beginning of this research project, probed the feasible formation of an incident reporting solution, which would increase the motivational level of users towards the reporting of incidents, by utilizing the positive features offered by existing solutions, on one hand, but also by providing added value to the users, on the other. The comprehensive literature review chapter set the stage, and identified the reasons for incident underreporting, while also evaluating the existing solutions and determining their advantages and disadvantages. The objectives of the proposed artefact were then set, and the artefact was designed and developed. The output of this development endeavour is “IRDA”, the first decentralized incident reporting application (DApp), built on “Quorum”, a permissioned blockchain implementation of Ethereum. Its effectiveness was demonstrated, when six organizations accepted to use the developed artefact and performed a series of pre-defined actions, in order to confirm the platform’s intended functionality. The platform was also evaluated using Venable et al’s (2012) evaluation framework for DSR projects. This research project contributes to knowledge in various ways. It investigates blockchain and incident reporting, two domains which have not been extensively examined and the available literature is rather limited. Furthermore, it also identifies, compares, and evaluates the conventional, reporting platforms, available, up to date. In line with previous findings (e.g Humphrey, 2017), it also confirms the lack of standard taxonomies for information security incidents. This work also contributes by creating a functional, practical artefact in the blockchain domain, a domain where, according to Taylor et al (2019), most studies are either experimental proposals, or theoretical concepts, with limited practicality in solving real-world problems. Through the evaluation activity, and by conducting a series of non-parametric significance tests, it also suggests that IRDA can potentially increase the motivational level of users towards the reporting of incidents. This thesis describes an original attempt in utilizing the newly emergent blockchain technology, and its inherent characteristics, for addressing those concerns which actively contribute to the business problem. To the best of the researcher’s knowledge, there is currently no other solution offering similar benefits to users/organizations for incident reporting purposes. Through the accomplishment of this project’s pre-set objectives, the developed artefact provides a positive answer to the research question. The artefact, featuring increased anonymity, availability, immutability and transparency levels, as well as an overall lower cost, has the potential to increase the motivational level of organizations towards the reporting of incidents, thus improving the currently dismaying statistics of incident under-reporting. The structure of this document follows the flow of activities described in the DSRM by Peffers et al (2007), while also borrowing some elements out of the nominal structure of an empirical research process, including the literature review chapter, the description of the selected research methodology, as well as the “discussion and conclusion” chapter.
Bitcoin is a well known cryptocurrency that has existed for over a decade. We examine the historical cross-market dynamic relationships among four important Bitcoin cryptocurrency markets at a pivotal point in cryptocurrency acceptance among markets and the public. We pay particular attention to cross-market relations during the introduction of a new, competing Bitcoin exchange, Bitfinex, and the subsequent demise of the once-prominent Bitcoin exchange, Mt. Gox. Our findings show that Bitfinex's introduction led to a shifting of trading activity from the once popular Mt. Gox exchange to other exchanges. Mt. Gox's loss of trading activity caused price distortions in all Bitcoin markets under study. In addition, cross-market relationships became less efficient while Mt. Gox experienced its death throes. Our study provides evidence that (1) Bitcoin markets are susceptible to volume losses to rival exchanges, (2) shifting trading activity is also associated with price distortions mainly originating from the suffering exchange, and (3) Bitcoin cross-market dynamics are resilient and, ultimately, self-healing from shocks, strengthening Bitcoin's long-term viability.
The largest and best-known Cryptocurrency in the global economy is Bitcoin but it is only one of approximately 2,000 cyptocurrencies in circulation today. A Bitcoin was worth 8,790.51 U.S. dollars as of March 4, 2020 and all the Bitcoins in the world were worth roughly $160.4 billion. In Bitcoin you don’t need to explicitly register or reveal your real world identity, but the pattern of your behavior might itself be identifying. This is the fundamental privacy question in a Cryptocurrency like Bitcoin leading to emergence of Privacy coins such a Monero and Zcash that utilize complex cryptography to achieve the greater Privacy levels with more anonymity features. However, in the zest for increased Privacy with focus on anonymity in Cryptocurrency transaction, the law and order issues are compromised wherein it would be near to impossible for the law enforcement agencies to track criminals dealing in money laundering, terrorist financing, tax evasion and other frauds by using Crypto currencies. In this background, it is necessary to understand “Cryptocurrency and Privacy” as an interface to better comprehends the subject of Cyptocurrency which is very dynamic in technology with multiple global implications on the economic and legal front. The present work aims to study Cryptocurrency in the context of Privacy. The foundational concepts and definitions of the two competing subjects: ‘Cryptocurrency and Privacy’ is taken up for better understanding the background of the interface. Tor, an anonymous communication network is referred in brief to state that the dilemma in the Privacy context is not unique to use of Crypto currencies technology in so far its negative effects are concerned . The conclusion suggest for finding an appropriate balance between an individual’s privacy and State’s security in Cryptocurrency technology.
An Braeken, Madhusanka Liyanage, Salil S. Kanhere, S. K. Dixit
This theme issue will elaborate on the opportunities, challenges, and solutions to be offered by combining blockchain and cyberphysical systems for different application domains. Cyberphysical systems (CPSs) combine physical objects or systems with integrated computing facilities and data storage. Such CPSs can be interconnected in networks, within which they can exchange and share data and information with other objects and systems. The Internet of Things (IoT) in general is making rapid progress by providing connectivity to consumer devices. Blockchain is another promising technology in the information and communications technology domain. Blockchain is a decentralized digital database (ledger), which stores the transactions committed by users. The authenticity of such transactions is verified by the connected community (miners) before adding them to the ledger. Thus, blockchain employs a distributed trust model by eliminating a third -party centralized trust model. In the blockchain, each block bundles an array of transaction records and their cryptographic chain links.
Cybercrime, including cryptocurrency-related cybercrime, has become widespread in recent years. Despite a thorough study of cybercrime issues, there is still no legislative position on the legal regulation of cryptocurrencies and the responsibility for cryptocurrency-related cybercrime in Ukraine. The authors classify and characterize all cryptocurrency-related cybercrimes into five groups. In view of the spread of cryptocurrency-related cybercrimes, the EU’s counteraction measures have been analyzed. Ways to prevent and counteract to cryptocurrency-related cybercrimes in Ukraine are suggested.
Open access
Cybercrime and Law Enforcement Studies
Ukrainian Legal and Forensic Studies
Legal, Health, Environmental and COVID-19 Challenges
Guglielmo Maria Caporale, Woo-Young Kang, Fabio Spagnolo, Nicola Spagnolo
This paper provides some comprehensive evidence on the effects of cyber-attacks on the returns, realized volatility and trading volume of five of the main cryptocurrencies (Bitcoin, Ethereum, Litecoin, XRP and Stellar) in 99 developed and developing countries. More specifically, it investigates the effects of four different types of cyber-attacks (cyber-crime, cyber-espionage, hacktivism and cyber-warfare) on four target sectors (government, industry, finance and cryptocurrency exchange). We find that in the US cyber security firms tend to overreact to cyberattacks affecting cryptocurrencies and more wealth is spent on cyber security compared to other countries. Both hacktivism and cyber-warfare have a significant impact on cryptocurrencies. Cryptocurrency exchanges are more vulnerable to cyber-attacks in non-US countries and in the presence of high economic uncertainty and less so if the industry sector is already being targeted. Finally, cryptocurrency investors exhibit risk-loving behaviour when the hash rate and cryptocurrency returns increase and risk-averse one when cyber-attacks target the financial and industry sectors and economic uncertainty is high.
Smart contracts have the potential to improve many existing transactions and to enable entirely new business models. However, the technology supporting this new method of transacting is complex and the legal framework applying to it is somewhat unclear. Though theorised several decades ago, it was not until the advent of the distributed ledger technology known as blockchain that smart contracts were able to be practically implemented. This paper summarises the concept of smart contracts while providing the background and context of its development. It then distinguishes those smart contracts which are considered legally binding within the scope of US laws from those that may not have legal effect. Next, it provides an in-depth example of an exploitation of smart contracts and explores how the legal reaction to it is inadequate. To reduce the likelihood of future smart contract exploitations and to improve confidence for contracting parties, this article suggests adding explicit smart contract cybersecurity provisions to existing US legal frameworks. Specifically, I propose adapting several of the National Institute of Standards and Technology’s Federal Information Processing Standards to create minimum cybersecurity requirements for all legally binding smart contracts. I also examine the shortcomings of the Computer Fraud and Abuse Act while identifying it as a piece of legislation ripe for reform which, if done adequately, may provide a legal deterrent to would-be cyber hackers of smart contracts.
Bank for International Settlements, Raphael Auer, Stijn Claessens, Bank for International Settlements
Cryptocurrencies are often thought to operate out of the reach of national regulation, but in fact their valuations, transaction volumes and user bases react substantially to news about regulatory actions. The impact depends on the specific regulatory category to which the news relates: events related to general bans on cryptocurrencies or to their treatment under securities law have the greatest adverse effect, followed by news on combating money laundering and the financing of terrorism, and on restricting the interoperability of cryptocurrencies with regulated markets. News pointing to the establishment of specific legal frameworks tailored to cryptocurrencies and initial coin offerings coincides with strong market gains. These results suggest that cryptocurrency markets rely on regulated financial institutions to operate and that these markets are segmented across jurisdictions.
Radosław Michalski, Daria Dziubałtowska, Piotr Macek
The term blockchain has its roots in cryptocurrencies. However, its applications are now more widespread, and in many areas, this technology has become the foundation of the distributed ledger. The blockchain protocol assumes that all the participants of the system are both contributors and safeguards of this ledger, since the lack of a trusted third party requires other security precautions in order to maintain the consistency of transactions. In this work, we investigate whether for the participants of a blockchain-based system that does not require revealing the character explicitly, it can be discovered by other means. In order to verify this, we built and publicly released a dataset of nearly 9,000 addresses of nodes in the most popular cryptocurrency - Bitcoin, and then labelled them. These labels represent the character the nodes have in the network, e.g. miners or exchanges. We then developed a set of features that quantify the behaviour of nodes in the network and used supervised machine learning algorithms to find out whether the character of nodes can be revealed based on these features. Our results demonstrate, due to the F-score reaching over 95% in the best-performing algorithms, that it is hard to hide the role the node has in a blockchain-based network. These results indicate that to build trustworthy blockchain-based systems that fully comply with original blockchain assumptions, specific countermeasures are needed in order to preserve the desired level of anonymity.
Samrah Arif, M. Arif Khan, Sabih ur Rehman, Muhammad Ashad Kabir · 5 authors
Smart Home automation is increasingly gaining popularity among current applications of Internet of Things (IoT) due to the convenience and facilities it provides to the home owners. Sensors are employed within the home appliances via wireless connectivity to be accessible remotely by home owners to operate these devices. With the exponential increase of smart home IoT devices in the marketplace such as door locks, light bulbs, power switches etc, numerous security concerns are arising due to limited storage and processing power of such devices, making these devices vulnerable to several attacks. Due to this reason, security implementations in the deployment of these devices has gained popularity among researchers as a critical research area. Moreover, the adoption of traditional security schemes has failed to address the unique security concerns associated with these devices. Blockchain, a decentralised database based on cryptographic techniques, is gaining enormous attention to assure security of IoT systems. The blockchain framework within an IoT system is a fascinating substitute to the traditional centralised models, which has some significant concerns in fulfilling the demand of smart homes security. In this article, we aim to examine the security of smart homes by instigating the adoption of blockchain and exploring some of the currently proposed smart home architectures using blockchain technology. To present our findings, we describe a simple secure smart home framework based on a refined version of blockchain called Consortium blockchain. We highlight the limitations and opportunities of adopting such an architecture. We further evaluate our model and conclude with the results by designing an experimental testbed using a few household IoT devices commonly available in the marketplace.
Guglielmo Maria Caporale, Woo-Young Kang, Fabio Spagnolo, Nicola Spagnolo
This paper examines mean and volatility spillovers between three major cryptocurrencies (Bitcoin, Litecoin and Ethereum) and the role played by cyber-attacks. Specifically, trivariate GARCH-BEKK models are estimated which include suitably defined dummies corresponding to different types, targets and number per day of cyber-attacks. Significant dynamic linkages (interdependence) between the three cryptocurrencies under investigation are found in most cases when cyber-attacks are taken into account, Bitcoin appearing to be the dominant cryptocurrency. Further, Wald tests for parameter shifts during episodes of turbulence resulting from cyber-attacks provide evidence that the latter affect the transmission mechanism between cryptocurrency returns and volatilities (contagion). More precisely, cyber-attacks appear to strengthen cross-market linkages, thereby reducing portfolio diversification opportunities for cryptocurrency investors. Finally, the conditional correlation analysis confirms the previous findings.
Cryptocurrencies represent one of the most attractive markets for financial speculation. As a consequence, they have attracted unprecedented attention on social media. Besides genuine discussions and legitimate investment initiatives, several deceptive activities have flourished. In this work, we chart the online cryptocurrency landscape across multiple platforms. To reach our goal, we collected a large dataset, composed of more than 50M messages published by almost 7M users on Twitter, Telegram and Discord, over three months. We performed bot detection on Twitter accounts sharing invite links to Telegram and Discord channels, and we discovered that more than 56% of them were bots or suspended accounts. Then, we applied topic modeling techniques to Telegram and Discord messages, unveiling two different deception schemes - “pump-and-dump” and “Ponzi” - and identifying the channels involved in these frauds. Whereas on Discord we found a negligible level of deception, on Telegram we retrieved 296 channels involved in pump-and-dump and 432 involved in Ponzi schemes, accounting for a striking 20% of the total. Moreover, we observed that 93% of the invite links shared by Twitter bots point to Telegram pump-and-dump channels, shedding light on a little-known social bot activity. Charting the landscape of online cryptocurrency manipulation can inform actionable policies to fight such abuse.
In recent years, the emergence of blockchain technology (BT) has become a unique, most disruptive, and trending technology. The decentralized database in BT emphasizes data security and privacy. Also, the consensus mechanism in it makes sure that data is secured and legitimate. Still, it raises new security issues such as majority attack and double-spending. To handle the aforementioned issues, data analytics is required on blockchain based secure data. Analytics on these data raises the importance of arisen technology Machine Learning (ML). ML involves the rational amount of data to make precise decisions. Data reliability and its sharing are very crucial in ML to improve the accuracy of results. The combination of these two technologies (ML and BT) can provide highly precise results. In this paper, we present a detailed study on ML adoption for making BT-based smart applications more resilient against attacks. There are various traditional ML techniques, for instance, Support Vector Machines (SVM), clustering, bagging, and Deep Learning (DL) algorithms such as Convolutional Neural Network (CNN) and Long short-term memory (LSTM) can be used to analyse the attacks on a blockchain-based network. Further, we include how both the technologies can be applied in several smart applications such as Unmanned Aerial Vehicle (UAV), Smart Grid (SG), healthcare, and smart cities. Then, future research issues and challenges are explored. At last, a case study is presented with a conclusion.
Smart contracts and blockchain technology have the potential to change tremendously the contractual practices. Together with the development of blockchain-based technology, many well-known companies and other private or public entities such as governments take advantage of smart contracts. On the one hand, there are costs connected with the programming and coding of smart contracts, or training those administering them, on the other hand, however, it seems to be true that smart contracts will bring greater certainty and extra cost saving for those who apply them in their business dealings. During recent years, rapid technological development has resulted in plenty of changes in the way how financial services are conducted. Blockchain technology is predicted to disrupt the current environment of business dealings by enabling the unprecedented ways to cooperate and communicate between the parties of the contract.
A U Mentsiev, V S Magomadov, M Z Ashakhanova, A U Mentsiev · 5 authors
Abstract This research gives a brief insight into one of the most widely used technologies known as Blockchain. The paper lays the groundwork of how Blockchain functions and how it has quickly become a network with millions of users throughout the world. This study discusses the most important use of Blockchain technology, which is the enhancement of the cyber-security industry. Blockchain has revolutionized the cyber-security industry by introducing a system which is not bound to any four walls and is widely distributed all around the world, seeking refuge on millions of user servers. This decentralized system helps Blockchain defend cyber networks against security threats and attacks such as malware, phishing attacks, and DDoS.
Block chain has drawn major attention recently in the area of cyber security. Till to date many detection techniques and protection mechanisms have been proposed to enhance the security. In this paper we have proposed an overview of distributed ledger framework, block chain to defense against the cyber attacks. We here present a comprehensive overview of block chain architecture and some major algorithms used in different block chains. The future trends of block chain technology in the applications such as IoT security, E-voting, Banking sector has also coined out in this paper.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Abeer ElBahrawy, Laura Alessandretti, Leonid Rusnac, Daniel Goldsmith · 6 authors
Dark markets are commercial websites that use Bitcoin to sell or broker transactions involving\ndrugs, weapons, and other illicit goods. Being illegal, they do not offer any user protection, and\nseveral police raids and scams have caused large losses to both customers and vendors over the past\nyears. However, this uncertainty has not prevented a steady growth of the dark market phenomenon\nand a proliferation of new markets. The origin of this resilience have remained unclear so far, also due\nto the difficulty of identifying relevant Bitcoin transaction data. Here, we investigate how the dark\nmarket ecosystem re-organises following the disappearance of a market, due to factors including raids\nand scams. To do so, we analyse 24 episodes of unexpected market closure through a novel datasets\nof 133 million Bitcoin transactions involving 31 dark markets and their users, totalling 4 billion USD.\nWe show that coordinated user migration from the closed market to coexisting markets guarantees\noverall systemic resilience beyond the intrinsic fragility of individual markets. The migration is\nswift, efficient and common to all market closures. We find that migrants are on average more active\nusers in comparison to non-migrants and move preferentially towards the coexisting market with\nthe highest trading volume. Our findings shed light on the resilience of the dark market ecosystem\nand we anticipate that they may inform future research on the self-organisation of emerging online\nmarkets.
Alex Groce, Josselin Feist, Gustavo Grieco, Michael Colburn
An important problem in smart contract security is understanding the likelihood and criticality of discovered, or potential, weaknesses in contracts. In this paper we provide a summary of Ethereum smart contract audits performed for 23 professional stakeholders, avoiding the common problem of reporting issues mostly prevalent in low-quality contracts. These audits were performed at a leading company in blockchain security, using both open-source and proprietary tools, as well as human code analysis performed by professional security engineers. We categorize 246 individual defects, making it possible to compare the severity and frequency of different vulnerability types, compare smart contract and non-smart contract flaws, and to estimate the efficacy of automated vulnerability detection approaches.