Muhammad Saad, Jeffrey Spaulding, Laurent Njilla, Charles Kamhoua · 7 authors
In this paper, we systematically explore the attack surface of the Blockchain technology, with an emphasis on public Blockchains. Towards this goal, we attribute attack viability in the attack surface to 1) the Blockchain cryptographic constructs, 2) the distributed architecture of the systems using Blockchain, and 3) the Blockchain application context. To each of those contributing factors, we outline several attacks, including selfish mining, the 51% attack, Domain Name System (DNS) attacks, distributed denial-of-service (DDoS) attacks, consensus delay (due to selfish behavior or distributed denial-of-service attacks), Blockchain forks, orphaned and stale blocks, block ingestion, wallet thefts, smart contract attacks, and privacy attacks. We also explore the causal relationships between these attacks to demonstrate how various attack vectors are connected to one another. A secondary contribution of this work is outlining effective defense measures taken by the Blockchain technology or proposed by researchers to mitigate the effects of these attacks and patch associated vulnerabilities
21. yüzyıl bilgi ve iletişim teknolojilerinde önemli gelişmelere sahne olmuştur. Özellikle iletişim teknolojilerinde yaşanan kayda değer gelişmeler sonucu akıllı telefonların ortaya çıkması, interneti insanların günlük yaşantılarında sürekli kullandıkları bir teknoloji haline getirmiştir. Bu gelişmeler hayatın pek çok alanını değiştirdiği gibi ekonomik faaliyetleri de değiştirmiş ve bu faaliyetleri internet ortamına taşımıştır. Günümüzde bankacılık işlemlerinden, alışverişe kadar pek çok faaliyet internet üzerinden kolaylıkla yapılabilmektedir. Ancak internetin sunduğu bu kolaylıklar, güvenlik açıkları, verilerin çalınması gibi pek çok sorunu da beraberinde getirmektedir. Bu noktada blockchain teknolojisinin güvenlik açıklarına karşı korumalı ve bir ağ üzerinde şifrelenen verilerin yönetimini sağlayan dağınık bir veri tabanı oluşu, bu kronikleşmiş sorunların çözülmesinin yanı sıra günümüz ekonomilerinde yaşanan pek çok soruna da çözümler sunmaktadır. Bu çerçevede blockchain tabanlı ekosistemlerin oluşturulması amacıyla kamu/özel destekli pek çok platform hali hazırda çalışmalar yürütmektedir. Bu çalışmada, Blockchain’in altyapısını oluşturan teknoloji hakkında bilgi verilmiş ve bu teknolojinin kullanım alanları doğrultusunda uygulama alanları incelenmiştir.
Sergey Ivantsov, E. L. Sidorenko, Борис Спасенников, Yuri Berezkin · 5 authors
The authors have analyzed crimes connected with the use of virtual currency in the regional and international aspects. They introduce a new category of «cryptocrime» understood as the aggregate of publically dangerous acts, united by their common systemic characteristics, committed against or using the products of distributed registries (cryptocurrency, tokens and other forms of digital financial assets). They analyze each of the cryptocrime segments separately: illegal trade in psychoactive substances (narcotics, psychoactive substances, precursors), pornography and other prohibited content (including illegal services); laundering of criminal proceeds; theft of cryptocurrency and tokens. Using the scientific research methods (comparative, sociological, statistical analysis and extrapolation of data, building a trend line, etc.) the authors identify regularities in the dynamics of each type of cryptocrime as well as key factors facilitating them. The goal of the authors is to conduct a systemic examination of crimes committed against and using cryptocurrency and to determine the prospects of developing different segments of cryptocrime. To achieve this goal, they analyze qualitative and quantitative characteristics of illegal trade in narcotics and pornography, legalization of criminal proceeds and theft of digital assets. They name the anonymity of cryptocurrency as a factor facilitating illegal trade in drugs, while the growing scope of the legalization of criminal proceeds and theft is facilitated by the fact that cryptocurrency and tokens do not have a legal status as objects of civil law and objects of encroachments on property. The analysis allows the authors to conclude that without effective criminological measures the level of such crimes will continue to grow and may double by the end of 2019. According to the authors, the priority directions of international criminal policy in the sphere of cryptocrime prevention include determining cryptocurrencies’ legal status, licensing cryptocurrency trade (stock exchange services, exchange platforms, companies issuing tokens), setting international standards of counteracting the legalization of criminal proceeds and the financing of terrorism, creating a cryptocrime database.
Mehrnoosh Mirtaheri, Sami Abu-El-Haija, Fred Morstatter, Greg Ver Steeg · 5 authors
Interest surrounding cryptocurrencies, digital or virtual currencies that are used as a medium for financial transactions, has grown tremendously in recent years. The anonymity surrounding these currencies makes investors particularly susceptible to fraud---such as ``pump and dump'' scams---where the goal is to artificially inflate the perceived worth of a currency, luring victims into investing before the fraudsters can sell their holdings. Because of the speed and relative anonymity offered by social platforms such as Twitter and Telegram, social media has become a preferred platform for scammers who wish to spread false hype about the cryptocurrency they are trying to pump. In this work we propose and evaluate a computational approach that can automatically identify pump and dump scams as they unfold by combining information across social media platforms. We also develop a multi-modal approach for predicting whether a particular pump attempt will succeed or not. Finally, we analyze the prevalence of bots in cryptocurrency related tweets, and observe a significant increase in bot activity during the pump attempts.
Jesús Canelón, Esperanza Huerta, José Incera, Instituto Tecnológico Autónomo de México, Mexico · 5 authors
This paper proposes a cybersecurity control framework for blockchain ecosystems, drawing from risks identified in the practitioner and academic literature. The framework identifies thirteen risks for blockchain implementations, ten common to other information systems and three risks specific to blockchains: centralization of computing power, transaction malleability, and flawed or malicious smart contracts. It also proposes controls to mitigate the risks identified; some were identified in the literature and some are new. Controls that apply to all types of information systems are adapted to the different components of the blockchain ecosystem.
The transparent and immutable nature of blockchain provides incentives for organizations wishing to create and implement an open, decentralized governance structure. As members exercise their voting rights, a fault-tolerant record accumulates on the blockchain that can be analyzed to diagnose and intercept potential threats to the governing body. To date, there has not been a systematic study of on-chain governance with respect to voting. In this paper, we provide an analysis of blockchain governance through a case study of the first cryptocurrency to adopt on-chain voting, Dash. Our analysis introduces the key characteristics of blockchain governance, steps through a data-driven exploration of Dash's on-chain voting system, and highlights exploitable attack vectors and vulnerabilities for the subversion of Dash's on-chain voting system via a novel network analysis methodology. We then conclude with guidelines for other organizations looking to implement similar blockchain governance solutions while maintaining integrity in their operations.
The purpose of this research is to demonstrate how public blockchains offer a greater degree of censorship resistance over traditional web-based information broadcasting mechanisms, and a comparison of existing options. Public blockchains present a means to mitigate censorship from nation states through both a broadcasting and data storage mechanism. They are costly to attack and difficult to remove from the public due to their distributed and accessible nature. A recent incident in China proved the worth of public blockchains by forcing the distribution of a censored letter describing harassment by Peking University into an Ethereum transaction by an anonymous individual or party. The Chinese government censored the letter on popular centralized services such as WeChat, but was unable to censor it once posted to the Ethereum blockchain. Through the demonstration of the letter’s presence on Ethereum as well as the act of placing it on other public blockchains, this research highlights the importance of how public blockchains will continue to be a vessel for the protection of information well into the future.
Blockchain is a relatively new technology originally created to store Bitcoin’s transaction records. The system is highly redundant and distributed, making it very difficult for fraudulent financial transactions. While cryptocurrencies might be the most well-known use case of blockchain technology, it is wrong to assume that this technology is restricted to the financial area. Indeed, many blockchain use cases are being developed today in different areas. Due to the complexity of certain processes, a new technology associated to blockchain has appeared – smart contracts. These digital contracts act like traditional contracts, with the major difference being their automaticity. In this article, we aim to discuss how blockchain and smart contracts may be used together in order to improve organizational operations. More specifically, we demonstrate how these technologies might be used to develop a solution that avoids certain types of fraud in the area of vehicle insurance.
The success of various cryptocurrencies' systems has triggered a great interest in their functioning. The fluctuation of their values is very unpredictable, so the periods of growth are often abruptly interrupted by stagnation or a pronounced decline. Nevertheless, a large number of investors have been involved in the processes of mining and trading cryptocurrencies in recent years. When it comes to the negative aspects of cryptocurrencies, the focus is primarily on various forms of cybercrime. The number of hacker attacks using the blackmail software - ransomware, is on the increase. In such cases, cryptocurrencies are often used as a means of paying ransom. However, the energy efficiency of certain types of cryptocurrencies is a less common topic. The Proof-of-Work (PoW) algorithm used for mining in some systems is an energetically intensive and really expensive process, which after economic analysis no longer seems as profitable as it first appeared to be. Cryptocurrency trading could bring a great income to the investors, but also great losses, because it essentially represents a zero-sum game. The sudden increase in the number of miners led to the disturbance on the computer components market, causing the price increase and even the complete disappearance of certain graphics card models. Everything previously mentioned indicates that cryptocurrencies have brought many negative aspects and disturbances. The subject of this paper is the economic aspect of cryptocurrencies based on the PoW algorithm. The aim of the paper is to indicate the economic unsustainability of their current concept, due to the high costs borne directly by participants in the mining process and indirectly by participants in the computer components market.
This article explores four critical groups of systematic risk embedded in smart contract employment using the analytic hierarchy process (AHP). The four principal risk analysis groups include: 1) transparency in the light of corporate governance 2) IT security 3) contract management automation and 4) legality. The AHP assists both decision-makers and stakeholders alike in the evaluation process essential for identifying potential technological constraints posed within a permissioned blockchain environment using peer-to-peer format in the absence of digital currency. Based upon critical assessment, the AHP methodology enables pairwise comparisons among different features and consequently increases the knowledge regarding these attributes in light of the software’s risk assessment.
Nikos Fotiou, Vasilios A. Siris, Spyros Voulgaris, George C. Polyzos · 5 authors
We address the limitations of existing information security solutions when applied to the cyber-physical world. In particular, we consider the case of Internet of Things (IoT) actuation and we argue that it is hard to secure such a process. To this end, we propose a "damage control" approach, where service time is divided into slots and users perform microservice transactions, paying essentially in advance for each one, corresponding to one service slot. Under these circumstances, in the case of service disruption, a user, in the worst case, may lose the amount of money that corresponds to a single micro-service transaction in a single time slot. We implement our solution by leveraging blockchain-based smart contracts, off-chain payments, and one-time Hash-based Message Authentication Code (HMAC) passwords. Our solution supports IoT devices with limited processing capabilities and which are not necessarily connected to the Internet. Moreover, with our solution, IoT devices do not interact directly with the blockchain. In fact, they are oblivious to the use of blockchain technology. They do not store any usersensitive information, neither are payments made to or is value stored on the devices.
Bitcoin, the world’s first cryptocurrency, was first introduced in 2009, by Satoshi Nakamoto. While many believe the name is a pseudonym, and the true identity of the creator(s) is unknown, it is an undisputed fact that cryptocurrencies have introduced an indelible change to monies worldwide. Consequently, cryptocurrencies have also introduced a plethora of new opportunities for money laundering activity.\nWhile cryptocurrencies follow the same three-step laundering process of placement, layering, and integration, the activity can be more difficult to detect due to the anonymous nature of cryptocurrencies. Moreover, while traditional schemes such as smurfing or gambling at a casino are still used as laundering techniques, more advanced methods such using mixers and tumblers or utilizing unscrupulous cryptocurrency exchanges are also being used to mask the flow of funds. Finally, the rapid increase in initial coin offerings (ICO’s) provides yet another outlet for cryptocurrency money laundering to occur.\nFortunately, advancements are being made on a variety of fronts to address the increase in illicit activity. First, the largest cryptocurrency exchange, Coinbase, has implemented a robust know-your-customer (KYC) program, as evidenced by my own experience of opening an account with the exchange. Secondly, researchers are finding new ways to extract information about certain cryptocurrency transactions which were previously thought to be unidentifiable. Finally, both law enforcement and government agencies, including the SEC and the Financial Crimes Enforcement Network, are using innovative, aggressive, and even clandestine techniques to combat cryptocurrency money laundering activity.
Guglielmo Maria Caporale, Woo-Young Kang, Fabio Spagnolo, Nicola Spagnolo
This paper uses a Markov-switching non-linear specification to analyse the effects of cyber attacks on returns in the case of four cryptocurrencies (Bitcoin, Ethernam, Litecoin and Stellar) over the period 8/8/2015–2/28/2019. The analysis considers both cyber attacks in general and those targeting cryptocurrencies in particular, and also uses cumulative measures capturing persistence. On the whole, the results suggest the existence of significant negative effects of cyber attacks on the probability for cryptocurrencies to stay in the low volatility regime. This is an interesting finding, that confirms the importance of gaining a deeper understanding of this form of crime and of the tools used by cybercriminals in order to prevent possibly severe disruptions to markets.
Cryptocurrencies,1 like bitcoin, raise new legal questions due to their innovative technological concepts. While academic research covers nearly all areas of the technological concepts of those currencies, legal studies focus only on a few topics. The papers that have been published so far discuss mainly economic law, tax law, and financial regulations. At the same time, governments are starting to explicitly regulate cryptocurrencies in terms of anti-money-laundering (AML) and to clarify or strengthen the legal basis for prosecuting crimes in the context of cryptocurrencies. Furthermore, criminal investigation in the context of cryptocurrencies is intensifying with the rising number of cryptocurrency-related crimes. Moreover, governments should also start to consider crime prevention in the context of cryptocurrencies. AML regulation, crime prevention, and prosecution have to take heed of the fundamental rights of the citizens affected. To date, legal research has not discussed the relationship between AML regulation (regarding cryptocurrencies), crime prevention (in conjunction with cryptocurrencies), the prosecution of crimes involving cryptocurrencies and fundamental rights. Many future regulatory concepts will collide with the fundamental right to property of the owners of cryptocurrency units and the freedom to pursue a trade or profession of owners and operators of exchange platforms, mining pools, etc. In cryptocurrencies organized as peer-to-peer systems, the freedom of association also has to be mentioned. With particular regard to prosecution, law enforcement agencies restrict the freedom of telecommunication, data privacy (including the right to informational self-determination), freedom of expression, and the freedom of information. Whenever some of these fundamental rights are impinged upon, regulation concepts and investigation or prosecution approaches must be provided for by law and must fulfill the criterion of necessity. Further interdisciplinary research is needed to develop efficient and legit prevention as well as criminal investigation concepts.
The Dark Web is notorious for being a major distribution channel of harmful content as well as unlawful goods.Perpetrators have also used cryptocurrencies to conduct illicit financial transactions while hiding their identities.The limited coverage and outdated data of the Dark Web in previous studies motivated us to conduct an in-depth investigative study to understand how perpetrators abuse cryptocurrencies in the Dark Web.We designed and implemented MFScope, a new framework which collects Dark Web data, extracts cryptocurrency information, and analyzes their usage characteristics on the Dark Web.Specifically, MFScope collected more than 27 million dark webpages and extracted around 10 million unique cryptocurrency addresses for Bitcoin, Ethereum, and Monero.It then classified their usages to identify trades of illicit goods and traced cryptocurrency money flows, to reveal black money operations on the Dark Web.In total, using MFScope we discovered that more than 80% of Bitcoin addresses on the Dark Web were used with malicious intent; their monetary volume was around 180 million USD, and they sent a large sum of their money to several popular cryptocurrency services (e.g., exchange services).Furthermore, we present two real-world unlawful services and demonstrate their Bitcoin transaction traces, which helps in understanding their marketing strategy as well as black money operations.