Cryptocurrencies are the new emerging and important financial software systems. Digital forms of money are advanced monetary standards that depend on cryptographic monetary forms. Clients can't track down the entire information in one place and every other website shows some different stats which mislead the user to invest in the correct time and do some good investments. The investor is not getting the proper stats for a long period of time. In Cryptophyle we are fetching the data from multiple resources of cryptocurrency news and track some of the latest cryptocurrencies. Our website will give the In-depth information about the crypto world. Cryptophyle will keep you updated with the latest news and the latest data of the crypto world to make beneficial transactions and take more advantages from the app. It also provides past data which makes investors analyze the data and make success in their investments. The growth and ubiquity of exchanging in this new market are rapidly increasing due to the invention of digital kinds of money. Due to these resources' high degree of volatility, it is important to comprehend and forecast their price in a constantly shifting market.
Digital and Cyber Forensics
Advanced Steganography and Watermarking Techniques
Organised crime and cybercriminals use Bitcoin, a popular cryptocurrency, to launder money and move it across borders with impunity. The UK and other countries have legislation to recover the proceeds of crime from criminals. Recent UK case law has recognised cryptocurrency assets as property that can be seized and realised under the Proceeds of Crime Act (POCA). To seize a cryptocurrency asset generally requires access to the private key. Anecdotal evidence suggests that if cryptocurrency is not seized quickly after enforcement action has taken place, it will be transferred to other wallets making it difficult to seize at a future time. We investigate how Bitcoin could be seized from an Electrum or Ledger hardware wallet, during a law enforcement search, using live forensic techniques and a dictionary attack. We conduct a literature review examining the state-of-the-art in Bitcoin application forensics and Bitcoin wallet attacks. Concluding, that there is a gap in research on Bitcoin wallet security and that a significant proportion of the available literature comes from a small group of academics working with industry and law enforcement (Volety et al. 2019; Van Der Horst et al., 2017; Zollner et al., 2019). We then forensically examine the Electrum software wallet and the Ledger Nano S hardware wallet, to establish what artefacts can be recovered to assist in the recovery of Bitcoin from the wallets. Our main contribution is a proposed framework for Bitcoin forensic triage, a collection tool to recover Bitcoin artefacts and identifiers, and two proof of concept dictionary-attack tools written in Python and OpenCL. We then evaluate these tools to establish if an attack is practicable using a low-cost cluster of public cloud-based Graphics Processing Unit (GPU) instances. During our investigation, we find a weakness in Electrum's storage of encrypted private keys in RAM. We leverage this to make around 2.4 trillion password guesses. We also demonstrate that we can conduct 16.6 billion guesses against a password protected Ledger seed phrase.
Smart contracts (SC) are computer programs that are major components of Blockchain. The "intelligent contract" is made up of the rules accepted by the parties concerned. When the transactions started by the parties obey these established rules, then only their transactions will be completed without the involvement of a third party. Because of the simplicity and succinct nature of the solidity language, most smart contracts are written in this language. Smart contracts have two limitations, which are vulnerabilities in SC and that smart contracts can't be understood by all stakeholders, especially non-technical people who are involved in the business, since they are written in a programming language. Hence, the proposed paper used the XGBoost model and BPMN (Business Process Modeling Notation) tool to solve the first and second limitations of the SC respectively. Attackers are drawn to attention because of the popularity and fragility of the Solidity language. Once smart contracts have been launched, they can’t be changed. If that smart contract is vulnerable, attackers may then cash it. BPMN is used to represent business rules or contracts in graphical notation, so everyone involved in the business can understand the business rules. This BPMN diagram can be converted into a smart contract template through the BPMN-SOL tool. A few publications and existing tools exist on smart contract vulnerability detection, but they require more time to forecast and interpretation of vulnerability causes is also difficult. Thus, the proposed model experimented with several deep learning approaches and improved F1 score results by an average of 2% using the XGBoost model based on the ensemble technique to detect vulnerabilities of SCs, which are: Denial of Service (DOS), Unchecked external call, Re-entrancy, and Origin of Transaction. This paper also combined two important features to construct a data set, which are code snippets and n-grams.
Machine Learning as a Service is a promising service for individuals and companies who would like to delegate model training to third parties. The customers desire proof of the integrity of the model training to prevent potential backdoor attacks launched by the server, while the server desires to prove the integrity without revealing their intellectual assets, hyper-parameters of the training scheme. Zero-knowledge proof, a cryptographic tool can theoretically satisfy the above demand, but is still practically infeasible due to the inefficiency of proving. Thus, we propose zkMLaaS, a privacy-preserving and verifiable scheme for efficient training proof generation in the MLaaS scenario. zkMLaaS features a two-round challenge-response pro-tocol equipped with the random sampling. This greatly reduces the time cost of proof generation and ensures the integrity of training procedure simultaneously. We analyze the security of zkMLaaS and conduct comprehensive evaluation which shows it saves around$273\times$times compared with naive scheme.
The security of crypto wallets is a major concern in light of the recent prevalence of thefts. Aiming at the problem that there is no complete and reliable security detection model for Android-based crypto wallets, this study provides an evaluation framework based on the standard Android application security detection and unique security assessment of crypto wallets. The framework presents an attack-based detection approach, which identifies potential wallet security issues by simulating attacks and exploiting vulnerabilities. Ten popular Android crypto wallets are evaluated and compared to validate the framework’s practicability and accuracy. The test results demonstrate that the framework can accurately reflect the performance security of wallets. Additionally, the study proposes the corresponding actions to address the identified common security threats in crypto wallets.
Advances in technology, easy access to the internet, inconsistent rules and regulations, inadequate police training on cybercrime, and the complexity of international or multiorganizational collaboration in police operations have created new forms of cybercrime. Illegal cryptomarkets/darknet marketplaces transactions on the hidden web use cryptocurrency as a payment method, which makes it difficult to trace the identity of sellers and buyers. The internet and Dark Web browsers have also provided tools for criminals to conduct cyberattacks on businesses, infrastructure, education, health care, government, and even individual citizens with little impunity. The cross-border nature of cybercrimes, lack of uniformity in regulations, difficulties in collecting digital evidence, and identifying the physical location of the perpetrators have proven to be challenging tasks for police. Lack of public awareness of police jurisdiction of cybercrimes and limited police training on cyber technology and digital evidence gathering are some critical gaps identified in this chapter.
Constant advancements in technology have a significant impact on our everyday lives and the ecosystem in which we live. The growing popularity of cryptocurrencies (e.g., Bitcoin and Ethereum), along with Non-Fungible Tokens (NFTs), which are founded on blockchain technology, has opened the way for these blockchain projects to be integrated into a wide range of other kinds of applications (apps). Today, cryptocurrencies are used as a popular method of payment online; however, their popularity on the dark Web is also increasing. For example, they can be used to buy and perform various illegal activities among criminals due to their anonymity. Web3 cryptocurrency wallets, used to store cryptocurrencies, have not been studied as thoroughly as many other apps from a digital forensic perspective on mobile devices, given the increasing number of these services and apps today for many platforms, including the leading mobile operating systems (i.e., iOS and Android). Therefore, the purpose of this research is to guide investigators to unlock the full potential of popular cryptocurrency Web3 wallets, Trust Wallet and Metamask, to understand what can be recovered, and to look at areas where there are knowledge gaps. We digitally analyzed and forensically examined two mobile wallets that do not require any personal identifiers to register and are widely used for Web3 cryptocurrencies on Android and iOS devices. We review the digital evidence we have collected and discuss the implications of the forensic tools we have used. Finally, we propose a proof of concept extension to the iOS Logs, Events, And Plists Parser (iLEAPP) tool to automatically recover artifacts.
Ke Yang, Da Li, Qinglei Guo, Hejian Wang · 6 authors
With the acceleration of the digital transformation of the power system, the electronic data in the power production operation has shown an explosive growth. However, the increasing proliferation of deep forgery technology has brought huge hidden dangers to the electronic data management of power grid enterprises, and it is urgent to build a trusted management system for electronic data. This paper proposes a blockchain-based deep forgery data identification and traceability framework. Firstly, a method of trusted identification of electronic data based on blockchain is proposed, which constructs the unique identification of data and embeds it in the electronic data as a digital watermark. Second, introduce blockchain-based electronic data forensic appraisal technology to conduct authenticity and similarity analysis of electronic data. Finally, a deep forgery data traceability mechanism based on digital identification is designed to realize deep forgery data traceability and dissemination supervision. After comparative analysis, the framework is more secure and efficient in deep forgery data supervision, and can provide key support for building a trusted content system in cyberspace.
Stablecoins are cryptocurrencies whose price is pegged to that of another asset (typically one with low price volatility). The market for stablecoins has grown tremendously - up to almost $200 billion USD in 2022. These coins are being used extensively in newly developing paradigms for digital money and commerce as well as for decentralized finance technology. This work provides a technical description of stablecoin technology to enable reader understanding of the variety of ways in which stablecoins are architected and implemented. This includes a descriptive definition, commonly found properties, and distinguishing characteristics, as well as an exploration of stablecoin taxonomies, descriptions of the most common types, and examples from a list of top stablecoins by market capitalization. This document also explores related security, safety, and trust issues with an analysis conducted from a computer science and information technology security perspective as opposed to the financial analysis and economics focus of much of the stablecoin literature.
Sarah Khadijah Taylor, Steve Ho-yong Kim, Khairul Akram Zainol Ariffin, Siti Norul Huda Sheikh Abdullah
Studies have shown that the existing methodology of digital forensics preservation, which is to acquire and hash the evidence, is insufficient for cryptocurrencies as it does not secure the value. To address this issue, investigators secure the cryptocurrency by transferring it to a crypto wallet controlled by the Law Enforcement Agencies(LEAs). This process will unavoidably modify some data. Despite the criticality of this issue, inadequate studies have been made in this area. In addition, current guidelines on securing the cryptocurrency lack a comprehensive description from the perspective of digital evidence preservation principles. Crucial data to be documented throughout the preservation process were also not properly listed. Therefore, this study aims to address the gap in preserving cryptocurrencies from crypto wallets. Three objectives were then laid out; (1) to develop a methodology that is mapped comprehensively with digital evidence preservation principle, (2) to describe and provide justification on the inevitably modified data, and (3) to list crucial data to be documented during preservation process. The methods to achieve the objectives were critical examinations on various types of crypto wallets and by using simulation. The result shows that the study is able to provide a comprehensive crypto wallets preservation methodology to forensic investigators. It is hoped that the outcome from this study will promote better understanding, ensure consistency of implementation, and to aid investigators in explaining and justifying their actions during search and seizure in court.
Digital forensic examiners and stakeholders face increasing challenges during the investigation of Internet of Things (IoT) environments due to the heterogeneous nature of the IoT infrastructure. These challenges include guaranteeing the integrity of forensic evidence collected and stored during the investigation process. Similarly, they also encounter challenges in ensuring the transparency of the investigation process which includes the chain-of-custody and evidence chain. In recent years, some blockchain-based secure evidence models have been proposed especially for IoT forensic investigations. These proof-of-concept models apply the inherent properties of blockchain to secure the evidence chain of custody, maintain privacy, integrity, provenance, traceability, and verification of evidence collected and stored during the investigation process. Although there have been few prototypes to demonstrate the practical implementation of some of these proposed models, there is a lack of descriptive review of these blockchain-based IoT forensic models. In this paper, we report a comprehensive Systematic Literature Review (SLR) of the latest blockchain-based IoT forensic investigation process models. Particularly, we systematically review how blockchain is being used to securely improve the forensic investigation process and discuss the efficiency of these proposed models. Finally, the paper highlights challenges, open issues, and future research directions of blockchain technology in the field of IoT forensic investigations.
In recent years, with the advent of the blockchain 2.0 era, the security problems of smart contracts have gradually emerged. The detection of contract vulnerabilities is currently a research hotspot in blockchain security [1]. Current research methods are mainly based on traditional software defect analysis methods for vulnerabilities detection, but the detection accuracy and false alarm rate are not satisfactory. In this paper, we propose a bidirectional long short-term memory neural network model (HAM-BiLSTM for short) with hierarchical attention mechanism, which takes the code segment and account information of a smart contract as input. It divides the input samples into three levels as documents: word level, sentence level and document level, and introduces attention mechanism in different levels. The aim is to detect reentrancy vulnerability more accurately and reduce the false alarm rate of the model as much as possible. The neural network model classifies smart contracts through softmax layers by learning feature information from training samples to determine the presence of reentrancy vulnerability. The experiments demonstrate that our proposed solution and model increase detection accuracy and reduce false alarm rate.
In recent years, mobile edge computing (MEC) has become a research hotspot in academia. The Internet of Things (IoT) is an excellent way to build the infrastructure required for a MEC environment. Its rich digital tracking repository can provide insights into people's daily activities at home and elsewhere. Meanwhile, due to the open connectivity of the Internet of things devices, they can easily become the target of network attacks and be used by criminals as criminal tools. As a result, civil and criminal cases have increased year by year. This article conducts in-depth research on IoT forensics. By comparing its difference with traditional digital forensics (DF), the definition of IoT forensics is given. We have systematically sorted out the research results since the concept of IoT forensics was proposed in 2013 and proposed a generalized IoT forensics model. By studying blockchain technology and introducing it into the IoT forensics framework, a blockchain-based IoT forensics architecture is further proposed. Further, an alliance chain IoT forensics system is proposed. From the perspective of the data provider and the data visitor, the process of evidence storage and forensics of the IoT system is discussed. Finally, taking Unmanned Aerial Vehicle (UAV) forensics as an example, we give an experiment of IoT forensics analysis.
Digital forensics deals with digital evidence. Digital forensics is the study of data detection, acquisition, processing, analysis, and reporting. Encouraging the use of digital forensics in law enforcement investigations. With digital forensics, you can find out what data was taken and how it was c
Christopher Molloy, Philippe Charland, Steven H. H. Ding, Benjamin C. M. Fung
Cyber threat intelligence (CTI) has become a critical component of the defense of organizations against the steady surge of cyber attacks. Malware is one of the most challenging problems for CTI, due to its prevalence, the massive number of variants, and the constantly changing threat actor behaviors. Currently, Malpedia has indexed 2,390 unique malware families, while the AVTEST Institute has recorded more than 166 million new unique malware samples in 2021. There exists a vast number of variants per malware family. Consequently, the signature-based representation of patterns and knowledge of legacy systems can no longer be generalized to detect future malware attacks. Machine learning-based solutions can match more variants. However, as a black-box approach, they lack the explainability and maintainability required by incident response teams.There is thus an urgent need for a data-driven system that can abstract a future-proof, human-friendly, systematic, actionable, and dependable knowledge representation from software artifacts from the past for more effective and insightful malware triage. In this paper, we present the first phenotype-based malware decomposition system for quick malware triage that is effective against malware variants. We define phenotypes as directly observable characteristics such as code fragments, constants, functions, and strings. Malware development rarely starts from scratch, and there are many reused components and code fragments. The target under investigation is decomposed into known phenotypes that are mapped to known malware families, malware behaviors, and Advanced Persistent Threat (APT) groups. The implemented system provides visualizable phenotypes through an interactive tree map, helping the cyber analysts to navigate through the decomposition results. We evaluated our system on 200,000 malware samples, 100,000 benign samples, and a malware family with over 27,284 variants. The results indicate our system is scalable, efficient, and effective against zero-day malware and new variants of known families.
Eugene B. Chang, Paul J. Darcy, Kim‐Kwang Raymond Choo, Nhien‐An Le‐Khac
Cryptocurrency has been (ab)used to purchase illicit goods and services such as drugs, weapons and child pornography (also referred to as child sexual abuse materials), and thus mobile devices (where cryptocurrency wallet applications are installed) are a potential source of evidence in a criminal investigation. Not surprisingly, there has been increased focus on the security of cryptocurrency wallets, although forensic extraction and attribution of forensic artefacts from such wallets is understudied. In this paper, we examine Bitcoin and Dogecoin. The latter is increasingly popular partly due to endorsements from celebrities and being positioned as an introductory path to cryptocurrency for newcomers. Specifically, we demonstrate how one can acquire forensic artefacts from Android Bitcoin and Dogecoin cryptocurrency wallets, such as wallet IDs, transaction IDs, timestamp information, email addresses, cookies, and OAuth tokens.
The distributed and decentralized property of Blockchain technologies is very much suitable for those applications where integrity, confidentiality and proper tracking of operations is at highest priority. In this chapter, a Blockchain-based secure evidence management system for tracking police complaints and forensic reports is proposed. The proposed system provides security and privacy preservation of important documents used as evidence in the police system. The proposed scheme provides a Ethereum-based DApp to track a police complaint starting from FIR to when the complaint gets resolved, and also to provide security to forensic reports as security, confidentiality and integrity are at the highest priority. The proposed application supports forensic investigation with authenticity, immutability, traceability, resilience and distributed trust between evidential entitles. Details of tracking police complaints, further investigation, forensic report preservation and analysis will be recorded in chains of block. The proposed system is validated through various experimental results for security, privacy and sensitivity of important documents used as evidence by a police department.
Security issues are increasing day by day all over the world. Cyber issues are one of the major issues that cause cyber-attacks involving Malware, Phishing, and Ransomware attack. Pakistan is also one of the major countries that are facing cybercrime issues. The most important firms are government agencies like NADRA, Law Firm, and Police Firm. Pakistan has still not made a refined structure to ensure its security from advanced risks. By, and by it has transformed into a national security hazard for Pakistan because the individual data of the government is not secured. Multiple attacks on the NADRA server have occurred in the past. The reason is the centralization server, and security flaws. With the coming of Technology in the 21st century, and security worries that happens due to cybercrimes. Individuals are currently pushing toward new advances, the main thing that comes in the mind to keep away from security hazards, is to circulate the information among various individuals, so the idea of decentralization comes in. A technology that recently has gathered a lot of attention is Blockchain technology. Its decentralized nature gives secure, secret, and basic intends to keep up the records without alteration. Blockchain provides immutability, Integrity, helps enhanced security, distributed ledger, and also provides consensuses. So for government organizations like NADRA data is the most important thing, if this data is compromised due to security flaws then it’s happened a national security hazard that causes leakages of the nation's personal information. So this thesis purpose how to secure data using Blockchain technology a private Blockchain technology. An architectural view is presented with the help of use cases for government organizations NADRA, Police Firm, and Law Firm using HLF Blockchain technology. This thesis also presents the design, and architecture of how organizations work, and interact with one another. Using this design, and architecture we will be able to provide forensic to government organization data which makes it more secure from cyber threats.
Blockchain is a progression of associated information structures called blocks, which contain or track all that occurs in disseminated frameworks in a distributed organization. Each block is connected to the previous block with an uncommon pointer called a hash pointer, forming a chain and resulting in a framework consisting of annexes: A perpetual and irreversible history that can be utilized as a constant review trail by any member to check the precision of the records by essentially surveying information itself. The chapter will discuss the role of blockchain in digital forensics with an introduction to blockchain technology and its applications and challenges. It also explores the architecture and protocols related to blockchain technology. The chapter also highlights the managing of digital evidence by maintaining the chain of custody with the help of Ethereum and Hyperledger. It will also enlighten readers about the application of blockchain for distributed cloud storage in digital forensics. It will reveal the role of blockchain in digital forensics, which will be helpful for cybercrime investigation, blockchain technology, and digital forensics enthusiasts, students, PhD scholars and researchers.