Zheng Che, Meng Shen, Zhehui Tan, Hanbiao Du · 9 authors
With the rapid evolution of Web3.0, cryptocurrency has become a cornerstone of decentralized finance. While these digital assets enable efficient and borderless financial transactions, their pseudonymous nature has also attracted malicious activities such as money laundering, fraud, and other financial crimes. Effective detection of malicious transactions is crucial to maintaining the security and integrity of the Web 3.0 ecosystem. Existing malicious transaction detection methods rely on large amounts of labeled data and suffer from low generalization. Label-efficient and generalizable malicious transaction detection remains a challenging task. In this paper, we propose ShadowEyes, a novel malicious transaction detection method. Specifically, we first propose a generalized graph structure named TxGraph as a representation of malicious transaction, which captures the interaction features of each malicious account and its neighbors. Then we carefully design a data augmentation method tailored to simulate the evolution of malicious transactions to generate positive pairs. To alleviate account label scarcity, we further design a graph contrastive mechanism, which enables ShadowEyes to learn discriminative features effectively from unlabeled data, thereby enhancing its detection capabilities in real-world scenarios. We conduct extensive experiments using public datasets to evaluate the performance of ShadowEyes. The results demonstrate that it outperforms state-of-the-art (SOTA) methods in four typical scenarios. Specifically, in the zero-shot learning scenario, it can achieve an F1 score of 76.98% for identifying gambling transactions, surpassing the SOTA method by12.05%. In the scenario of across-platform malicious transaction detection, ShadowEyes maintains an F1 score of around 90%, which is 10% higher than the SOTA method.
Cyber-Physical Systems (CPS) have become a research hotspot due to their vulnerability to stealthy network attacks like ZDA and PDA, which can lead to unsafe states and system damage. Recent defense mechanisms for ZDA and PDA often rely on model-based observation techniques prone to false alarms. In this paper, we present an innovative approach to securing CPS against Advanced Persistent Threat (APT) injection attacks by integrating machine learning with blockchain technology. Our system leverages a robust ML model trained to detect APT injection attacks with high accuracy, achieving a detection rate of 99.89%. To address the limitations of current defense mechanisms and enhance the security and integrity of the detection process, we utilize blockchain technology to store and verify the predictions made by the ML model. We implemented a smart contract on the Ethereum blockchain using Solidity, which logs the input features and corresponding predictions. This immutable ledger ensures the integrity and traceability of the detection process, mitigating risks of data tampering and reducing false alarms, thereby enhancing trust in the system's outputs. The implementation includes a user-friendly interface for inputting features, a backend for data processing and model prediction, and a blockchain interaction module to store and verify predictions. The integration of blockchain with Machine learning enhances both the precision and resilience of APT detection while providing an additional layer of security by ensuring the transparency and immutability of the recorded data. This dual approach represents a substantial advancement in protecting CPS from sophisticated cyber threats.
Renyuan Xu, Jun Zhang, Xiaoyue Zhu, Zhaoxiong Song · 5 authors
In recent years, the frequent occurrence of phishing scams on Ethereum has posed serious threats to transaction security and the financial safety of users. This paper proposes an Ethereum phishing scam detection method based on Hyperbolic Neural Networks (HGNNs) and temporal information. The method maps the Ethereum transaction network to hyperbolic space for structural feature extraction, effectively capturing hierarchical structures and complex relationships within the graph, thereby improving the accuracy of phishing scam detection. The model includes a structural feature extraction module and a temporal feature extraction module. It uses HGNN and self-attention mechanism to extract the structural features of the transaction graph, and uses a multi-head attention mechanism to capture the dynamic evolution pattern of the graph. Experimental validation on real Ethereum datasets demonstrates that the proposed model outperforms benchmark models, showcasing its effectiveness.
Clement Daah, Amna Qureshi, Irfan Awan, Savas Konur
The financial sector is increasingly facing advanced cyber threats, necessitating a shift from traditional security measures to more dynamic frameworks. This study presents a novel integration of Zero Trust architecture with hybrid access control system and blockchain technology to enhance security in financial institutions. Zero Trust enforces continuous authentication and dynamic access controls, while blockchain secures digital identities and transaction logs through its immutable ledger, ensuring data integrity and non-repudiation. The proposed framework, evaluated using OMNeT++ simulations enhanced by Ethereum-Ganache, shows improved detection accuracy, reduced false positives, and increased resistance to insider threats and other attacks. It also strengthens compliance with regulatory requirements through robust audit trails, providing enhanced protection for sensitive financial data.
Smart contracts are prone to vulnerabilities, with reentrancy attacks posing significant risks due to their destructive potential. While various methods exist for detecting reentrancy vulnerabilities in smart contracts, such as static analysis, these approaches often suffer from high false positive rates and lack the ability to directly illustrate how vulnerabilities can be exploited in attacks.
The web3 applications have recently been growing, especially on the Ethereum platform, starting to become the target of scammers. The web3 scams, imitating the services provided by legitimate platforms, mimic regular activity to deceive users. The current phishing account detection tools utilize graph learning or sampling algorithms to obtain graph features. However, large-scale transaction networks with temporal attributes conform to a power-law distribution, posing challenges in detecting web3 scams. In this paper, we present ScamSweeper, a novel framework to identify web3 scams on Ethereum. Furthermore, we collect a large-scale transaction dataset consisting of web3 scams, phishing, and normal accounts. Our experiments indicate that ScamSweeper exceeds the state-of-the-art in detecting web3 scams.
With the growing significance of blockchain-based Bitcoin systems, ensuring robust security measures is imperative. This research introduces an innovative approach to enhance system-level threat detection through the integration of a novel ensemble learning model, bolstered by the Water Cycle Algorithm (WCA). The proposed model aims to address the evolving landscape of security challenges in the blockchain domain, specifically targeting the detection of threats that may compromise the integrity and efficiency of Bitcoin systems.The ensemble learning model combines diverse algorithms, leveraging their collective intelligence to improve accuracy and resilience against sophisticated threats. The integration of the Water Cycle Algorithm further enhances the adaptability of the model by mimicking the natural processes of water cycles for dynamic optimization. This adaptive feature enables the system to efficiently respond to emerging threats, ensuring real-time threat detection and mitigation.
Cross-chain bridges, one of the foundational infrastructures of blockchain, provide the infrastructure and solutions for inter-operability, asset liquidity, data transfer, decentralized finance, and cross-chain governance between blockchain networks. However, because cross-chain bridges often have to handle communication and asset transfers between multiple blockchains, they involve complex protocols and technologies. This complexity increases the likelihood of vulnerabilities and potential attacks. In order to ensure the security and reliability of cross-chain bridges, this article launches a thorough investigation of existing cross-chain bridge projects, clarifying bridging mechanisms, bridge types, and security features. The following part goes into the subject of security and sheds light on the considerable challenges faced by cross-chain bridges. It conducts a thorough analysis of security flaws, covering problems like smart contract vulnerabilities, centralization risks, liquidity issues, and oracle manipulations. Furthermore, this study promotes a compendium of security solutions and best practises, pointing the way toward a cross-chain bridge scenario that is more secure.
Zeyu Zhou, Ding Liu, Tatiana R. Shmeleva, Dmitry A. Zaitsev
Bitcoin is under the threat of fork since it operates with a distributed ledger. Predicting the fork probability in advance is beneficial for taking early action to avoid malicious attacks. In this study, we compose a colored Petri net model of Bitcoin. Our model consists of a given number of nodes, and each node has five subpages representing the node structure: proof of work, broadcast blocks, verify blocks, and the process of adding blocks to blockchain, respectively. Simulation results of fork probability can be easily obtained and analyzed by observing the data in the measuring components of subpages. The results show that our model correctly simulates the fork probability: on recent Bitcoin data, compared with the results of the wide-known SimBlock simulator, a difference of some 4.3% has been obtained. Thus, taking into account vivid graphical representation, our model has certain advantages for the developing techniques of attack avoidance.
Advanced Steganography and Watermarking Techniques
Karanjot Singh Saggu, Paula Branco, Guy-Vincent Jourdan
The Bitcoin generator scam is one example of existing deceptive schemes enticing users with promises of free or effortless Bitcoin generation. These scams predominantly exploit individuals unfamiliar with cryptocurrency seeking low-effort avenues to obtain Bitcoin without financial investment. In this paper, we propose and analyze methods to improve the performance of Graph Neural Networks (GNNs) in detecting fraudulent cases within Bitcoin transactional data. We explore multiple GNN variants, alongside various graph sampling methodologies. To overcome the shortcomings of these sampling methods, we propose a new sampling method BFRON—a hybrid approach mixing Breadth-First Search and Frontier Sampling. Additionally, we introduce an enhanced optimization pipeline and a new metric to improve fraudulent node detection. Evaluation metrics, including Instance Information Gain and Group Distance Ratio, are employed to analyze the challenges of over-smoothing in Graph Neural Networks and the efficacy of diverse graph sampling techniques. Our results show that overall BFRON is the best solution and RGGCN is the best-performing GNN. Moreover, we show that our enhanced pipeline and the usage of graph normalization have important advantages.
Akhil John Mampilly, Vijaya Kittu Manda, Chithirai Pon Selvan
Blockchain is a promising technology that can help organizations improve their cybersecurity. Blockchain has many inherent features that can help enhance data security, improve threat detection and response, strengthen authentication and authorization, and enhance cyber threat intelligence sharing. This is possible because of the innovative approach that Blockchain uses, such as immutable ledgers to store transactions, monitor assets, and build trust by providing access only to authorized participants. The chapter discusses cybersecurity best practices related to smart contracts, key management, network security, user education and awareness, incident reporting, privacy challenges, software updates, and decentralization. Key regulatory compliance aspects, such as GDPR and HIPPA, are discussed. The increasing interactions of Artificial Intelligence (AI), Machine Learning (ML), and the Internet of Things (IoT) with Blockchain can further provide improved cybersecurity services and hence form the discussion of the trends and potential future research section of this chapter.
Anand Srivatsa, Ananthapadmanabha Thammaiah, M. V. Likith Kumar, D Rajeshwari · 5 authors
Recent advances in intelligent systems have significantly improved power management, load distribution, and resource management capabilities, far beyond past constraints. Despite these gains, the development of internet-connected technology has brought various vulnerabilities, leading to negative results. The integration of intelligent technology has unintentionally offered chances for hackers to enter networks and modify data sent to central systems for analysis. One of the most serious risks is the false data injection attack (FDIA), which may drastically impair analytical outcomes. Previous research has shown that standard approaches for recovering data affected by FDIA are unreliable and inefficient. This paper investigates the use of the proof of stake (PoS) consensus method in this framework improves data integrity and makes it easier to identify illegal changes. Participating nodes may reject or change block transactions, ensuring the ledger's correctness. Our results show that the PoS consensus method is exceptionally successful in creating and adding transactions to the blockchain. Furthermore, the PoS mechanism's simplicity in block formation enhances both time and energy efficiency, resulting in considerable benefits in operational performance.
Wenhan Hou, Bo Cui, Yongxin Chen, Ru Li · 5 authors
As a representative of the public blockchain, Ethereum has been applied in various industries. However, the vast number of transactions on the platform has also brought a number of illegal activities, such as phishing scams, which have caused significant damage to the Ethereum ecosystem. Due to anonymity of the blockchain, it is difficult for detectors to extract features that can be directly applied to phishing scams detection. Existing studies mainly model Ethereum transaction records as a network and mine key information from them to identify phishing addresses. However, these methods usually employ traditional feature engineering or network embedding, ignoring the fine-grained features in the transaction network. In addition, since the original network is too large to make learning difficult, existing work usually uses random walk (RW) to sample a part of nodes for training, thus ignoring the multiplicity of the network. To address these issues, in this article, we propose a three-stream feature fusion (TSFF) approach to enhance the feature representation of nodes. Specifically, we construct node states to guide RW sampling, and manually extracted 8-D features from the resulting dataset as basic features. Temporal features are jointly learned through long short-term memory network and contrastive learning. We combine residual blocks and graph convolutional network to extract fine-grained structural features from transactional networks. Finally, we fuse these three types of features and input them into a downstream classifier. Experiments show that our TSFF (85.3% Precision) outperforms the state-of-the-art methods, and the effectiveness of each feature is demonstrated.
André Augusto, Rafael Belchior, Jonas Pfannschmidt, André Vasconcelos · 5 authors
Cross-chain bridges are a type of middleware for blockchain interoperability that supports the transfer of assets and data across blockchains. However, several of these bridges have vulnerabilities that have caused 3.2 billion dollars in losses since May 2021. Some studies have revealed the existence of these vulnerabilities, but there is little quantitative research available, and there are no safeguard mechanisms to protect bridges from such attacks. Furthermore, no studies are available on the practices of cross-chain bridges that can cause financial losses. We propose \toolName~(Cross-Chain Watcher), a modular and extensible logic-driven anomaly detector for cross-chain bridges. It operates in three main phases: (1) decoding events and transactions from multiple blockchains, (2) building logic relations from the extracted data, and (3) evaluating these relations against a set of detection rules. Using \toolName, we analyze data from two previously attacked bridges: the Ronin and Nomad bridges. \toolName~was able to successfully identify the transactions that led to losses of \$611M and \$190M (USD) and surpassed the results obtained by a reputable security firm in the latter. We not only uncover successful attacks, but also reveal other anomalies, such as 37 cross-chain transactions (\CCTX) that these bridges should not have accepted, failed attempts to exploit Nomad, over \$7.8M worth of tokens locked on one chain but never released on Ethereum, and \$200K lost by users due to inadequate interaction with bridges. We provide the first open dataset of 81,000 \CCTXS~across three blockchains, capturing more than \$4.2B in token transfers.
Software-Defined Networking (SDN) has emerged as a revolutionary architecture in computer networks, offering comprehensive network control and monitoring capabilities. However, securing the east–west interface, which is crucial for communication between distributed SDN controllers, remains a significant challenge. This study proposes a novel blockchain-based security framework that integrates Ethereum technology with customized blockchain algorithms for authentication, encryption, and access control. The framework introduces decentralized mechanisms to protect against diverse attacks, including false data injection, man-in-the-middle (MitM), and unauthorized access. Experimental results demonstrate the effectiveness of this framework in securing distributed controllers while maintaining high network performance and low latency, paving the way for more resilient and trustworthy SDN infrastructures.
Francisco Javier Aguilar Feijóo, Diego Fernando Andaluz Espinosa
This research aims to determine the incidence of computer attacks on servers with the Linux operating system of local government entities. The study is limited to the decentralized autonomous government (GAD) of the Ecuadorian Amazon. Initially, the most common computer attacks that have affected organizations in recent years were determined using statistical reports from important computer security companies positioned as leaders in Gartner’s magic quadrant. Phishing and distributed denial of service (DDoS) attacks are established as computer attacks under study. Computer attacks are carried out before and after mitigation measures are established. With the help of the information systems risk analysis and management methodology (MAGERIT), the vulnerability, level of impact, and risk computer attacks cause on servers with the Linux operating system are determined. This research aims to serve as a guide to the information technology departments of local governments in implementing mechanisms that safeguard the most important asset of an organization, such as information. Keywords: computer attack, phishing, DDoS, MAGERIT, Linux. Resumen La presente investigación tiene como finalidad determinar la incidencia de los ataques informáticos en los servidores con sistema operativo Linux de entidades de gobierno local. El estudio está delimitado a un gobierno autónomo descentralizado (GAD) de la Amazonía ecuatoriana. Inicialmente se determina los ataques informáticos más comunes que han afectado a las organizaciones en los últimos años haciendo uso de reportes estadísticos de importantes empresas de seguridad informática posicionadas como líderes en el cuadrante mágico de Gartner. Se establece como ataques informáticos objeto de estudio los ataques de phishing y de denegación de servicio distribuido (DDoS). Se realizan ataques informáticos antes y después de establecer las medidas de mitigación y con la ayuda de la metodología de análisis y gestión de riesgos de los sistemas de información (MAGERIT) se determina la vulnerabilidad, el nivel de impacto y el riesgo que los ataques informáticos provocaban en los servidores con sistema operativo Linux. El presente trabajo de investigación pretende ser de gran utilidad y servir de guía a los departamentos de tecnologías de la información de gobiernos locales en la implementación de mecanismos que salvaguarden el activo más importante de una organización como lo es la información. Palabras Clave: ataque informático, phishing, ddos, magerit, linux.
Introduction: Botnets have become a significant threat to cybersecurity, as they can be used for a wide range of malicious activities, including Distributed Denial-of-Service (DDoS) attacks, spamming, and cryptocurrency mining. Bitcoin Mining, in particular, has become a lucrative target for cybercriminals, as it requires massive computing power and can generate significant profits. Methods: In this paper, the author presents a study on a botnet that uses an HTA file to gain initial access and execute code on a victim's device, followed by the installation of mining software to infect the device and bitcoins. Results: The author analyzes the botnet's behaviour, including its evasion techniques and Bitcoin Mining activities, and discusses the implications of current findings for cybersecurity and Bitcoin Mining. Conclusion: Future research should also investigate the use of different command and control servers and other advanced attack frameworks in botnet operations and examine the potential connections between botnets and other cybercrime activities, such as ransomware and espionage.
Fatma S. Alrayes, Mohammed Aljebreen, MOHAMMED ALGHAMDI, Faheed A. F. Alrslani · 8 authors
Consumer electronics (CE) and the Internet of Things (IoTs) are transforming daily routines by integrating smart technology into household gadgets. IoT allows devices to link and communicate from the Internet with better functions, remote control, and automation of various complex systems simulation platforms. The quick progress in IoT technology has continuously driven the progress of further connected and intelligent CEs, shaping more smart cities and homes. Blockchain (BC) technology is emerging as a promising technology offering immutable distributed ledgers that improve the security and integrity of data. However, even with BC resilience, the IoT ecosystem remains vulnerable to Distributed Denial of Service (DDoS) attacks. In contrast, the malicious actor overwhelms the network with traffic, disrupting services and compromising device functionality. Incorporating BC with IoT infrastructure presents groundbreaking techniques to alleviate these threats. IoT networks can better detect and respond to DDoS attacks in real time by leveraging BC cryptographic techniques and decentralized consensus mechanisms, which safeguard against disruptions and enhance resilience. There must be a reliable mechanism of recognition based on adequate techniques to detect and identify whether these attacks have happened or not in the system. Artificial intelligence (A) is the most common technique that uses machine learning (ML) and deep learning (DL) to recognize cyber threats. This research presents a new Blockchain with Ensemble Deep Learning-based Distributed DoS Attack Detection (BCEDL-DDoSD) approach in the IoT platform. The primary intention of the BCEDL-DDoSD approach is to leverage BC with a DL-based attack recognition process in the IoT platform. BC technology is utilized to enable a secure data transmission process. In the BCEDL-DDoSD approach, Z-score normalization is initially employed to measure the input data. Besides, the selection of features takes place using the Fractal Wombat optimization algorithm (WOA). For attack recognition, the BCDL-DDoSD technique applies an ensemble of three models, namely denoising autoencoder (DAE), gated recurrent unit (GRU), and long short-term memory (LSTM). Lastly, an orca predator algorithm (OPA)-based hyperparameter tuning procedure has been implemented to select the parameter value of DL models. A sequence of simulations is made on the benchmark database to authorize the performance of the BCDL-DDoSD approach. The simulation results showed that the BCDL-DDoSD approach performs better than other DL techniques.
In wireless sensor networks (WSNs), the presence of malicious nodes (MNs) poses significant challenges to data integrity, network stability, and system reliability. These issues are intensified by energy resource constraints and limitations within centralized authentication systems, necessitating an energy-efficient solution to ensure real-time responsiveness. Although artificial intelligence-driven approaches enhance detection capabilities, they overcome challenges related to data volume, coordination overhead, and latency in centralized control. This study introduces blockchain-machine learning (BC-ML), a novel hybrid model that seamlessly integrates blockchain and machine learning (ML) techniques to effectively identify MNs in WSNs. The model establishes an energy-efficient blockchain among cluster heads (CHs) for robust node authentication, incorporating a Schnorr-like zero-knowledge-proof technique to validate node data during communication initiation. Utilizing a hybrid lightweight approach with both symmetric and asymmetric ciphers enhances the security of node data transmission. A new proof-of-authority method is introduced, which leverages node digital certificates instead of conventional data transactions. This consensus mechanism reduces the processing overhead associated with larger data sizes in traditional proof-of-work methods, thereby improving both energy efficiency and scalability. To address dataset imbalances, the model employs a hybrid unsupervised ML technique, combining adaptive synthetic sampling with a convolutional neural network for efficient analysis of nodes and network features. The ML model, hosted on a robust data server, ensures ongoing oversight by updating CHs with security levels for detected MNs, thereby reducing storage and mitigating coordination challenges. Comprehensive analyses validate the effectiveness of the BC-ML model for detecting MNs, optimizing resource utilization, minimizing delays, and prolonging node and network lifetimes. Security analysis further confirms the ability of the model to mitigate diverse attacks and meet the stringent WSN security requirement.
The Internet of Things (IoT) refers to a network where different smart devices are interconnected through the Internet. This network enables these devices to communicate, share data, and exert control over the surrounding physical environment to work as a data-driven mobile computing system. Nevertheless, due to wireless networks' openness, connectivity, resource constraints, and smart devices' resource limitations, the IoT is vulnerable to several different routing attacks. Addressing these security concerns becomes crucial if data exchanged over IoT networks is to remain precise and trustworthy. This study presents a trust management evaluation for IoT devices with routing using the cryptographic algorithms Rivest, Shamir, Adleman (RSA), Self-Adaptive Tasmanian Devil Optimization (SA_TDO) for optimal key generation, and Secure Hash Algorithm 3-512 (SHA3-512), as well as an Intrusion Detection System (IDS) for spotting threats in IoT routing. By verifying the validity and integrity of the data exchanged between nodes and identifying and thwarting network threats, the proposed approach seeks to enhance IoT network security. The stored data is encrypted using the RSA technique, keys are optimally generated using the Tasmanian Devil Optimization (TDO) process, and data integrity is guaranteed using the SHA3-512 algorithm. Deep Learning Intrusion detection is achieved with Convolutional Spiking neural network-optimized deep neural network. The Deep Neural Network (DNN) is optimized with the Archimedes Optimization Algorithm (AOA). The developed model is simulated in Python, and the results obtained are evaluated and compared with other existing models. The findings indicate that the design is efficient in providing secure and reliable routing in IoT-enabled, futuristic, smart vertical networks while identifying and blocking threats. The proposed technique also showcases shorter response times (209.397 s at 70% learn rate, 223.103 s at 80% learn rate) and shorter sharing record times (13.0873 s at 70% learn rate, 13.9439 s at 80% learn rate), which underlines its strength. The performance metrics for the proposed AOA-ODNN model were evaluated at learning rates of 70% and 80%. The highest metrics were achieved at an 80% learning rate, with an accuracy of 0.989434, precision of 0.988886, sensitivity of 0.988886, specificity of 0.998616, F-measure of 0.988886, Matthews Correlation Coefficient (MCC) of 0.895521, Negative predictive value (NPV) of 0.998616, False Positive Rate (FPR) of 0.034365, and False Negative Rate (FNR) of 0.103095.
Software-Defined Networking (SDN) has revolutionized network management by providing unprecedented flexibility, control, and efficiency. However, its centralized architecture introduces critical security vulnerabilities. This paper introduces a novel approach to securing SDN environments using IOTA 2.0 smart contracts. The proposed system utilizes the IOTA Tangle, a directed acyclic graph (DAG) structure, to improve scalability and efficiency while eliminating transaction fees and reducing energy consumption. We introduce three smart contracts: Authority, Access Control, and DoS Detector, to ensure trusted and secure network operations, prevent unauthorized access, maintain the integrity of control data, and mitigate denial-of-service attacks. Through comprehensive simulations using Mininet and the ShimmerEVM IOTA Test Network, we demonstrate the efficacy of our approach in enhancing SDN security. Our findings highlight the potential of IOTA 2.0 smart contracts to provide a robust, decentralized solution for securing SDN environments, paving the way for the further integration of blockchain technologies in network management.