Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,600 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,600 results · page 14 of 67

Clear filters
Apr 20, 2024·Journal of Network and Computer Applications
5 cites
Fuzzychain: An equitable consensus mechanism for blockchain networks

Bruno Ramos-Cruz, Javier Andreu-Pérez, Francisco J. Quesada, Luis Martı́nez

Blockchain technology has become a trusted method for establishing secure and transparent transactions through a distributed, encrypted network. The operation of blockchain is governed by consensus algorithms, among which Proof of Stake (PoS) is popular yet has its drawbacks, notably the potential for centralising power in nodes with larger stakes or higher rewards. Our proposed novel solution, Fuzzychain, leverages fuzzy sets to define stake semantics, introducing a degree of softness in validator selection. This approach mitigates rigid threshold-based decision-making by allowing gradual transitions between stake levels, reducing sharp disparities among validators. By incorporating this enhanced stake evaluation, Fuzzychain promotes a more adaptive and distributed selection process, ensuring a fairer and more inclusive blockchain network. A thorough assessment of a real-time multi-agent blockchain system to examine validator selection and reduce inequality, promoting a more equitable distribution of stakes among validators compared to other consensus mechanisms. This fosters a more inclusive selection process and a more equitably distributed network.

Open access
3 source records
Blockchain Technology Applications and Security
Cognitive Computing and Networks
Spam and Phishing Detection
Original source
Apr 15, 2024·Proceedings of the 32nd IEEE/ACM International Conference on Program Comprehension
7 cites
The Sword of Damocles: Upgradeable Smart Contract in Ethereum

Yuan Huang, Xiaoyuan Wu, Quanqi Wang, Z. Qian · 7 authors

Although smart contracts are immutable once they are deployed, the reality is that they need upgrades to fix bugs or add new features. Nowadays, there are a few upgrade methods in Ethereum, some of which can change the contract without changing the contract address that users interact with. This upgrade way increases potential danger and results in users' distrust, because it may secretly change the function of the contract and cause users financial loss. We examine two of these upgrade methods, i.e., proxy pattern and metamorphic contract. For the proxy pattern, we propose a bytecode-based method for detecting these upgradeable contracts, which achieves a 99.37% F1-score. We use the bytecode-based method to detect the contracts in the first 12 million blocks of Ethereum and find 126,500 upgradeable contracts. For the metamorphic contracts, we employ an Ethereum replay tool to replay the transactions and find the metamorphic contracts according to the SELFDESTRUCT and CREATE2 instructions. We find that 64.3% of the contracts upgraded using this way are malicious MEV bots. Finally, we summarize the reasons for smart contract upgrades and make development recommendations.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Apr 12, 2024·2024 IEEE/ACM 46th International Conference on Software Engineering (ICSE '24)
52 cites
Improving Smart Contract Security with Contrastive Learning-based Vulnerability Detection

Yizhou Chen, Zeyu Sun, Zhihao Gong, Dan Hao

Currently, smart contract vulnerabilities (SCVs) have emerged as a major factor threatening the transaction security of blockchain. Existing state-of-the-art methods rely on deep learning to mitigate this threat. They treat each input contract as an independent entity and feed it into a deep learning model to learn vulnerability patterns by fitting vulnerability labels. It is a pity that they disregard the correlation between contracts, failing to consider the commonalities between contracts of the same type and the differences among contracts of different types. As a result, the performance of these methods falls short of the desired level. To tackle this problem, we propose a novel Contrastive Learning Enhanced Automated Recognition Approach for Smart Contract Vulnerabilities, named Clear. In particular, Clear employs a contrastive learning (CL) model to capture the fine-grained correlation information among contracts and generates correlation labels based on the relationships between contracts to guide the training process of the CL model. Finally, it combines the correlation and the semantic information of the contract to detect SCVs. Through an empirical evaluation of a large-scale real-world dataset of over 40K smart contracts and compare 13 state-of-the-art baseline methods. We show that Clear achieves (1) optimal performance over all baseline methods; (2) 9.73%-39.99% higher F1-score than existing deep learning methods.

Open access
3 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Apr 8, 2024·Journal of Electrical Systems
4 cites
Comparative Analysis of Fake Product Identification System Using Blockchain Technology

Rishabh Rajavardhan Singh Rishabh Ratnesh Singh

Fictitious products have emerged as a substantial challenge in the manufacturing sector, inflicting adverse consequences on a company's financial health, reputation, and overall prosperity. Thankfully, blockchain technology provides an effective remedy for discerning fake items and verifying the legitimacy of authentic ones, all within a decentralized and widely distributed digital ledger. Quick Response (QR) codes serve as pivotal tools in the fight against fictitious goods, as each product is now furnished with a QR code that acts as a direct bridge to the blockchain system, essentially bestowing each item with a digital identification card. QR code scanners communicate with the blockchain to promptly validate whether a product is genuine or fictitious. Moreover, customers can harness this technology to track a product's journey through the supply chain and authenticate ownership details, akin to a digital breadcrumb trail that securely preserves product information and unique codes as database blocks. Considering the globalized business landscape and the perpetual advancements in technology, industrial manufacturers and distributors are wholeheartedly committed to optimizing their supply chain processes, ensuring they remain one step ahead of fictitious product proliferation and fortifying their operations against the dissemination of spurious items. In this paper we compare Different Fake product identification Methods like Barcodes, QR Codes, RFID Tags, Serial numbers with methods using Blockchain technology which is having high security, transferability & traceability throughout Supply Chain.

Open access
Smart Systems and Machine Learning
Spam and Phishing Detection
Internet of Things and AI
Original source
Apr 8, 2024·Proceedings of the 39th ACM/SIGAPP Symposium on Applied Computing
0 cites
Account Discovery: Identifying Web3 SNS Accounts at Risk of De-anonymization

Daiki Ito, Yuta Takata, Keika Mori, Ryoya Furukawa · 6 authors

Web services that use a blockchain and crypto-assets (Web3 services) improve user privacy by anonymous logins using wallet addresses. However, since many users list their account identities (IDs) on social networking service (SNS) profile pages and reuse their account IDs for self-branding and curation purposes, which increases the risk of de-anonymization on Web3 services by linking these accounts. If such high-risk SNS accounts hold large amounts of crypto-assets, they are subject to account hijacking and spoofing attacks for financial gain. In this study, we proposed a method to discover highly relevant SNS accounts from a seed account on Web2 and Web3 SNSs and estimate their account ownership. We applied our method to 480 seed accounts of 9 different SNSs and discovered 1,233 new accounts. We found that SNSs with multiple URL input forms on their profile setting pages linked more accounts and revealed that 207 out of 253 (81.8%) users reused their IDs across different SNSs. We identified 26 accounts linked to personal and crypto-asset information that are at risk of de-anonymization. Our user study using crowdsourcing services showed that as many as 232 (40.8%) out of 568 respondents do not understand the traceability of blockchain transaction histories. We examined the security and privacy risks caused by account listing and ID reuse, and made recommendations for service providers and users based on our findings.

Open access
Privacy, Security, and Data Protection
Spam and Phishing Detection
User Authentication and Security Systems
Original source
Apr 6, 2024·2024 IEEE 13th International Conference on Communication Systems and Network Technologies (CSNT)
0 cites
A Fuzzy Trust Model for Ethereum Blockchain

Sakshi Singh, Shampa Chakraverty

With the rapid proliferation of blockchain technology, Ethereum has emerged as a prominent platform for decentralised applications and smart contracts. Ensuring the integrity and reliability of the Ethereum network is paramount for its sustained success. This research introduces an innovative approach for approximating the trust levels of Ethereum nodes, which is crucial for maintaining the network's security and performance. Leveraging the Mamdani fuzzy model, this study proposes a comprehensive framework that evaluates trustworthiness by considering multiple parameters, including token count. Transaction count and Ether percentage held by Ethereum node user. These parameters are fuzzified and transformed into linguistic variables, then processed through a Mamdani Fuzzy Model. The model uses predefined linguistic rules and membership functions to assign a trust score to each node user.

Blockchain Technology Applications and Security
Cloud Data Security Solutions
Spam and Phishing Detection
Original source
Mar 30, 2024·Electronics
5 cites
Learning to Traverse Cryptocurrency Transaction Graphs Based on Transformer Network for Phishing Scam Detection

Su‐Hwan Choi, Seok-Jun Buu

Cryptocurrencies have experienced a surge in popularity, paralleled by an increase in phishing scams exploiting their transactional networks. Therefore, detecting anomalous transactions in the complex structure of cryptocurrency transaction data and the imbalance between legitimate and fraudulent data is considered a very important task. To this end, we introduce a model specifically designed for scam detection within the Ethereum network, focusing on its capability to process long and complex transaction graphs. Our method, Deep Graph traversal based on Transformer for Scam Detection (DGTSD), employs the DeepWalk algorithm to traverse extensive graph structures and a Transformer-based classifier to analyze intricate node relationships within these graphs. The necessity for such an approach arises from the inherent complexity and vastness of Ethereum transaction data, which traditional techniques struggle to process effectively. DGTSD applies subgraph sampling to manage this complexity, targeting significant portions of the network for detailed analysis. Then, it leverages the multi-head attention mechanism of the Transformer model to effectively learn and analyze complex patterns and relationships within the Ethereum transaction graph to identify fraudulent activity more accurately. Our experiments with other models demonstrate the superiority of this model over traditional methods in performance, with an F1 score of 0.9354. By focusing on the challenging aspects of Ethereum’s transaction network, such as its size and intricate connections, DGTSD presents a robust solution for identifying fraudulent activities, significantly contributing to the enhancement of blockchain security.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Graph Neural Networks
Original source
Mar 28, 2024·arXiv (Cornell University)
26 cites
Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker Contracts

Shuo Yang, Jiachi Chen, Mingyuan Huang, Zibin Zheng · 5 authors

Reentrancy, a notorious vulnerability in smart contracts, has led to millions of dollars in financial loss. However, current smart contract vulnerability detection tools suffer from a high false positive rate in identifying contracts with reentrancy vulnerabilities. Moreover, only a small portion of the detected reentrant contracts can actually be exploited by hackers, making these tools less effective in securing the Ethereum ecosystem in practice. In this paper, we propose BlockWatchdog, a tool that focuses on detecting reentrancy vulnerabilities by identifying attacker contracts. These attacker contracts are deployed by hackers to exploit vulnerable contracts automatically. By focusing on attacker contracts, BlockWatchdog effectively detects truly exploitable reentrancy vulnerabilities by identifying reentrant call flow. Additionally, BlockWatchdog is capable of detecting new types of reentrancy vulnerabilities caused by poor designs when using ERC tokens or user-defined interfaces, which cannot be detected by current rule-based tools. We implement BlockWatchdog using cross-contract static dataflow techniques based on attack logic obtained from an empirical study that analyzes attacker contracts from 281 attack incidents. BlockWatchdog is evaluated on 421,889 Ethereum contract bytecodes and identifies 113 attacker contracts that target 159 victim contracts, leading to the theft of Ether and tokens valued at approximately 908.6 million USD. Notably, only 18 of the identified 159 victim contracts can be reported by current reentrancy detection tools.

Open access
3 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Mar 18, 2024·Asian Journal of Computer Science and Technology
0 cites
Decentralized Authentication for Enhanced Security: Leveraging Blockchain Technology to Prevent Credential Theft

Sulemana Awal, Diyawu Mumin, Arnold Mashud Abukari, Abukari Aziz Danaa · 5 authors

Online services currently rely heavily on centralized authentication methods to manage user identification and authentication. However, these methods are vulnerable to account hacking, which can compromise user data and lead to attacks. A potential solution to this issue is the use of distributed ledger technology, such as blockchain, to decentralize credential ownership and provide a secure, immutable platform for verifying user identity. This paper aims to analyze the drawbacks of centralized authentication systems and propose an alternative that uses blockchain technology for authentication, ensuring robustness, transparency, and security. The proposed system is tested on web applications using the Ethereum testnet and an authentication provider (backend server).

Open access
Privacy, Security, and Data Protection
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Mar 18, 2024·ICASSP 2024 - 2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)
2 cites
CLPSD: Detecting Ethereum Phishing Scams based on Curriculum Learning

Wenhan Hou, Bo Cui, Yongxin Chen, Ru Li

Phishing scams have become one of the primary frauds on Ethereum, leading to substantial financial losses for users. Therefore, developing an effective phishing detection method for Ethereum holds significant importance for the blockchain ecosystem. However, the heterogeneity of Ethereum poses challenges when it comes to detecting phishing scams. In this paper, we propose a Curriculum Learning-based approach (CLPSD) for Ethereum phishing detection. We collect transaction records to build a graph. In order to distinguish the varying degrees of contribution among nodes, we design a difficulty measurer combining Local Outlier Factor and information entropy. Thus, CLPSD utilizes Graph Convolutional Network to initially learn from easy samples and progressively advance to more complex ones. The experimental results demonstrate that CLPSD outperforms existing methods, highlighting the superior performance of our approach and its significant relevance in enhancing the Ethereum ecosystem.

Spam and Phishing Detection
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Original source
Mar 15, 2024·Scientific Reports
23 cites
Statistical detection of selfish mining in proof-of-work blockchain systems

Shengnan Li, Carlo Campajola, Claudio J. Tessone

The core of many cryptocurrencies is the decentralised validation network operating on proof-of-work technology. In these systems, validation is done by so-called miners who can digitally sign blocks once they solve a computationally-hard problem. Conventional wisdom generally considers this protocol as secure and stable as miners are incentivised to follow the behaviour of the majority. However, whether some strategic mining behaviours occur in practice is still a major concern. In this paper we target this question by focusing on a security threat: a selfish mining attack in which malicious miners deviate from protocol by not immediately revealing their newly mined blocks. We propose a statistical test to analyse each miner's behaviour in five popular cryptocurrencies: Bitcoin, Litecoin, Monacoin, Ethereum and Bitcoin Cash. Our method is based on the realisation that selfish mining behaviour will cause identifiable anomalies in the statistics of miner's successive blocks discovery. Secondly, we apply heuristics-based address clustering to improve the detectability of this kind of behaviour. We find a marked presence of abnormal miners in Monacoin and Bitcoin Cash, and, to a lesser extent, in Ethereum. Finally, we extend our method to detect coordinated selfish mining attacks, finding mining cartels in Monacoin where miners might secretly share information about newly mined blocks in advance. Our analysis contributes to the research on security in cryptocurrency systems by providing the first empirical evidence that the aforementioned strategic mining behaviours do take place in practice.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Steganography and Watermarking Techniques
Original source
Mar 7, 2024·Electronics
9 cites
Multiscale Feature Fusion and Graph Convolutional Network for Detecting Ethereum Phishing Scams

Zhe Chen, Jia Huang, ShengZheng Liu, Haixia Long

With the emergence of blockchain technology, the cryptocurrency market has experienced significant growth in recent years, simultaneously fostering environments conducive to cybercrimes such as phishing scams. Phishing scams on blockchain platforms like Ethereum have become a grave economic threat. Consequently, there is a pressing demand for effective detection mechanisms for these phishing activities to establish a secure financial transaction environment. However, existing methods typically utilize only the most recent transaction record when constructing features, resulting in the loss of vast amounts of transaction data and failing to adequately reflect the characteristics of nodes. Addressing this need, this study introduces a multiscale feature fusion approach integrated with a graph convolutional network model to detect phishing scams on Ethereum. A node basic feature set comprising 12 features is initially designed based on the Ethereum transaction dataset in the basic feature module. Subsequently, in the edge embedding representation module, all transaction times and amounts between two nodes are sorted, and a gate recurrent unit (GRU) neural network is employed to capture the temporal features within this transaction sequence, generating a fixed-length edge embedding representation from variable-length input. In the time trading feature module, attention weights are allocated to all embedding representations surrounding a node, aggregating the edge embedding representations and structural relationships into the node. Finally, combining basic and time trading features of the node, graph convolutional networks (GCNs), SAGEConv, and graph attention networks (GATs) are utilized to classify phishing nodes. The performance of these three graph convolution-based deep learning models is validated on a real Ethereum phishing scam dataset, demonstrating commendable efficiency. Among these, SAGEConv achieves an F1-score of 0.958, an AUC-ROC value of 0.956, and an AUC-PR value of 0.949, outperforming existing methods and baseline models.

Open access
2 source records
Spam and Phishing Detection
Network Security and Intrusion Detection
Internet Traffic Analysis and Secure E-voting
Original source
Mar 2, 2024·International Research Journal of Modernization in Engineering Technology and Science
0 cites
A SECURE PLATFORM FOR CROWDFUNDING PROCESS

Authors unavailable

Crowdfunding is an online fundraising method whereby individuals contribute small amounts to support the startup projects or businesses of young entrepreneurs. The emergence of crowdfunding sites has improved the financing process. Individuals, business owners, and innovators can now reach a worldwide audience to raise money for their ideas. In addition to examining the emergence, important models, and societal impact of crowdfunding platforms, this abstract offers a succinct summary of their many facets. Building confidence between donors and recipients is important, especially in light of the increasing number of scams. Donating to unknown parties generally scares people since they don't know if their money will go towards the appropriate causes or not. Thus, the development of a safe crowdfunding platform is required. Blockchain technology has revolutionized a number of industries by bringing previously unheard-of levels of security, transparency, and decentralization. The aim of this research paper is to examine how blockchain technology integration might improve transparency, build confidence between project creators and backers, and solve current issues with crowdfunding platforms. The decentralized ledger technology of blockchain guarantees the security, accountability, and transparency of project creators and backers. This presentation concludes by outlining the revolutionary potential of crowdfunding platforms to change financial dynamics and promote inclusive financing process involvement.

Open access
FinTech, Crowdfunding, Digital Finance
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Feb 27, 2024·arXiv
11 cites
SoK: Cryptocurrency Wallets – A Security Review and Classification based on Authentication Factors

Ivan Homoliak, Martin Perešíni

In this work, we review existing cryptocurrency wallet solutions with regard to authentication methods and factors from the user's point of view. In particular, we distinguish between authentication factors that are verified against the blockchain and the ones verified locally (or against a centralized party). With this in mind, we define notions for $k-factor$ authentication against the blockchain and $k-factor$ authentication against the authentication factors. Based on these notions, we propose a classification of authentication schemes. We extend our classification to accommodate the threshold signatures and signing transactions by centralized parties (such as exchanges or co-signing services). Finally, we apply our classification to existing wallet solutions, which we compare based on various security and key-management features.

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Spam and Phishing Detection
Original source
Feb 26, 2024·2024 2nd International Conference on Cyber Resilience (ICCR)
2 cites
Malware Threats Targeting Cryptocurrency: A Comparative Study

Mohammad Alauthman, Ahmad Al–Qerem, Mouhammd Alkasassbeh, Nauman Aslam · 5 authors

As cryptocurrencies have grown in prevalence and value, associated malware threats have rapidly emerged, exploiting vulnerabilities in wallets, markets, and decentralization mechanisms. This paper provides a comparative review of dominant cryptocurrency malware categories, including ransomware, crypto-jacking, supply chain hijacking, malicious browser extensions, phishing kits, and miner botnets. Analysis of behaviors, targets, propagation tactics, motivations, and detection challenges reveal commonalities and differences across threat types. Examination of recent literature enables comprehensive characterization of the cryptocurrency malware ecosystem to derive insights into evolution trajectories and systemic issues. Ransomware, crypto-jacking, and coordinated botnets represent prevalent threats highlighted, with malware innovation incentivized by pseudonymous payments, irreversible transactions, and criminal usage of mineable privacy-focused coins. Software supply chain attacks and phishing kits showcase propagation risks. Comparative assessment enables identifying research priorities like transaction tracing, behavioral monitoring, and predictive indicators to strengthen adaptive defenses against cryptocurrency-targeting threats. As cryptocurrency permeates society, proactive ecosystem perspectives will grow crucial in responding to malware creativity.

Advanced Malware Detection Techniques
Spam and Phishing Detection
Blockchain Technology Applications and Security
Original source
Feb 26, 2024·Computers
36 cites
Cyber Threat Intelligence on Blockchain: A Systematic Literature Review

Dimitrios Chatziamanetoglou, Konstantinos Rantos

Cyber Threat Intelligence (CTI) has become increasingly important in safeguarding organizations against cyber threats. However, managing, storing, analyzing, and sharing vast and sensitive threat intelligence data is a challenge. Blockchain technology, with its robust and tamper-resistant properties, offers a promising solution to address these challenges. This systematic literature review explores the recent advancements and emerging trends at the intersection of CTI and blockchain technology. We reviewed research papers published during the last 5 years to investigate the various proposals, methodologies, models, and implementations related to the distributed ledger technology and how this technology can be used to collect, store, analyze, and share CTI in a secured and controlled manner, as well as how this combination can further support additional dimensions such as quality assurance, reputation, and trust. Our findings highlight the focus of the CTI and blockchain convergence on the dissemination phase in the CTI lifecycle, reflecting a substantial emphasis on optimizing the efficacy of communication and sharing mechanisms, based on an equitable emphasis on both permissioned, private blockchains and permissionless, public blockchains, addressing the diverse requirements and preferences within the CTI community. The analysis reveals a focus towards the tactical and technical dimensions of CTI, compared to the operational and strategic CTI levels, indicating an emphasis on more technical-oriented utilization within the domain of blockchain technology. The technological landscape supporting CTI and blockchain integration emerges as multifaceted, featuring pivotal roles played by smart contracts, machine learning, federated learning, consensus algorithms, IPFS, deep learning, and encryption. This integration of diverse technologies contributes to the robustness and adaptability of the proposed frameworks. Moreover, our exploration unveils the overarching significance of trust and privacy as predominant themes, underscoring their pivotal roles in shaping the landscape within our research realm. Additionally, our study addresses the maturity assessment of these integrated systems. The approach taken in evaluating maturity levels, distributed across the Technology Readiness Level (TRL) scale, reveals an average balance, indicating that research efforts span from early to mid-stages of maturity in implementation. This study signifies the ongoing evolution and maturation of research endeavors within the dynamic intersection of CTI and blockchain technology, identifies trends, and also highlights research gaps that can potentially be addressed by future research on the field.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Feb 23, 2024·Heliyon
15 cites
Decoding the cryptocurrency user: An analysis of demographics and sentiments

José Campino, Shiwen Yang

In recent years, new payment methods have emerged, aimed at improving convenience for users. Cryptocurrencies, in principle, are no different. In this study, we seek to analyze the general population's attitudes towards the adoption of cryptocurrencies as a payment method. To achieve this, we have developed a descriptive survey that targets both current cryptocurrency users and non-users, recognizing that differences in perception may exist. Additionally, we have conducted a sentiment analysis of open-ended questions to understand respondents' views on the future of the cryptocurrency market and its potential as a payment tool, utilizing different lexicons in the English language. Our findings indicate that most cryptocurrency users prefer to invest in these digital assets, often choosing coins based on their popularity rather than other intrinsic features. E-commerce payments are the most attractive activity, followed by international transactions when using cryptocurrencies as a payment method. However, high volatility and a lack of ease of use are the most common difficulties reported by users. Our study also highlights the importance of regulation in a time when users are increasingly demanding higher levels of oversight, in contrast to the past. While users are concerned about the instability and volatility of cryptocurrencies, they also value the anonymity these transactions offer. Our analysis showcases an innovative approach to analyzing interviews and qualitative questionnaires that can be applied in other research fields.

Open access
Spam and Phishing Detection
Digital Marketing and Social Media
Sentiment Analysis and Opinion Mining
Original source
Feb 14, 2024·Connection Science
14 cites
Detecting unknown vulnerabilities in smart contracts using opcode sequences

Peiqiang Li, Guojun Wang, Xiaofei Xing, Xiangbin Li · 5 authors

Unknown vulnerabilities, also known as zero-day vulnerabilities, are vulnerabilities in software, systems, or networks that have not yet been publicly disclosed or fixed. If these vulnerabilities are ever discovered by hackers, intentionally or unintentionally, they pose a major threat to network security. This is particularly true in the blockchain field, as smart contracts hold a lot of money, and if they are discovered and exploited by hackers, the financial losses to users will be even greater. However, the current research on smart contract vulnerabilities mainly focuses on known vulnerabilities, and the research on unknown vulnerabilities has been limited. Based on this, we introduce a machine learning-based method for detecting unknown vulnerabilities in smart contracts. First, the method obtains the opcode sequences executed by smart contract transactions in the EVM by instrumenting Geth and replaying the Ethereum transactions. Next, we employ an n-gram model and a vector weight penalty mechanism to extract the opcode sequence features. We then use machine learning algorithms to detect unknown vulnerabilities based on the similarity principle. Finally, we test the effectiveness of our method with four machine learning models: the K-Nearest Neighbor algorithm (KNN), Support Vector Machine (SVM), Logistic Regression (LR), and Decision Tree (DT). The SVM model performs best at detecting unknown vulnerabilities, with an accuracy of 96%, a precision of 91%, a recall of 100%, and an F1-score of 95%. We also discuss the benefits of the method: timely detection of attacks due to unknown vulnerabilities, thus reducing user losses.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Network Security and Intrusion Detection
Original source
Feb 13, 2024·International Journal for Research in Applied Science and Engineering Technology
2 cites
Intrusion Detection System using Blockchain

Avneet Kaur, Shruti Pawar, Neha Jore, V.B. Chavan · 5 authors

Abstract: This paper investigates the integration of an Intrusion Detection System (IDS) within the context of blockchain technology. The objective is to enhance the security posture of blockchain networks by detecting and mitigating potential intrusions. Through a meticulous examination of the current threat landscape and the unique challenges posed by blockchain systems, this research proposes a robust IDS framework tailored to the specific requirements of decentralized and distributed ledger environments. The study employs [specific methodology/approach] to assess the effectiveness of the proposed IDS, presenting conclusive findings that contribute to the ongoing discourse on securing blockchain ecosystems. The implications of this research extend to bolstering the resilience of blockchain networks against emerging threat.

Open access
Network Security and Intrusion Detection
Spam and Phishing Detection
Smart Systems and Machine Learning
Original source
Feb 8, 2024·2024 2nd International Conference on Computer, Communication and Control (IC4)
1 cites
Web Scraping Illicit Bitcoin Addresses

Ravindra Ghugare, Aditya Thakare, Prasad Deshmukh, Yashverdhan Bhatia · 5 authors

Recent years saw the birth of cryptocurrencies, and among them is Bitcoin. The platform it offers allows people to move money without needing a middleman or revealing their true identity. All very good things that are aimed at fostering financial independence and privacy, but this also allows for bad stuff like fraud, money laundering, and aiding illegal practices. The problem arises when you consider how hard it is to scrutinize Bitcoin transactions. This is made even more difficult when trying to track illicit activities. That’s what makes even the mention of fraud put a frown on law enforcement officers’ faces. Our solution? Utilizing web scraping we set out on a data collection expedition across the Bitcoin blockchain. Our goal was simple: track down Bitcoin addresses associated with illicit activities. It may seem like an easy task but in reality, major roadblocks led us astray. Those who make use of their anonymity know exactly what they’re doing and often cover their tracks very well. But after countless hours of scouring online platforms, marketplaces, forums, and other places we managed to find a network of illicit Bitcoin addresses involved in fraudulent transactions and money laundering schemes. Moreover, the study delves into the ethical aspects of gathering publicly accessible data from blockchain technology. It explores the regulations governing web scraping and the moral considerations related to privacy and data collection in the realm of cryptocurrencies. By shedding light on the ethical principles that guide web scraping endeavors this research emphasizes the need for an approach that respects privacy rights while enabling effective identification and monitoring of illicit cryptocurrency activities. The findings of this investigation not reveal aspects of cryptocurrency transactions but also propose a robust methodology. This methodology can be utilized by stakeholders, including bodies, law enforcement agencies and the wider cryptocurrency community. It will aid in monitoring, regulating and fostering a lawful ecosystem, for cryptocurrencies. Our research emphasizes the need for an effort to establish a set of regulations that not only discourages illegal activities but also promotes the integration of cryptocurrencies into the mainstream financial sector.

Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Feb 6, 2024·Internet of Things Volume 26, July 2024, 101193
34 cites
Merkle Trees in Blockchain: A Study of Collision Probability and Security Implications

Alexandr Kuznetsov, Alex Rusnak, Anton Yezhov, Kateryna Kuznetsova · 6 authors

In the rapidly evolving landscape of blockchain technology, ensuring the integrity and security of data is paramount. This study delves into the security aspects of Merkle Trees, a fundamental component in blockchain architectures, such as Ethereum. We critically examine the susceptibility of Merkle Trees to hash collisions, a potential vulnerability that poses significant risks to data security within blockchain systems. Despite their widespread application, the collision resistance of Merkle Trees and their robustness against preimage attacks have not been thoroughly investigated, leading to a notable gap in the comprehensive understanding of blockchain security mechanisms. Our research endeavors to bridge this gap through a meticulous blend of theoretical analysis and empirical validation. We scrutinize the probability of root collisions in Merkle Trees, considering various factors such as hash length and path length within the tree. Our findings reveal a direct correlation between the increase in path length and the heightened probability of root collisions, thereby underscoring potential security vulnerabilities. Conversely, we observe that an increase in hash length significantly reduces the likelihood of collisions, highlighting its critical role in fortifying security. The insights garnered from our research offer valuable guidance for blockchain developers and researchers, aiming to bolster the security and operational efficacy of blockchain-based systems.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source