Autonomous vehicles (AVs) are gaining in popularity over the years as a viable cab service apps as well as for personal use. However, incidents of crashes involving AVs continue to occur, adversely affecting their prospects for widespread acceptance by both end users and regulatory authorities. While such cases are routinely investigated, in the absence of a human to testify on what caused the crash, one has to rely solely on available data. It is therefore imperative that the data logged by AVs is accessible to the concerned parties in a trustworthy manner. In this paper, we present AVChain—a novel framework for using a permissioned blockchain like HyperLedger Fabric (HLF) to record and share AV data comprised of sensors, actuators, maps, planning algorithms and machine learning models so that the data stays immutable even in the face of cross blaming among involved parties. Since the data volume is extremely large, we appropriately compress and down sample the same before storing in a distributed file system, namely, IPFS (Inter-Planetary File System). The hashes of such IPFS data called Content Ids (CIDs) are committed to the HLF network for making them tamper proof. The HLF ledger can later be queried to obtain the CIDs, which are then further used to retrieve and un-compress the original data from IPFS. Effectiveness and usability of AVChain is demonstrated by generating AV data from CARLA, which is a widely used open source AV simulator. For sharing AV data across organizations like sensor and actuator suppliers, map service providers, machine learning model developers and law enforcement authorities, the Weaver tool has been used to make multiple HLF networks interoperate. We have also developed a web application to demonstrate the working of AVChain. Results of an extensive set of experiments establish the efficacy of our approach.
As the Internet of Vehicles (IoV) advances, the security concerns surrounding vehicular networks have grown increasingly critical due to the openness of networking among vehicles, inadvertently creating more opportunities for adversaries to infiltrate and potentially disrupt vehicle operations. Intrusion detection systems (IDSs) stand as a promising solution, effectively mitigating the myriad of threats and security concerns that plague vehicles. In this article, we delve into the realm of IDSs within vehicular networks and propose an innovative collaborative intrusion detection framework based on blockchain technology and auction game. First, we integrate a vehicular blockchain into the IDS, offering a holistic approach to tackling both internal and external threats within vehicular networks. Second, we introduce a novel assistant-delegated Byzantine fault tolerance (A-DBFT) consensus algorithm, designed to bolster the efficiency of intrusion detection within the blockchain while maintaining the efficacy of the consensus mechanism. Third, we develop an auction game mechanism that incentivizes assistants and verifiers to actively initiate and participate in auctions, thereby enhancing the overall security of our intrusion detection scheme. Ultimately, we present simulation results that validate the superiority of our proposed scheme compared to conventional approaches.
The proliferation of Internet of Things (IoT) devices has facilitated the exchange of information among individuals and devices. This development has introduced several challenges, including increased vulnerability to potential cyberattacks and digital forensics. IoT forensic investigations need to be managed in a forensically sound manner using a standard framework. However, adopting traditional digital forensics tools introduces various challenges, such as identifying all IoT devices and users at the crime scene. Therefore, collecting evidence from these devices is a major problem. This paper proposes a permissioned blockchain integration solution for IoT forensics (PBCIS-IoTF) that aims to observe data transactions within the blockchain. The PBCIS-IoTF framework designs and tests Hyperledger blockchains simulated with a Raspberry Pi device and chaincode to address the challenges of IoT forensics. This blockchain is deployed using multiple nodes within the network to avoid a single point of failure. The authenticity and integrity of the acquired evidence are analysed by comparing the SHA-256 hash metadata in the blockchain of all peers within the network. We further integrate webpage access with the blockchain to capture the forensics data from the user’s IoT devices. This allows law enforcement and a court of law to access forensic evidence directly and ensures its authenticity and integrity. PBCIS-IoTF shows high authenticity and integrity across all peers within the network.
Adam L. Hooker, Wenjian Huang, Shalini Kapali Kurumathur, Nishant Vishwamitra · 5 authors
The (ab)use of encryption and compression in hiding illegal digital content complicates efforts by law enforcement agencies (LEAs) to procure evidence to support the elements of proof required in criminal prosecution. This reinforces the importance of designing solutions to determine the file type of an encrypted file (e.g., videos and still images in the context of illegal picture investigations), which can be used to build probable cause in a court order application to have the file decrypted. While machine learning (ML) has shown immense capabilities in several detection tasks, the suitability of ML for detecting file types in encrypted or compressed files has not been explored. Furthermore, since detecting file types in real-world LEA applications is a high-stake decision-making problem, existing ML techniques that do not provide prediction uncertainty are not as useful. In this work, we take the first step toward detecting file types in encrypted or compressed files using ML for LEA applications based on their Byte Frequency Distributions (BFD). We then compose a dataset1of BFDs of 300,000 encrypted and compressed data from 12,000 diverse files for five different file types. We conduct an in-depth analysis of our dataset and demonstrate the utility of ML techniques in detecting file types of content in encrypted and compressed files based on BFDs. Informed by these findings, we present our proposed framework, eDefender, designed to facilitate the detection of file types in encrypted and compressed files for LEA applications, by employing uncertainty quantification of detection scores based on ensembling. eDefender successfully flags directories with encrypted or compressed image/video-type files with an F1-score of 90.7%.
Intrusion Detection Systems (IDS) are the key for securing the rapidly evolving Internet-of-Things (IoT), where data security and privacy will become increasingly important in the forthcoming era. This research presents an innovative method for improving IDS performance through the integration of Artificial Intelligence (AI), Blockchain, and Digital Twin (DT) technologies. AI is utilized for real-time anomaly detection, whereas DT replicate device behavior for predicting threats and Blockchain ensures secure, decentralized data transmission. Energy-efficient zero-knowledge proofs are employed to meet the energy requirements of Blockchain, enhancing both security and resource efficiency. The performance of the suggested system will be assessed based on detection accuracy, latency, scalability, energy efficiency, and privacy preservation. This distinctive integration of advanced technologies delivers a multi-faceted security system, providing a thorough respond to for strengthening security in IoT networks.
An eclipse attack is a strategy where attackers control communication between nodes in peer-to-peer networks, such as Ethereum, using compromised nodes to escalate further attacks. Given the vast and complex nature of big data in Ethereum networks, detecting these attacks is challenging. This paper aims to identify effective features for eclipse attack detection by analyzing large volumes of network traffic data. We simulate an Ethereum network, conducting eclipse attacks to generate datasets where 28% of the traffic consists of malicious packets. We apply five feature extraction methods—common network traffic, Entropy, φ-Divergence, packet communication statistics, and packet characteristics statistics—leveraging big data analysis techniques to process and refine extensive traffic data. To address the challenges posed by imbalanced and overlapping data, SMOTE and Tomek link algorithms are used, and Mutual Information selects the most significant features to enhance classifier performance. We evaluate five machine learning models, including XGBoost, kNN, and Random Forest, finding that XGBoost achieves the highest performance, with 99.25% accuracy and a computational time of 184 ms when processing the top 25 features, which indicates real-time detection could be possible.
Oqeili Saleh, Abu-alzanat Thamer, Alkaraimah Qutaibah, al smadi Takialddin
CAPTCHA, which stands for Completely Automated Public Turing Test to Tell Computers and Humans Apart, is a commonly employed security measure to distinguish between humans and computers. The Turing Test, designed to guarantee network security, is the foundation of this security technique. Usability is a crucial concern that can prevent human users from engaging in laborious and time-consuming tasks. When designing CAPTCHA, security and usability must be addressed simultaneously. When designing CAPTCHA, it is crucial to address security and usability simultaneously. A concerted effort is required to protect online data and guarantee privacy and security. The personal information of Internet users remains susceptible to theft. This study uses an information extraction technique called CAPTCHA to investigate the hazards associated with violating user privacy. It is a highly harmful process due to hacking, theft, unauthorized reuse, and the breach of user information. This study proposes a privacy preservation system employing concurrent encryption techniques, multilateral security computing, and zero-knowledge proof. The objective is to create a system that allows for uncomplicated and secure puzzle-solving using dice gas. CAPTCHA limits access to users' information. In the overview and application of evidentiary measurable methods, we can draw significant conclusions about the more extensive client group's discernments and encounters with CAPTCHA as a privacy-preserving component.
The decentralized finance (DeFi) ecosystem experienced significant growth in 2024, accompanied by a rise in sophisticated cyberattacks. This article analyzes key security incidents, including the PenPie reentrancy attack, flash loan exploits on Radiant Capital and Goledo Finance, a social engineering breach at Concentric Finance, a multi-signature compromise on Orbit Chain, and phishing campaigns targeting Binance users. Detailed technical insights and countermeasures, such as reentrancy guards, decentralized oracles, and enhanced user authentication, highlight strategies for mitigating risks and strengthening DeFi security.
Protecting integrated circuits (ICs) from piracy and theft throughout their lifecycle is a persistent and complex challenge. In order to safeguard against illicit piracy attacks, this work proposes a novel framework utilizing Non-Fungible Tokens (NFTs) called ICtokens, uniquely linked to their corresponding physical ICs. Each ICtoken contains comprehensive information, including authentication data, supply chain stage and status, ownership details, and other IC metadata, while also making provision for the secure integration of a logic-locking key. Designed to be publicly logged, ICtokens securely obscure metering information without compromising functionality. In addition, the ICtracker, a distributed ledger technology powered by a swift and energy-efficient consortium blockchain, is used to register and manage ICtokens and their respective owners, tracking all associated interactions. This robust ledger guarantees the traceability and auditing of ICtokens while simultaneously developing a product-level NFT at every transaction point within the supply chain. Consequently, a scalable framework is established, creating unique, immutable digital twins for ICs and IC-embedded products in the form of ICtokens and their transactions. This provides a robust and reliable supply chain trail back to the original IP owner, while also offering unprecedented assurance to consumers of IC-embedded products. The rich information contained within ICtokens facilitates more detailed audits than previous proposals for IC supply chain monitoring. A proof-of-concept, implemented as an open-source solution, ensures the ease of adoption of the proposed framework.
WebAssembly (WASM) has emerged as a crucial technology in smart contract development for several blockchain platforms. Unfortunately, since their introduction, WASM smart contracts have been subject to several security incidents caused by contract vulnerabilities, resulting in substantial economic losses. However, existing tools for detecting WASM contract vulnerabilities have accuracy limitations, one of the main reasons being the coarse-grained emulation of the on-chain data APIs. In this article, we introduce WACANA, an analyzer for WASM contracts that accurately detects vulnerabilities through fine-grained emulation of on-chain data APIs. WACANA precisely simulates both the structure of on-chain data tables and their corresponding API functions, and integrates concrete and symbolic execution within a coverage-guided loop to balance accuracy and efficiency. Evaluations on a vulnerability dataset of 2,012 contracts show WACANA outperforming state-of-the-art tools in accuracy. Further validation on 5,602 real-world contracts confirms WACANA’s practical effectiveness.
Yibin Yang, David Heath, Carmit Hazay, Vladimir Kolesnikov · 5 authors
We explore Zero-Knowledge Proofs (ZKPs) of statements expressed as programs written in high-level languages, e.g., C or assembly. At the core of executing such programs in ZK is the repeated evaluation of a CPU step, achieved by branching over the CPU's instruction set. This approach is general and covers traversal-execution of a program's control flow graph (CFG): here CPU instructions are straight-line program fragments (of various sizes) associated with the CFG nodes. This highlights the usefulness of ZK CPUs with a large number of instructions of varying sizes.
The frequent security incidents of contracts indicate a pressing need to ensure contract security from deployment to running stages, but the state-of-the-art (SOTA) analysis methods cannot work well for three requirements.(i) Identify contract defective code snippets, while generating exploit call sequences to help developers fix them.(ii) Monitor abnormal call behaviors, especially for multiple continuous transactions.(iii) Validate numerous unexploitable detection results automatically because manual verification is labor-intensive.To tackle these problems, we propose SymX, a symbolic executionbased security analysis art accounting for contract development and running stages.The experiment results demonstrate that it can accurately identify 90.22% of contracts and 98.04% of call transactions, as well as validate misreports as intended, which is superior to SOTAs, thereby protecting contracts better during the contract lifecycle.Currently, SymX is available at https://github.com/Secbrain/SymX.
The preservation of the vaccine cold chain is crucial in order to ensure the proper preservation of vaccines throughout transport in a controlled environment. Maintaining the vaccine at suitable temperature and humidity levels during transportation will significantly significantly impacts vaccine effectiveness and quality. However, exposure to high temperature or improper conditions will result in vaccine degradation and public health concerns. Moreover, centralized real-time monitoring systems often suffer from issues related to integrity, transparency, availability, and single points of failure. This paper aims to transition data infrastructure from centralized to decentralized to enhance confidentiality, integrity, and availability (CIA). The proposed system, InoculLedger, employs IOTA and smart contracts to monitor and control environmental parameters, taking into account the vaccine's manufacturing process until the patient receives it. The system ensures transparency at every stage the vaccine undergoes and disseminates this information to all stakeholders, including the patient. The system utilizes IOTA for data infrastructure and employs smart contracts for data management. Additionally, the proposed system uses the Internet of Things (IoT) to monitor environmental parameters in real time.
Maxim Kalinin, Alexey Busygin, A. S. Konoplev, Vasiliy Krundyshev
Abstract— This article discusses the ways of using distributed ledger technology to ensure the security of smart city information systems. The authors outline the limitations of the existing solutions in this area and the main directions of development of distributed ledger technology, determining its successful integration into the smart city ecosystem.
Mikhail Dymkov, Vladimir Gorgadze, Alexey Karanyuk, Artem Barger
This paper establishes a groundbreaking framework for pinpointing and scrutinizing web3 protocols that display attributes akin to Ponzi schemes. We meticulously define the defining features of these protocols and introduce sophisticated methodologies to assess their stability, fine-tuning their parameters, and crafting economic mechanisms to boost their sustainability. The robustness of our framework is vividly showcased through comprehensive case studies of two prominent web3 protocols: Safemoon and Ethena. In the Ethena case study, we take a step further by devising an advanced economic mechanism for automatic interest rate regulation, employing an innovative feedback loop system.