Web3 applications, which are built on blockchain and decentralized technologies, introduce a unique set of security threats compared to traditional web applications. In this chapter we are going to look at some common security threats for Web3 applications and best practices to mitigate these risks.
The increasing connectivity and complexity of automotive systems require enhanced mechanisms for firmware updates to ensure security and integrity. Traditional methods are insufficient for modern vehicles that require seamless over-the-air (OTA) updates. Current OTA mechanisms often lack robust security measures, leaving vehicles vulnerable to attacks. This paper proposes an innovative approach based on the use of decentralized identifiers (DIDs) and distributed ledger technology (DLT) for secure OTA firmware updates of on-vehicle software. By utilizing DIDs for unique vehicle identification, as well as verifiable credentials (VCs) and verifiable presentations (VPs) for secure information exchange and verification, the solution ensures the integrity and authenticity of software updates. It also allows for the revocation of specific updates, if necessary, thereby improving overall security. The security analysis applied the STRIDE methodology, which enabled the identification of potential threats, including spoofing, tampering, and privilege escalation. The results showed that our solution effectively mitigates these threats, while a performance evaluation indicated low latency during operations.
This research uses deep learning and blockchain frameworks to provide a safe platform that promotes digital governance data exchange and interoperability. Use the bonobo optimization algorithm to start a blockchain-based smart city data authentication approach. This paper presents a Blockchain-based malware detection method and framework that uses AI to account for multiple distributed conditions. An upgraded greedy search algorithm and the XGBoost decision tree construct a two-layer extreme gradient boosting (XGBoost) classification model that detects attacks. Three pre-existing XGBoost significance indices were split and merged based on the model's leaf nodes' tree traversal structural features. The augmented greedy search technique retrieved and imported spectral band variables into the XGBoost model's second layer. Bat method was used to optimize XGBoost modeling parameters. The deployed model increased power consumption per device by 13.5%, while Raspberry Pi devices used 0.2 GB and NVIDIA Jetson devices used 0.42 GB. ML models had 93% f1-scores and 95% detection accuracy on both datasets. Our technology detects malware and attacks in Smart Environments efficiently and accurately, as shown by the models.
Proof of Stake (PoS) is a consensus methodology for blockchain platforms, proposed as an alternative to Proof of Work (PoW) mechanisms. Its primary objective is to validate transactions and ascertain the truthfulness of on-chain data. Users who stake their funds receive incentives in the form of newly minted cryptoassets or transaction fees, making staking a prevalent investment activity in the cryptocurrency domain. However, for users adhering to the Islamic faith, staking introduces a distinctive challenge, particularly concerning its alignment with halal principles. This area represents a significant research gap, with shariah scholars actively engaging in the assessment of this phenomenon from a fiqh perspective. A thorough understanding of the relevant fiqh principles and rulings, in conjunction with the technical and operational facets of staking, is imperative. This chapter delineates two forms of staking: (1) staking on a Proof of Stake (PoS) blockchain, and (2) staking as the act of locking funds in a smart contract for a designated purpose. Subsequently, it explores the shariah compliance of both types.
Ahmad AA Alkhatib, Layla Albdor, Seraj Fayyad, Hussain Ali
The rapid expansion of Internet of Things (IoT) devices underscores the critical importance of robust security protocols, particularly in the realm of children's toys. This study introduces an innovative multi-factor authentication strategy integrating Quick Response (QR) codes with Blockchain technology to fortify the security of IoT toys designed for children. The primary objective is to safeguard young users against potential threats stemming from unauthorized access, thereby ensuring a secure interaction with IoT-enabled toys. By amalgamating authentication factors, including QR codes, the proposed approach establishes a multilayered security framework. Leveraging the inherent immutability and transparency of Blockchain, the system verifies the authenticity of IoT toys by scanning a unique QR code, thus mitigating risks associated with malwares and unauthorized access. The decentralization of Blockchain ensures no single point of failure, enhancing resilience against cyber threats. Extensive usability studies underscore the efficacy and practicality of the advanced multi-factor authentication solution, poised to elevate the safety standards of IoT toys in the digital age. This innovative approach not only bolsters security but also fosters trust among users, enabling seamless and worry-free interaction with IoT-enabled toys for children worldwide.
Hardware security is the root of trust in all modern ICT (Information and Communications Technology) systems. However, hardware security means something different for different communities. It has also a very wide scope. It covers efficient, secure implementations of new generations of cryptography such as light-weight crypto, post-quantum crypto as well as advanced schemes such as zero-knowledge proofs, fully homomorphic encryption, and computing on encrypted data in general [1][2]. Yet, implementations also must resist a wide variety of side-channel, fault, and micro-architectural attacks. Post-quantum algorithms might resist the attacks developed for quantum computers. Yet, they also have to be resistant to these attacks on classic platforms, see e.g. [3]. Security protocols rely on more than only cryptographic algorithms. They require analog and digital circuit techniques to design quality true random number generators, physically unclonable functions, secure key storage, and many more [4]. A recent report on "Revitalizing the U.S. Semiconductor Ecosystem" (from Executive Office of the President, President's Council of Advisors on Science and Technology, September 2022) [5] describes a set of recommendations on semiconductors and system security. In this presentation, we will demonstrate how our research addresses these recommendations and we will illustrate this with recent results and ongoing projects.
Open access
2 source records
Physical Unclonable Functions (PUFs) and Hardware Security
Koustav Kumar Mondal, Ashi Gupta, Debasis Das, Chun‐I Fan
This research introduces PISTON, a novel protocol designed to enhance the security, efficiency, and performance of Internet of Vehicles (IoV) networks. PISTON integrates advanced authentication mechanisms utilizing Physically Unclonable Functions (PUFs) and multifactor authentication with dynamic challenges and zero-knowledge proof-based authentication to ensure robust security and mitigate various cyber threats, including Denial-of-Service (DoS) attacks. The protocol further incorporates sleep-wake scheduling, priority-based scheduling, and adaptive modulation and coding to optimize network performance. The communication overhead in PISTON is derived through a formula that incorporates latency, energy consumption, and throughput, demonstrating the protocol’s efficiency in dynamic vehicular environments. Comparative analysis against existing protocols highlights PISTON’s superiority in seamless handover, provable security, and DoS attack resilience. Experimental results show that PISTON reduces energy consumption by 30% and achieves 20% higher data throughput while maintaining low latency, essential for real-time IoV applications. The empirical findings underscore PISTON’s advancements in establishing a new benchmark for future IoV deployments, ensuring secure, energy-efficient, low-latency, and high-throughput communication.
Mimouna Abdullah Alkhonaini, Manal Abdullah Alohali, Mohammed Aljebreen, Majdy M. Eltahir · 8 authors
Intrusion detection in the Internet of Things (IoTs) is a vital unit of IoT safety. IoT devices face diverse kinds of attacks, and intrusion detection systems (IDSs) play a significant role in detecting and responding to these threats. A typical IDS solution can be utilized from the IoT networks for monitoring traffic, device behaviour, and system logs for signs of intrusion or abnormal movement. Deep learning (DL) approaches are exposed to promise in enhancing the accuracy and effectiveness of IDS for IoT devices. Blockchain (BC) aided intrusion detection from IoT platforms provides many benefits, including better data integrity, transparency, and resistance to tampering. This paper projects a novel sandpiper optimizer with hybrid deep learning-based intrusion detection (SPOHDL-ID) from the BC-assisted IoT platform. The key contribution of the SPOHDL-ID model is to accomplish security via the intrusion detection and classification process from the IoT platform. In this case, the BC technology can be used for a secure data-sharing process. In the presented SPOHDL-ID technique, the selection of features from the network traffic data takes place using the SPO model. Besides, the SPOHDL-ID technique employs the HDL model for intrusion detection, which involves the design of a convolutional neural network with a stacked autoencoder (CNN-SAE) model. The beetle search optimizer algorithm (BSOA) method is used for the hyperparameter tuning procedure to increase the recognition outcomes of the CNN-SAE technique. An extensive simulation outcome is created to exhibit a better solution to the SPOHDL-ID method. The experimental validation of the SPOHDL-ID method portrayed a superior accuracy value of 99.59 % and 99.54 % over recent techniques under the ToN-IoT and CICIDS-2017 datasets.
This paper studies the detection model of network access data tampering attack based on blockchain technology to solve the problem of over-dependence on central server and easy data tampering in traditional network environment. The model uses decentralization and encryption technology to monitor user behavior in real time through smart contracts, enhances data protection with SHA-256 hash algorithm, and combines consensus algorithm to ensure data consistency and security. The experimental results show that the model performs well in detecting multiple attack types with an accuracy of 99.51% and an F1 score of 0.98, far exceeding traditional methods and other deep learning techniques. The model shows good robustness under multi-node attacks, even with 200 attack nodes, the recognition accuracy is still close to 90%, and the response time is less than 3 seconds. Cross-platform testing showed that the model quickly and consistently detected tampering on both Ethereum and Hyperledger, with an average detection time between 0.33 and 0.47 seconds.The hardware acceleration test further shows that the processing speed and hardware utilization of TPU and GPU have been improved, with TPU processing speed reaching 135 MB/s and GPU 122 MB/s. This study will provide a theoretical basis for improving the security, effectiveness and reliability of current network systems, and also lay a solid theoretical and technical foundation for network applications in future network environments.
Zheng Che, Meng Shen, Zhehui Tan, Hanbiao Du · 9 authors
With the rapid evolution of Web3.0, cryptocurrency has become a cornerstone of decentralized finance. While these digital assets enable efficient and borderless financial transactions, their pseudonymous nature has also attracted malicious activities such as money laundering, fraud, and other financial crimes. Effective detection of malicious transactions is crucial to maintaining the security and integrity of the Web 3.0 ecosystem. Existing malicious transaction detection methods rely on large amounts of labeled data and suffer from low generalization. Label-efficient and generalizable malicious transaction detection remains a challenging task. In this paper, we propose ShadowEyes, a novel malicious transaction detection method. Specifically, we first propose a generalized graph structure named TxGraph as a representation of malicious transaction, which captures the interaction features of each malicious account and its neighbors. Then we carefully design a data augmentation method tailored to simulate the evolution of malicious transactions to generate positive pairs. To alleviate account label scarcity, we further design a graph contrastive mechanism, which enables ShadowEyes to learn discriminative features effectively from unlabeled data, thereby enhancing its detection capabilities in real-world scenarios. We conduct extensive experiments using public datasets to evaluate the performance of ShadowEyes. The results demonstrate that it outperforms state-of-the-art (SOTA) methods in four typical scenarios. Specifically, in the zero-shot learning scenario, it can achieve an F1 score of 76.98% for identifying gambling transactions, surpassing the SOTA method by12.05%. In the scenario of across-platform malicious transaction detection, ShadowEyes maintains an F1 score of around 90%, which is 10% higher than the SOTA method.
Bitcoin employs an anonymity mechanism to protect users' real identities from being exposed, making it widely used in illegal activities such as money laundering, dark web black market transactions, and more. As a result, tracing the source of illegal Bitcoin transactions has become a critical task. A comprehensive Bitcoin address label library is essential for achieving this traceability. However, existing label libraries suffer from low labeling rates and poor label quality. Additionally, current labeling methods are unable to enhance label quality while minimizing labeling costs. To address these issues, we propose an automatic labeling method for Bitcoin transaction addresses based on transaction behavior analysis. Firstly, we analyzed the relationships between Bitcoin miners, mining pools, and the operational modes of these pools. By examining on-chain transaction behavior data, we successfully labeled the addresses of miners and mining pools. Simultaneously, we gathered transaction behavior information from off-chain news media and applied entity recognition and relationship extraction algorithms for automatic address labeling. Experimental results demonstrate that this method can accurately and automatically label Bitcoin addresses, offering advantages such as high accuracy, low labeling cost, and excellent real-time performance.
Renyuan Xu, Jun Zhang, Xiaoyue Zhu, Zhaoxiong Song · 5 authors
In recent years, the frequent occurrence of phishing scams on Ethereum has posed serious threats to transaction security and the financial safety of users. This paper proposes an Ethereum phishing scam detection method based on Hyperbolic Neural Networks (HGNNs) and temporal information. The method maps the Ethereum transaction network to hyperbolic space for structural feature extraction, effectively capturing hierarchical structures and complex relationships within the graph, thereby improving the accuracy of phishing scam detection. The model includes a structural feature extraction module and a temporal feature extraction module. It uses HGNN and self-attention mechanism to extract the structural features of the transaction graph, and uses a multi-head attention mechanism to capture the dynamic evolution pattern of the graph. Experimental validation on real Ethereum datasets demonstrates that the proposed model outperforms benchmark models, showcasing its effectiveness.
The increasing pervasiveness of digital infrastructures, also extending into marine domains, makes Underwater Wireless Sensor Networks (UWSNs) an essential tool for the development of novel marine sustainability and monitoring paradigms. Applications in sensitive scenarios may require data encryption, non-repudiation, and provenance tracking. Moreover, the broadcast nature of the underwater acoustic channel makes the task of identifying and authenticating nodes of critical importance. To meet such requirements, we introduce AquaID, a protocol for resource-constrained hardware that leverages Distributed Ledger Technologies (DLTs) and Decentralised Identities. It guarantees confidentiality, authentication, and integrity using low bandwidth and CPU usage, while supporting high scalability and interoperability. We validate our solution in a threefold manner: via embedded board implementation, network simulation, and sea trials using commercially-available acoustic modems and underwater nodes. We also include a cost comparison among possible DLT choices. Results show AquaID to be robust to scaling, achieving low authentication delays and overhead, thus proving suitable even for large deployments.
In the Internet of Things (IoT), blockchain-based cross-domain authentication schemes can effectively establish trust and share data across different administrative domains. However, current blockchain-based cross-domain authentication solutions often overlook dynamic node participation challenges, which is crucial for the flexible IoT environment. In this study, we propose a blockchain-based cross-domain authentication scheme that supports dynamic node participation, allowing administrative domainss to freely join or leave under legal conditions. First, we introduce an efficient blockchain-based cross-domain authentication framework. Second, we propose a blockchain consensus algorithm that supports dynamic node participation to serve the aforementioned framework. Specifically, inspired by the transmission control protocol (TCP) protocol’s piggybacking strategy, this algorithm integrates the process of node joining and leaving into the regular consensus flow to enhance efficiency. To further improve the algorithm’s efficiency, we designed compressed block and parallel chain structures to increase bandwidth utilization and throughput. Detailed correctness proofs demonstrate the algorithm’s security. Extensive experiments have been conducted to show that our scheme increases throughput by approximately 8x compared to existing approaches.
In the rapidly expanding field of the Internet of Things, ensuring secure and efficient communication between IoT devices and servers is crucial. This paper henceforth designs a lightweight authentication system under the Zero Knowledge Proof (ZKP) protocol, utilizing the HMAC hashing algorithm for the improvement of security measures put in place. This system is designed to enable the authentication of IoT devices without sending their actual password, thus avoiding risks due to password interception at the point of authentication. For instance, if using the phrase "God is great" as the password, one can get it hashed into HMAC with this method and still be assured that it is secure even if proof is intercepted. Simulations in the simulator shall evaluate the system’s effectiveness and performance. Performance metrics include accuracy, response time, memory consumption, latency, and throughput. The presented results intend to serve lightweight device authentication mechanisms for IoT devices such that the trustworthiness of IoT devices is achieved without hampering their performance. The presented results are also shown to outperform conventional methods.
User Authentication and Security Systems
Advanced Malware Detection Techniques
Advanced Steganography and Watermarking Techniques
A non-fungible token (NFT) is a kind of digital asset that signifies ownership or proof of authenticity of a special good or piece of material, such as artwork, music, films, or tweets. This study investigates how a deep convolutional generative adversarial network (DCGAN) can be used to create distinctive pictures of Cryptopunks that can be converted into NFTs. Cryptopunks, a pioneering form of NFTs, were introduced on the Ethereum blockchain in 2017 as part of a social experiment. In the NFT community, they have since grown in popularity as collectibles. To create brand-new, previously undiscovered characters, we trained a model on a dataset of existing Cryptopunks using the DCGAN architecture. In an effort to raise the calibre of the images produced, we tested various hyper settings and layer combinations. We also assessed the created images using a variety of criteria, such as the inception score and Fréchet inception distance, to make sure they were distinctive and of high calibre. Our experiments yielded a 15 % increase in the inception score and a 20 % decrease in the Fréchet inception distance, showing that our DCGAN model produces images that are more visually appealing and closer in quality to real Cryptopunks. These results highlight the effectiveness of our machine learning algorithms in improving the quality and uniqueness of NFT assets.
Smart contracts are susceptible to various vulnerabilities that can be exploited by hackers via developing adversarial contracts. Existing vulnerability detection techniques often concentrate solely on vulnerable contracts, neglecting adversarial contracts, which may weaken the effectiveness of vulnerability detection and fail to meet practical needs.
With the growing significance of blockchain-based Bitcoin systems, ensuring robust security measures is imperative. This research introduces an innovative approach to enhance system-level threat detection through the integration of a novel ensemble learning model, bolstered by the Water Cycle Algorithm (WCA). The proposed model aims to address the evolving landscape of security challenges in the blockchain domain, specifically targeting the detection of threats that may compromise the integrity and efficiency of Bitcoin systems.The ensemble learning model combines diverse algorithms, leveraging their collective intelligence to improve accuracy and resilience against sophisticated threats. The integration of the Water Cycle Algorithm further enhances the adaptability of the model by mimicking the natural processes of water cycles for dynamic optimization. This adaptive feature enables the system to efficiently respond to emerging threats, ensuring real-time threat detection and mitigation.
Background. A smart contract is a computer program enclosing the terms of a legal agreement between two or more parties which is automatically verified and executed via a computer network called blockchain. Once a smart contract transaction is completed the blockchain is updated and the transaction cannot be changed anymore. This implies that any error codified in the smart contract program cannot be rectified. Therefore, it is of vital importance that developers of smart contracts properly exploit error handling to prevent issues during and after the contract execution. Existing programming languages for smart contracts, support developers in this task by providing a set of Error Handling (EH) features. However, it is unclear the extent to which developers effectively use EH in practice. Aims. Our work aims to fill this gap by empirically investigating the state of practice on the adoption of EH features of one of the most popular programming languages for smart contracts, namely Solidity. Method. We empirically analyse the usage of EH features in 283K unique open-source Solidity smart contracts for the Ethereum blockchain. Results. Our analysis of the documentation of the different versions of Solidity coupled with the empirical evaluation of the EH uses and misuses found in real-word smart contracts, indicate that, among other things, Solidity EH features have been changing frequently across versions, and that the adoption of most of the Solidity EH features has been limited in practice. However, we observe an upward trend in the usage of the require EH feature, which is specifically designed for smart contract development. Conclusions. The insights from our study could help developers improve their EH practice as well as designers of smart contract programming languages to equip their language with appropriate EH features.