The integration of secure message authentication systems within the Industrial Internet of Things (IIoT) is paramount for safeguarding sensitive transactions. This paper introduces a Lightweight Blockchain-based Message Authentication System, utilizing k-means clustering and isolation forest machine learning techniques. With a focus on the Bitcoin Transaction Network (BTN) as a reference, this study aims to identify anomalies in IIoT transactions and achieve a high level of accuracy. The feature selection coupled with isolation forest achieved a remarkable accuracy of 92.90%. However, the trade-off between precision and recall highlights the ongoing challenge of minimizing false positives while capturing a broad spectrum of potential threats. The system successfully detected 429,713 anomalies, paving the way for deeper exploration into the characteristics of IIoT security threats. The study concludes with a discussion on the limitations and future directions, emphasizing the need for continuous refinement and adaptation to the dynamic landscape of IIoT transactions. The findings contribute to advancing the understanding of securing IIoT environments and provide a foundation for future research in enhancing anomaly detection mechanisms.
The rapid evolution of ransomware attacks necessitates robust and scalable detection mechanisms to safeguard digital assets. This study leverages the Bitcoin Ransomware Dataset, comprising 2,916,697 transactions, to evaluate the effectiveness of the Random Forest algorithm in classifying ransomware-related activities. Through comprehensive preprocessing, including feature encoding and standardization, and exploratory data analysis (EDA), the dataset is prepared for modeling. The Random Forest model achieves an overall accuracy of 99%, demonstrating exceptional performance in identifying the majority class. However, challenges persist in classifying minority classes, highlighting the impact of class imbalance. Feature importance analysis reveals that attributes such as income, weight, and length play pivotal roles in the classification process. The study underscores the potential of Random Forest for ransomware detection while emphasizing the need for advanced techniques to address class imbalance and improve minority class performance.
The openness and transparency of Ethereum transaction data make it easy to be exploited by any entities, executing malicious attacks. The sandwich attack manipulates the Automated Market Maker (AMM) mechanism, profiting from manipulating the market price through front or after-running transactions. To identify and prevent sandwich attacks, we propose a cascade classification framework GasTrace. GasTrace analyzes various transaction features to detect malicious accounts, notably through the analysis and modeling of Gas features. In the initial classification, we utilize the Support Vector Machine (SVM) with the Radial Basis Function (RBF) kernel to generate the predicted probabilities of accounts, further constructing a detailed transaction network. Subsequently, the behavior features are captured by the Graph Attention Network (GAT) technique in the second classification. Through cascade classification, GasTrace can analyze and classify the sandwich attacks. Our experimental results demonstrate that GasTrace achieves a remarkable detection and generation capability, performing an accuracy of 96.73% and an F1 score of 95.71% for identifying sandwich attack accounts.
The advent of connected autonomous vehicles (CAVs) is bringing forth a revolutionary new era of technology transforming transportation. For traffic to be optimized and safe, efficient vehicle-to-everything collaboration and improved autonomous vehicles (AV) decision-making are crucial. It becomes essential to make decisions in real time using information from vehicle sensors, software, and traffic data. As a part of such an In-Vehicle Network (IVN), over-the-air (OTA) software update service in CAVs needs to be facilitated rapidly, reliably, and securely. However, by taking advantage of vulnerabilities, attackers may quickly target the OTA software update as part of botnets to execute distributed denial-of-service (DDoS) attacks. The enormous volume and widespread nature of these DDoS cyber-attacks make it vital for the CAV industry to work quickly on identifying and preventing these threats. This paper proposes proof-of-concept experiments with the Hyperledger Fabric (HLF) Blockchain model to detect and prevent DDoS attacks in CAVs, OTA update systems. The proposed method implements Practical Byzantine Fault Tolerance (PBFT) as the consensus mechanism and a distributed firewall to ensure the ledger is secure and tamper’ proof. The system is tested on the Amazon Elastic Compute Cloud (EC2) Blockchain (BC) platform. The results show that the proposed approach effectively prevents DDoS attacks while ensuring fast transaction execution time.
The rise of cryptocurrencies has created new avenues for criminal money exchanges. Among various techniques, Bitcoin address clustering plays a crucial role in detecting and grouping addresses owned by the same entity. This fundamental step is essential for deanonymizing addresses and analyzing the flow of funds in the blockchain. This advancement contributes to the battle against illicit commerce, money laundering, fraud, scams, and similar activities. In this paper, we introduce two new heuristics, NSS and PEKET. NSS leverages Bitcoin non-standard scripts, while PEKET exploits the re-use of public keys to establish connections controlled by the same entity. Our contributions encompass (i) the detailed explanation of these two novel methods; (ii) the open-source publication of the tools we developed; and, (iii) the assessment of these heuristics using a proprietary extensive dataset of labeled addresses, which achieve precision levels of 1.0 and 0.979 respectively.
Cryptocurrency is frequently used in a variety of virtual transactions to secure transactions. The few years have seen an increase in online scams, and with the advent of cryptocurrencies and their masquerading, it has never been easier for scammers. A cryptocurrency is a type of digital currency that can be exchanged for virtual goods and services over the Internet. Despite cryptocurrencies containing complex codes being kept secret which are meant to protect or preserve their security, capable hackers can nevertheless breach them. Ransomware attacks have emerged as a significant method of malware intrusion in recent years, usually, ransomware attacks take place through a website like linking the link the file gets corrupted. But here is the major scam during Bitcoin transactions. Therefore, we require improved ransomware prediction methods utilizing a suitable machine learning algorithm and a publicly accessible dataset. Using a variety of features to predict malicious transactions, abnormal Bitcoin transactions are used to evaluate these strategies.
Our research paper addresses the pressing security challenges emerging within the rapidly expanding Internet of Things (IoT) landscape, with a specific focus on the IOTA Tangle—a distributed ledger based on Directed Acyclic Graph (DAG) technology. The proliferation of IoT devices has heightened the demand for secure and efficient transaction processing on distributed ledgers, but this surge also amplifies the risk of spam transactions that can compromise the integrity and efficiency of the ledger. In response to this imperative, we introduce EdgeGuard—a sophisticated rule-based spam detection system implemented on edge devices. This real-time system dynamically analyzes transaction data, applying predefined rules to differentiate between legitimate transactions and spam. Immediate action is taken to prevent spam transactions from infiltrating the IOTA Tangle, and the use of edge devices enhances the efficiency of spam detection by alleviating the load on servers. Notably, the system includes integration with real-time alerts using a messaging channel to notify system owners when spam transactions are identified. The effectiveness of EdgeGuard is rigorously validated through real-world data scenarios, demonstrating its capacity to thwart potentially harmful transactions. This research paper significantly contributes to the broader discourse on decentralized security measures, emphasizing the paramount importance of fortifying distributed ledgers. This is particularly crucial in critical IoT applications where unauthorized transactions could yield severe consequences. EdgeGuard stands as a robust solution, embodying innovation in tackling the evolving challenges posed by the intersection of IoT and distributed ledger technologies.
The role played by email communication in our lives nowadays has been such a tremendous one especially when it comes to fast exchange of information. Nevertheless, this convenience is marred by the omnipresent threat of email spam that not only disrupts channels of communication but also present serious security and privacy concerns. Traditional models of spam detection which are based on rules or heuristics tend to fail because they do not adapt quickly enough to the new techniques employed by spammers. In response to these challenges, this paper proposes an inventive solution to the problem—integration of blockchain technology into the process of detecting email spams.Email spam is often defined as an unwanted and usually malicious form of correspondence, thus it has continued being a notable cyber security worry. The conventional mechanisms for discovering them are prone to false positives and negatives at times. Additionally, such systems have centralized data which can be interfered with and accessed without permission. Weighing up the limitations inherent in existing methods, this research examines how blockchain may change email spam detection. Keywords— Blockchain technology, ethereum, Spam, email
Abstract: In the ever-evolving landscape of distributed systems, ensuring safety, efficiency, and scalability remains a paramount challenge. BlockEdge emerges as a pioneering framework designed to address these critical issues by leveraging the principles of blockchain technology and advanced consensus mechanisms. This abstract outlines the key features, innovations, and potential impacts of BlockEdge on the realm of distributed computing. BlockEdge integrates blockchain's immutable ledger properties with a novel consensus algorithm tailored for distributed systems. Unlike traditional blockchain applications that prioritize decentralization for financial transactions, BlockEdge focuses on enhancing the performance and reliability of distributed applications. The framework employs a hybrid consensus model that combines Byzantine Fault Tolerance (BFT) with Proof-of-Stake (PoS), optimizing both security and energy efficiency. A standout feature of BlockEdge is its modular architecture, which allows seamless interoperability between different types of distributed networks. This modularity facilitates the integration of various consensus protocols, catering to the specific needs of diverse applications, from IoT networks to large-scale data processing systems. By enabling secure and efficient cross-chain communication, BlockEdge effectively mitigates the silo effect prevalent in current distributed system designs.
Mining pools have been the driving force for ensuring the security of multiple proof-of-work (PoW) cryptocurrencies. Under the de facto protocol Stratum, pools allow miners to collaborate, discover new blocks, and earn rewards collectively. Recently, the blockchain community has been promoting the adoption of a more secure Stratum protocol known as Stratum V2. In this paper, we introduce Erosion, a novel network-level attack that applies to both Stratum and Stratum V2 protocols. The essence of the Erosion attack lies in its ability to disrupt connections between miners and a targeted mining pool, significantly impairing the miners’ contributed PoWs and reducing the victim’s mining power. We also discover a vulnerability in the Stratum V2 protocol that allows the adversary to persistently disrupt a connection by tampering with a single packet, thus enhancing the attack’s stealthiness. Our survey shows that the Erosion adversary can readily execute attacks against a significant majority (e.g., 91%) of mining pools across the top ten cryptocurrencies. We also observe an extreme mining centralization that enables Erosion adversaries to simultaneously target multiple pools and cryptocurrencies. Furthermore, our focused evaluation of pooled mining in Bitcoin reveals that thousands of different adversaries can gain control over the majority of Bitcoin mining power, with one potentially malicious Autonomous System capable of taking down 96% of the total mining power.
Abstract This paper introduces a novel integrated hybrid malware attack detection algorithm, focusing on enhancing cybersecurity within blockchain systems by addressing the prevalent challenges of Byzantine fault tolerance, Reentrancy, and DDOS attacks. The significance of this research lies in its contribution to safeguarding blockchain technology, a cornerstone for secure, decentralized digital transactions, against sophisticated malware threats. Current cybersecurity solutions frequently fall short of offering a complete defense mechanism, making it difficult to effectively combat a variety of dynamic malware attacks at the same time. Thus, the main objective of this research is to provide a hybrid framework that combines DDOS attack prevention, reentrancy attack detection, and Byzantine fault tolerance detection into a single, cohesive architecture. The proposed hybrid framework encompasses a detailed algorithmic approach integrating SHA-256 and DSA to analyze the aforementioned three malware attacks. A hybrid model combining these algorithms, implemented in one block, has been developed to mitigate malicious activity. These measures aim to improve computational complexity and expedite execution within the network of nodes. To test the efficacy of the proposed framework, the approach is tested on the NSL-KDD dataset to analyze the malicious activities. The performance analysis of the proposed frameworks presents a recall and F1 score of 73 and .68 respectively. Furthermore, for efficient mitigation, the time and space complexity analysis is performed on proposed algorithms for attack analysis, which resulted in a combination of constant and linear time complexity operations. The findings reveal that the proposed algorithm successfully identifies and mitigates the targeted malware attacks and maintains optimal performance in terms of time and space complexity. Specifically, the algorithm showcases linear and constant time complexities across different attack vectors, ensuring swift and scalable defense capabilities. This research’s contribution to the cybersecurity field is significant, offering a robust, scalable solution that enhances the resilience of blockchain networks against a broad spectrum of malware attacks.
The widespread adoption and success of blockchain, particularly Bitcoin, was influenced by the promise of decentralization and anonymity. Sadly, these same characteristics have made it attractive to illegal activities, requiring careful oversight and targeted interventions. In order to mitigate illicit usage of this technology, we need to analyze and de-anonymize transactions occurring in the blockchain. For that purpose, change addresses identification is a promising technique, since change addresses can be associated to the inputs of the same transaction since they are meant to hold leftover funds for the same user. In this article, we propose a new approach of change address detection using hierarchical clustering. First, we developed a new method for data extraction of connected transactions. After collecting the transaction, we combined multiple input heuristics with a hierarchical clustering algorithm at the transaction level to study similarities in usage patterns between inputs and outputs. After applying our detection model, we analyze the generating cluster and evaluate the performance of our solution in terms of F1-score, result accuracy, recall and precision.
Ethereum has become one of the primary global platforms for cryptocurrency, playing an important role in promoting the diversification of the financial ecosystem. However, the relative lag in regulation has led to a proliferation of malicious activities in Ethereum, posing a serious threat to fund security. Existing regulatory methods usually detect malicious accounts through feature engineering or large-scale transaction graph mining. However, due to the immense scale of transaction data and malicious attacks, these methods suffer from inefficiency and low robustness during data processing and anomaly detection. In this regard, we propose an Ethereum Transaction Graph Compression method named TGC4Eth, which assists malicious account detection by lightweighting both features and topology of the transaction graph. At the feature level, we select transaction features based on their low importance to improve the robustness of the subsequent detection models against feature evasion attacks; at the topology level, we employ focusing and coarsening processes to compress the structure of the transaction graph, thereby improving both data processing and inference efficiency of detection models. Extensive experiments demonstrate that TGC4Eth significantly improves the computational efficiency of existing detection models while preserving the connectivity of the transaction graph. Furthermore, TGC4Eth enables existing detection models to maintain stable performance and exhibit high robustness against feature evasion attacks.
(Distributed) Denial-of-Service (DoS/DDoS) attacks are among the most dangerous cybersecurity threats to computer networks. Lately, blockchain and artificial intelligence (AI) cyberdefense applications have successfully been implemented to identify attack patterns. This paper proposes a novel collaborative, blockchain-based multi-agent reinforcement learning (RL) cyberdefense method using smart contracts. Initial numerical experiments have shown that the agents quickly learn to predict attacks, which can lead to mitigating network-wide service disruptions.
Aulia Arif Wardana, Grzegorz Kołaczek, Parman Sukarno
This research introduces a comprehensive collaborative intrusion detection system (CIDS) framework aimed at bolstering the security of Internet of Things (IoT) environments by synergistically integrating lightweight architecture, trust management, and privacy-preserving mechanisms. The proposed hierarchical architecture spans edge, fog, and cloud layers, ensuring efficient and scalable collaborative intrusion detection. Trustworthiness is established through the incorporation of distributed ledger technology (DLT), leveraging blockchain frameworks to enhance the reliability and transparency of communication among IoT devices. Furthermore, the research adopts federated learning (FL) techniques to address privacy concerns, allowing devices to collaboratively learn from decentralized data sources while preserving individual data privacy. Validation of the proposed approach is conducted using the CICIoT2023 dataset, demonstrating its effectiveness in enhancing the security posture of IoT ecosystems. This research contributes to the advancement of secure and resilient IoT infrastructures, addressing the imperative need for lightweight, trust-managing, and privacy-preserving solutions in the face of evolving cybersecurity challenges. According to our experiments, the proposed model achieved an average accuracy of 97.65%, precision of 97.65%, recall of 100%, and F1-score of 98.81% when detecting various attacks on IoT systems with heterogeneous devices and networks. The system is a lightweight system when compared with traditional intrusion detection that uses centralized learning in terms of network latency and memory consumption. The proposed system shows trust and can keep private data in an IoT environment.
Kithmini Godewatte Arachchige, Philip Branch, Jason But
The Internet of Things (IoT) and blockchain are emerging technologies that have attracted attention in many industries, including healthcare, automotive, and supply chain. IoT networks and devices are typically low-powered and susceptible to cyber intrusions. However, blockchains hold considerable potential for securing low-power IoT networks. Blockchain networks provide security features such as encryption, decentralisation, time stamps, and ledger functions. The integration of blockchain and IoT technologies may address many of the security concerns. However, integrating blockchain with IoT raises several issues, including the security vulnerabilities and anomalies of blockchain-based IoT networks. In this paper, we report on our experiments using our blockchain test bed to demonstrate that blockchains on IoT platforms are vulnerable to DDoS attacks, which can also potentially lead to device hardware failures. We show that a number of anomalies are visible during either a DDoS attack or IoT device failure. In particular, the temperature of IoT hardware devices can exceed 90 °C during a DDoS attack, which could lead to hardware failure and potential fire hazards. We also found that the Block Transaction Rate (BTR) and network block loss percentage can increase due to corrupted hardware, with the BTR dropping to nearly zero blocks/sec and a block loss percentage of over 50 percent for all evaluated blockchains, and as high as 81.3 percent in one case. Our experiments demonstrate that anomalous temperature, latency, bandwidth, BTR, and network block loss percentage can potentially be used to identify DDoS attacks.
The Internet of Things (IoT) refers to a complex network comprising interconnected devices that transmit their data via the Internet. Due to their open environment, limited computation power, and absence of built-in security, IoT environments are susceptible to various cyberattacks. Denial of service (DDoS) attacks are among the most destructive types of threats. The Multi-vector DDoS attack is a contemporary and formidable form of DDoS wherein the attacker employs a collection of compromised IoT devices as zombies to initiate numerous DDoS attacks against a target server. A Blockchain-based Operational Threat Intelligence framework, OTI-IoT, is proposed in this article to counter multi-vector DDoS attacks in IoT networks. A “Prevent-then-Detect” methodology was utilized to deploy the OTI-IoT framework in two distinct stages. During Phase 1, the consortium Blockchain network validators employ the IPS module, composed of a smart contract for attack prevention and access control, and Proof of Voting consensus, to thwart attacks. Validators are outfitted with deep learning-based IDS instances to detect multi-vector DDoS attacks during Phase 2. Alert messages are generated by the IDS module’s alert generation and propagation smart contract in response to identifying malicious IoT sources. The feedback loop from the IDS module to the IPS module prevents incoming traffic from malicious sources. The proposed OTI framework capabilities are realized as an outcome of combining and storing the outcomes of the IDS and IPS modules on the consortium Blockchain. Each validator maintains a shared ledger containing information regarding threat sources to ensure robust security, transparency, and integrity. The operational execution of OTI-IoT occurs on an individual Ethereum Blockchain. The empirical findings indicate that our proposed framework is most suitable for real-time applications due to its ability to lower attack detection time, decreased block validation time, and higher attack prevention rate.
U Kumaran, Thammisetty Swetha, Ishi Sharma, R Keerthana · 6 authors
In the fast changing world of cloud based internet of things (IoT) eco-systems, secure connectivity between devices and cloud services is vital. On the other hand, the rising Man-in-the- Middle (MitM) attacks present serious threats to data integrity and confidentiality. In this regard, through a combination of Software Defined Networking (SDN) and Blockchain technology, this study proposes an innovative technique for improving security architecture in cloud IoT settings against MitM attacks. The solution put forward relies on blockchain to provide immutable transactions that are used as tamper-proof ledgers for device authentication and secure data sharing. Smart contracts create unchangeable transactions that also maintain the anonymity of devices and their communication processes. Additionally, SDN technology segments traffic, implements dynamic network policies, and therefore reduces MitM attack vectors through traffic inspection and access control. The testing process has shown that the approach effectively prevents MitM attacks while ensuring safe communication channels in cloud-based IoT systems. This implementation demonstrates improved data integrity, confidentiality, and security against unwanted intrusion attempts. This research paper contributes to the development of the cloud-based IoT security paradigm and highlights the synergistic potential of Blockchain and SDN in dealing with common security issues and improving the trustworthiness of networked devices for the Internet of Things.
The seamless integration of cryptocurrencies and blockchain technology in various sectors has revolutionized financial transactions. While cryptocurrencies serve as a convenient mode of payment, they have also opened avenues promoting fraudulent schemes such as Ponzi schemes, HYIPs, or money laundering activities leading to substantial financial losses. Traditional ways of anomaly detection, such as heuristic and signature-based approaches, have proven inadequate in addressing the intricacies of burgeoning fraud patterns. This paper explores the application of ensemble learning for anomaly detection in Bitcoin transactions by combining various ML techniques such as Isolation Forest, One-class SVM, and DBSCAN within a stacking framework. The proposed model harnesses the complementary strengths of each algorithm to achieve a nearly $98 \%$ accuracy rate in anomaly detection, thereby addressing the shortcomings of existing techniques. The study utilizes hyperparameter tuning techniques to enhance the effectiveness of the ensemble model and create a resilient model for detecting fraud and security threats in cryptocurrency transactions. Leveraging the cryptographic foundations of blockchain technology, the proposed method aims to create a more secure and reliable system for detecting threats and maintaining the integrity of Bitcoin transactions.
Cooperation among telecom carriers and datacenter (DC) providers (DCPs) is essential to ensure resiliency of network-cloud ecosystems. To enable efficient cooperative recovery in case of resource crunch, e.g., due to traffic congestion or network failures, we previously studied several frameworks for cooperative recovery among different stakeholders (e.g., telecom carriers and DCPs). Now, we introduce a novel Multi-entity Cooperation Platform (MCP) for implementing cooperative recovery planning, to achieve efficient use of carriers' valuable optical-network resources during recovery. We adopt a Distributed Ledger Technology (DLT) that ensures decentralized and tamper-proof information exchange among stakeholders to achieve open and fair cooperation. To support diverse types of cooperation, we develop a state machine representing the MCP operation and define state transitions associated to stakeholders' cooperation within the state machine. Moreover, we propose a signaling system in MCP to ensure simple and reliable state transitions for stakeholders during the cooperative recovery planning in large ecosystems. We experimentally demonstrate a proof-of-concept DLT-based MCP on a testbed. We showcase a DCP-carrier cooperative planning process, showing the flexibility of the proposed MCP to support diverse types of cooperation.
In the world of decentralized finance and smart contracts, the Ethereum blockchain stands as a pillar of innovation. However, with innovation comes the responsibility to fortify the systems against potential vulnerabilities. Reentrancy attacks pose a significant threat, exploiting vulnerabilities in the fabrication of smart contracts. These attacks can have severe consequences, compromising the integrity of transactions and jeopardizing the trust placed in blockchain technology. Many reentrancy solutions like yenta and ReVulDL have been implemented and various detection approaches have been proposed by various researchers. This paper proposed a “Hybrid Locking” mechanism to prevent Ethereum reentrancy which involves the combination of dynamic mutex locks and hierarchical locking which is lacking yet in research. This represents an innovative security enhancement for smart contracts by leveraging the proven concepts from concurrency control; establishing a multi-layered defense against reentrancy attacks, and addressing vulnerabilities that led to financial losses. This compelling solution press security issue in decentralized finance and proposed Hybrid Locking Mechanism shows promise, further empirical validation, and considerations for practical implementation which strengthen its contribution to the field of blockchain using context-aware defense mechanism against reentrancy attacks. The Hybrid Locking Mechanism demonstrated a 24.14% increase in effectiveness in preventing re-entrance compared to the average effectiveness of other approaches.
In recent years, smart contracts have risen rapidly in the blockchain field, but security issues have also become increasingly prominent. Due to the lack of unified evaluation standards, the security analysis of smart contracts mainly relies on complex and not easily scalable expert rules. To address these issues, we employ slicing techniques to reduce the interference of extraneous code on the detection process, apply normalisation techniques to eliminate the differences between different compiler versions and use particle swarm optimisation algorithms to determine the similarity between contracts, thus improving the accuracy and efficiency of detection. In addition, we combine a variety of features such as static analysis, dynamic analysis and symbolic execution to gain a more comprehensive understanding of contract characteristics and behaviours for more accurate vulnerability identification. Experimental results show that the scheme significantly improves the detection capability and provides a new solution for the security detection of smart contracts.
This paper comprehensively examines cyberattacks targeting blockchain networks and systems, inspects attacks at different blockchain layers, and adapts MITRE ATT&CK concepts to the blockchain and cryptocurrency context. It identifies the most common attack methods used by cybercriminals. This research underscores that attacks can occur at various layers of the blockchain, including the Data, Consensus, Execution, and Application layers, which implies the importance of understanding the different layers of the blockchain and the potential security risks associated with each layer. The findings stress that no single layer is immune to cyberattacks, and each requires a distinctive approach to secure blockchain platforms. By defining prominent cyberattacks on the blockchain, this paper analyzes cyberattacks and their related recommendations for enhancing the security of the blockchain platform from a layered perspective and MITRE ATT&CK approach. These recommendations include robust consensus protocol selection, secure coding, regularly executing updates, using protection tools, and social engineering sensibilization. Furthermore, this paper highlights the pivotal role of developers and industry professionals in prioritizing the platform’s security throughout the entire development lifecycle to prevent potential security risks. Finally, this work’s recommendations aim to empower developers and industry professionals to secure their Blockchain systems against cyberattacks, thereby enhancing the security and reliability of blockchain technology.