Xiaoyan Hu, Zhuozhuo Shu, Zhongqi Tong, Guang Cheng · 6 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,269 results · page 22 of 53
Xiaoyan Hu, Zhuozhuo Shu, Zhongqi Tong, Guang Cheng · 6 authors
No abstract is available for this record.
Xianqi Yang, Qing Gao, Michael Basin, Hao Li · 5 authors
No abstract is available for this record.
Evgeny A. Basinya, MEPhl", , Moscow, 115409, Russian Federation, N. Karapetyants · 5 authors
The lack of a user identification system and the existence of a variety of ways to obfuscate a transaction on the Bitcoin network is of great interest to attackers and can be used by them to conduct illegal activities. There is a need to develop new methods of cash identification in the Bitcoin network. The purpose of this work is to develop a method of transaction verification in the Bitcoin network to improve the efficiency of the process of identification of illegally obtained funds and their sources. The work solves the following tasks: the development of a method for transaction verification in the Bitcoin network and the development of a decision support system, which includes the proposed method. The article describes each of the stages of the method: collection, aggregation, processing and analysis of information. The information analysis stage proposes a clustering method that takes into account an extended set of empirical rules (heuristics) of transaction analysis, as well as information about Bitcoin network address owners. The scientific novelty lies in increasing the efficiency of the identification process of illegally obtained funds and their sources through a comprehensive analysis of transactions, including the extended collection of information and its subsequent aggregation in the multi-model database of the decision support system. In contrast to existing methods, the reliability of the identification of Bitcoin network subjects is increased through the use of intelligent methods of data analysis. The results of this work will provide an opportunity to develop new and improve existing transaction analysis tools in future research, which will allow more effective identification of funds in the Bitcoin network associated with illegal activities.
Na Cheng, Yin Liang, Shike Li, Jian‐Bin Li
The rapid development of blockchain technology and the rise of Ethereum as its representative platform has triggered a wide range of research and applications. However, this development is also accompanied by new security challenges, among which the Eclipse attack is one of the significant security threats currently facing Ethereum networks. In response to these challenges, we propose an Ethereum Eclipse attack detection method based on a multi-head attention mechanism with Bi-LSTM. This approach utilizes the Bi-LSTM model and multi-head attention mechanism to process time-series data, capturing and focusing on the features most relevant to the Eclipse attack for accurate identification. Additionally, we employ PCA and UMAP dimensionality reduction techniques in data preprocessing to enhance processing efficiency. Experimental results demonstrate that this method distinguishes regular traffic from attack traffic more accurately. Compared to the existing random forest method, our detection approach based on a multi-head attention mechanism with Bi-LSTM achieves a higher detection rate and lower false alarm rate, highlighting its effectiveness in addressing Ethereum network security.
Patrick Mwansa, Boniface Kabaso
The application of blockchain technology in electronic voting (e-voting) systems represents a promising solution to the perennial challenges of trust, transparency, and security in electoral processes. This study aims to identify a suitable blockchain protocol that supports trustworthy vote aggregation and has a suitable consensus algorithm to validate vote counting. Our research methodology includes an extensive literature review and a comparative analysis of different blockchain protocols. Considering this, we examine various consensus algorithms such as Proof of Work, Proof of Stake, and Practical Byzantine Fault Tolerance among others, each of which presents unique strengths and challenges. In addition, this study enriches the existing body of knowledge by proposing a novel algorithm that works at the edge of the network to validate and aggregate votes on the blockchain. This newly proposed algorithm is designed to provide maximum security, reliability, and accuracy while minimizing computational resources and network overhead. Our comprehensive research and innovative proposal serve to strengthen the potential of blockchain protocols and their consensus algorithms in the field of electronic voting systems. The results of this research could significantly influence the development and implementation of secure, transparent, and reliable e-voting systems based on blockchain technology, paving the way for more democratic and accountable voting mechanisms.
Et al. Laxmi Poonia
Computer networks and internet services are increasingly threatened by attacks like Distributed Denial-of-Service (DDoS). DDoS attack mitigation techniques now in use are ineffective due to a lack of resources and a lack of adaptability. Using blockchains like Ethereum, DDoS attacks can be thwarted in innovative ways. With smart contracts, it is possible to track down the IP addresses of attackers without additional hardware. This study examines blockchain-based solutions to combat DDoS attacks for feasibility, effectiveness, as well as cost and performance. The cost model delves into economic aspects like gas, gas price, and Ether value. In it, the evaluation of various smart contracts for the signalization of DDoS attacks is documented and compared to assess three system variants, analyzing gas costs, deployment, speed, and accuracy. It also details Ethereum's ecosystem and how that affects smart contract design and it also acknowledges scalability challenges and suggests outsourcing data for a more scalable solution, advocating for specialized blockchains for DDoS signaling applications. The analysis provides insights into the gas costs associated with different variants, considering various scenarios and highlighting the trade-offs and efficiencies of each approach.
Shreshta Kaushik, Nour El Madhoun
Blockchain is an innovative technology that gives built-in security to any software or application. There is a wide range of applications for blockchain, from risk management to financial services, crypto-currencies and the Internet of Things (IoT). This innovation is based on transparency, immutability, security, efficiency and decentralization. It is a trending topic since cryptocurrencies are a hot topic in the market. Blockchain is a combination of mathematics, cryptography, algorithms and models. In this paper, we present a general overview of the security aspects of blockchain technology.
Hansa Vaghela, Vivek Khirasaria
Now a day's, blockchain technology is an emerging technology. The Blockchain is a distributed network technology that uses a decentralized approach to information storage. When transactions are performed using blockchain technology, security concerns are a top priority. It required more storage and used more energy. Security is affected by endpoint vulnerability. Attackers exploit this weakness to damage the system and carry out attacks. A DDoS attack is the most harmful attack on the blockchain peer-to-peer network. It affects the unavailability of every internet-based network. Node crashes, software failure, network congestion, and a bloated ledger are the aspects of blockchain DDoS attacks that are most affected. In this paper we find out solutions to prevent this attack from occurring by increase system security, and defend against security attacks.
Tejal Rathod, Nilesh Kumar Jadav, Sudeep Tanwar, Zdzisław Pólkowski · 8 authors
The Internet of Things (IoT) is the most abundant technology in the fields of manufacturing, automation, transportation, robotics, and agriculture, utilizing the IoT's sensors-sensing capability. It plays a vital role in digital transformation and smart revolutions in critical infrastructure environments. However, handling heterogeneous data from different IoT devices is challenging from the perspective of security and privacy issues. The attacker targets the sensor communication between two IoT devices to jeopardize the regular operations of IoT-based critical infrastructure. In this paper, we propose an artificial intelligence (AI) and blockchain-driven secure data dissemination architecture to deal with critical infrastructure security and privacy issues. First, we reduced dimensionality using principal component analysis (PCA) and explainable AI (XAI) approaches. Furthermore, we applied different AI classifiers such as random forest (RF), decision tree (DT), support vector machine (SVM), perceptron, and Gaussian Naive Bayes (GaussianNB) that classify the data, i.e., malicious or non-malicious. Furthermore, we employ an interplanetary file system (IPFS)-driven blockchain network that offers security to the non-malicious data. In addition, to strengthen the security of AI classifiers, we analyze data poisoning attacks on the dataset that manipulate sensitive data and mislead the classifier, resulting in inaccurate results from the classifiers. To overcome this issue, we provide an anomaly detection approach that identifies malicious instances and removes the poisoned data from the dataset. The proposed architecture is evaluated using performance evaluation metrics such as accuracy, precision, recall, F1 score, and receiver operating characteristic curve (ROC curve). The findings show that the RF classifier transcends other AI classifiers in terms of accuracy, i.e., 98.46%.
Et al. Issac K Varghese
The ability of blockchain technology to improve security and transparency across a range of industries has receivedA great deal of attention has been garnered lately in correcting the sentence.. In the domain of intrusion detection, where the identification and mitigation of cyber threats are paramount, blockchain has emerged as a promising solution. This abstract examines how blockchain is used in intrusion detection systems and emphasizes its advantages. Blockchain technology improves the security and integrity of intrusion detection systems by using a decentralized and immutable ledger. It provides an immutable audit trail, distributed consensus, and increased resilience to attacks. Moreover, blockchain fosters trust, transparency, and collaboration among stakeholders, enabling faster threat detection and response. This research can explore novel approaches to integrating blockchain into intrusion detection systems, providing stronger protection against cyber threats.Immutable Audit Trail: In the context of intrusion detection, the capacity of blockchain to produce an unalterable and transparent audit trail is of enormous value. Research in this area can focus on developing techniques to leverage the blockchain's audit trail for effective incident response, forensic investigations, and attribution of cyberattacks. We will use theweighted product model in this study, which is a research approach that gives weights to various factors and combines them to make conclusions based on their relative relevance in a weighted way. Taken as alternative is“IDS1, IDS2, IDS3, IDS4, IDS5, IDS6, IDS7, and IDS8”.Detection Quality, Performance, Stability, User Interface, Profile update, ConvenienceThe By this we can see that IDS4 has 1 RANK and IDS5 has the 8th RANK.In conclusion, blockchain technology holds great potential in the intrusion detection domain. Its decentralized and immutable nature can enhance the security and reliability of intrusion detection systems by providing transparent and tamper-proof logs of network activity. Blockchain-based solutions can improve threat detection, facilitate secure information sharing among entities, and enhance the overall resilience of intrusion detection systems. As the technology continues to evolve, further research and development in integrating blockchain with intrusion detection will unlock new possibilities for combating cyber threats.
Salem S. M. Khalifa, Ali Mohamed E. Ejmaa, Abdulmawla Mohammad Ali Najih, Mohamed Abd Arahman Masoud Zneen
A transition to democratic rule is considered the first step down a long road towards Libya’s recovery and prosperity. Thus, it strives to improve the country’s elections by introducing new technologies. A blockchain is a distributed ledger that is characterised by independence and security. Therefore, it has been widely applied in various fields ranging from credit encryption and digital currency. With the development of internet technology, electronic voting (E-voting) systems have been greatly popularised. However, they suffer from various security threats, which create a sense of distrust among existing systems. Integrating blockchain with online elections is a promising trend, which could lead to make an election transparent, immutable, reliable, and more secure. In this paper, we present a literature review and a case analysis of blockchain technology. Moreover, a framework for an E-voting system based on blockchain is proposed. The methodology is adopted on the basis of three activities, they are identification of the relevant literature about E-voting, system modelling, and the determination of suitable technological tools. The framework is secure and reliable. Thus, it could help increase the number of voters and ensure a high level of participation, as well as facilitate free and fair electoral processes
R. Hanumantharaju, Shreenath Kn, Sowmya BJ, Srinivasa Kg
Intrusion detection is a familiar phrase in the information and network security domain. An Intrusion Detection System (IDS) is a device or software that will keep track of the networks, for unlawful movements, and policy breaches that arise within the network. There are different forms of IDS, Host Intrusion Detection System (HIDS) helps in identifying unauthorized activities on the host, Network Intrusion Detection System (NIDS) helps in identifying attacks in the network, whereas Distributed Intrusion Detection System (DIDS) consists of multiple IDS over a large area of network where individual IDS communicates with each other or with the central the authorized central server. The proposed work has a three-layered architecture for DIDS for securing data sharing among different IDS. The bottom layer uses multiple IDS, the fog layer is supported with Blockchain functionality, and the cloud service at the upper layer stores required data permanently for future analysis. The fog computing-based architecture for DIDS tries to implement the application in a scalable and trustless environment using distributed ledger technology. The evaluation of the proposed work is carried out for fog, cloud, and integrated fog-cloud with the Blockchain functionality and without Blockchain functionality in measuring performance metrics related to throughput, service latency, response time, block creation time, and block execution time.
Niranjan Kala
No abstract is available for this record.
Josef Koumar, Richard Plný, Tomáš Čejka
While the popularity of cryptocurrencies and the whole industry's value are rising, the number of threat actors who use illegal “coin miner mal ware” is increasing as well. The threat actors commonly use computational resources of companies, research and educational institutions, or end users. In this paper, we analyzed the long-term periodic behavior of the cryptocurrency miners communicating in computer networks. We propose a novel method for cryptominers detection using specially designed periodicity features. The detection algorithm is based on the mathematical detection of periodic Flow time series (FTS) and feature mining. Altogether with the Machine Learning technique, the resulting system achieves high-precision performance. Furthermore, our approach enhances a flow-based cryptominers detection system DeCrypto to further improve its reliability and feasibility for high-speed networks.
Jehad Ali, Gaoyang Shan, Noor Gul, Byeong‐hee Roh
No abstract is available for this record.
Kai Li, Shixuan Guan, Darren Lee
This paper presents the first comprehensive analysis of an emerging cryptocurrency scam named "arbitrage bot" disseminated on online social networks. The scam revolves around Decentralized Exchanges (DEX) arbitrage and aims to lure victims into executing a so-called "bot contract" to steal funds from them. To entice victims and convince them of this scheme, we found that scammers have flocked to publish YouTube videos to demonstrate plausible profits and provide detailed instructions and links to the bot contract. To collect the scam at a large scale, we developed a fully automated scam detection system namedCryptoScamHunter, which continuously collects YouTube videos and automatically detects scams. Meanwhile,CryptoScamHunter can download the source code of the bot contract from the provided links and extract the associated scam cryptocurrency address. Through deployingCryptoScamHunter from Jun. 2022 to Jun. 2023, we have detected 10,442 arbitrage bot scam videos published from thousands of YouTube accounts. Our analysis reveals that different strategies have been utilized in spreading the scam, including crafting popular accounts, registering spam accounts, and using obfuscation tricks to hide the real scam address in the bot contracts. Moreover, from the scam videos we have collected over 800 malicious bot contracts with source code and extracted 354 scam addresses. By further expanding the scam addresses with a similar contract matching technique, we have obtained a total of 1,697 scam addresses. Through tracing the transactions of all scam addresses on the Ethereum mainnet and Binance Smart Chain, we reveal that over 25,000 victims have fallen prey to this scam, resulting in a financial loss of up to 15 million USD. Overall, our work sheds light on the dissemination tactics and censorship evasion strategies adopted in the arbitrage bot scam, as well as on the scale and impact of such a scam on online social networks and blockchain platforms, emphasizing the urgent need for effective detection and prevention mechanisms against such fraudulent activity.
Qianrui Zhao, Yinan Wang, Bo Yang, Ke Shang · 8 authors
Cross-chain bridges are crucial mechanisms for facilitating interoperation between different blockchains, allowing the flow of assets and information across various chains. Their pivotal role and the vast value of assets they handle make them highly attractive to attackers. Major security incidents involving cross-chain bridge projects have been occurring frequently, resulting in losses of several billion due to cyber attacks. The diversity of vulnerability exploitation methods by hackers is vast, but not entirely untraceable. There are scarce research outcomes studying cross-chain bridge cyber incidents, and we have conducted a study based on the most recent cross-chain bridge security incidents. We introduce the working principles, components, and architecture of cross-chain bridges, explain the categorization mechanisms of the trust layer in cross-chain bridges, summarize four categories of hacker vulnerability exploitation techniques from real cases, and propose preventative measures for cross-chain bridge security.
Saqib Ali, Qianmu Li, Abdullah Yousafzai
No abstract is available for this record.
Haoyu Gao, Leixiao Li, Hong Lei, Ning Tian · 6 authors
Although botnet had been at the top of the list of main threats to the cyber world for an extended period of time, its harmfulness has been constrained nowadays due to the development of kaleidoscopic network security enforcing tools and people’s increasing awareness. And the underlying technology of the botnet has been stagnant ascribing to many drawbacks such as inadequate protection of the identity of the Botmaster and weak resilience of the botnet’s infrastructure. In this article, we first introduce a new classification of the botnet based on botnets’ underlying network, then briefly analyze the main flaws of the traditional botnet and some looming Blockchain-based botnets, with pros and cons of leveraging Blockchain to construct botnets. Furthermore, we propose one IOTA of countless legions (OICL), a newfangled versatile botnet infrastructure that overcomes the bottlenecks that other contemporaries cannot eliminate. It leverages Blockchain, also known as distributed ledger technology (DLT), to be its premises and uses many advantages of it without paying too many tradeoffs. Also, we invent a whole set of communication protocols for OICL and a novel scheme called Proof of Honest (PoH) to identify the espionage infiltrated into the botnet to further promote the robustness. In addition, we discover and propose a mechanism called collateral damage binding (CDB), which proves that the botnet has it such as OICL is far more robust than those who do not. Performance evaluations show that OICL is effective, more cost-saving, and fast-responding compared with the Bitcoin-based botnets as baselines.
Shanshan Han, Wenxuan Wu, Baturalp Buyukates, Weizhao Jin · 7 authors
Federated Learning (FL) systems are susceptible to adversarial attacks, such as model poisoning attacks and backdoor attacks. Existing defense mechanisms face critical limitations in deployments, such as relying on impractical assumptions (e.g., adversaries acknowledging the presence of attacks before attacking) or undermining accuracy in model training, even in benign scenarios. To address these challenges, we propose CustodianFL, a two-staged anomaly detection method specifically designed for FL deployments. In the first stage, it flags suspicious client activities. In the second stage that is activated only when needed, it further examines these candidates using Three-Sigma Rule to identify and exclude truly malicious local models from FL training. To ensure integrity and transparency within the FL system, CustodianFL integrates zero-knowledge proofs, enabling clients to cryptographically verify the server's detection process without relying on the server's goodwill. CustodianFL operates without unrealistic assumptions and avoids interfering with FL training in attack-free scenarios. It bridges the gap between theoretical advances in FL security and the practical demands of real FL systems. Experimental results demonstrate that CustodianFL consistently delivers performance comparable to benign cases, highlighting its effectiveness in identifying and eliminating malicious models with high accuracy.
Chuyi Yan, Chen Zhang, Meng Shen, Ning Li · 8 authors
Abstract Ethereum’s high attention, rich business, certain anonymity, and untraceability have attracted a group of attackers. Cybercrime on it has become increasingly rampant, among which scam behavior is convenient, cryptic, antagonistic and resulting in large economic losses. So we consider the scam behavior on Ethereum and investigate it at the node interaction level. Based on the life cycle and risk identification points we found, we propose an automatic detection model named Aparecium . First, a graph generation method which focus on the scam life cycle is adopted to mitigate the sparsity of the scam behaviors. Second, the life cycle patterns are delicate modeled because of the crypticity and antagonism of Ethereum scam behaviors. Conducting experiments in the wild Ethereum datasets, we prove Aparecium is effective which the precision, recall and F1-score achieve at 0.977, 0.957 and 0.967 respectively.
Benjamin Ampel, Kaeli Otto, Sagar Samtani, Hsinchun Chen
Ransomware is a growing problem and significant threat to cybersecurity in the United States. One primary vector for ransomware payments is the Bitcoin network. Network science techniques are a potential approach to analyze ransomware payment networks to discover salient ransomware actors. In this study, we propose a design framework for labeling nodes in a ransomware payment network and identifying key ransomware Bitcoin addresses that can be targeted for disruption. By leveraging semi-supervised graph embedding methodology and updating the loss function of a prevailing algorithm, GraphSAGE, to manage dataset imbalance, we identify key wallets in our ransomware network. We demonstrate the utility of our approach with a case study identifying a Bitcoin wallet that has been reported as a ransomware actor as recently as December 2021 and has transferred over $450 million in Bitcoin.
Chengxiang Jin, Jiajun Zhou, Shengbo Gong, Chenxuan Xie · 5 authors
Blockchain technology revolutionizes the Internet, but also poses increasing risks, particularly in cryptocurrency finance. On the Ethereum platform, Ponzi schemes, phishing scams, and a variety of other frauds emerge. Existing Ponzi scheme detection approaches based on heterogeneous transaction graph modeling leverages semantic information between node (account) pairs to establish connections, overlooking the semantic attributes inherent to the edges (interactions). To overcome this, we construct heterogeneous Ethereum interaction graphs with multiple triplet interaction patterns to better depict the real Ethereum environment. Based on this, we design a new framework named multi-triplet augmented heterogeneous graph neural network (MAHGNN) for Ponzi scheme detection. We introduce the Conditional Variational Auto Encoder (CVAE) to capture the semantic information of different triplet interaction patterns, which facilitates the characterization on account features. Extensive experiments demonstrate that MAHGNN is capable of addressing the problem of multi-edge interactions in heterogeneous Ethereum interaction graphs and achieving state-of-the-art performance in Ponzi scheme detection.
Yanan Gong, K. P. Chow, Siu Ming Yiu, Hing Fung Ting
Bitcoin is a widely used decentralized cryptocurrency. The proportion of Bitcoin transactions used for illegal activities is increasing. Mixing services are commonly applied to enhance anonymity and make transaction records more challenging to follow and analyze. The current research on peeling chains is generally based on heuristic algorithms to identify change addresses. However, due to the characteristics and limitations of the Bitcoin blockchain, there is no such ground truth to ensure the accuracy of each derived change address. This research analyzes the peeling chain patterns based on self-change addresses. The use of self-change addresses implies that the input address and the address used for receiving the change are controlled by the same entity. Also, each chain's transaction details and generated chain parameters are further verified for more precise results. Combining the two methods ensures the accuracy of the extracted peeling chains to some extent. And the corresponding behavior pattern of the extracted chains is studied.