Hongsong Chen, Xietian Luo, Lei Shi, Yongrui Cao · 5 authors
As an advantageous technique and service, the blockchain has shown great development and application prospects. However, its security has also met great challenges, and many security vulnerabilities and attack issues in blockchain-based services have emerged. Recently, security issues of blockchain have attracted extensive attention. However, there is still a lack of blockchain security research from a full-stack architecture perspective, as well as representative quantitative experimental reproduction and analysis. We aim to provide a security architecture to solve security risks in blockchain services from a full-stack architecture perspective. Meanwhile, we propose a formal definition of the full-stack security architecture for blockchain-based services, and we also propose a formal expression of security issues and defense solutions from a full-stack security perspective. We use ConCert to conduct a smart contract formal verification experiment by property-based testing. The security vulnerabilities of blockchain services in the Common Vulnerabilities and Exposures (CVE) and China Nation Vulnerability Database (CNVD) are selected and enumerated. Additionally, three real contract-layer real attack events are reproduced by an experimental approach. Using Alibaba's blockchain services and Identity Mixer in Hyperledger Fabric as a case study, the security problems and defense techniques are analyzed and researched. At last, the future research directions are proposed.
This paper predicts sentiments of crypto currency news articles using BERT (Bidirectional Encoder Representation) model, as there is a lack of research in crypto currency price prediction using natural language processing. The text data obtained is unlabeled and it is labelled using a parsimonious rule-based model and then BERT is used to dassify news sentiment as “Positive”, “Negative” or “Neutral” which may be helpful in reading cryptocurrency market movement.
In recent years, the losses caused by scams on Ethereum have reached a level that cannot be ignored. As one of the most rampant crimes, phishing scams have caused a huge economic loss to blockchain platforms and users. Under these circumstances, to address the threat to the financial security of blockchain, an Edge Aggregated Graph Attention Network (EGAT) based on the static subgraph representation of the transaction network is proposed. This study intends to detect Ethereum phishing accounts through the classification of transaction network subgraphs with the following procedures. Firstly, the accounts are used as nodes and the flow of transaction funds is used as directed edges to construct the transaction network graph. Secondly, the transaction record data of phishing accounts in the publicly available Ethereum are analyzed and statistical features of Value, Gas, and Timestamp values are manually constructed as node and edge features of the graph. Finally, the features are extracted and classified using the EGAT network. According to the experimental results, the Recall of the proposed method from the article is 99.3% on the dataset of phishing accounts. As demonstrated, the EGAT is more efficient and accurate compared with Graph2Vec and DeepWalk, and the graph structure features can express semantics better than manual features and simple transaction networks, which effectively improves the performance of phishing account detection.
K M Ramya, L Rachana, Ranjita Kiran Naik, Rashmika Satish · 5 authors
Abstract: Medical product counterfeiting is one of the many major problems facing the healthcare sector. It is estimated that 10 to 30 percent of medical products sold are fake. Because they do not have access to quality healthcare, these issues are more prevalent in undeveloped and developing nations. As the healthcare supply chain is centralised and the procedure from the product's creation to its delivery to the user is opaque, it is challenging to identify counterfeit goods. As a result, the traceability of medicinal products becomes crucial. In addition to the difficulties of data privacy, data authenticity, and adaptability, traditional methods have not been very effective in resolving these problems. In this study, we reviewed several blockchain-based approaches for detecting fake medical items that employ the Ethereum blockchain, Hyperledger fabric, etc. The adoption of innovative ideas, like the inclusion of a QR code which enables customers to discover more about medical products are also studied. We also discuss the various architectures and techniques that are employed. The key challenges faced, and the research gaps are also analysed.
In the healthcare industry, providing a vital backbone for services is critical. The supply chain is a complex network that crosses organizational and geographical borders. In the healthcare business, counterfeit pills are one of the primary reasons for the harmful impact on human health and financial loss. Thus, pharmaceutical supply chains and end-to-end tracking systems are the recent research in healthcare. In this paper, the authors propose blockchain-based traceability of counterfeited drugs (BBTCD) that implements tracking of counterfeited drugs using smart contracts on the Ethereum blockchain. They offer a solution to fully decentralize the tracking by storing BBTCD on IPFS (inter planetary file system) to provide transparency and cost-effectiveness.
Adrian Petcu, Bogdan Pahonțu, Mădălin Frunzete, Dan Alexandru Stoichescu
Over the past decade, there has been significant evolution in the security field, specifically in the authentication and authorization part. The standard authentication protocol nowadays is OAuth 2.0-based authentication. This method relies on a third-party authentication service provider with complete control over the users’ data, which it can filter or modify at will. Blockchain and decentralization have generated much interest in recent years, and the decentralized web is considered the next significant improvement in the world wide web (also known as Web 3.0). Web3 authentication, also known as decentralized authentication, allows for the secure and decentralized authentication of users on the web. The use cases for this technology include online marketplaces, social media platforms, and other online communities that require user authentication. The advantages of Web3 authentication include increased security and privacy for users and the ability for users to have more control over their data. The proposed system implementation uses Ethereum as the blockchain and a modern web stack to enhance user interaction and usability. The solution brings benefits both to the private and the public sector, proving that it has the capability of becoming the preferred authentication mechanism for any decentralized web application.
Khandaker Mohammad Mohi Uddin, Sadia Mahamuda, Sikder Sajib Al Shahriar, Md. Ashraf Uddin
In recent times, various forms of crime have been happening worldwide.The law-and-order department of any country officially records a crime in electronic forms or on paper when the crime is reported by a victim or someone on behalf of the victim.The document that is prepared to file any perceptible committed crimes including dowry, kidnap, murder, rape, theft, and others is called First Information Report(FIR).Nowadays, online FIR also known as e-FIR has been used worldwide.Every day a number of e-FIR are filed, and they are maintained in a centralized database with the aid of third-party trust.Consequently, malicious entities including insiders and outsiders' dishonest personnel, and third-party authorities may tamper with e-FIR that questions the transparency and integrity of FIR reports.To address this exposure, in this paper, we propose a blockchain based FIR system to store all kinds of offense-related records to assure security, fidelity and privacy of FIR records.In this proposed system, the blockchain technology that refers to a decentralized and distributed ledger across peer-to-peer networks continually updates the shared ledger and strictly maintains synchronization among all network nodes.Though blockchain technology guarantees tamper-proof of the data, it cannot store a large amount of data due to the replication of ledger among all network nodes.To solve this issue, we adopt the Inter-Planetary File system (IPFS) protocol to store data in the blockchain.IPFS is a distributed file-sharing system that can be leveraged to store and share large files.The blockchain based FIR system has been tested on an Ethereum environment using blockchain and IPFS technology.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
In crowdsourcing systems, requesters publish tasks, and interested workers provide answers to get rewards. Worker anonymity motivates participation since it protects their privacy. Anonymity with unlinkability is an enhanced version of anonymity because it makes it impossible to ``link'' workers across the tasks they participate in. Another core feature of crowdsourcing systems is worker quality which expresses a worker's trustworthiness and quantifies their historical performance. Notably, worker quality depends on the participation history, revealing information about it, while unlinkability aims to disassociate the workers' identities from their past activity. In this work, we present AVeCQ, the first crowdsourcing system that reconciles these properties, achieving enhanced anonymity and verifiable worker quality updates. AVeCQ relies on a suite of cryptographic tools, such as zero-knowledge proofs, to (i) guarantee workers' privacy, (ii) prove the correctness of worker quality scores and task answers, and (iii) commensurate payments. AVeCQ is developed modularly, where the requesters and workers communicate over a platform that supports pseudonymity, information logging, and payments. In order to compare AVeCQ with the state-of-the-art, we prototype it over Ethereum. AVeCQ outperforms the state-of-the-art in three popular crowdsourcing tasks (image annotation, average review, and Gallup polls). For instance, for an Average Review task with $5$ choices and $128$ participating workers AVeCQ is 40\% faster (including overhead to compute and verify the necessary proofs and blockchain transaction processing time) with the task's requester consuming 87\% fewer gas units.
With the rise of internet accessibility and situations like the pandemic, the world has seen an ever-increasing number of people turning to online shopping. Over the years, these E-commerce websites have been able to win the trust of their users. With this trust in mind, people have started buying high-value goods like electronics, smart gadgets and even furniture. While these goods are delivered with ease, another important concern in regard to these items is product warranties. Present-day warranties exist in two forms a) Physical Warranties and b) Digital Warranties. Physical warranties involve paperwork, can be easily tampered with and manipulated and are almost non-transferable. Digital warranties, although they do not need paperwork, do not ensure complete ownership transfers. To overcome the abovementioned issues, we propose a new blockchain-based solution. Our proposed solution uses Non-Fungible Tokens to issue and verify warranties. This research proposes a new way of issuing, managing and validating product warranties by making use of Non-Fungible Token(NFT). The NFT Warranty stays on the blockchain as long the warranty is valid after which it ‘burns’.
Jacques Bulchand‐Gidumal, Santiago Melián González
Online consumer-generated reviews are part of eWOM (electronic word of mouth). These reviews are very important for tourists in their decision-making processes regarding purchases and bookings. The reviews can be found in two types of sources: websites that sell the product and independent websites. In both cases, current review systems have relevant shortcomings: the possibility of fake reviews, the representativeness of those who review, platform decisions than can bias the results and other possible manipulations. Additionally, some users may not feel comfortable posting reviews due to the possible loss of anonymity. In this scenario, blockchain provides a suitable framework for solving most of the stated problems. In this paper, we describe an implementation of an online review system based on blockchain that would help solve most of the problems that exist in the current systems. We discuss managerial implications of the proposed system, possible limitations and future research needed in the area.
Decentralized video sharing structures are much like video sharing structures wherein creators post content material and customers view it. However, the primary distinction lies withinside the community in the back of the decentralized video sharing platform. A peer-to-peer (P2P) community of decentralized video sharing structures helps the steady switch of files. To make sure speedy facts switch, facts is break up into smaller blocks for less complicated switch and download, making sure quicker downloads and browsing. The decentralized video sharing platform transfers facts over a P2P community, however with an extra layer of blockchain era encryption. Less operational value, higher fault tolerance, much less consider necessities among garage carriers and facts owners, and much less vulnerability to attacks. An occasion in blockchain era has delivered a decentralized garage mode to the public. Video transcoding is extensively carried out in video streaming commerce, changing films into a couple of codecs for extraordinary audiences.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Purpose- The aim of this study is to reveal the publications that shed light on the dark side of the cryptocurrency markets with a systematic approach. Methodology- For this purpose, 369 publications in the Scopus database between 2014-2022 were determined as samples. In the publications provided by the database, the keywords "cryptocurrency" and "fraud", "scam", "phishing", "ponzi", "crime" were scanned over the publication title, abstract and keywords, and an integrated bibliometric analysis was employed. The R program was used in the analysis, and the "Biblioshiny" application in the RStudio program was employed to visualize the findings. Findings- The analysis reveals that the number of publications, the number of citations and the interest in the field have increased especially in recent years. The rate of increase in the number of publications in the field and the fact that most of these publications are at the stage of notification have shown that the field is an important developing field. The most intense interest in the field has been shown from universities in China. On the other hand, it was seen that the most interest in the field was from computer sciences and the interest of journals in the field of finance remained weak. It has been determined that the topics that may attract attention in the future are digital forensics, digital assets, fraudulent cryptocurrencies, corruption prevention, mining and cyber attacks. Conclusion- The study reveals the evolution of the dark side of cryptocurrency markets in academic research. The findings provide researchers interested in the field with the opportunity to explore themes and issues that may be on the agenda in the future. Keywords: Cryptocurrency, fraud, ponzi, crime, bibliometric analysis JEL Codes: G11, G19
As smart contracts process digital assets, their security is essential for blockchain applications. Many approaches have been proposed to detect smart contract vulnerabilities. Studies show that few of the reported vulnerabilities are exploited and hypothesize that many of the reported vulnerabilities are false positives. However, no follow-up study is performed to confirm the hypothesis and understand why the reported vulnerabilities are not exploited. In this study, we first collect 136,969 unique real-world smart contracts and analyze them using four vulnerability detectors, namely Oyente, SmartCheck, Slither, and SolDetector. Then, we apply Strauss’ grounded theory approach to manually analyze the source code of the smart contracts reported as vulnerable to recognizing false positives and understand the reasons for false results. In addition, we analyze the transaction logs of the smart contracts reported as vulnerable to identifying and understanding their exploitations. Our results show that 75.37% of the 4,364 smart contracts reported as vulnerable are false positives, and eleven reasons are causing the false positives. After analyzing the 4,106,134 transaction logs of the contracts reported as vulnerable, we find that vulnerabilities of only 67 (0.015%) of the contracts have been exploited in history. We also identify six reasons for demotivating and preventing the attackers from exploiting the vulnerabilities. Our results reveal that state-of-the-art smart contract vulnerability detectors primarily treat the smart contracts as yet another application developed using Object Oriented (OO) languages when analyzing and reporting the smart contract vulnerabilities. Without considering the specific design principles of the Solidity programming language and the characteristics of smart contracts’ application scenarios and execution environments, many of the reported vulnerabilities are not exploitable or not cost-effective to be exploited by adversaries.
Hanna Kim, Jian Cui, Eugene Jang, Chanhee Lee · 7 authors
As Non-Fungible Tokens (NFTs) continue to grow in popularity, NFT users have become targets of phishing attacks by cybercriminals, called \textit{NFT drainers}. Over the last year, \$100 million worth of NFTs were stolen by drainers, and their presence remains a serious threat to the NFT trading space. However, no work has yet comprehensively investigated the behaviors of drainers in the NFT ecosystem. In this paper, we present the first study on the trading behavior of NFT drainers and introduce the first dedicated NFT drainer detection system. We collect 127M NFT transaction data from the Ethereum blockchain and 1,135 drainer accounts from five sources for the year 2022. We find that drainers exhibit significantly different transactional and social contexts from those of regular users. With these insights, we design \textit{DRAINCLoG}, an automatic drainer detection system utilizing Graph Neural Networks. This system effectively captures the multifaceted web of interactions within the NFT space through two distinct graphs: the NFT-User graph for transaction contexts and the User graph for social contexts. Evaluations using real-world NFT transaction data underscore the robustness and precision of our model. Additionally, we analyze the security of \textit{DRAINCLoG} under a wide variety of evasion attacks.
Ideas lead to innovation which benefits the society. Innovation is a way of advancing, evolving, and improving our way of living. It is also a method of growing our economy. But to bring these ideas into reality, a huge capital investment is required. Sometimes, the person himself is capable of funding the project. Other times, when he’s not capable of funding his project, he may resort to other methods of raising money. One of these successful methods include crowd funding. Crowdfunding refers to the use of small amounts of capital from a large number of individuals to finance a new business venture. In exchange for their investment, the contributors get certain rewards. These rewards may include profits or some other stuff.Crowdfunding can be done through various platforms like social media. There are also some specific websites that focus on the idea of crowdfunding. These crowdfunding websites include crowdfunding platforms like Kickstarter, GoFundMe, Experiment, Fundly. But with the rising popularity of these investment based crowdfunding websites, there is also a rise in the cases of scam via these websites where the people don’t get any reward in exchange for their investment.Another issue with the traditional payment systems is that noticeable transaction fee is levied on payment via these payment methods. Our main goal is to create an intermediate network between the communities and the project idea for the scam-proof arrangement. The issue with the transaction fee would also be resolved to some extent. We proposed to do this by using Ethereum Smart Contracts-Blockchain instead of the traditional payment methods. This would result in considerable decrease in the scams and make it a trustworthy payment system and would attract more audience.
Sayak Saha Roy, Dipanjan Das, Priyanka Bose, Christopher Kruegel · 6 authors
The rapid growth in popularity and hype surrounding digital assets such as art, video, and music in the form of non-fungible tokens (NFTs) has made them a lucrative investment opportunity, with NFT-based sales surpassing $25B in 2021 alone. However, the volatility and general lack of technical understanding of the NFT ecosystem have led to the spread of various scams. The success of an NFT heavily depends on its online virality. As a result, creators use dedicated promotion services to drive engagement to their projects on social media websites, such as Twitter. However, these services are also utilized by scammers to promote fraudulent projects that attempt to steal users' cryptocurrency assets, thus posing a major threat to the ecosystem of NFT sales. In this paper, we conduct a longitudinal study of 439 promotion services (accounts) on Twitter that have collectively promoted 823 unique NFT projects through giveaway competitions over a period of two months. Our findings reveal that more than 36% of these projects were fraudulent, comprising of phishing, rug pull, and pre-mint scams. We also found that a majority of accounts engaging with these promotions (including those for fraudulent NFT projects) are bots that artificially inflate the popularity of the fraudulent NFT collections by increasing their likes, followers, and retweet counts. This manipulation results in significant engagement from real users, who then invest in these scams. We also identify several shortcomings in existing anti-scam measures, such as blocklists, browser protection tools, and domain hosting services, in detecting NFT-based scams. We utilize our findings to develop and open-source a machine learning classifier tool that was able to proactively detect 382 new fraudulent NFT projects on Twitter.
U Tejashwin, S J Kennith, Rohit Manivel, K C Shruthi · 5 authors
While the web3 is used to form a decentralized society and focuses particularly on financial transactions in the form of transferable tokens rather than ensuring trust among its entities. With this paper we discuss how non-transferable tokens referred as soulbound tokens (SBTs) can be used to make individuals more credible by having their affiliations encoded in the form of souls to ensure trust within the network. More specifically we discuss how the credentials of students regards to their academic achievements and their credibility can be stored and verified in an decentralized society which shall provide more privacy and security than a centralized system which shall eventually lead to have a higher credibility of data.
Bitcoin is a distributed cryptocurrency that verifies transactions using the Proof-of-Work system. It is now being accepted as payment by an increasing number of establishments, particularly quick-service restaurants and vending that must quickly satisfy orders. Unfortunately, given the correct circumstances, such as quick payments, a Bitcoin double expenditure scam may occur. Finding scalable and simple to-install defenses against such assaults is essential since consumers shouldn't be responsible for paying the price for cyberattacks. In an earlier study, some potential countermeasures were published without enough thought. In this study, they use the Shadow framework to predict the outcomes of deploying these security measures in a sizable Bitcoin P2P network. Our model shows that if an upgraded observer combines these countermeasures, a vendor may be informed of a double-spend assault in much less than 28 milliseconds on average.
G. Rajiv Trivedi, Jhansi Vazram Bolla, M. Sireesha
Crypto currencies usage increasing every year around the world. The Bitcoin is the one of the famous cryptocurrencies, which is an unofficial usable currency in various nations. The bitcoin transactions are increasing, which needs to be monitored carefull y. However, the conventional methods are failed to analyze the bitcoin transaction effectively. Therefore, this work focused on development of bitcoin transaction network (BTN) using pattern matching rules (PMR). Initially, the dataset preprocessing is carried out to identify the missed symbols, unknown characters from forensic blockchain dataset. Then, Petri-Net model applied on preprocessed dataset, which identifies the time stamp, transaction id, work tera hash, and work error properties. The Petri-Net model mainly used to parse and build the BTN model. Then, PMR conditions are developed to extract the transaction addresses extracted with time stamp details. So, PMR detects the illegal payment addresses by matching the known data with illegal (spam) addresses. Further, cache based PMR (CPMR) is also applied to detect the fraud transaction, which store all previous detected illegal payment addresses. So, for every new transaction, CPMR will ignore all those previously stored (detected) illegal payment addresses. This phenomenon causes reduction of fraud transaction detection time and processing becomes faster. The simulations shows that the proposed method resulted in reduced transaction processing time (TPT), fraud transaction detection time (FTDT), and improved fault transaction detection accuracy (FTDA) as compared to conventional methods.
Cyber security is the safest way to protect the data from hackers and unauthorized users. Healthcare technologies nowadays face lots of cyber security issues related with the security of the health information and privacy of the data. Cyber security is one of the popularized ways to protect the data from hackers and spammers. HealthCare is the field where the data is highly sensitive and the security for the systems is low. Protecting the sensitive data is achieved by the blockchain method, which is similar to a database but the difference is the data stored in the blockchain in blocks. The new blocks included are connected to previous blocks from a chain like structure, it is very secure, each block stores data and also the hash of previous blocks. So, data cannot be easily accessed or manipulated. The mechanism used in blockchain for the security of the data consensus mechanism which contains the different methodologies includes Proof of Work (PoW), Proof of Stake (PoS), Proof of Space and Proof of Authority. Enhanced proof of stake is a combination of the PoS and DPoS used to increase the security of the system by eliminating the 51% attack in blockchain and reduces the data theft threats and protects the medical records of patients from hackers.
The concept of Bitcoin first came into creation in 2008, as a response to the Great Financial Crisis, and the world of finances relies upon banks for all kinds of financial transactions as intermediaries. Bitcoin is more than a cryptocurrency used as payment for investors to hold and hope for value; it is considered a digital asset these days. While Bitcoin transactions take place in the cyber network, possibilities are there for cyber-attacks. To protect Bitcoins from illegal miners of Bitcoin data, it is required to find all possible intrusions, called vulnerabilities. If more vulnerabilities exist in the network that makes the transactions vulnerable. As of now, Bitcoin uses centralized Blockchain technology, where the transaction made by the user are managed by various blockchain methods like Merkelroot, Mining, Halving, Keys, and Wallets. These methods provide security to the cryptocurrencies online. Among all the four methods, Wallets are somewhat vulnerable due to their dual services i.e., custodians and non-custodians. Non-custodian Wallet type doesn’t cause vulnerability due to not having any storage for keys. Whereas the Custodian Wallet type provides storage of keys for the customers which makes it as vulnerable. The techniques that lead to vulnerability in the custodian type are hot storage, cold storage, and deep cold storage. The exploitation of all these individual techniques is the main task of this work. When it comes to transactions of bitcoin along the network where the receiver needs to wait around 30 minutes due to mempool. This is also a loophole that may trigger the threat to the bitcoin exchange. These vulnerabilities can be reduced by regulatory oversight and reducing the mempool waiting time or it is possible by maintaining more legal crypto miners for every block of transaction. To verify the whole process of bitcoin transaction exchanges, few cloud services use blockchain technology for processing transactions. The proposed work is to implement the above methods, so that protection is provided to cryptocurrencies toward bitcoin exchanges.
With the increase of the adoption of blockchain technology in providing decentralized solutions to various problems, smart contracts have become more popular to the point that billions of US Dollars are currently exchanged every day through such technology. Meanwhile, various vulnerabilities in smart contracts have been exploited by attackers to steal cryptocurrencies worth millions of dollars. The automatic detection of smart contract vulnerabilities therefore is an essential research problem. Existing solutions to this problem particularly rely on human experts to define features or different rules to detect vulnerabilities. However, this often causes many vulnerabilities to be ignored, and they are inefficient in detecting new vulnerabilities. In this study, to overcome such challenges, we propose a framework to automatically detect vulnerabilities in smart contracts on the blockchain. More specifically, first, we utilize novel feature vector generation techniques from bytecode of smart contract as source code is rarely publicly available. These feature vectors are then analyzed using our innovative metric learning-based Deep Neural Networks (DNNs) to produce detection results. The framework’s predictions are further refined through a voting mechanism to achieve consensus. We conduct comprehensive experiments on large-scale benchmarks, and the quantitative results demonstrate the effectiveness and efficiency of our approach.
A democratic election is a crucial act in each nation, as it determines the country's future for a specific term. Some of the older voting methods, such as Ballot Paper and EVM (Electronic Voting Machine), have disadvantages such as lack of transparency, poor voter turnout, vote rigging, and many others. Using Blockchain technology and Smart Contracts, it is simple to circumvent the flaws of the Ballot system and EVM. Electronic Voting Powered by Blockchain and Smart Contracts outperforms these antiquated voting methods by delivering secure results in less time and at a lower cost. With E-Voting utilizing Blockchain, prices can be lowered, the necessity for Polling stations and the consumption of resources such as EVMs and Ballot Papers may be decreased, and security can be improved by offering End-to-End Encryption and authenticity. This blockchain-powered e-voting can readily acquire trust due to the transaction's transparency, immutability, and difficulty of modification once hosted, as a result of smart contracts. Using OTP Verification and face verification, the suggested solution is a MERN-based web application with a multitude of upgraded authentication and permission techniques. To improve security, this voting data is saved as a transaction in a Blockchain-based distributed ledger using smart contracts.