Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,269 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,269 results · page 26 of 53

Clear filters
Mar 11, 2023·Electronics
690 cites
A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions

Ömer Aslan, Semih Serkant Aktuğ, Merve Ozkan-Okay, Abdullah Asım Yılmaz · 5 authors

Internet usage has grown exponentially, with individuals and companies performing multiple daily transactions in cyberspace rather than in the real world. The coronavirus (COVID-19) pandemic has accelerated this process. As a result of the widespread usage of the digital environment, traditional crimes have also shifted to the digital space. Emerging technologies such as cloud computing, the Internet of Things (IoT), social media, wireless communication, and cryptocurrencies are raising security concerns in cyberspace. Recently, cyber criminals have started to use cyber attacks as a service to automate attacks and leverage their impact. Attackers exploit vulnerabilities that exist in hardware, software, and communication layers. Various types of cyber attacks include distributed denial of service (DDoS), phishing, man-in-the-middle, password, remote, privilege escalation, and malware. Due to new-generation attacks and evasion techniques, traditional protection systems such as firewalls, intrusion detection systems, antivirus software, access control lists, etc., are no longer effective in detecting these sophisticated attacks. Therefore, there is an urgent need to find innovative and more feasible solutions to prevent cyber attacks. The paper first extensively explains the main reasons for cyber attacks. Then, it reviews the most recent attacks, attack patterns, and detection techniques. Thirdly, the article discusses contemporary technical and nontechnical solutions for recognizing attacks in advance. Using trending technologies such as machine learning, deep learning, cloud platforms, big data, and blockchain can be a promising solution for current and future cyber attacks. These technological solutions may assist in detecting malware, intrusion detection, spam identification, DNS attack classification, fraud detection, recognizing hidden channels, and distinguishing advanced persistent threats. However, some promising solutions, especially machine learning and deep learning, are not resistant to evasion techniques, which must be considered when proposing solutions against intelligent cyber attacks.

Open access
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Smart Grid Security and Resilience
Original source
Mar 8, 2023·Sensors
15 cites
P-IOTA: A Cloud-Based Geographically Distributed Threat Alert System That Leverages P4 and IOTA

Amir Al Sadi, Carlo Mazzocca, Andrea Melis, Rebecca Montanari · 6 authors

The recent widespread novel network technologies for programming data planes are remarkably enhancing the customization of data packet processing. In this direction, the Programming Protocol-independent Packet Processors (P4) is envisioned as a disruptive technology, capable of configuring network devices in a highly customizable way. P4 enables network devices to adapt their behaviors to mitigate malicious attacks (e.g., denial of service). Distributed ledger technologies (DLTs), such as blockchain, allow secure reporting alerts on malicious actions detected across different areas. However, the blockchain suffers from major scalability concerns due to the consensus protocols needed to agree on a global state of the network. To overcome these limitations, new solutions have recently emerged. IOTA is a next-generation distributed ledger engineered to tackle the scalability limits while still providing the same security capabilities such as immutability, traceability, and transparency. This article proposes an architecture that integrates a P4-based data plane software-defined network (SDN) and an IOTA layer employed to notify about networking attacks. Specifically, we propose a fast, secure, and energy-efficient DLT-enabled architecture that combines the IOTA data structure, named Tangle, with the SDN layer to detect and notify about network threats.

Open access
Software-Defined Networks and 5G
Network Security and Intrusion Detection
Caching and Content Delivery
Original source
Feb 16, 2023·Information
79 cites
A Blockchain-Inspired Attribute-Based Zero-Trust Access Control Model for IoT

Samia Masood Awan, Muhammad Ajmal Azad, Junaid Arshad, Urooj Waheed · 5 authors

The connected or smart environment is the integration of smart devices (sensors, IoT devices, or actuator) into the Internet of Things (IoT) paradigm, in which a large number of devices are connected, monitoring the physical environment and processes and transmitting into the centralized database for advanced analytics and analysis. This integrated and connected setup allows greater levels of automation of smart systems than is possible with just the Internet. While delivering services to the different processes and application within connected smart systems, these IoT devices perform an impeccably large number of device-to-device communications that allow them to access the selected subsets of device information and data. The sensitive and private nature of these data renders the smart infrastructure vulnerable to copious attacks which threat agents exploit for cyberattacks which not only affect critical services but probably bring threat to people’s lives. Hence, advanced measures need to be taken for securing smart environments, such as dynamic access control, advanced network screening, and monitoring behavioural anomalies. In this paper, we have discussed the essential cyberthreats and vulnerabilities in smart environments and proposed ZAIB (Zero-Trust and ABAC for IoT using Blockchain), a novel secure framework that monitors and facilitates device-to-device communications with different levels of access-controlled mechanisms based on environmental parameters and device behaviour. It is protected by zero-trust architecture and provides dynamic behavioural analysis of IoT devices by calculating device trust levels for each request. ZAIB enforces variable policies specifically generated for each scenario by using attribute-based access control (ABAC). We have used blockchain to ensure anonymous device and user registrations and immutable activity logs. All the attributes, trust level histories, and data generated by IoT devices are protected using IPFS. Finally, a security evaluation shows that ZAIB satisfies the needs of active defence and end-to-end security enforcement of data, users, and services involved in a smart grid network.

Open access
Internet Traffic Analysis and Secure E-voting
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Original source
Feb 13, 2023·Security and Communication Networks
22 cites
Blockchain-Based Cyber Threat Intelligence Sharing Using Proof-of-Quality Consensus

Dimitrios Chatziamanetoglou, Konstantinos Rantos

Cyber threat intelligence (CTI) is contextualised knowledge, built on information that is collected, processed, analysed, and disseminated to the right audience, in order to comprehend a malicious threat actor’s motivation, goals, objectives, targets, and attack behaviours. The CTI value increases by the ability to be shared, consumed, and actioned timely, by the right stakeholders, based always on quality standards and parameters, which boost the cyber security community to understand how adversaries act and to counter the constantly emerging sophisticated cyber threats. In this article, along with the identification of research gaps, after a comparison between existing research studies in the similar scope of CTI evaluation and sharing mechanisms, we propose a blockchain-based cyber threat intelligence system architecture, which collects, evaluates, stores, and shares CTI, enabling tamper-proof data and exclusion of untrustworthy evaluation peers, while evaluating, at the same time, the quality of CTI Feeds against a defined set of quality standards. The evaluation of the data is performed utilising a reputation and trust-based mechanism for selecting validators, who further rate the CTI feeds using quality-based CTI parameters, while the consensus for preserving the fairness of the results and their final storage is performed via the recently introduced proof-of-quality (PoQ) consensus algorithm. The data, which are stored in the proposed ledger, constitute a reliable, distributed, and secure repository of CTI Feeds and contain their objective evaluation, as well as the performance of the validators who participated in each evaluation, while these data can be further used for assessing the reputation of CTI Sources. Finally, in order to assess the proposed system’s reliability, integrity, and tolerance against malicious activities, the model is subject to a theoretical analysis using a probabilistic simulation, taking into account various aspects and features of the integrated mechanisms. The results show that the tolerance against malicious validators is acceptable, even when the ratio between legitimately vs. maliciously behaving validators is 1 : 50.

Open access
Blockchain Technology Applications and Security
Information and Cyber Security
Network Security and Intrusion Detection
Original source
Feb 9, 2023·Internet of Things
27 cites
PETIoT: PEnetration Testing the Internet of Things

Giampaolo Bella, Pietro Biondi, Stefano Bognanni, Sergio Esposito

Attackers may attempt exploiting Internet of Things (IoT) devices to operate them unduly as well as to gather personal data of the legitimate device owners’. Vulnerability Assessment and Penetration Testing (VAPT) sessions help to verify the effectiveness of the adopted security measures. However, VAPT over IoT devices, namely VAPT targeted at IoT devices, is an open research challenge due to the variety of target technologies and to the creativity it may require. Therefore, this article aims at guiding penetration testers to conduct VAPT sessions over IoT devices by means of a new cyber Kill Chain (KC) termed PETIoT. Several practical applications of PETIoT confirm that it is general, while its main novelty lies in the combination of attack and defence steps. PETIoT is demonstrated on a relevant example, the best-selling IP camera on Amazon Italy, the TAPO C200 by TP-Link, assuming an attacker who sits on the same network as the device’s in order to assess all the network interfaces of the device. Additional knowledge is generated in terms of three zero-day vulnerabilities found and practically exploited on the camera, one of these with High severity and the other two with Medium severity by the CVSS standard. These are camera Denial of Service (DoS), motion detection breach and video stream breach. The application of PETIoT culminates with the proof-of-concept of a home-made fix, based on an inexpensive Raspberry Pi 4 Model B device, for the last vulnerability. Ultimately, our responsible disclosure with the camera vendor led to the release of a firmware update that fixes all found vulnerabilities, confirming that PetIoT has valid impact in real-world scenarios.

Open access
2 source records
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Adversarial Robustness in Machine Learning
Original source
Feb 7, 2023·Digital Communications and Networks
10 cites
A hierarchical blockchain-enabled security-threat assessment architecture for IoV

Yuanni Liu, Ling Pan, Shanzhi Chen

In Internet of Vehicles (IoV), the security-threat information of various traffic elements can be exploited by hackers to attack vehicles, resulting in accidents, privacy leakage. Consequently, it is necessary to establish security-threat assessment architectures to evaluate risks of traffic elements by managing and sharing security-threat information. Unfortunately, most assessment architectures process data in a centralized manner, causing delays in query services. To address this issue, in this paper, a Hierarchical Blockchain-enabled Security threat Assessment Architecture (HBSAA) is proposed, utilizing edge chains and global chains to share data. In addition, data virtualization technology is introduced to manage multi-source heterogeneous data, and a metadata association model based on attribute graph is designed to deal with complex data relationships. In order to provide high-speed query service, the ant colony optimization of key nodes is designed, and the HBSAA prototype is also developed and the performance is tested. Experimental results on the large-scale vulnerabilities data gathered from NVD demonstrate that the HBSAA not only shields data heterogeneity, but also reduces service response time. © 20xx Published by Elsevier Ltd.

Open access
Vehicular Ad Hoc Networks (VANETs)
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Original source
Jan 31, 2023·IEEE Transactions on Dependable and Secure Computing
3 cites
Why Smart Contracts Reported as Vulnerable were not Exploited?

Tianyuan Hu, Jingyue Li, Bixin Li, André Storhaug

As smart contracts process digital assets, their security is essential for blockchain applications. Many approaches have been proposed to detect smart contract vulnerabilities. Studies show that few of the reported vulnerabilities are exploited and hypothesize that many of the reported vulnerabilities are false positives. However, no follow-up study is performed to confirm the hypothesis and understand why the reported vulnerabilities are not exploited. In this study, we first collect 136,969 unique real-world smart contracts and analyze them using four vulnerability detectors, namely Oyente, SmartCheck, Slither, and SolDetector. Then, we apply Strauss’ grounded theory approach to manually analyze the source code of the smart contracts reported as vulnerable to recognizing false positives and understand the reasons for false results. In addition, we analyze the transaction logs of the smart contracts reported as vulnerable to identifying and understanding their exploitations. Our results show that 75.37% of the 4,364 smart contracts reported as vulnerable are false positives, and eleven reasons are causing the false positives. After analyzing the 4,106,134 transaction logs of the contracts reported as vulnerable, we find that vulnerabilities of only 67 (0.015%) of the contracts have been exploited in history. We also identify six reasons for demotivating and preventing the attackers from exploiting the vulnerabilities. Our results reveal that state-of-the-art smart contract vulnerability detectors primarily treat the smart contracts as yet another application developed using Object Oriented (OO) languages when analyzing and reporting the smart contract vulnerabilities. Without considering the specific design principles of the Solidity programming language and the characteristics of smart contracts’ application scenarios and execution environments, many of the reported vulnerabilities are not exploitable or not cost-effective to be exploited by adversaries.

Open access
5 source records
Blockchain Technology Applications and Security
Digital and Cyber Forensics
Advanced Malware Detection Techniques
Original source
Jan 25, 2023·Transactions on Emerging Telecommunications Technologies
54 cites
Prevention of DDoS attacks using an optimized deep learning approach in blockchain technology

Ilyas Benkhaddra, Abhishek Kumar, Mohamed Ali Setitra, ZineEl Abidine Bensalem · 5 authors

Abstract The attack named Distributed Denial of Service (DDoS) that takes place in the large blockchain network requires an efficient and robust attack detection and prevention mechanism for authenticated access. Blockchain is a distributed network in which the attacker tries to hack the network by utilizing all the resources with the application of enormous requests. Several methods like Rival Technique, filter modular approach and so on, were developed to detect and prevent the DDoS attack in the blockchain; still, detection accuracy is a challenging task. Hence, this research introduces an efficient technique using optimization‐based deep learning by considering the blockchain network and smart contract for the detection and prevention of DDoS attacks. Based on the user request, the traffic is analyzed, and the verification using the smart contract is made to find the authenticated user. After the verification, the response is provided for the authenticated user, and the suspicious traffic is utilized for the detection of DDoS attacks using the Poaching Raptor Optimization‐based deep neural network (Poaching Raptor‐based DNN), in which the classifier is tuned using the proposed optimization algorithm to reduce the training loss. The proposed algorithm is designed by hybridizing the habitual practice of the raptor by considering the concurring behavior, hunting style along with poaching behavior of the Lobo to enhance the detection accuracy. After the attack detection, the nonattacker is responded, and the attacker is prevented by entering the IP/MAC address in the logfile. The performance of the proposed method is evaluated in terms of recall, precision, FPR, and accuracy and obtained the values of 96.3%, 98.22%, 3.33%, and 95.12%, respectively.

Open access
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Internet Traffic Analysis and Secure E-voting
Original source
Jan 23, 2023·2023 1st International Conference on Advanced Innovations in Smart Cities (ICAISC)
17 cites
Blockchain Integration with Machine Learning for Securing Fog Computing Vulnerability in Smart City Sustainability

Lukman Adewale Ajao, Simon T. Apeh

The advent of a smart city-based industrial Internet of Things (IIoT) is confidently built on the combined protocols of a virtual IPv6 addressing scheme and the fifth generation (5G) mobile network. For better network service and to achieve Quality of Experience (QoE) in the architecture. But this intelligent city architecture is vulnerable to several cyber-attack and malicious actors at the different layers which make it exposed to the same attacks as in the conventional IPv4 wireless sensor networks. However, this work aims to develop a blockchain-based machine learning (BML) security framework that secures the fog computing layer vulnerability in the smart city’s sustainability. The machine learning approach is firstly implemented between the edge layer and fog server nodes of the city architecture for the variants of intrusion detection using different ML algorithms for the attack’s discovery and classification. While the augmented blockchain technology is implemented between the fog layer and cloud computing to enhance the privacy and confidentiality of packet traffic broadcast to the public. The results obtained from ML-IDS show high-performance detection accuracy and low processing time. While the blockchain framework is also evaluated based on the certmcate generation, and retrieval size in bytes and time in milliseconds.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Network Security and Intrusion Detection
Original source
Jan 23, 2023·Sustainability
16 cites
Improving Collaborative Intrusion Detection System Using Blockchain and Pluggable Authentication Modules for Sustainable Smart City

Rajeev Kumar Gupta, Vedant Chawla, R. K. Pateriya, Piyush Kumar Shukla · 6 authors

The threat of cyber-attacks is ever increasing in today’s society. There is a clear need for better and more effective defensive tools. Intrusion detection can be defined as the detection of anomalous behavior either in the host or in the network. An intrusion detection system can be used to identify the anomalous behavior of the system. The two major tasks of intrusion detection are to monitor data and raise an alert to the system administrators when an intrusion takes place. The current intrusion detection system is incapable of tackling sophisticated attacks which take place on the entire network containing large number of nodes while maintaining a low number of login attempts on each node in the system. A collaborative intrusion detection system (CIDS) was designed to remove the inefficiency of the current intrusion detection system which failed to detect coordinated distributed attacks. The main problem in the CIDS is the concept of trust. Hosts in the network need to trust the data sent by other peers in the network. To bring in the concept of trust and implement the proof-of-concept, blockchain was used. Pluggable authentication modules (PAM) were also used to track login activity securely before an intruder could modify the login activity. To implement blockchain, an Ethereum-based private blockchain was used.

Open access
Network Security and Intrusion Detection
Blockchain Technology Applications and Security
Smart Grid Security and Resilience
Original source
Jan 23, 2023·2023 International Conference on Computer Communication and Informatics (ICCCI)
9 cites
Enhancing the Security for Healthcare Data using Blockchain Technology

T Devi., S. Bangaru Kamatchi, N. Deepa

Cyber security is the safest way to protect the data from hackers and unauthorized users. Healthcare technologies nowadays face lots of cyber security issues related with the security of the health information and privacy of the data. Cyber security is one of the popularized ways to protect the data from hackers and spammers. HealthCare is the field where the data is highly sensitive and the security for the systems is low. Protecting the sensitive data is achieved by the blockchain method, which is similar to a database but the difference is the data stored in the blockchain in blocks. The new blocks included are connected to previous blocks from a chain like structure, it is very secure, each block stores data and also the hash of previous blocks. So, data cannot be easily accessed or manipulated. The mechanism used in blockchain for the security of the data consensus mechanism which contains the different methodologies includes Proof of Work (PoW), Proof of Stake (PoS), Proof of Space and Proof of Authority. Enhanced proof of stake is a combination of the PoS and DPoS used to increase the security of the system by eliminating the 51% attack in blockchain and reduces the data theft threats and protects the medical records of patients from hackers.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Network Security and Intrusion Detection
Original source
Jan 23, 2023·Journal of King Saud University - Computer and Information Sciences
31 cites
Machine learning-based ransomware classification of Bitcoin transactions

Omar Dib, Zhenghan Nan, Jinkua Liu

Ransomware attacks are one of the most dangerous related crimes in the coin market. To increase the challenge of fighting the attack, early detection of ransomware seems necessary. In this article, we propose a high-performance Bitcoin transaction predictive system that investigates Bitcoin payment transactions to learn data patterns that can recognize and classify ransomware payments for heterogeneous bitcoin networks into malicious or benign transactions. The proposed approach makes use of three supervised machine learning methods to learn the distinctive patterns in Bitcoin payment transactions, namely, logistic regression (LR), random forest (RF), and Extreme Gradient Boosting (XGBoost). We evaluate these ML-based predictive models on the BitcoinHeist ransomware dataset in terms of classification accuracy and other evaluation measures such as confusion matrix, recall, and F1-score. It turned out that the experimental results recorded by the XGBoost model achieved an accuracy of 99.08%. As a result, the resulting model accuracy is higher than many recent state-of-the-art models developed to detect ransomware payments in Bitcoin transactions.

Open access
3 source records
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Cybercrime and Law Enforcement Studies
Original source
Jan 20, 2023·Digital Communications and Networks
38 cites
Blockchain-based DDoS attack mitigation protocol for device-to-device interaction in smart home

Bello Musa Yakubu, Majid Iqbal Khan, Abid Khan, Farhana Jabeen · 5 authors

Smart home devices are vulnerable to a variety of attacks. The matter gets more complicated when a number of devices collaborate to launch a colluding attack (e.g. Distributed-Denial-of-Service (DDoS)) in a network (e.g., Smart home). To handle these attacks, most studies have hitherto proposed authentication protocols that cannot necessarily be implemented in devices, especially during Device-to-Device (D2D) interactions. Tapping into the potential of Ethereum blockchain and smart contracts, this work proposes a lightweight authentication mechanism that enables safe D2D interactions in a smart home. The Ethereum blockchain enables the implementation of a decentralized prototype as well as a peer-to-peer distributed ledger system. The work also uses a single server queuing system model and the authentication mechanism to curtail DDoS attacks by controlling the number of service requests in the system. The simulation was conducted twenty times, each with varying number of devices chosen at random (ranging from 1 to 30). Each requester device sends an arbitrary request with a unique resource requirement at a time. This is done to measure the system's consistency across a variety of device capabilities. The experimental results show that the proposed protocol not only prevents colluding attacks, but also outperforms the benchmark protocols in terms of computational cost, message processing, and response times.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Original source
Jan 20, 2023·IEEE Internet of Things Journal
231 cites
A Secure Intrusion Detection Platform Using Blockchain and Radial Basis Function Neural Networks for Internet of Drones

Arash Heidari, Nima Jafari Navimipour, Mehmet Ünal

The Internet of Drones (IoD) is built on the Internet of Things (IoT) by replacing “Things” with “Drones” while retaining incomparable features. Because of its vital applications, IoD technologies have attracted much attention in recent years. Nevertheless, gaining the necessary degree of public acceptability of IoD without demonstrating safety and security for human life is exceedingly difficult. In addition, intrusion detection systems (IDSs) in IoD confront several obstacles because of the dynamic network architecture, particularly in balancing detection accuracy and efficiency. To increase the performance of the IoD network, we proposed a blockchain-based radial basis function neural networks (RBFNNs) model in this article. The proposed method can improve data integrity and storage for smart decision-making across different IoDs. We discussed the usage of blockchain to create decentralized predictive analytics and a model for effectively applying and sharing deep learning (DL) methods in a decentralized fashion. We also assessed the model using a variety of data sets to demonstrate the viability and efficacy of implementing the blockchain-based DL technique in IoD contexts. The findings showed that the suggested model is an excellent option for developing classifiers while adhering to the constraints placed by network intrusion detection. Furthermore, the proposed model can outperform the cutting-edge methods in terms of specificity, F1, recall, precision, and accuracy.

Network Security and Intrusion Detection
Advanced Technologies in Various Fields
Machine Learning and ELM
Original source
Jan 19, 2023·Research Square
1 cites
Vanet FDIA Solutions using Blockchain Based IPFS-Trust Management System with ML SVR Model

Preeti Grover, Sanjeev Kumar Prasad

Abstract The Internet of Vehicles (IoV) is the next phase in the evolution of vehicular ad hoc networks (VANETs).Multiple types of Smart Networks exists in our surrounding.i.e., Wireless Sensor Networks (WSNs), Crowd Sensing Networks (CSNs), and Internet of Vehicles, etc A VANET is a collection of mobile nodes (vehicles) that share data through ad hoc on-demand connections. Vehicle Tracking is one of the uses of IOV(Internet of Vehicles) and Vehicle Security is one of the major issues for all vehicle owners. On a vehicle, there are various on-board sensors that sense a vehicle’s motion and the surrounding environment. On-board sensors can also warn drivers about approaching vehicles, speeding, and slippery road conditions. The main aim of the paper is to provide solutions for False Data Injection Attack by Integration of Blockchain Based IPFS-Trust Management System with ML SVR Regression Model. Due to Network Assaults and Threats under Vanet System, the safety of the drivers is under stake and Critical. A rogue node can send out erroneous messages, causing unavoidable scenarios. We first filter the received data from Vehicles creating false traffic jam warning messages using the Machine learning SVR Regression Model where data is created and split into train and test data. We used Machine learning supervised algorithm to find whether the vehicle is a legitimate vehicle or an attacker vehicle and the result is validated using the parameters like Accuracy, Loss Rate, Precision, Recall, and F-Test Score. Algorithm Implementation results show that the FDIA attack strategy achieves a better performance than the without using ML algorithm of SVR Regression Model based attack strategy in Predicting the Vanet Security. Also, we studied the various ways to mitigate the impact of false data injection into the network through a compromised node. Users can access the system through DApp, an Ethereum-distributed application, and manage their vehicle data.

Open access
Network Security and Intrusion Detection
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Original source
Jan 19, 2023·Istanbul Technical University Academic Open Archive (Istanbul Technical University)
0 cites
Cluster analysis applications of cryptocurrencies

Ezgi Doğan

Tez (Yüksek Lisans) -- İstanbul Teknik Üniversitesi, Lisansüstü Eğitim Enstitüsü, 2023

Open access
Advanced Clustering Algorithms Research
Big Data and Digital Economy
Network Security and Intrusion Detection
Original source
Jan 16, 2023·IEEE Transactions on Network Science and Engineering
123 cites
MiTFed: A Privacy Preserving Collaborative Network Attack Mitigation Framework Based on Federated Learning Using SDN and Blockchain

Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi

Distributed denial-of-service (DDoS) attacks continue to grow at a rapid rate plaguing Internet Service Providers (ISPs) and individuals in a stealthy way. Thus, intrusion detection systems (IDSs) must evolve to cope with these increasingly sophisticated and challenging security threats. Traditional IDSs are prone to zero-day attacks since they are usually signature-based detection systems. The recent advent of machine learning and deep learning (ML/DL) techniques can help strengthen these IDSs. However, the lack of up-to-date labeled training datasets makes these ML/DL based IDSs inefficient. The privacy nature of these datasets and widespread emergence of adversarial attacks make it difficult for major organizations to share their sensitive data. Federated Learning (FL) is gaining momentum from both academia and industry as a new sub-field of ML that aims to train a global statistical model across multiple distributed users, referred to as collaborators, without sharing their private data. Due to its privacy-preserving nature, FL has the potential to enable privacy-aware learning between a large number of collaborators. This paper presents a novel framework, called MiTFed, that allows multiple software defined networks (SDN) domains ($i.e.,$collaborators) to collaboratively build a global intrusion detection model without sharing their sensitive datasets. In particular, MiTFed consists of: (1) a novel distributed architecture that allows multiple SDN based domains to securely collaborate in order to cope with sophisticated security threats while preserving the privacy of each SDN domain; (2) a novel Secure Multiparty Computation (SMPC) scheme to securely aggregate local model updates; and (3) a blockchain based scheme that uses Ethereum smart contracts to maintain the collaboration in a fully decentralized, trustworthy, flexible, and efficient manner. To the best of our knowledge, MiTFed is the first framework that leverages FL, blockchain and SDN technologies to mitigate the new emerging security threats in large scale. To evaluate MiTFed, we conduct several experiments using real-world network attacks; the experimental results using the well-known public network security dataset NSL-KDD show that MiTFed achieves efficiency and high accuracy in detecting the new emerging security threats in both binary and multi-class classification while preserving the privacy of collaborators, making it a promising framework to cope with the new emerging security threats in SDN.

Network Security and Intrusion Detection
Internet Traffic Analysis and Secure E-voting
Software-Defined Networks and 5G
Original source
Jan 12, 2023·arXiv (Cornell University)
12 cites
Explainable Ponzi Schemes Detection on Ethereum

Letterio Galletta, Fabio Pinelli

Blockchain technology has been successfully exploited for deploying new economic applications. However, it has started arousing the interest of malicious actors who deliver scams to deceive honest users and to gain economic advantages. Ponzi schemes are one of the most common scams. Here, we present a classifier for detecting smart Ponzi contracts on Ethereum, which can be used as the backbone for developing detection tools. First, we release a labelled data set with 4422 unique real-world smart contracts to address the problem of the unavailability of labelled data. Then, we show that our classifier outperforms the ones proposed in the literature when considering the AUC as a metric. Finally, we identify a small and effective set of features that ensures a good classification quality and investigate their impacts on the classification using eXplainable AI techniques.

Open access
3 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Network Security and Intrusion Detection
Original source
Jan 1, 2023·IEEE Access
16 cites
SecFedIDM-V1: A Secure Federated Intrusion Detection Model With Blockchain and Deep Bidirectional Long Short-Term Memory Network

Emmanuel Baldwin Mbaya, Emmanuel Adetiba, Joke A. Badejo, John S. Wejin · 9 authors

Cloud computing is a technology for efficiently using computing infrastructures and a business model for selling computing resources and services. However, intruders find such complex and distributed infrastructures appealing targets for cyber-attacks. Cyber-attacks are severe threats that can jeopardize the quality of service provided to clients and compromise data integrity, confidentiality, and availability. Cyber-attacks are becoming more complex, making it more challenging to detect intrusions effectively. Due to the high traffic and increased malicious activities on the Internet, a single Intrusion Detection System (IDS) can be overwhelmed. Despite the various Deep Learning (DL) approaches that have been proposed as alternative solutions, there are still pertinent security issues to be addressed especially in federated cloud computing domains. This work proposes a Secure Federated Intrusion Detection Model Version 1 (SecFedIDM-V1) using blockchain technology and Bidirectional Long Short-Term Memory (BiLSTM) Recurrent Neural Network (RNN). The Cobourg Intrusion Detection Dataset (CIDDS) was acquired, pre-processed and split into 60:20:20, 70:15:15, and 80:10:10 for training, testing, and validation respectively to develop the proposed intrusion traffic classification component of the proposed model. The developed SecFedIDM-V1 was later deployed as a Python-based web application that captures network packets for classifying attacks into normal or an attack type. The attack packets are recorded in a Hyperledger Fabric (a private blockchain technology) to serve as a signature database to be used by other nodes in the network. From the evaluation results of the intrusion classifier, the 80:10:10 BiLSTM network performed better than GRU with a Precision of 0.99624, Recall of 0.99906, F1 Score of 0.99614, False Positive Rate (FPR) of 0.00094, False Negative Rate (FNR) of 0.00395 and True Positive Rate (TPR) of 0.99605. The SecFedIDM-V1 can be deployed alongside Firewalls in a federated cloud computing environment to reinforce the security of the infrastructure.

Open access
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Internet Traffic Analysis and Secure E-voting
Original source
Jan 1, 2023·Computer Systems Science and Engineering
8 cites
A Modified PointNet-Based DDoS Attack Classification and Segmentation in Blockchain

Jieren Cheng, Xiulai Li, Xinbing Xu, Xiangyan Tang · 5 authors

With the rapid development of blockchain technology, the number of distributed applications continues to increase, so ensuring the security of the network has become particularly important. However, due to its decentralized, ... | Find, read and cite all the research you need on Tech Science Press

Open access
Network Security and Intrusion Detection
Anomaly Detection Techniques and Applications
Complex Network Analysis Techniques
Original source
Jan 1, 2023·IEEE Access
18 cites
Blockchain-Assisted Secure Smart Home Network Using Gradient-Based Optimizer With Hybrid Deep Learning Model

Latifah Almuqren, Khalid Mahmood, Sumayh S. Aljameel, Ahmed S. Salama · 6 authors

The Internet of Things (IoT) refers to a technology enabler to enhance the urban physical architecture and render public services. But, public access to accumulated heterogeneous IoT urban information is prone to hackers attacking connected devices to the internet intellectual property as well. IoT security serves a dynamic part in the smart city. Some IoT devices are connected in smart homes, and these connections were centred on gateways. In smart homes, the gateways gain a lot of significance; but their centralized structure causes many security vulnerabilities like availability, integrity, and certification. Unified “cloud-like” computing networks and Blockchain (BC) type systems should be used to sort out these problems. Therefore, this article develops a Blockchain-Assisted Secure Smart Home Network using Gradient Based Optimizer with Hybrid Deep Learning (BSSHN-GBOHDL) model. The presented BSSHN-GBOHDL technique employs BC technology to improve the confidentiality of the data in the smart home environment. In addition, the BSSHN-GBOHDL technique identifies malicious activities in the smart home environment via three sub-processes namely data preprocessing, hybrid deep learning (HDL)-based malicious activity classification, and GBO-based hyperparameter tuning. The GBO algorithm assists in the proficient hyperparameter selection of the HDL model, which aids in accomplishing increased detection efficiency. The experimental validation of the BSSHN-GBOHDL approach is tested on a benchmark NSL-KDD dataset with 65495 normal and 60743 attack samples. The results highlight the betterment of the BSSHN-GBOHDL approach over other recent methods with maximum accuracy of 98.29%.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Internet of Things and AI
Original source