Hao Sui, Jiale Zhang, Xiaobing Sun, Bing Chen · 6 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,600 results · page 27 of 67
Hao Sui, Jiale Zhang, Xiaobing Sun, Bing Chen · 6 authors
No abstract is available for this record.
Yanmei Zhang, Yuwen Su
No abstract is available for this record.
Meng Huang, Jia Yang, Cong Liu
No abstract is available for this record.
Abebe Diro, Lu Lu Zhou, Akanksha Saini, Shahriar Kaisar · 5 authors
No abstract is available for this record.
Weijie Chen, Ran Guo, Guopeng Wang, Lejun Zhang · 9 authors
No abstract is available for this record.
Duc Khai Lam, Quoc Linh Phan, Quoc Truong Nguyen, Van Quang Tran
No abstract is available for this record.
Sulyab Thottungal Valapu, Tamoghna Sarkar, Jared Coleman, Anusha Avyukt · 8 authors
We introduce DARSAN, a decentralized review system designed for Non-Fungible Token (NFT) marketplaces, to address the challenge of verifying the quality of highly resalable products with few verified buyers by incentivizing unbiased reviews. DARSAN works by iteratively selecting a group of reviewers (called ``experts'') who are likely to both accurately predict the objective popularity and assess some subjective quality of the assets uniquely associated with NFTs. The system consists of a two-phased review process: a ``pre-listing'' phase where only experts can review the product, and a ``pre-sale'' phase where any reviewer on the system can review the product. Upon completion of the sale, DARSAN distributes incentives to the participants and selects the next generation of experts based on the performance of both experts and non-expert reviewers. We evaluate DARSAN through simulation and show that, once bootstrapped with an initial set of appropriately chosen experts, DARSAN favors honest reviewers and improves the quality of the expert pool over time without any external intervention even in the presence of potentially malicious participants.
Myles Lewis
As time progresses, the need for more secure applications grows exponentially. The different types of sensitive information that is being transferred virtually has sparked a rise in systems that leverage blockchain. Different sectors are beginning to use this disruptive technology to evaluate the risks and benefits. Sectors like finance, medicine, higher education, and wireless communication have research regarding blockchain. Futhermore, the need for security standards in this area of research is pivotal. In recent past, several attacks on blockchain infrastructures have resulted in hundreds of millions dollars lost and sensitive information compromised. Some of these attacks include DAO attacks, bZx attacks, and Parity Multisignature Wallet Double Attacks which targeted vulnerabilities within smart contracts on the Ethereum network. These attacks exposed the weaknesses of current smart contract development practices which has led to the increase in distrust and adoption of systems that leverage blockchain for its functionality. In this paper, I identify common software vulnerabilities and attacks on blockchain infrastructures, thoroughly detail the smart contract development process and propose a model for ensuring a stronger security standard for future systems leveraging smart contracts. The purpose for proposing a model is to promote trust among end users in the system which is a foundational element for blockchain adoption in the future.
Ankit Mundra, Jai Prakash Mishra, Harshit Jha, Chityanj Sharma
No abstract is available for this record.
Jing Wang, Senkai Wu, Hai Liang, Yong Ding · 5 authors
Aim: A blockchain provides data consistency and builds a fair mining environment for a network by using a consensus mechanism such as proof of work (PoW) and proof of stake. However, selfish mining is a well-known mining attack. It can reduce the fairness and destabilize the network, especially for a PoW-based blockchain. Therefore, in this paper, we propose a new approach, named the adaptive mining difficulty adjustment protocol, which can deter a selfish attack. Methods: We propose using the unit profit as an improved version of the relative revenue, because it is more flexible for calculating the miners’ profits in different periods and can be used to analyze repeated mining games. Based on the unit profit, we propose using the adaptive mining-difficulty adjustment protocol to reduce an attacker’s profit. Our protocol evaluates the effective hash power in a network more accurately and corrects the mining difficulty. Moreover, we introduce the discount factor and model the long-term profit to analyze the impact of a miner’s patience on its future profit. Results: We used an open-source simulator to simulate the competition between a selfish miner and an honest miner and determined their profits under different protocols. Our experimental results show that our protocol can effectively raise the attack threshold, but it reduces the total network profit if the attacker still attacks. However, the long-term profit model shows that a more patient attacker needs to invest more hash power and pay increased mining costs to maintain its attack. Conclusion: We conclude that, under our protocol, selfish attackers will tend to become honest miners if their hash power does not exceed the threshold, which means that our protocol can effectively deter selfish attacks and some variants of selfish attacks. Briefly, our protocol can correct the mining difficulty and leads to a more stable and fairer mining environment for a PoW-based blockchain.
Zhipeng Wang, Xihan Xiong, William J. Knottenbelt
No abstract is available for this record.
Suparat Srifa, Yury Yanovich, Ahmad Salehi Shahraki, Robert Vasilyev · 6 authors
No abstract is available for this record.
Wanyi Gu, Guojun Wang, Peiqiang Li, Xubin Li · 7 authors
No abstract is available for this record.
Swati Jadhav, Siddhant Nawale, Vaishnav Loya, Varun Gujarathi · 5 authors
No abstract is available for this record.
Yousra Belfaik, Yassine Sadqi, Yassine Maleh, Safi Said · 6 authors
OpenID Connect (OIDC) is one of the most widely used delegated authentication protocols in web and mobile applications providing a single sign-on experience. It allows third-party applications, called Relying Parties (RP), to securely request and receive information about authenticated sessions and end-users from an identity provider. The OIDC specification defines several parameters, including the client_id, client_secret, authorization code, access token, id token, state, and redirect_uri, as keys to the protocol operation, with significant security and privacy implications. Therefore, securing these parameters is critical to prevent attackers from impersonating legitimate entities, gaining unauthorized access, having complete control over users’ accounts, and/or violating their privacy. To enhance OIDC security and preserve its users’ privacy, we propose a novel model for OIDC based on the Ethereum Blockchain and the non-fungible token (ERC721) standard. To prove the robustness and safety of the proposed system, we perform a detailed security analysis formally using the most widely accepted protocols security verification tools, AVISPA and Scyther, and informally by discussing various attacks. The analysis results show that the proposed system is resilient against well-known attacks. Furthermore, we evaluate the cost and performance of the proposed solution, confirming its affordability and assuring that our approach does not impact the user experience and performance of existing OIDC-based systems. Finally, we conduct a security and privacy comparative analysis with similar existing systems, proving the superiority and efficiency of our proposed Blockchain-based OIDC system.
Xiangbin Li, Xiaofei Xing, Guojun Wang, Peiqiang Li · 5 authors
No abstract is available for this record.
Chidimma Opara, Yingke Chen, Bo Wei
No abstract is available for this record.
Satpal Singh Kushwaha, Sandeep Joshi, Amit Gupta
The technology behind blockchain is quickly becoming one of the most crucial innovations in recent years. The Smart contracts are digital agreements, made in between two untrusted parties. Smart contracts are self-executable small piece of code that gets executed due to some predefined triggering conditions. Smart contracts store cryptocurrencies as their balances and deal in cryptocurrencies on network transactions. Because of this, smart contracts are constantly open to the possibility of being attacked. A single security vulnerability can make the smart contract very much insecure. The immutability property of the blockchain ensures that, once a smart contract has been placed on the blockchain, cannot be modified in any way. So, the smart contract must be analyzed for any kind of security vulnerability before its deployment on the blockchain. Existing analysis approaches detect vulnerabilities with high false positive rates. Our proposed approach analyses the smart contracts using a hybrid combination of pattern matching and symbolic execution, which produces results with a low false positive rate. We have performed a comparative analysis of our proposed approach to prove its efficiency with the existing research approaches on a data set of 453 smart contracts with tagged vulnerabilities.
Jiajing Wu, Kaixin Lin, Dan Lin, Ziye Zheng · 6 authors
No abstract is available for this record.
Chang Xu, Shiyao Zhang, Liehuang Zhu, Xiaodong Shen · 5 authors
No abstract is available for this record.
A. Gómez RamÃrez, Loui Al Sardy, Francis Gomez Ramirez
Blockchain security is becoming increasingly relevant in today's cyberspace as it extends its influence in many industries. This paper focuses on protecting the lowest level layer in the blockchain, particularly the P2P network that allows the nodes to communicate and share information. The P2P network layer may be vulnerable to several families of attacks, such as Distributed Denial of Service (DDoS), eclipse attacks, or Sybil attacks. This layer is prone to threats inherited from traditional P2P networks, and it must be analyzed and understood by collecting data and extracting insights from the network behavior to reduce those risks. We introduce Tikuna, an open-source tool for monitoring and detecting potential attacks on the Ethereum blockchain P2P network, at an early stage. Tikuna employs an unsupervised Long Short-Term Memory (LSTM) method based on Recurrent Neural Network (RNN) to detect attacks and alert users. Empirical results indicate that the proposed approach significantly improves detection performance, with the ability to detect and classify attacks, including eclipse attacks, Covert Flash attacks, and others that target the Ethereum blockchain P2P network layer, with high accuracy. Our research findings demonstrate that Tikuna is a valuable security tool for assisting operators to efficiently monitor and safeguard the status of Ethereum validators and the wider P2P network
Jinghao Li, Hexiao Li, Na Cheng, Wuqing Zhang · 7 authors
With the prevalent adoption of blockchain in the financial system, there has been an increase in phishing scams on cryptocurrency platforms such as Ethereum, and an effective anomaly detection method is urgently required. The latest studies have focused on anomaly identification using natural language processing techniques or constructing simple static graphs. However, the existing methods are insufficient to convey the diversity of connectivity patterns in the Ethereum transaction network concerning amount and time. To this end, we proposed a novel transaction network embedding algorithm transE based on the multi-channel random walk to model the detection of Ethereum phishing scam accounts as a multigraph node classification task. Specifically, we first model the Ethereum transaction as a time-amount directed multigraph. Then, the hybrid feature representation of network nodes is learned via transE from their local and global neighbours, which uses the attention mechanism to maximize the probability of preserving node network neighbours. Ultimately, we employ visualization techniques and machine learning models to validate the effectiveness of the algorithms, and the model with the top performance is picked for Ethereum account classification. Experimental results indicate that the embedding vector extracted by transE improves the detection accuracy of Ethereum phishing accounts in the different classification tasks.
T. M. Nithya, A. Amrita Varsheni, S. Brindha
The volume of information on the internet is currently rising dramatically. Social media platforms/e-commerce market place is producing a lot of data, including reviews, comments, and opinions, every day. As there are a number of fake reviews should incorporate Spam detection to produce a genuine opinion. Fake reviews are growing problem in online shopping, and they have a significant impact on consumer’s decision-making. Many people today base their decisions when choosing a product or service on social media opinions. Because so many false or phoney evaluations have been written by businesses or individuals for a variety of reasons, detecting opinion spam is a difficult and time-consuming task. They produce fictitious reviews to deceive users or automated detection systems by elevating or degrading the reputations of their target products in order to elevate or lower them. In this article, we’ll regulate it by leveraging blockchain technology to make the review system more authentic by allowing only legitimate product purchasers to submit evaluations using their account credentials. We use the Ethereum blockchain to authenticate user credentials, and we only permit verified users to purchase things. Also, we only permit customers to leave reviews or comments on products, ensuring that the reviews are accurate.
Ken Huang
No abstract is available for this record.