Blockchain-enabled smart contracts have revolutionized the insurance industry due to their potential to streamline backend operations, mitigate fraudulent claims, and enhance data security and transparency. Guided by the design science methodology, the authors propose two specific smart contract frameworks to enhance insurance claims processing related to vehicle damage claims and personal injury claims. These proposed frameworks can improve the overall efficiency and effectiveness of insurance claims processing by automating claims submission, review, analysis, and payment, while reducing fraud and data leakage, by merging various data sources and disintermediation. Furthermore, the authors design a smart contract template supported by eight operational algorithms to facilitate the processing of insurance claims with the help of smart contracts. This template provides practitioners with a standardized prototype for the development of secure and efficient insurance applications.
The role and significance of the cryptocurrency phenomenon is defined. The directions of criminal use of cryptocurrencies are outlined. Algorithms for the use of cryptocurrencies and illegal crypto markets by Russian criminals have been revealed. The prerequisites and features of the use of cryptocurrency mixers and tumblers for the purpose of concealing criminal cryptocurrency operations are disclosed. The decentralized service “Tornado Cash” and the directions of its criminal use are characterized. Modern ways of circumventing sanctions and avoiding sanctions pressure during the purchase of cryptocurrencies by Russian war criminals and hackers have been identified. The features of the functioning of centralized and decentralized cryptocurrency exchanges in the context of existing and probable restrictions on cross-border cryptocurrency payments and p2p transfers by Russians are detailed. The basic provisions of the EU law on AML were considered in order to introduce restrictions on the implementation of anonymous cryptocurrency transactions. The positive experience of Israel in combating the financing of terrorism with the help of cryptocurrencies is highlighted. The further directions of improvement of the mechanisms to prevent the use of cryptocurrencies for the purpose of supporting war criminals and financing terrorism have been identified, including within the framework of regulatory settlement.
Modern advancement in technological field has brought changes into the banking, financial, and capital market in India. Blockchain is a new-age transaction mode that has come into the radar after scams had raised concern pertaining to the regulatory mechanism of blockchain in the legal system of India. Cryptocurrencies that are used as a mode of transfer or payment in India is not regulated by any of the centralized authorities; nor there are any rules, regulations, laws, or guidelines provided for settling of any of the disputes between parties who are dealing the cryptocurrency. They are dealing with their own risk as investors, as there is no involvement of banking or capital market regulators like Reserve Bank of India (RBI) or Securities and Exchange Board of India (SEBI). Cryptocurrency is used anonymously to conduct transactions globally between account holders.
Crypto malware has become a major threat to the security of cryptocurrency holders and exchanges. As the popularity of cryptocurrency continues to rise, so too does the number and sophistication of crypto malware attacks. This paper leverages machine learning techniques to understand the evolution, impact, and detection of cryptocurrency-related threats. We analyse the different types of crypto malware, including ransomware, crypto jacking, and supply chain attacks, and explore the use of machine learning algorithms for detecting and preventing these threats. Our research highlights the importance of using machine learning for detecting crypto malware and compares the effectiveness of traditional methods with deep learning techniques. Through this analysis, we aim to provide insights into the growing threat of crypto malware and the potential benefits of using machine learning in combating these attacks.
The Ponzi scheme, an old-fashioned fraud, is now popular on the Ethereum blockchain, causing considerable financial losses to many crypto investors. A few Ponzi detection methods have been proposed in the literature, most of which detect a Ponzi scheme based on its smart contract source code. This contract-code-based approach, while achieving very high accuracy, is not robust because a Ponzi developer can fool a detection model by obfuscating the opcode or inventing a new profit distribution logic that cannot be detected. On the contrary, a transaction-based approach could improve the robustness of detection because transactions, unlike smart contracts, are harder to be manipulated. However, the current transaction-based detection models achieve fairly low accuracy. In this paper, we aim to improve the accuracy of the transaction-based models by employing time-series features, which turn out to be crucial in capturing the life-time behaviour a Ponzi application but were completely overlooked in previous works. We propose a new set of 85 features (22 known account-based and 63 new time-series features), which allows off-the-shelf machine learning algorithms to achieve up to 30% higher F1-scores compared to existing works.
Tran Viet Khoa, Do Hai Son, Chi-Hieu Nguyen, Dinh Thai Hoang · 11 authors
With the escalating prevalence of malicious activities exploiting vulnerabilities in blockchain systems, there is an urgent requirement for robust attack detection mechanisms. To address this challenge, this paper presents a novel collaborative learning framework designed to detect attacks in blockchain transactions and smart contracts by analyzing transaction features. Our framework exhibits the capability to classify various types of blockchain attacks, including intricate attacks at the machine code level (e.g., injecting malicious codes to withdraw coins from users unlawfully), which typically necessitate significant time and security expertise to detect. To achieve that, the proposed framework incorporates a unique tool that transforms transaction features into visual representations, facilitating efficient analysis and classification of low-level machine codes. Furthermore, we propose an advanced collaborative learning model to enable real-time detection of diverse attack types at distributed mining nodes. Our model can efficiently detect attacks in smart contracts and transactions for blockchain systems without the need to gather all data from mining nodes into a centralized server. In order to evaluate the performance of our proposed framework, we deploy a pilot system based on a private Ethereum network and conduct multiple attack scenarios to generate a novel dataset. To the best of our knowledge, our dataset is the most comprehensive and diverse collection of transactions and smart contracts synthesized in a laboratory for cyberattack detection in blockchain systems. Our framework achieves a detection accuracy of approximately 94% through extensive simulations and 91% in real-time experiments with a throughput of over 2,150 transactions per second.
Abstract Despite the rapid growth of the cyber insurance market in recent years, insurance companies in this area face several challenges, such as a lack of data, a shortage of automated tasks, increased fraudulent claims from legal policyholders, attackers masquerading as legal policyholders, and insurance companies becoming targets of cybersecurity attacks due to the abundance of data they store. On top of that, there is a lack of Know Your Customer procedures. To address these challenges, in this article, we present , an innovative architecture that utilizes Blockchain technology to provide data transparency and traceability. The backbone of the architecture is complemented by Smart Contracts, which automate cyber insurance processes, and Self-Sovereign Identity for robust identification. The effectiveness of ’s architecture is compared with the literature against the challenges the cyber insurance industry faces. In a nutshell, our approach presents a significant advancement in the field of cyber insurance, as it effectively combats the issue of fraudulent claims and ensures proper customer identification and authentication. Overall, this research demonstrates a novel and effective solution to the complex problem of managing cyber insurance, providing a solid foundation for future developments in the field.
The rise of blockchain technology and smart contracts has brought widespread attention due to their capacity to transform multiple industrial sectors through decentralized, transparent, secure transactions. However, despite their promise to revolutionize various fields worldwide, lingering concerns regarding security risks impede their adoption rate. Addressing these concerns is crucial now more than ever; therefore, we conducted a comprehensive literature review within our study's scope that focused on published papers between 2014-2023 centered around security risks concerning blockchain and smart contracts. Our systematic approach using the PRISMA checklist analyzed nine categorized research model-based primary studies while recognizing vulnerabilities in smart contract development and providing best practices to mitigate such issues. These findings benefit both researchers and practitioners as they showcase how acknowledging these vulnerabilities can further develop into exploring more significant aspects of blockchain technology's security issues and smart contract development processes. Our study contributes significantly by expanding knowledge in this field while providing novel insights valuable for individuals involved in designing or implementing blockchain technologies.
The cyberspace is a convenient platform for creative, intellectual, and accessible works that provide a medium for expression and communication. Malware, phishing, ransomware, and distributed denial-of-service attacks pose a threat to individuals and organisations. To detect and predict cyber threats effectively and accurately, an intelligent system must be developed. Cybercriminals can exploit Internet of Things devices and endpoints because they are not intelligent and have limited resources. A hybrid decision tree method (HIDT) is proposed in this article that integrates machine learning with blockchain concepts for anomaly detection. In all datasets, the proposed system (HIDT) predicts attacks in the shortest amount of time and has the highest attack detection accuracy (99.95% for the KD99 dataset and 99.72% for the UNBS-NB 15 dataset). To ensure validity, the binary classification test results are compared to those of earlier studies. The HIDT’s confusion matrix contrasts with previous models by having low FP/FN rates and high TP/TN rates. By detecting malicious nodes instantly, the proposed system reduces routing overhead and has a lower end-to-end delay. Malicious nodes are detected instantly in the network within a short period. Increasing the number of nodes leads to a higher throughput, with the highest throughput measured at 50 nodes. The proposed system performed well in terms of the packet delivery ratio, end-to-end delay, robustness, and scalability, demonstrating the effectiveness of the proposed system. Data can be protected from malicious threats with this system, which can be used by governments and businesses to improve security and resilience.
Weichu Deng, Huanchun Wei, Teng Huang, Cong Cao · 6 authors
With the rapid development and widespread application of blockchain technology in recent years, smart contracts running on blockchains often face security vulnerability problems, resulting in significant economic losses. Unlike traditional programs, smart contracts cannot be modified once deployed, and vulnerabilities cannot be remedied. Therefore, the vulnerability detection of smart contracts has become a research focus. Most existing vulnerability detection methods are based on rules defined by experts, which are inefficient and have poor scalability. Although there have been studies using machine learning methods to extract contract features for vulnerability detection, the features considered are singular, and it is impossible to fully utilize smart contract information. In order to overcome the limitations of existing methods, this paper proposes a smart contract vulnerability detection method based on deep learning and multimodal decision fusion. This method also considers the code semantics and control structure information of smart contracts. It integrates the source code, operation code, and control-flow modes through the multimodal decision fusion method. The deep learning method extracts five features used to represent contracts and achieves high accuracy and recall rates. The experimental results show that the detection accuracy of our method for arithmetic vulnerability, re-entrant vulnerability, transaction order dependence, and Ethernet locking vulnerability can reach 91.6%, 90.9%, 94.8%, and 89.5%, respectively, and the detected AUC values can reach 0.834, 0.852, 0.886, and 0.825, respectively. This shows that our method has a good vulnerability detection effect. Furthermore, ablation experiments show that the multimodal decision fusion method contributes significantly to the fusion of different modalities.
The Move smart contract (MSC) is designed to enhance the type security of digital assets by utilizing a resource-based structure. However, vulnerabilities may be introduced during the development process. In response to the security threats faced by digital assets in the MSC, we have identified five resource-related vulnerabilities for the first time. Additionally, we have defined two test oracles and proposed a method to detect these vulnerabilities in the MSC using resource-flow analysis. Our method begins by analyzing the resource types present in the MSC. Based on the resource operation information within the contract function, we create a resource-flow graph. Next, the resource-flows are derived from the Resource-Flow Graph using a traversal algorithm, and they are then transformed into test cases. In the final step, the generated test cases are executed, and the vulnerabilities are detected by utilizing the proposed test oracles. Through a comprehensive case study, we showcase the various resource-related vulnerabilities and assess the feasibility of our method in detecting these vulnerabilities. The results demonstrate that our proposed method is effective in identifying resource-related vulnerabilities.
Danielle Alves Batista, Ana Mangeth, Isabella Frajhof, Paulo Henrique Alves · 8 authors
Blockchain technology, initially known for its applications in the financial industry, has emerged as a promising solution for various other domains. One prominent area for the use of blockchain-based solutions is forensics, specifically the chain of custody maintenance and control. While there have been numerous research projects exploring the use of blockchain technology in digital forensics, limited attention has been given to its application in controlling of the physical evidence chain of custody. In this research, we aim to explore the literature on the use of blockchain technology to solve problems related to the physical evidence chain of custody. Through a systematic literature review (SLR), we analyzed 26 resources discussing blockchain-based solutions for evidence chain of custody issues, based on requirements that could be applied to both physical and digital evidence. The results showed that there is a lack of studies involving the use of blockchain technology to solve problems related to the physical evidence chain of custody, and future research should focus on solving the issue.
Smart contract runs on blockchain platforms and plays a critical role in decentralized applications. Unfortunately, since smart contracts manage valuable digital assets, attacks against them can result in substantial economic losses. Especially, most of the attack are carried out by exploiting the vulnerabilities in smart contracts. Aiming to perform efficient and comprehensive identification for contract vulnerabilities, there emerges a number of research on smart contract security and vulnerability detection. This paper provides a comprehensive surveys on various smart contract vulnerabilities and corresponding detection methods proposed in recent years. Meanwhile, this paper implements an automatic discover approach by using static analysis for smart contract vulnerability, which can effectively identify and localize vulnerabilities within contracts. Experimental results show this method can precisely locate and classify contract vulnerabilities.
Currently, Deep learning techniques are being investigated by researchers as a way to automatically detect smart contract flaws. This strategy seeks to get beyond the drawbacks of employing expert-defined patterns for detecting vulnerabilities in smart contracts, such as low detection rates and inefficiencies. However, The majority of recent research focuses on extracting features from smart contract code using a single code representation, such as an abstract syntax tree, control flow graph, or program dependency graph. These single code representations may lead to erroneous vulnerability detection and missing semantic information. This paper introduces a method called FBB-VD that uses a graph neural network to combine multiple code representations and detect vulnerabilities in smart contracts. This method can cover a wider range of code and detect vulnerabilities more accurately through more detailed features. The FBB-VD method is more successful and accurate in identifying vulnerabilities in smart contracts when compared to approaches that just transform smart contracts into abstract syntax trees, control flow graphs, or program dependency graphs.
Purpose This study aims to, firstly, develop a red flag checklist for cryptocurrency Ponzi schemes and, secondly, to test this red flag checklist against publicly available marketing material for Mirror Trading International (MTI). The red flag checklist test seeks to establish if MTI’s marketing material posted on YouTube ® (in the form of a live video presentation) exhibits any of the red flags from the checklist. Design/methodology/approach The study uses a structured literature review and qualitative analysis of red flags for Ponzi and cryptocurrency Ponzi schemes. Findings A research lacuna was discovered with regard to cryptocurrency Ponzi scheme red flags. By means of a structured literature review, journal papers were identified that listed and discussed Ponzi scheme red flags. The red flags from the identified journal papers were subsequently used in a qualitative analysis. The analyses and syntheses resulted in the development of a red flag checklist for cryptocurrency Ponzi schemes, with five red flag categories, containing 18 associated red flags. The red flag checklist was then tested against MTI’s marketing material (a transcription of a live YouTube presentation). The test resulted in MTI’s marketing material exhibiting 88% of the red flags contained within the checklist. Research limitations/implications The inherent limitations in the design of using a structured literature review and the lack of research regarding the cryptocurrency Ponzi scheme red flags. Practical implications The study provides a red flag checklist for cryptocurrency Ponzi schemes. The red flag checklist can be applied to a cryptocurrency investment scheme’s marketing material to establish if it exhibits any of these red flags. Social implications The red flag checklist can be applied to a cryptocurrency investment scheme’s marketing material to establish if it exhibits any of these red flags. Originality/value The study provides a red flag checklist for cryptocurrency Ponzi schemes.
Mohammed A. Mohammed, Manel Boujelben, Mohamed Abid
Recently, the advent of blockchain (BC) has sparked a digital revolution in different fields, such as finance, healthcare, and supply chain. It is used by smart healthcare systems to provide transparency and control for personal medical records. However, BC and healthcare integration still face many challenges, such as storing patient data and privacy and security issues. In the context of security, new attacks target different parts of the BC network, such as nodes, consensus algorithms, Smart Contracts (SC), and wallets. Fraudulent data insertion can have serious consequences on the integrity and reliability of the BC, as it can compromise the trustworthiness of the information stored on it and lead to incorrect or misleading transactions. Detecting and preventing fraudulent data insertion is crucial for maintaining the credibility of the BC as a secure and transparent system for recording and verifying transactions. SCs control the transfer of assets, which is why they may be subject to several adverbial attacks. Therefore, many efforts have been proposed to detect vulnerabilities and attacks in the SCs, such as utilizing programming tools. However, their proposals are inadequate against the newly emerging vulnerabilities and attacks. Artificial Intelligence technology is robust in analyzing and detecting new attacks in every part of the BC network. Therefore, this article proposes a system architecture for detecting fraudulent transactions and attacks in the BC network based on Machine Learning (ML). It is composed of two stages: (1) Using ML to check medical data from sensors and block abnormal data from entering the blockchain network. (2) Using the same ML to check transactions in the blockchain, storing normal transactions, and marking abnormal ones as novel attacks in the attacks database. To build our system, we utilized two datasets and six machine learning algorithms (Logistic Regression, Decision Tree, KNN, Naive Bayes, SVM, and Random Forest). The results demonstrate that the Random Forest algorithm outperformed others by achieving the highest accuracy, execution time, and scalability. Thereby, it was considered the best solution among the rest of the algorithms for tackling the research problem. Moreover, the security analysis of the proposed system proves its robustness against several attacks which threaten the functioning of the blockchain-based healthcare application.
The IoT (Internet of Things) encompasses numerous networks and connected devices. One of the primary concerns surrounding IoT, according to researchers and security experts, is the potential risks to privacy and cybersecurity. Deep learning offers significant capabilities for self-adjustment, self-organization, and generalization. Recognizing this, advanced deep learning algorithms are employed in this research to address the privacy and security issues plaguing the IoT landscape. To address these concerns, a novel model called BC-Trans Network is proposed, leveraging the strengths of both Blockchain technology and a transformer component. The transformer plays a vital role in identifying abnormal data, enabling the system to take proactive measures against potential threats. In addition Hash-2 is introduced for the verification of IoT users, adding an extra layer of security to the authentication process. The Blockchain model is utilized to securely store user passwords and details, ensuring a robust and tamper-proof authentication mechanism. To validate the proposed model, a publicly available dataset CSE-CIC-IDS2018 is employed. Pre-processing techniques, including feature selection using the chi-square method, are applied to refine the dataset. The transformer module then classifies the data as normal or abnormal, allowing for accurate identification of potential security breaches. To further safeguard the data and protect the privacy of users, a Fully Homomorphic Encryption (FHE) method is employed. This advanced encryption enables the encryption of categorized normal data, ensuring its confidentiality even during transmission and storage. The study's findings support IoT-cloud server security and privacy by demonstrating the effectiveness of the suggested paradigm in identifying and thwarting network threats. With detection times of 225.3 seconds, an accuracy of 99.25%, a precision of 99.53%, a recall of 99.32%, and an F1 score of 99.59%, the proposed system exhibits impressive performance. Furthermore, as the output numbers increase, the system's metrics improve, suggesting its scalability and flexibility.
Abstract This work considers a combinatorial optimization problem in graphs, the nilcatenation problem, and investigates its potential application for detecting money laundering activities in cryptocurrency networks. The nilcatenation problem consists of finding a set of arcs that can be removed from an arc‐weighted directed graph without changing the balance of any vertex. The balance of a vertex is defined as the difference between the sum of the weights of outgoing and incoming arcs. We propose a 0/1 integer linear programming formulation and a local branching algorithm. The approaches are computationally evaluated and compared using three sets of test instances, two of them generated from Bitcoin's testnet and mainnet networks. An experiment on the testnet showed that it is possible to retrieve a nilcatenation artificially introduced with fake bitcoin transactions. Experiments on the mainnet showed that it is possible to find large nilcatenations, possibly indicating money laundering activities.
The Internet of Things (IoT) has become a focus of information infrastructure development in recent years. The smart blockchain can provide various solutions for trust, security, and privacy (TSP) challenges to protect IoT data, and smart contracts are the foundation of blockchain intelligence, and greatly enhance the ability of smart blockchain to solve TSP problems. So, the security of smart contracts must be addressed. We propose an efficient smart contract vulnerability detector to improve the safety of smart contracts. It comprises a graph extraction method and a complete vulnerability detection process. The graph extraction method consists of vulnerability pattern extraction and a graph generation process. The vulnerability detection process first uses the approximate graph matching algorithm to select representative SCGraphs from the data set to build vulnerability SCGraph libraries. Second, determine whether the contract contains vulnerabilities by calculating the similarity between the SCGraphs generated from the contracts to be detected and the SCGraphs in the vulnerability library. Experiments show that our approach achieves an inspiring high detection rate and is the fastest among existing vulnerability detection tools, which indicates that it can provide good vulnerability detection for smart contracts.
In recent years, Ethereum has become a hotspot for criminal activities such as phishing scams that seriously compromise Ethereum transaction security. However, existing methods cannot accurately model Ethereum transaction data and make full use of the temporal structure information and basic account features. In this paper, we propose an Ethereum phishing detection framework based on temporal motif features. By designing a sampling method, we convert labeled Ethereum addresses into multi-directed transaction subgraphs with time and amount to avoid losing structure and attribute information. To learn representations for subgraphs, we define and extract the temporal motif features and general transaction features. Extensive experiments on Support Vector Machine, Random Forest, Logistic Regression, and XGBoost demonstrate that our method significantly outperforms all baselines and provides an effective phishing scams detection for Ethereum.
Abstract The rise of Non-Fungible Tokens (NFTs) is beginning to revolutionize the digital world thanks to the unique property of these tokens. Indeed, they can represent the ownership of physical or digital assets. They are implemented using smart contracts, therefore if the code of the smart contract contains bugs, an attacker can exploit its vulnerabilities to perform an attack called sleepminting. Sleepminting consists of transferring NFTs owned by an address, without the owner’s consent. In this paper, we provide a detailed analysis of the sleepminting attack and, thanks to the insights gained, we propose a prevention system to reduce the number of sleepminting attacks. Our prevention system is based on analysing the transactions included in new blocks, detecting those that are related to sleepminting attacks and keeping track of the addresses that are involved in these transactions. A dictionary-like data structure can be used to keep track of the addresses involved, where the key is the address and the value acts as a counter for the number of times the address is involved in sleepminting. With this information, block-creating nodes can add another verification step before adding a transaction to a block, which consists of blocking transactions when the addresses involved appear in sleepminting attacks a number of times greater than a threshold. The evaluation shows that sleepminting is a relevant phenomenon, and now it involves NFT transfers rather than NFT minting. Our proposed prevention system is able to block up to 87% of attacks.
Smart contracts have driven the development of blockchain technology, but their security vulnerabilities pose numerous problems for blockchain applications.The existing smart contract vulnerability detection methods based on deep learning are not comprehensive in detecting vulnerability categories, have low accuracy, and are limited to binary classification tasks. This paper proposes a smart contract vulnerability detection model called SCGRU combining CNN and bidirectional gating recurrent unit-attention mechanism (BiGRU-Attention) for Ethereum smart contracts to solve these problems. The model transforms the standardized data into word vectors representation of smart contracts with semantic information through the Word2Vec word embedding module. The feature extraction module takes the word vector as input. It uses CNN and BiGRU training to extract high-level abstract features and sequence features of the smart contract respectively. Following the BiGRU feature extraction, an attention mechanism is introduced to highlight the key features related to vulnerabilities of the smart contract code. The features extracted by CNN are concatenated with the features extracted by BiGRU-Attention as the input to the vulnerability classification module. The softmax function normalizes the vulnerability classification module to complete the detection of vulnerabilities in Ethereum smart contracts. The experiments in this paper show that SCGRU has a high accuracy rate of vulnerability detection on the current public dataset. Moreover, SCGRU can identify all categories of smart contract vulnerabilities in the dataset with an average accuracy rate of 92.64%, among which the precision of Infinite Loop vulnerability detection is 99.06%.