Gang Liu, Chi‐Yuan Chen, Jingyuan Han, Yi Zhou · 5 authors
The Internet of Things (IoT) suffers from a profound lack of trust between central gateways and sensors, e.g., gateways suspect sensors of flooding malicious packets, and vice versa, sensors suspect gateways of manipulating traffic data. One important reason for the mistrust is the asymmetry of a centralized network organization. A Decentralized Autonomous Organization (DAO) can establish a trustful and symmetric network with the blockchain. However, it is a vacant area for IoT networks to build trust between gateways and sensors within the DAO. In this paper, we firstly propose a trustful and secure IoT Network DAO solution (NetDAO) to mitigate the data manipulation and the malicious flooding packets. In particular, the NetDAO has a security rating algorithm to assign a reputation value for each entity in the network. Based on this, each entity can mitigate the malicious flooding packets using a proof-of-reputation packet-forwarding mechanism. In addition, the NetDAO stores traffic data using the blockchain to mitigate the data manipulation. The experimental results show that the NetDAO effectively mitigates malicious flooding packets and costs 1 s for ∼480 entities to complete the rating algorithm.
Numerous resource-constrained Internet of Things (IoT) devices make the edge IoT consisting of unmanned aerial vehicles (UAVs) vulnerable to network intrusion. Therefore, it is critical to design an effective intrusion detection system (IDS). However, the differences in local data sets among UAVs show small samples and uneven distribution, further reducing the detection accuracy of network intrusion. This article proposes a conditional generative adversarial net (CGAN)-based collaborative intrusion detection algorithm with blockchain-empowered distributed federated learning to solve the above problems. This study introduces long short-term memory (LSTM) into the CGAN training to improve the effect of generative networks. Based on the feature extraction ability of LSTM networks, the generated data with CGAN are used as augmented data and applied in the detection and classification of intrusion data. Distributed federated learning with differential privacy ensures data security and privacy and allows collaborative training of CGAN models using multiple distributed data sets. Blockchain stores and shares the training models to ensure security when the global model’s aggregation and updating. The proposed method has good generalization ability, which can greatly improve the detection of intrusion data.
Mikail Mohammed Salim, Alowonou Kowovi Comivi, Tojimurotov Nurbek, Heejae Park · 5 authors
Resource constraints in the Industrial Internet of Things (IIoT) result in brute-force attacks, transforming them into a botnet to launch Distributed Denial of Service Attacks. The delayed detection of botnet formation presents challenges in controlling the spread of malicious scripts in other devices and increases the probability of a high-volume cyberattack. In this paper, we propose a secure Blockchain-enabled Digital Framework for the early detection of Bot formation in a Smart Factory environment. A Digital Twin (DT) is designed for a group of devices on the edge layer to collect device data and inspect packet headers using Deep Learning for connections with external unique IP addresses with open connections. Data are synchronized between the DT and a Packet Auditor (PA) for detecting corrupt device data transmission. Smart Contracts authenticate the DT and PA, ensuring malicious nodes do not participate in data synchronization. Botnet spread is prevented using DT certificate revocation. A comparative analysis of the proposed framework with existing studies demonstrates that the synchronization of data between the DT and PA ensures data integrity for the Botnet detection model training. Data privacy is maintained by inspecting only Packet headers, thereby not requiring the decryption of encrypted data.
Cyber physical system (CPS) is a network of cyber and physical elements, which interact with one another in a feedback form. CPS approves critical infrastructure and is treated as essential in day to day since it forms the basis of futuristic smart devices. An increased usage of CPSs poses security as a challenging issue and intrusion detection systems (IDS) can be applied for the identification of network intrusions. The latest advancements in the field of artificial intelligence (AI) and deep learning (DL) enables to design effective IDS models for the CPS environment. At the same time, metaheuristic algorithms can be employed as a feature selection approach in order to reduce the curse of dimensionality. With this motivation, this study develops a novel Poor and Rich Optimization with Deep Learning Model for Blockchain Enabled Intrusion Detection in CPS Environment, called PRO-DLBIDCPS technique. The proposed PRO-DLBIDCPS technique initially introduces an Adaptive Harmony Search Algorithm (AHSA) based feature selection technique for proper selection of feature subsets. For intrusion detection and classification, and attention based bi-directional gated recurrent neural network (ABi-GRNN) model is applied. In addition, the detection efficiency of the ABi-GRNN technique has been enhanced by the use of Poor and rich optimization (PRO) algorithm based hyperparameter optimizer, which resulted in enhanced intrusion detection results. Furthermore, blockchain technology is applied for enhancing security in the CPS environment. In order to demonstrate the enhanced outcomes of the PRO-DLBIDCPS technique, a wide range of simulations was carried out on benchmark dataset and the results reported the better outcomes of the PRO-DLBIDCPS technique in terms of several measures.
João Paulo de Brito Gonçalves, Gustavo Alochio, Rodolfo da Silva Villaça, Roberta Lima Gomes
The fifth-generation (5G) wireless networks are expected to provide various services compared to the 4G and previous generations of networks. The Quality of Service requirements can be quite different in terms of latency, bandwidth, reliability, and availability. 5G technology allows the fragmentation of the network into small pieces, known as network slices. This network slicing is done by specific tools and the configuration must be protected from attacks that may be performed by malicious users. Thus in this paper, a solution to protect and prevent these failures from happening is addressed. For this solution to be carried out, a study was conducted on the Blockchain technology, as well as the use of Oracles in order to implement an integrity verification system, a system capable of assuring 5G network slices' configuration integrity through a complete architecture involving Blockchain, Smart Contracts and Oracles.
Gopal Gurung, Gueltoum Bendiab, Maria Shiaele, Stavros Shiaeles
Due to the colossal advancement of cyber security threats and attacks, intrusion detection system (IDS) seems to shift their culture toward more collaborative working methods. An aggressor can exploit these vulnerabilities and penetrate the network organisation. There is a tremendous demand for larger networking set-ups to be secured in order to protect from malicious activities. Collaborative Intrusion Detection Networks (CIDN) techniques have been deployed in pragmatic scenarios to maximise the realistic detection performance, allowing a collection of IDS nodes to share and communicate mandatory information, such as signature-based IDS and attack alerts. Due to the distributed system of CIDN, there is an immense likelihood of insider security threats presenting the susceptibility of the system. In this paper, we examine the potential of Blockchain technology to enhance the robustness and efficiency of CIDSs in terms of trust management by proposing a CIDSs architecture based on Hyperledger Fabric and Snort IDS.
Since the inception of Bitcoin in 2009, the market of cryptocurrencies has grown beyond initial expectations as daily trades exceed $10 billion. As industries become automated, the need for an automated fraud detector becomes very apparent. Detecting anomalies in real time prevents potential accidents and economic losses. Anomaly detection in multivariate time series data poses a particular challenge because it requires simultaneous consideration of temporal dependencies and relationships between variables. Identifying an anomaly in real time is not an easy task specifically because of the exact anomalistic behavior they observe. Some points may present pointwise global or local anomalistic behavior, while others may be anomalistic due to their frequency or seasonal behavior or due to a change in the trend. In this paper we suggested working on real time series of trades of Ethereum from specific accounts and surveyed a large variety of different algorithms traditional and new. We categorized them according to the strategy and the anomalistic behavior which they search and showed that when bundling them together to different groups, they can prove to be a good real-time detector with an alarm time of no longer than a few seconds and with very high confidence.
The advancement in technology with the internet commences the new era of communication by allowing people to communicate through text, audio and video calling, images and video clips and various other applications. The applications of internet paved the way to a technology called Internet of Things (IoT). IoT is interpreted as communication between components, (e.g., sensors and actuators) through the internet designed for application-oriented assistance. IoT is simple and user friendly which attracted the people to adapt the technology. Despite the immense benefits of the IoT device, it is vulnerable.This results in the devices to undergo various attacks. Distributed Denial-of-Service (DDoS) attack challenges the security in IoT devices. Therefore, this paper proposes the integrated SDN-Blockchain architecture to provide the secure connection for IoT devices. Software Defined Networking (SDN) technology is used in optimizing the network management, enabling a dynamic and efficient network configuration programming thereby optimizing the performance and monitoring the network. SDN transforms computer network by segregating control plane and data plane. Blockchain is represented as collection of blocks which are linked together as a back traced list.The previous block hash is used to connect the blocks together in the chain. The characteristics of Blockchain include decentralization, peer-to-peer connectivity, and immutable ledgers.
Blockchain has become one of the key techniques for the security of the industrial internet. However, the blockchain is vulnerable to FAW (Fork after Withholding) attacks. To protect the industrial internet from FAW attacks, this paper proposes a novel FAW attack protection algorithm (FAWPA) based on the behavior of blockchain miners. Firstly, FAWPA performs miner data preprocessing based on the behavior of the miners. Then, FAWPA proposes a behavioral reward and punishment mechanism and a credit scoring model to obtain cumulative credit value with the processed data. Moreover, we propose a miner's credit classification mechanism based on fuzzy C-means (FCM), which combines the improved Aquila optimizer (AO) with strong solving ability. That is, FAWPA combines the miner's accumulated credit value and multiple attack features as the basis for classification, and optimizes cluster center selection by simulating Aquila's predation behavior. It can improve the solution update mechanism in different optimization stages. FAWPA can realize the rapid classification of miners' credit levels by improving the speed of identifying malicious miners. To evaluate the protective effect of the target mining pool, FAWPA finally establishes a mining pool and miner revenue model under FAW attack. The simulation results show that FAWPA can thoroughly and efficiently detect malicious miners in the target mining pool. FAWPA also improves the recall rate and precision rate of malicious miner detection, and it improves the cumulative revenue of the target mining pool. The proposed algorithm performs better than ND, RSCM, AWRS, and ICRDS.
Anamika Singh, Md. Akkas Ali, B. Balamurugan, Vandana Sharma
Ransomware is a malware practice which cyber criminals usually inject through phishing practices to make money as their priority. With the high rise in the use of the internet amid the COVID phase, the cyber world is also reaching its peak as well. The attacker is also getting smarter with technology. We in this paper are taking blockchain technology as a weapon to fight against the terror of ransomware attacks, as this is the most notorious and devastating attack of all, and there is no doubt that it is going to be with us in the future too. Detection of ransomware attacks before they infect and decode the data is a complex thing. Several algorithms exist to detect attacks at their early stages, but the lack of information about the pre and post behavior similarities is proving to be an obstacle to accurately observing and detecting ransomware at its very first stage rather than making sense of paying the ransom and even not being sure of getting back the confidentialities. With the use of blockchain technology, we focus on making a record of the pre-encryption and post-encryption behaviour of ransomware attacks so that it is not going to be complex to track the nature, similarities, and behaviour of ransomware attacks. With inaccurate availability of data about pre and post behaviour of attacks and also weak design of detection models, both have a negative impact on selecting the features and similarities of the attack and thus developing a design model for the same. The paper is focusing on one of the most challenging variations of ransomware attacks, i.e., the crypto ransomware. Many researches before proposed solutions as performing regular backup of files but this measure has a significant overhead too as key backup schemes results in high computational cost as well. Thus, with the use of blockchain for gathering and maintaining records, we expect to be prepared for every unexpected attack.
Abstract Data security and confidentiality are major goals now days due to the extensive use of the internet for data sharing. In modern era, most of the networks are compromised by intruders to grab access to private, confidential, and highly secured data. An intrusion detection system (IDS) is widely used to secure the network from getting compromised by intruders. Most of the IDS share the signatures of the novel attacks detected by anomaly approach for improving the detection rate and processing time. Security of signature shared by nodes is becoming a considerable problem. This paper presents a novel framework blockchain based hybrid intrusion detection system (BC-HyIDS), which uses the blockchain framework for exchanging signatures from one node to the other in distributed IDS. BC-HyIDS works in three phases where it uses both detection methods and blockchain in the third phase to provide security to data transferred through the network. This system makes use of a cryptosystem to encrypt the data stored in blocks to improve security one level higher. Hyperledger fabric v2.0 and Hyperledger sawtooth is used to implement system. Blockchain framework is created as a prototype using distributed ledger technology which helps in securing signature exchange. Performance of BC-HyIDS is evaluated in terms of accuracy, detection rate, and false alarm rate. From results, it is observed that a 2.8% increase in accuracy, 4.3% increase in detection rate, and a reduction of 2.6% in FAR is achieved. Blockchain performance is evaluated using Hyperledger fabric v2.0 and Hyperledger sawtooth on throughput, processing time, and average latency. BC-HyIDS shows improved performance when used with blockchain.
Love it or loathe it, Bitcoin and other cryptocurrencies are here to stay. Yet do you know how crypto is "manufactured"? It turns out to be a very noisy operation! Hundreds, if not thousands of powerful computer servers and processors are needed to solve the vexing Bitcoin mining algorithms. And those computers generate heat, a lot of heat (!), that must be cooled and ventilated, thus creating noise. This paper will describe the noise assessment and control efforts performed on a major Bitcoin mining operation in Tennessee. Megawatts of power are needed to support the operations, and the ventilation noise was causing significant community complaints that threatened to shut down the mining operation. Fortunately, application of some traditional and custom-made noise mitigation measures solved the noise problem and allowed the mining operation to proceed around the clock. At the time of writing this abstract, 1 Bitcoin = $46,500.
Technological advancements in block chain (BC)-based frameworks have empowered scientists to create innovative inventions such as e-casting ballots. The traditional agreement models utilized proof-of-work (PoW) in the Bitcoin that affected energy utilization and bargained the adaptability for the ballot framework. The existing works evaluates the trust basically only on the centralized party as it was not feasible because of the dynamic changes in the pervasive social networking (PSN) topology and their characteristics. The present research work proposes a block chain based trust evaluation model for the PSN based BC. The proposed hybrid proof of stake-trust (PST) BC is based on the proof-of trust (PoT) and also the proof of stake (PoS) overcomes the issues that are occurring in the e-vote casting. The trust evaluation is performed for public verification and becomes transparent for each node of PSN. The advantage of the proposed method is that a new block will be designed for trust evaluation during the block generation. The process of sharding erases the workload when the network works fast for the individual nodes provides the sum of their alternative parts. Therefore, the model utilizes the agreements for generating the safe process that guarantee the precision to vote it from the time of the election results. The present research work utilizes the proof of stake-trust based BC resulted in security improvement. The model improves the adaptability and execution of the BC based on the ballot framework provided a secured voting system for the government. The proposed PST-BC model showed better results in terms of latency as 15/s when compared with the existing models merkle hash tree -bloom filter that obtained 107.3/s and performance constraints based electron of 18/s.
Individual mental feelings and reactions are getting more significant as they help researchers, domain experts, businesses, companies, and other individuals understand the overall response of every individual in specific situations or circumstances. Every pure and compound sentiment can be classified using a dataset, which can be in the form of Twitter text by various Twitter users. Twitter is one of the vital platforms for individuals to participate and share their ideas about different topics; it is also considered to be one of the most famous and the biggest website for micro-blogging on the Internet. One of the key purposes of this study is to classify pure and compound sentiments based on text related to cryptocurrencies, an innovative way of trading and flourishing daily. The cryptocurrency market incurs many fluctuations in the coins’ value. A small positive or negative piece of news can sensate the whole scenario about the specific cryptocurrencies. In this paper, individuals’ pure and compound sentiments based on cryptocurrency-related Twitter text are classified. The dataset is collected through the Twitter API. In WEKA, the two deployment schemes are compared; firstly, straight with single feature selection technique (Tweet to lexicon feature vector), and secondly, a tetrad of feature selection techniques (Tweet to lexicon feature vector, Tweet to input lexicon feature vector, Tweet to SentiStrength feature vector, and Tweet to embedding feature vector) are used to purify the data LibLINEAR (LL) classifier, which contains fast algorithms for linear classification using L2-regularization L2-loss support vector machines (Dual SVM). The LL classifier differs in that it can potentially alleviate the sum of the absolute values of errors rather than the sum of the squared errors and is typically much speedier. Based on the overall performance parameters, the deployment scheme containing the tetrad of feature selection techniques with the LL classifier is considered the best choice for the purpose of classification. Among machine learning techniques, LL produces effective results and gives an efficient performance compared to other prevailing techniques. The findings of this research would be beneficial for Twitter users as well as cryptocurrency traders.
Eman Ashraf, Nihal F. F. Areed, Hanaa Salem, Ehab H. Abdelhay · 5 authors
Recently, there has been considerable growth in the internet of things (IoT)-based healthcare applications; however, they suffer from a lack of intrusion detection systems (IDS). Leveraging recent technologies, such as machine learning (ML), edge computing, and blockchain, can provide suitable and strong security solutions for preserving the privacy of medical data. In this paper, FIDChain IDS is proposed using lightweight artificial neural networks (ANN) in a federated learning (FL) way to ensure healthcare data privacy preservation with the advances of blockchain technology that provides a distributed ledger for aggregating the local weights and then broadcasting the updated global weights after averaging, which prevents poisoning attacks and provides full transparency and immutability over the distributed system with negligible overhead. Applying the detection model at the edge protects the cloud if an attack happens, as it blocks the data from its gateway with smaller detection time and lesser computing and processing capacity as FL deals with smaller sets of data. The ANN and eXtreme Gradient Boosting (XGBoost) models were evaluated using the BoT-IoT dataset. The results show that ANN models have higher accuracy and better performance with the heterogeneity of data in IoT devices, such as intensive care unit (ICU) in healthcare systems. Testing the FIDChain with different datasets (CSE-CIC-IDS2018, Bot Net IoT, and KDD Cup 99) reveals that the BoT-IoT dataset has the most stable and accurate results for testing IoT applications, such as those used in healthcare systems.
Ben Weintraub, Christof Ferreira Torres, Cristina Nita-Rotaru, Radu State
The rise of Ethereum has lead to a flourishing decentralized marketplace that has, unfortunately, fallen victim to frontrunning and Maximal Extractable Value (MEV) activities, where savvy participants game transaction orderings within a block for profit. One popular solution to address such behavior is Flashbots, a private pool with infrastructure and design goals aimed at eliminating the negative externalities associated with MEV. While Flashbots has established laudable goals to address MEV behavior, no evidence has been provided to show that these goals are achieved in practice. In this paper, we measure the popularity of Flashbots and evaluate if it is meeting its chartered goals. We find that (1) Flashbots miners account for over 99.9% of the hashing power in the Ethereum network, (2) powerful miners are making more than $2\times$ what they were making prior to using Flashbots, while non-miners' slice of the pie has shrunk commensurately, (3) mining is just as centralized as it was prior to Flashbots with more than 90% of Flashbots blocks coming from just two miners, and (4) while more than 80% of MEV extraction in Ethereum is happening through Flashbots, 13.2% is coming from other private pools.