Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,600 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,600 results · page 34 of 67

Clear filters
Apr 9, 2022·ACM Transactions on Software Engineering and Methodology
28 cites
Time-travel Investigation: Toward Building a Scalable Attack Detection Framework on Ethereum

Siwei Wu, Lei Wu, Yajin Zhou, Runhuai Li · 8 authors

Ethereum has been attracting lots of attacks, hence there is a pressing need to perform timely investigation and detect more attack instances. However, existing systems suffer from the scalability issue due to the following reasons. First, the tight coupling between malicious contract detection and blockchain data importing makes them infeasible to repeatedly detect different attacks. Second, the coarse-grained archive data makes them inefficient to replay transactions. Third, the separation between malicious contract detection and runtime state recovery consumes lots of storage. In this article, we propose a scalable attack detection framework named EthScope , which overcomes the scalability issue by neatly re-organizing the Ethereum state and efficiently locating suspicious transactions. It leverages the fine-grained state to support the replay of arbitrary transactions and proposes a well-designed schema to optimize the storage consumption. The performance evaluation shows that EthScope can solve the scalability issue, i.e., efficiently performing a large-scale analysis on billions of transactions, and a speedup of around \( \text{2,300}\times \) when replaying transactions. It also has lower storage consumption compared with existing systems. Further analysis shows that EthScope can help analysts understand attack behaviors and detect more attack instances.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Malware Detection Techniques
Original source
Apr 7, 2022·2022 International Conference on Sustainable Computing and Data Communication Systems (ICSCDS)
10 cites
Social Media Fake News Detection using mNB in Blockchain

Akash Dnyandeo Waghmare, Girish Kumar Patnaik

Nowadays, due to the high usage of social media-based global news, verification and authentication is a very challenging task. Most social media platforms are easily enabled to access news anytime, anywhere over the internet, but it also produces a lot of false news and false information simultaneously. Therefore, in such a case, it is necessary to determine whether available information is genuine, whether it is fake or real. This allows users to make confused and lose the trust of social media. A blockchain-based fake news detection can better handle such problems. The proposed classification algorithm is used to detect fake news in training and testing evolution. Another major objective of this work is to revoke the attackers who update the published news. The blockchain-based decentralized peer-to-peer environment has been used to protect the published data even in a vulnerable environment Various features extraction and selection techniques have been used to generate effective training rules and validate the test classifier accordingly. An extensive experimental analysis demonstrates the classification accuracy of fake news detection on the LIAR dataset. The system achieves 95.20% average accuracy for training as well as testing, which is higher than conventional machine learning algorithms like SVM, ANN, NB etc.

Misinformation and Its Impacts
Spam and Phishing Detection
Blockchain Technology Applications and Security
Original source
Apr 1, 2022·ACM Transactions on Software Engineering and Methodology
34 cites
A Study on Blockchain Architecture Design Decisions and Their Security Attacks and Threats

Sabreen Ahmadjee, Carlos Mera‐Gómez, Rami Bahsoon, Rick Kazman

Blockchain is a disruptive technology intended to implement secure decentralised distributed systems, in which transactional data can be shared, stored, and verified by participants of the system without needing a central authentication/verification authority. Blockchain-based systems have several architectural components and variants, which architects can leverage to build secure software systems. However, there is a lack of studies to assist architects in making architecture design and configuration decisions for blockchain-based systems. This knowledge gap may increase the chance of making unsuitable design decisions and producing configurations prone to potential security risks. To address this limitation, we report our comprehensive systematic literature review to derive a taxonomy of commonly used architecture design decisions in blockchain-based systems. We map each of these decisions to potential security attacks and their posed threats. MITRE’s attack tactic categories and Microsoft STRIDE threat modeling are used to systematically classify threats and their associated attacks to identify potential attacks and threats in blockchain-based systems. Our mapping approach aims to guide architects to make justifiable design decisions that will result in more secure implementations.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Malware Detection Techniques
Original source
Mar 31, 2022·IEICE Transactions on Information and Systems
3 cites
Discovering Message Templates on Large Scale Bitcoin Abuse Reports Using a Two-Fold NLP-Based Clustering Method

Jinho Choi, Taehwa LEE, Kwanwoo KIM, Min-Jae Seo · 6 authors

Bitcoin is currently a hot issue worldwide, and it is expected to become a new legal tender that replaces the current currency started with El Salvador. Due to the nature of cryptocurrency, however, difficulties in tracking led to the arising of misuses and abuses. Consequently, the pain of innocent victims by exploiting these bitcoins abuse is also increasing. We propose a way to detect new signatures by applying two-fold NLP-based clustering techniques to text data of Bitcoin abuse reports received from actual victims. By clustering the reports of text data, we were able to cluster the message templates as the same campaigns. The new approach using the abuse massage template representing clustering as a signature for identifying abusers is much efficacious.

Open access
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Mar 30, 2022·International Journal of Environmental Research and Public Health
30 cites
A Blockchain Secured Pharmaceutical Distribution System to Fight Counterfeiting

Kavyan Zoughalian, Jims Marchang, Bogdan Ghita

Counterfeiting drugs has been a global concern for years. Considering the lack of transparency within the current pharmaceutical distribution system, research has shown that blockchain technology is a promising solution for an improved supply chain system. This study aims to explore the current solution proposals for distribution systems using blockchain technology. Based on a literature review on currently proposed solutions, it is identified that the secrecy of the data within the system and nodes' reputation in decision making has not been considered. The proposed prototype uses a zero-knowledge proof protocol to ensure the integrity of the distributed data. It uses the Markov model to track each node's 'reputation score' based on their interactions to predict the reliability of the nodes in consensus decision making. Analysis of the prototype demonstrates a reliable method in decision making, which concludes with overall improvements in the system's confidentiality, integrity, and availability. The result indicates that the decision protocol must be significantly considered in a reliable distribution system. It is recommended that the pharmaceutical distribution systems adopt a relevant protocol to design their blockchain solution. Continuous research is required further to increase performance and reliability within blockchain distribution systems.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Supply Chain and Inventory Management
Original source
Mar 26, 2022·Business And Management Studies An International Journal
1 cites
Algılanan kullanım kolaylığı, algılanan fayda, güven ve Bitcoin kullanma niyeti için tasarlanan modelin yapısal geçerliliğini process macro ile test etme

Abdullah Oğrak

İlk kripto para birimi olan Bitcoin, son zamanlarda araştırmacılardan büyük ilgi görmektedir. Bitcoin literatürüne daha fazla katkı sağlamak için araştırmacılar tarafından yapılan çalışmalar bulunmaktadır. Bununla birlikte, Bitcoin literatürünü farklı çalışmalarla desteklemek önemlidir. Bu çalışma, teknoloji kabul modelini güven yapısı ile genişleten entegre bir modelin yapısal geçerliliğini test ederken, kullanıcıların Bitcoin'i kolay ve faydalı olarak algılamalarına ve Bitcoin'e olan güvenlerine dayalı olarak Bitcoin kullanma niyetlerini açıklamayı amaçlamaktadır. Bu amaçla 206 katılımcıdan online anket kullanılarak veri toplanmıştır. Process macro tekniği ile test edilen modelin yapısal geçerliliği istatistiksel analizlerle doğrulanmıştır. İstatistiksel analiz sonuçlarına göre Bitcoin'in algılanan kullanım kolaylığı, Bitcoin'in algılanan faydası ve Bitcoin'e olan güven ile bu faktörler arasındaki mevcut ilişkiler Bitcoin kullanma niyeti üzerinde etkilidir. Bununla birlikte, kullanıcıların Bitcoin kullanma niyetlerinin cinsiyet, yaş aralığı/jenerasyon, eğitim durumu ve aylık gelir açısından önemli ölçüde farklılık göstermediği belirtilmelidir. Bu çalışma hem teori hem de uygulama için çıkarımların yanı sıra gelecekteki araştırmalar için öneriler sunmaktadır.

Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Original source
Mar 26, 2022·Security and Communication Networks
5 cites
Cryptocurrency Mining Malware Detection Based on Behavior Pattern and Graph Neural Network

Rui Zheng, Qiuyun Wang, Jia He, Jianming Fu · 6 authors

Miner malware has been steadily increasing in recent years as the value of cryptocurrency rises, which poses a considerable threat to users’ device security. Miner malware has obvious behavior patterns in order to participate in blockchain computing. However, most miner malware detection methods use raw bytes feature and sequential opcode as detection features. It is difficult for these methods to obtain better detection results due to not modeling robust features. In this paper, a miner malware identification method based on graph classification network is designed by analyzing the features of function call graph and control flow graph of miner malware, called MBGINet. MBGINet can model the behavior graph relationship of miner malware by extracting the connection features of critical nodes in the behavior graph. Finally, MBGINet transforms these node features into the feature vectors of the graph for miner malware identification. In the test experiments, datasets with different volumes are used for simulating real-world scenarios. The experimental results show that the MBGINet method achieves a leading and stable performance compared to the dedicated opcode detection method and obtains an accuracy improvement of 3.08% on the simulated in-the-wild dataset. Meanwhile, MBGINet gains an advantage over the general malware detection method Malconv. These experimental results demonstrate the superiority of the MBGINet method, which has excellent characteristics in adapting to realistic scenarios.

Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Spam and Phishing Detection
Original source
Mar 21, 2022·IEEE Transactions on Systems, Man, and Cybernetics: Systems (2024)
21 cites
Collaborative Learning for Cyberattack Detection in Blockchain Networks

Tran Viet Khoa, Do Hai Son, Dinh Thai Hoang, Nguyen Linh Trung · 8 authors

This article aims to study intrusion attacks and then develop a novel cyberattack detection framework to detect cyberattacks at the network layer (e.g., Brute Password and Flooding of Transactions) of blockchain networks. Specifically, we first design and implement a blockchain network in our laboratory. This blockchain network will serve two purposes, i.e., to generate the real traffic data (including both normal data and attack data) for our learning models and to implement real-time experiments to evaluate the performance of our proposed intrusion detection framework. To the best of our knowledge, this is the first dataset that is synthesized in a laboratory for cyberattacks in a blockchain network. We then propose a novel collaborative learning model that allows efficient deployment in the blockchain network to detect attacks. The main idea of the proposed learning model is to enable blockchain nodes to actively collect data, learn the knowledge from data using the Deep Belief Network, and then share the knowledge learned from its data with other blockchain nodes in the network. In this way, we can not only leverage the knowledge from all the nodes in the network but also do not need to gather all raw data for training at a centralized node like conventional centralized learning solutions. Such a framework can also avoid the risk of exposing local data's privacy as well as excessive network overhead/congestion. Both intensive simulations and real-time experiments clearly show that our proposed intrusion detection framework can achieve an accuracy of up to 98.6% in detecting attacks.

Open access
2 source records
cs.CR
cs.LG
Network Security and Intrusion Detection
Original source
Mar 18, 2022·arXiv (Cornell University)
1 cites
Extorsionware: Exploiting Smart Contract Vulnerabilities for Fun and Profit

Alessandro Brighente, Mauro Conti, Sathish Kumar

Smart Contracts (SCs) publicly deployed on blockchain have been shown to include multiple vulnerabilities, which can be maliciously exploited by users. In this paper, we present extorsionware, a novel attack exploiting the public nature of vulnerable SCs to gain control over the victim's SC assets. Thanks to the control gained over the SC, the attacker obliges the victim to pay a price to re-gain exclusive control of the SC.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Mar 15, 2022·IEEE Transactions on Circuits & Systems II Express Briefs
58 cites
Phishing Detection on Ethereum via Attributed Ego-Graph Embedding

Yijun Xia, Jieli Liu, Jiajing Wu

In recent years, the losses caused by phishing scams on Ethereum have reached a level that cannot be ignored. In such a phishing detection scenario, network embedding is seen as an effective solution. In this brief, we propose an attributed ego-graph embedding framework to distinguish phishing accounts. We first obtain the account labels from an authority site and the transaction records from Ethereum on-chain blocks. Then we extract ego-graphs for each labeled account to represent it. To learn representations for ego-graphs, we utilize non-linear substructures sampled from ego-graphs and use a skip-gram model. Finally, a classifier is applied to graph embeddings to predict phishing accounts. To overcome the limit that transaction attributes are not encoded into ego-graph embeddings, we give nodes and subgraphs with richer attribute-based semantics. Specifically, we propose a novel node relabeling strategy based on Ethereum transaction attributes including transaction amount, number, and direction, and differentiating nodes and subgraphs by new labels. Through this, structural and attributed features of the Ethereum transaction networks can be learned at the same time. Experimental results show that our framework achieves effective performance on class imbalanced phishing detection on Ethereum.

Spam and Phishing Detection
Imbalanced Data Classification Techniques
Advanced Graph Neural Networks
Original source
Mar 9, 2022·Journal of Healthcare Engineering
14 cites
A Traceable Blockchain-Based Vaccination Record Storage and Sharing System

Jingshou Chen, Xiaofeng Chen, Chin‐Ling Chen

Blockchain technology is essentially a decentralized database maintained by relevant parties and has been widely used in various scenarios such as logistics and finance. In terms of applications in the medical field, it is becoming more and more important because the patient's symptoms may be related to a certain vaccine. Whether the patient has been vaccinated with this vaccine will lead to different diagnostic results by the doctor. However, in the current vaccination environment of many regions, the vaccination record (VR) can only be kept in the patient's vaccination booklet, which is easy to lose or destroy. Therefore, the doctor needs to retrieve the patient's VR through a centralized database maintained by the government, which is time-consuming and will increase the medical risk. This study proposes a traceable blockchain-based vaccination record storage and sharing system. In the proposed system, the patient gets the vaccination at any legal clinic and the VR can be saved accompanied by the signature into the blockchain center, which ensures traceability. When the patient visits the hospital for treatment, the doctor can obtain the detail of the VR from the blockchain center and then make a diagnosis. The security of the proposed system will be protected by the programmed smart contracts. Through mutual authentication, our system can also provide and guarantee data integrity and nonrepudiation. Moreover, the proposed system has resistance to replay and man-in-the-middle attacks, and the performance is good.

Open access
Blockchain Technology Applications and Security
User Authentication and Security Systems
Spam and Phishing Detection
Original source
Mar 7, 2022·Third International Conference on Electronics and Communication; Network and Computer Technology (ECNCT 2021)
0 cites
The development of blockchain privacy protection: from Bitcoin to Monero

Jiahao Li

In the age of virtual currency's prosperity, the privacy of virtual currency cannot be ignored. By comparing the degree of privacy of Monero and Bitcoin and analyzing the technical background of Monero, it is found that the encryption method and privacy of Monero will become a major mainstream trend leading to the digital currency in the future. Through the discussion of the privacy, security, and non-traceability of Monero, we found that the security of Monero is obvious to all. The forecast of future market analysis compares the future development trend, market supply, and profitable rate of return of Monero and Bitcoin, confirming that Monero's market outlook is very impressive. Facing the emergence of digital currencies such as Zcash and Dash, Monero will still become the mainstream currency that will lead the development of digital currencies in the future.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Mar 7, 2022·Third International Conference on Electronics and Communication; Network and Computer Technology (ECNCT 2021)
3 cites
Semi-supervised graph convolutional network for Ethereum phishing scam recognition

Junjing Tang, Gansen Zhao, Bangqi Zou

In recent years, as the blockchain and the cryptocurrency built on it have become popular, a large number of decentralized financial applications have been built on the Ethereum network. This makes the security issues on Ethereum attract more and more researchers' attention. Phishing scams on Ethereum have caused people to suffer huge economic losses. Recently, with the popularity of graph convolutional neural networks (GCN), many models based on GCN for node classification have emerged. However, these current GCN models are difficult to cope with the challenges caused by the lack of side information and labels of nodes in the Ethereum network. In this paper, we propose a semisupervised graph convolutional neural network model based on important neighbors for the identification of phishing scam nodes on Ethereum. In our work, we design the pretext task for the node embedding module so that our model can learn the appropriate node embedding by using a large amount of unlabeled node data. Subsequent experiments show that our proposed model is better than all other baselines, which proves the effectiveness of our model.

Blockchain Technology Applications and Security
Brain Tumor Detection and Classification
Spam and Phishing Detection
Original source
Mar 2, 2022·International Conference on Cyber Warfare and Security
10 cites
Towards Detection of Selfish Mining Using Machine Learning

Matthew Gregor Peterson, Todd R. Andel, Ryan Benton

Selfish mining is an attack against a blockchain where miners hide newly discovered blocks instead of publishing them to the rest of the network. The selfish miners continue to mine on their private chain while the honest miners waste resources mining on a shorter chain. According to the blockchain protocol, a longer chain takes precedent and shorter chains are discarded which allows the selfish miners to gain an advantage by keeping their chain secret. This attack can be used by malicious miners to earn a disproportionate share of the mining rewards or in conjunction with other attacks to steal money from cryptocurrency exchanges. Several of these attacks were launched in 2018 and 2019 with the attackers stealing as much as $18 Million. Developers made several different attempts to fix this issue, but the effectiveness of the fixes is currently unknown. Although this attack is possible against both Proof-of-Work and Proof-of-Stake blockchains, this research concentrates on detection in Proof-of-Work blockchains. As is difficult to evaluate security advances in the real-time blockchain, it is imperative to focus on simulation to evaluate blockchain security properties. To this end, we extend a blockchain simulator and add the ability to simulate selfish mining attacks. Several existing simulators are examined before choosing SimBlock for this research. Our goal is to identify the factors that identify selfish mining. Using existing research, we choose several factors that could identify an attack in an unlaunched state, an active state, or historically. We plan to use simulated data to train a machine learning model to detect selfish mining. Using the modified simulator, we generate training and test data for unlaunched and active attacks. For historical attacks, we will use historical data from known selfish mining attacks. While some existing research has examined the detection of selfish mining, it only examines active attacks. In this paper, we seek to lay the groundwork for future research into detecting attacks that are unlaunched, active, or historical.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Recycling and Waste Management Techniques
Original source
Mar 1, 2022·Journal of Communications and Information Networks
9 cites
Blockchain-Based Secure Crowdsourcing in Wireless IoT

Daquan Feng, Long Zhang, Shengli Zhang, Qihui Wu · 5 authors

With the explosive growth of interconnected smart devices and sensors, the Internet has been entering the Internet of things (IoT) era and revolutionizing many aspects of our daily life. Meanwhile, crowdsourcing has been considered as a promising technology to realize collaborative intelligence. Therefore, more and more IoT-based crowdsourcing applications are emerged to take advantages of the widely distributed IoT devices to sense, collect, and analyze data with the aim to solve complex and nontrivial tasks. However, there exist many technical challenges to be addressed in the IoT-based crowdsourcing, such as security, privacy, and incentive provision. In this paper, we propose a blockchain-based architecture as an integrated solution to realize the secure and trustworthy crowdsourcing in wireless IoT. We first overview the challenges in the traditional crowdsourcing system. Then, we briefly introduce the background of the blockchain and smart contract, and propose a blockchain-based crowdsourcing architecture. In particular, we elaborate the utilization of smart contract on the specific phases of crowdsourcing. By deploying the smart contract instance, we confirm the proposed blockchain-based architecture is feasible.

Spam and Phishing Detection
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Original source
Mar 1, 2022·arXiv (Cornell University)
2 cites
VOLCANO: Detecting Vulnerabilities of Ethereum Smart Contracts Using Code Clone Analysis

Noama Fatima Samreen, Manar H. Alalfi

Ethereum Smart Contracts based on Blockchain Technology (BT) enables monetary transactions among peers on a blockchain network independent of a central authorizing agency. Ethereum Smart Contracts are programs that are deployed as decentralized applications, having the building blocks of the blockchain consensus protocol. This enables consumers to make agreements in a transparent and conflict-free environment. However, there exist some security vulnerabilities within these smart contracts that are a potential threat to the applications and their consumers and have shown in the past to cause huge financial losses. This paper presents a framework and empirical analysis that use code clone detection techniques for identifying vulnerabilities and their variations in smart contracts. Our empirical analysis is conducted using the Nicad code clone detection tool on a dataset of approximately 50k Ethereum smart contracts. We evaluated VOLCANO on two datasets, one with confirmed vulnerabilities and another with approximately 50k random smart contracts collected from the Etherscan. Our approach shows an improvement in the detection of vulnerabilities in terms of coverage and efficiency when compared to two of the publicly available static analyzers to detect vulnerabilities in smart contracts. To the best of our knowledge, this is the first study that uses a clone detection technique to identify vulnerabilities and their evolution in Ethereum smart contracts.

Open access
2 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Malware Detection Techniques
Original source
Feb 25, 2022·Haliç Üniversitesi Fen Bilimleri Dergisi
1 cites
Blok Zinciri Platformları, Fikir Birliği Mekanizmaları ve Ağın Güvenlik Analizi

Mimar ASLAN, Mustafa Cem KASAPBAŞI

Finans, sağlık, sosyal medya vb ortamlardaki insanların ihtiyacı olan güven problemine blok zinciri teknolojisi, şifreli algoritmalar ile çözümler sunmaktadır. Güven problemini çözen ve verileri dağıtık olarak kayıt altına alan ve her şeyi şeffaf olarak bizlere sunan blok zinciri bir devrim niteliğindedir. Blok zinciri, akıllı sözleşmeler sayesinde kurumsal projelerde de kullanabilmektedir. Kurumların arasında yeni nesil bir ağ olarak da adlandırılan blok zinciri ile bir çok şeyin değişmesi beklenmektedir. İnternetin, mobile cihazların ve sensörlerin yaygınlaşmasıyla birlikte güven problemi her geçen gün daha da önem kazanmaktadır. Farklı amaçlara hizmet eden Ethereum, Cardano, EOS, Cosmos, Hyperledger gibi blok zincir platformları vardır. Altyapılarında Proof of Work (PoW), Proof of Stake (PoS), Delegated Proof of Stake (DPoS) ve Directed Acyclic Graph (DAG) gibi farklı fikir birliği mekanizmalarını kullanmaktadırlar. Bu çalışmada blok zinciri platformları, altyapılarında kullandıkları mutabakat mekanizmaları ve blok zinciri ağının güvenliği araştırılmıştır.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source
Feb 24, 2022·Islamic Banking and Finance Review
0 cites
Money-Prospects of Cryptocurrencies- A Bibliometric Review

Muhammad Suleman Afzal, Arshad Ali Bhatti

The status of the money-prospects of cryptocurrencies in both conventional and Shari’ah based literature remains hotly debated and largely indecisive. We apply/used the bibliometric approach to review the literature on/regarding the money-prospects of cryptocurrencies. We selected 264 articles published during the years 2011-2021 from Web of Science (WoS) through systematic screening to explore their influential and intellectual aspects. Bibliometric citation analysis was conducted to present/identify influential research categories, leading authors, top articles, prominent countries, and major journals within the sample. We also highlighted the trend of annual scientific production to show sustained growth in the area under research. Furthermore, keyword analysis and bibliometric coupling analysis were applied/carried out to generate networks to highlight the intellectual aspects of the money-prospects of cryptocurrencies. We used the networks of emerging themes and main clusters to conduct content analysis further. We included and reviewed studies which discussed the money-prospects of cryptocurrencies in the light of Shari’ah precepts in relevant clusters. We also identified potential future research areas (cluster-wise). Theis study helps the researchers to understand the evolution, dimensions, and emerging themes regarding the money-prospects of cryptocurrencies.

Open access
2 source records
Blockchain Technology Applications and Security
Blockchain Technology in Education and Learning
Spam and Phishing Detection
Original source
Feb 24, 2022·IEEE Transactions on Engineering Management
23 cites
Truth: A Blockchain-Aided Secure Reputation System With Genuine Feedbacks

Saiyu Qi, Yue Li, Wei Wei, Qian Li · 6 authors

E-commerce has changed the way of shopping and played an important role in the world. Therefore, e-commerce platforms require a secure reputation service, which provides genuine reputation of sellers so as to support potential buyers making the right decision while interacting with an e-commerce platform. Unfortunately, most current e-commerce platforms failed to do so because they fully control the reputation service, which make it easy for an adversary to violate the genuineness of the reputation. In this article, we focus on feedback anonymity and authenticity, which are two critical security properties to ensure a genuine reputation of sellers. We present Truth, a blockchain-aided secure reputation system to remove the trustworthiness of the e-commerce platform while ensuring the two security properties. To overcome the usability and security barriers of blockchain systems, Truth adopts a hybrid framework to rely on the centralized e-commerce platform to provide traditional trading services while the blockchain is only used to authenticate the correctness of feedbacks. To decouple the blockchain from the e-commerce platform, we anchor correctness of feedbacks to correctness of cryptographic tokens and leverage the blockchain to solely escrow the tokens. The Truth also proposes a new concept named purchasing endorsed feedback, which is enforced via a collaborative method to prevent injection of fake feedbacks. We have implemented a prototype to demonstrate that the Truth incurs second-level computation overhead and KB-level communication overhead, and achieves hundreds TPS-level thoughts.

Blockchain Technology Applications and Security
Cryptography and Data Security
Spam and Phishing Detection
Original source
Feb 16, 2022·arXiv (Cornell University)
1 cites
PhishChain: A Decentralized and Transparent System to Blacklist Phishing URLs

Shehan Edirimannage, Mohamed Nabeel, Charith Elvitigala, Chamath Keppitiyagama

Blacklists are a widely-used Internet security mechanism to protect Internet users from financial scams, malicious web pages and other cyber attacks based on blacklisted URLs. In this demo, we introduce PhishChain, a transparent and decentralized system to blacklisting phishing URLs. At present, public/private domain blacklists, such as PhishTank, CryptoScamDB, and APWG, are maintained by a centralized authority, but operate in a crowd sourcing fashion to create a manually verified blacklist periodically. In addition to being a single point of failure, the blacklisting process utilized by such systems is not transparent. We utilize the blockchain technology to support transparency and decentralization, where no single authority is controlling the blacklist and all operations are recorded in an immutable distributed ledger. Further, we design a page rank based truth discovery algorithm to assign a phishing score to each URL based on crowd sourced assessment of URLs. As an incentive for voluntary participation, we assign skill points to each user based on their participation in URL verification.

Open access
2 source records
cs.CR
Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Original source
Jan 27, 2022·Security and Communication Networks
9 cites
Attacker Traceability on Ethereum through Graph Analysis

Hang Zhu, Weina Niu, Xuhan Liao, Xiaosong Zhang · 7 authors

Since the Ethereum virtual machine is Turing complete, Ethereum can implement various complex logics such as mutual calls and nested calls between functions. Therefore, Ethereum has suffered a lot of attacks since its birth, and there are still many attackers active in Ethereum transactions. To this end, we propose a traceability method on Ethereum, using graph analysis to track attackers. We collected complete user transaction data to construct the graph and analyzed data on several harmful attacks, including reentry attacks, short address attacks, DDoS attacks, and Ponzi contracts. Through graph analysis, we found accounts that are strongly associated with these attacks and are still active. We have done a systematic analysis of these accounts to analyze their threats. Finally, we also analyzed the correlation between the information collected through RPC and these accounts and finally found that some accounts can find their IP addresses.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Network Security and Intrusion Detection
Original source
Jan 25, 2022·IEEE Engineering Management Review
45 cites
A Blockchain-Based Solution for COVID-19 Vaccine Distribution

Yuriy Kamenivskyy, Abhinav Palisetti, Layal Hamze, Sara Saberi

The COVID-19 vaccine distribution chain faced multiple challenges associated with the lack of production capacity, security issues, and miscommunication between different actors. Blockchain technology has been shown to solve the security and miscommunication issues in other industries. We first identify distribution chain challenges via literature reviews and primary interviews. Case studies that solved these challenges in other industries also served as a source. This information allowed us to devise a blockchain framework for the vaccine distribution chain and evaluate its application feasibility. We present the framework using data flow diagrams. The proposed framework helps minimize the circulation of counterfeit vaccines and vaccination records, improves communication between stakeholders in the distribution chain, increases supply chain security, and simplifies vaccine inventorying and handling processes.

Open access
Blockchain Technology Applications and Security
COVID-19 Pandemic Impacts
Spam and Phishing Detection
Original source