The continuous expansion of the Internet of Things(IoT) market has brought serious security problems. As cryptocurrency attracts more and more people's attention, the price of cryptocurrency has reached unprecedented heights, and now IoT devices are likely to become the target of cybercriminals for stealing computing resources to mine cryptocurrency. This paper proposes a method based on machine learning to detect the existence of malicious miners using IoT devices in a local area network. Compared with previous methods that leverage static signatures or dynamic analysis, this method has low overhead, is easy to maintain, and independent of specific IoT devices and manufacturers. We collected normal traffic from 4 different IoT devices and the traffic of an IoT device that mines the Monero cryptocurrency. Based on the collected data set, 5 machine learning models have been trained to classify normal traffic and mining traffic. Experimental results show that the proposed method effectively detects IoT device mining traffics.
Bitcoin is a virtual encrypted digital currency based on a peer-to-peer network. In recent years, for higher anonymity, more and more Bitcoin users try to use Tor hidden services for identity and location hiding. However, previous studies have shown that Tor are vulnerable to traffic fingerprinting attack, which can identify different websites by identifying traffic patterns using statistical features of traffic. Our work shows that traffic fingerprinting attack is also effective for the Bitcoin hidden nodes detection. In this paper, we proposed a novel lightweight Bitcoin hidden service traffic fingerprinting, using a random decision forest classifier with features from TLS packet size and direction. We test our attack on a novel dataset, including a foreground set of Bitcoin hidden node traffic and a background set of different hidden service websites and various Tor applications traffic. We can detect Bitcoin hidden node from different Tor clients and website hidden services with a precision of 0.989 and a recall of 0.987, which is higher than the previous model.
Internet Traffic Analysis and Secure E-voting
Network Security and Intrusion Detection
Advanced Steganography and Watermarking Techniques
5G has Introduced the primary and secondary authentication procedures to authenticate the user equipment requesting access to mobile network operators (MNOs) and service providers (SPs) data networks, respectively. However, the possibility of running distributed denial of service (DDoS) attacks on the MNO 5G core network (CN) and the SPs data networks still remains. In this paper, we introduce a zero- knowledge proof (ZKP) authentication algorithm called Partial- ID ZKP that authenticates users without revealing their service credentials. We show that Partial-ID ZKP has completeness and soundness properties. Based on Partial-ID ZKP, we then propose an extensible authentication protocol called EAP-ZKP that can be used in primary and secondary authentications to mitigate DDoS attacks at the CN edge. Finally, as a proof of concept, we implement EAP-ZKP in the 5G authentication procedure. Using the 5G simulators free5GC and gnbsim, we show that EAP-ZKP significantly reduces the authentication time for fake authentication attempts during DDoS attacks. Results also demonstrate that EAP-ZKP is able to recognize DDoS attack authentication attempts in about 10 msec. Interestingly, for the legitimate authentication attempts, the average authentication time slightly increases from 3.05 sec in current 5G authentication protocols to 3.06 sec in EAP-ZKP. This indicates that EAP-ZKP is promising for Beyond 5G.
Operators of networks are striving to provide functional network-based services, while keeping the cost of deploying the service to a minimum. Network Function Virtualization (NFV) is considered to be a promising model to modify such employment by separating network functions from the basic hardware properties, after which they are converted into the style of software. These are eventually referred to as Virtual Network Functions (VNFs). This separation offers numerous benefits, including the decrease of Capital Expenditure (CAPEX) and Operation Expense (OPEX), in addition to the enhanced elasticity of service preparation. Network Functions Virtualization (NFV) is found to cause a remarkable development or even a technological revolution in terms of network-based services, leading to a decrease in deployment costs for network operators. NFV reduces hardware tool costs and energy exhaustion, and it improves its operational performance whereby the network configuration is part of this optimization. Even so, there are a number of possible security problems which are the main focus in NFV. The present study surveys the applications and opportunities of NFV in terms of IoT, SDN, cloud computing and blockchain. A description of the NFV architecture is presented, and several possibilities of NFV security issues and challenges are discussed. Finally, a systematic idea is provided on the design of a Blockchain Network Virtualization System.
Xabier Echeberria-Barrio, Francesco Zola, Lander Segurola-Gil, Raúl Orduna-Urrutia
Blockchain technology has gained much relevance in recent years, specifically the smart contract functionality, due to its great potential to decentralize different required scenarios. This technology brings many advantages, in particular, smart contracts provide blockchain with very great versatility. However, these smart contracts can bring some threats to the blockchain. This study has focused on the development of an intrusion detection system (IDS) based on the path study. This IDS defends the smart contracts, monitoring the transactions received by the targeted smart contract and generating the paths where the transactions are coming. These generated paths will have some features that are extracted and analyzed. Our approach suggests implementing an automated IDS on smart contracts to defend them from potential threats.
Blockchain technology has developed significantly over the last decade. One of the reasons for this is its sustainability architecture, which does not allow modification of the history of committed transactions. That means that developers should consider blockchain vulnerabilities and eliminate them before the deployment of the system. In this paper, we demonstrate a statistical model checking approach for the verification of blockchain systems on three real-world attack scenarios. We build and verify models of DNS attack, double-spending with memory pool flooding, and consensus delay scenario. After that, we analyze experimental results and propose solutions to avoid these kinds of attacks.
Alessio Catalfamo, Armando Ruggeri, Antonio Celesti, Maria Fazio · 5 authors
Nowadays, the increasing complexity of digital applications for social and business activities has required more and more advanced mechanisms to prove the identity of subjects like those based on the Two-Factor Authentication (2FA). Such an approach improves the typical authentication paradigm but it has still some weaknesses. Specifically, it has to deal with the disadvantages of a centralized architecture causing several security threats like denial of service (DoS) and man-in-the-middle (MITM). In fact, an attacker who succeeds in violating the central authentication server could be able to impersonate an authorized user or block the whole service. This work advances the state of art of 2FA solutions by proposing a decentralized Microservices and Blockchain Based One Time Password (MBB-OTP) protocol for security-enhanced authentication able to mitigate the aforementioned threats and to fit different application scenarios. Experiments prove the goodness of our MBB-OTP protocol considering both private and public Blockchain configurations.
The Bitcoin cryptocurrency is a worldwide prevalent virtualized digital currency conceptualized in 2008 as a distributed transactions system. Bitcoin transactions make use of peer-to-peer network nodes without a third-party intermediary, and the transactions can be verified by the node. Although Bitcoin networks have exhibited high efficiency in the financial transaction systems, their payment transactions are vulnerable to several ransomware attacks. For that reason, investigators have been working on developing ransomware payment identification techniques for bitcoin transactions’ networks to prevent such harmful cyberattacks. In this paper, we propose a high performance Bitcoin transaction predictive system that investigates the Bitcoin payment transactions to learn data patterns that can recognize and classify ransomware payments for heterogeneous bitcoin networks. Specifically, our system makes use of two supervised machine learning methods to learn the distinguishing patterns in Bitcoin payment transactions, namely, shallow neural networks (SNN) and optimizable decision trees (ODT). To validate the effectiveness of our solution approach, we evaluate our machine learning based predictive models on a recent Bitcoin transactions dataset in terms of classification accuracy as a key performance indicator and other key evaluation metrics such as the confusion matrix, positive predictive value, true positive rate, and the corresponding prediction errors. As a result, our superlative experimental result was registered to the model-based decision trees scoring 99.9% and 99.4% classification detection (two-class classifier) and accuracy (multiclass classifier), respectively. Hence, the obtained model accuracy results are superior as they surpassed many state-of-the-art models developed to identify ransomware payments in bitcoin transactions.
Blockchain and Data Mining are not simply buzzwords, but rather concepts that are playing an important role in the modern Information Technology (IT) revolution. Blockchain has recently been popularized by the rise of cryptocurrencies, while data mining has already been present in IT for many decades. Data stored in a blockchain can also be considered to be big data, whereas data mining methods can be applied to extract knowledge hidden in the blockchain. In a nutshell, this paper presents the interplay of these two research areas. In this paper, we surveyed approaches for the data mining of blockchain data, yet show several real-world applications. Special attention was paid to anomaly detection and fraud detection, which were identified as the most prolific applications of applying data mining methods on blockchain data. The paper concludes with challenges for future investigations of this research area.
Exchange of data in networks necessitates provision of security and confidentiality. Most networks compromised by intruders are those where the exchange of data is at high risk. The main objective of this paper is to present a solution for secure exchange of attack signatures between the nodes of a distributed network. Malicious activities are monitored and detected by the Intrusion Detection System (IDS) that operates with nodes connected to a distributed network. The IDS operates in two phases, where the first phase consists of detection of anomaly attacks using an ensemble of classifiers such as Random forest, Convolutional neural network, and XGBoost along with genetic algorithm to improve the performance of IDS. The novel attacks detected in this phase are converted into signatures and exchanged further through the network using the blockchain framework in the second phase. This phase uses the cryptosystem as part of the blockchain to store data and secure it at a higher level. The blockchain is implemented using the Hyperledger Fabric v1.0 and v2.0, to create a prototype for secure signature transfer. It exchanges signatures in a much more secured manner using the blockchain architecture when implemented with version 2.0 of Hyperledger Fabric. The performance of the proposed blockchain system is evaluated on UNSW NB15 dataset. Blockchain performance has been evaluated in terms of execution time, average latency, throughput and transaction processing time. Experimental evidence of the proposed IDS system demonstrates improved performance with accuracy, detection rate and false alarm rate (FAR) as key parameters used. Accuracy and detection rate increase by 2% and 3% respectively whereas FAR reduces by 1.7%.
Intrusion detection systems that have emerged in recent decades can identify a variety of malicious attacks that target networks by employing several detection approaches. However, the current approaches have challenges in detecting intrusions, which may affect the performance of the overall detection system as well as network performance. For the time being, one of the most important creative technological advancements that plays a significant role in the professional world today is blockchain technology. Blockchain technology moves in the direction of persistent revolution and change. It is a chain of blocks that covers information and maintains trust between individuals no matter how far apart they are. Recently, blockchain was integrated into intrusion detection systems to enhance their overall performance. Blockchain has also been adopted in healthcare, supply chain management, and the Internet of Things. Blockchain uses robust cryptography with private and public keys, and it has numerous properties that have leveraged security’s performance over peer-to-peer networks without the need for a third party. To explore and highlight the importance of integrating blockchain with intrusion detection systems, this paper provides a comprehensive background of intrusion detection systems and blockchain technology. Furthermore, a comprehensive review of emerging intrusion detection systems based on blockchain technology is presented. Finally, this paper suggests important future research directions and trending topics in intrusion detection systems based on blockchain technology.
Caciano dos Santos Machado, Renan R. S. dos Santos, Carla Merkle Westphall
Community networks are prone to free-riders, i.e., participants who take advantage of cooperation from others' routers but do not contribute reciprocally. In this paper, we present HARPIA, a system for credit-based incentive mechanisms for data forwarding in community networks aimed to prevent selfish behavior. HARPIA does not require a trusted third-party or tamper-resistant security modules as in other incentive mechanisms. Instead, it uses a distributed accounting scheme (DPIFA) to estimate the balance of data forwarding contribution and consumption of each network router and settle correspondent cryptocurrency debts on an Ethereum smart contract. On-chain settlement transactions are performed every HARPIA cycle (e.g., daily, weekly, monthly) and must be validated by at least m-of-n network routers using a multi-signature scheme (MuSig). We also realized a performance evaluation, security threat assessment, and cryptocurrency costs estimation. Results show that our proposal is suitable for community networks with up to 64 infrastructure routers under specific m-of-n MuSig thresholds.
Social media news are most important in today's worlds, it puts positive or negative influence on social views. There is a wide propagation of fake news on social media so it will be difficult to believe on the news. Fake news has negative impacts on individuals as well as on society. Information spreads rapidly over the social media and so there is a need of mechanism which detects and stops the spreading of fake news. Therefore, detection of fake news is the need of time and also a challenging problem. The goal of this proposed research work is to detect fake news and minimize spreading of the fake news. In the proposed research a machine learning approach is used for detection of fake news with blockchain framework. In first section a supervised machine learning techniques is design to identify the trustiness of specific news while blockchain framework revoke the malicious activity of spreading fake news. A blockchain environment is created with mining, smart contract as well as Proof of Work (PoW) of consensus. The current systematic review broadly focuses on the various methods to detect fake news in social media. After partial implementation of system, performance evaluation has done with traditional blockchain framework. It is found that 10% less time for transaction verification by consensus in P2P environment over the existing systems.
Cooperative Intelligent Transport System (C-ITS) is a promising technology that aims to improve the traditional transport management systems. In C-ITS infrastructure Autonomous Vehicles (AVs) communicate wirelessly with other AVs, Road Side Units (RSUs) and Traffic Command Centres (TCCs) using an open channel Internet. However, the use of the Internet brings inherent vulnerabilities related to privacy (e.g., adversary performing inference and data poisoning attacks), and security (e.g., AVs can be compromised using advanced hacking techniques) issues and prevents the faster realization of C-ITS applications. To address these challenges, this paper presents a privacy-preserving-based secure framework to provide both privacy and security in C-ITS infrastructure. The proposed framework provides two level of security and privacy using blockchain and deep learning modules. First, a blockchain module is designed to securely transmit the C-ITS data between AVs–RSUs-TCCs, and a smart contract-based enhanced Proof of Work (ePoW) technique is designed to verify data integrity and mitigate data poisoning attacks. Second, a deep-learning module is designed that includes Long-Short Term Memory-AutoEncoder (LSTM-AE) technique for encoding C-ITS data into a new format to prevent inference attacks. The encoded data is used by the proposed Attention-based Recurrent Neural Network (A-RNN), for intrusive events recognition in C-ITS infrastructure. The proposed A-RNN is trained using Truncated Backpropagation Through Time (BPTT) algorithm. The framework is further validated and tested using two publicly available ToN-IoT and CICIDS-2017 datasets. The proposed framework is compared with peer privacy-preserving intrusion detection techniques, and the result shows the effectiveness of the proposed framework over several state-of-the-art techniques in both blockchain and non-blockchain systems.
Botnets are used by hackers to conduct cyber attacks and pose a huge threat to Internet users. The key of botnets is the command and control (C&C) channels. Security researchers can keep track of a botnet by capturing and analyzing the communication traffic between C&C servers and bots. Hence, the botmaster is constantly seeking more covert C&C channels to stealthily control the botnet. This paper designs a new botnet dubbed mp-botnet wherein bots communicate with each other based on the Stratum mining pool protocol. The mp-botnet botnet completes information transmission according to the communication method of the Stratum protocol. The communication traffic in the botnet is disguised as the traffic between the mining pool and the miners in a Bitcoin network, thereby achieving better stealthiness and flexibility.
The development and application of blockchain technology makes it possible to build a more robust and flexible botnet command and control channel. In order to better study this type of potential new botnet threats, a highly confrontational botnet model based on blockchain smart contracts-SCBot was proposed. The SCBot model adopts a hierarchical hybrid topology structure, builds a command transmission channel based on smart contracts at the zombie subnet layer, and establishes a credibility evaluation mechanism to determine the authenticity of nodes, and enhances the confrontation of the network from the two major levels of traffic and terminals. The construction of small botnet clusters were simulated, comparative experiments on SCBot's command transmission efficiency and robustness were conducted, and its feasibility in the real environment from the perspective of economic costs was analyzed. Finally, a brief analysis and discussion of the defense strategy of this type of botnet were given.
In recent years, the Internet of Things (IoT) has been contemplated as the next technological advancement in the era of data communication and networking. However, although hundreds of new IoT platforms are introduced to the market every few months, the security of IoT ecosystems is still not fully understood. This paper discloses the architecture of a multilayer, multimode security system for the IoT. The proposed system is capable of providing multiple security solutions that support anonymous authentication, device privacy, data integrity, device sybil attack detection and IoT server spoofing attack detection. For IoT access control and authentication, our system can support two modes of operations, with one mode endorsing device privacy protection over the network and the second mode relinquishing device identity to establish data tracing during safety-critical IoT events. The new security system includes two innovative crypto approaches, zero knowledge proof (ZKP) and blockchains. IoT device anonymity was achieved via the multimode ZKP protocol, while data integrity and protection against sybil and IoT spoofing attacks were maintained via blockchains. Our threat analysis models showed that data modification and data injection attacks are not feasible. Probabilistic modeling of an IoT spoofing attack was performed in this paper, and the results show that our security system provides high resiliency against such attacks, with a probability approaching 1.
In distributed environments, such as distributed ledgers technologies and other peer-to-peer architectures, communication represents a crucial topic. The ability to efficiently disseminate contents is strongly influenced by the type of system architecture, the protocol used to spread such contents over the network and the actual dynamicity of the communication links (i.e. static vs. temporal nets). In particular, the dissemination strategies either focus on achieving an optimal coverage, minimizing the network traffic or providing assurances on anonymity (that is a fundamental requirement of many cryptocurrencies). In this work, the behaviour of multiple dissemination protocols is discussed and studied through simulation. The performance evaluation has been carried out on temporal networks with the help of LUNES-temporal, a discrete event simulator that allows to test algorithms running on a distributed environment. The experiments show that some gossip protocols allow to either save a considerable number of messages or to provide better anonymity guarantees, at the cost of a little lower coverage achieved and/or a little increase of the delivery time.
Routa Moussaileb, Nora Cuppens, Jean‐Louis Lanet, Hélène Le Bouder
Ransomware remains an alarming threat in the 21st century. It has evolved from being a simple scare tactic into a complex malware capable of evasion. Formerly, end-users were targeted via mass infection campaigns. Nevertheless, in recent years, the attackers have focused on targeted attacks, since the latter are profitable and can induce severe damage. A vast number of detection mechanisms have been proposed in the literature. We provide a systematic review of ransomware countermeasures starting from its deployment on the victim machine until the ransom payment via cryptocurrency. We define four stages of this malware attack: Delivery, Deployment, Destruction, and Dealing. Then, we assign the corresponding countermeasures for each phase of the attack and cluster them by the techniques used. Finally, we propose a roadmap for researchers to fill the gaps found in the literature in ransomware’s battle.
Cyberattacks constitute a significant threat to information technology systems. Computer worms are used to conduct cyberattacks to compromise computers and the data stored on them. The self-propagation characteristic of computer worms allows them to spread fast and infect many hosts in a computer network. Thus, this makes it difficult for humans to deploy a timely countermeasure to confront worm infections within the attacked network. Worm containment is utilized to stop worm spread in a computer network. The containment technique should be automatic, timely, reliable, and implemented in a distributed manner. In this paper, we introduce Rearguard, a novel blockchain-based automatic worm containment system. Rearguard achieves worm containment by creating and distributing vulnerability-based filters for the vulnerabilities being exploited. A vulnerability-based filter is employed to drop any received network message contains variants of a worm that attempts to exploit the same vulnerability. The vulnerability-based filter generation is carried out utilizing a blockchain smart contract deployed in the attacked network. The blockchain ensures reliability, timely response, trustworthy filters, and the availability of all filters in a distributed ledger that is maintained by network hosts. Rearguard has been implemented against a synthetic worm. The obtained results show that Rearguard introduces low overhead as well as ensures timely and automatic response to worm attacks.
The popularity and amazing attractiveness of cryptocurrencies, and especially Bitcoin, absorb countless enthusiasts daily. Although Blockchain technology prevents fraudulent behavior, it cannot detect fraud on its own. There are always unimaginable ways to commit fraud, and the need to use anomaly detection methods to identify abnormal and fraudulent behaviors has become a necessity. The main purpose of this study is to present a new method for detecting anomalies in Bitcoin with more appropriate efficiency. For this purpose, in this study, the diagnosis of the collective anomaly was used, and instead of diagnosing the anomaly of individual addresses and wallets, the anomaly of users was examined, and the anomaly was more visible among users who had multiple wallets. In addition to using the collective anomaly detection method in this study, the Trimmed_Kmeans algorithm was used for clustering and the proposed method succeeded in identifying 14 users who had committed theft, fraud, and hack with 26 addresses in 9 cases. Compared to previous works, which detected a maximum of 7 addresses in 5 cases of fraud, the proposed method has performed well. Therefore, the proposed method, by presenting a new approach, in addition to reducing the processing power to extract features, succeeded in detecting abnormal users and also was able to find more transactions and addresses committed a scam.
Jie Liu, Yi Sun, Fengkai Xu, Keping Yu · 6 authors
Device identification is of great importance in system management and network security. Especially, it is the priority in industrial internet of things (IIoT) scenario. Since there are massive devices producing various kinds of information in manufacturing process, the robustness, reliability, security and real-time control of the whole system is based on the identification of the massive IIoT devices. Previous IIoT device identification solutions are mostly based on a centralized architecture, which brings a lot of problems in scalability and security. In addition, most traditional identification systems can only identify inherent types of devices which is not suitable for the adaptive device management in IIoT. In order to solve these problems, this paper proposes a Intelligent Identification Scheme(IIS) of Massive IoT Devices, a completely distributed intelligent identification scheme of massive IIoT devices. The scheme changes the traditional centralized architecture and realizes more efficient clustering identification of massive IIoT devices. Moreover, IIS can identify more and more types of devices intelligently with the continuous learning ability since the identification model is constantly updated according to the ledger which is maintained by all gateways collaboratively. We also conduct experiments to evaluate the performance of IIS based on the data obtained from real IIoT devices, which proves that IIS is efficient in device identification and intelligent for the adaptive device management in IIoT.