In recent years, Ethereum, one of the leading applications to realize the service of blockchain technology, has received a great deal of attention with the usability and functionality to execute smart contracts, arbitrary programmable calculations in addition to cryptocurrency trading. However, misconfigured Ethereum clients with application programming interface (API) enabled, JSON-RPC in particular, are targeted by cyberattacks. In this research, we propose a new framework to detect malicious and suspicious Ethereum accounts using 3 different data sources (honeypot, Internet-wide scanner and blockchain explorer). The honeypot, named Etherpot, utilizes a proxy server placed between a real Ethereum client and the Internet. It modifies responses from the Ethereum client to attract attackers, identifies malicious accounts and analyzes their behaviors. With the Internet-wide scan results from Shodan, we also detect suspicious Ethereum accounts that are registered on multiple nodes. Finally, we utilize Etherscan, a well-known blockchain explorer for Ethereum, to track and analyze the activities related to the detected accounts. Through the observation of 6 weeks, we observed 538 hosts trying to call JSON- RPC of our honeypots with 41 different types of methods, including 2 types of unreported attacks in the wild. We detected 16 malicious accounts from the honeypots and 64 suspicious accounts from Shodan scan results, 5 out of which are overlapped. Finally, from Etherscan, we collected records of activities related to the detected accounts, including transactions of 21.50 ETH and mining of 22.61 ETH (equivalent to 167,560 USS at the rate of 2021/10/14). To an end, we provide a much brighter view of malicious activities on Ethereum.
In recent years, Bitcoin and other cryptocurrencies have been increasingly considered an investment option for emerging markets. However, its erratic behavior has discouraged some potential investors. To get insights into its behavior and price fluctuation, past studies have discovered the correlation between Twitter sentiments and Bitcoin behavior. Most of them have focused exclusively on their relationships, instead of the Twitter sentiment analysis itself. Finding the most suitable classification algorithms for sentiment analysis for this kind of data is challenging. For enormous data of Twitter, unlabeled data can be time-consuming and expensive for the supervised sentiment analysis approach, which has been studied to be superior to unsupervised ones. As such, we propose HyVADRF: Hybrid VADER – Random Forest and Grey Wolf Optimizer Model. Semantic and rule-based VADER was used to calculate polarity scores and classify sentiments, which overcame the weakness of manual labeling, while Random Forest was utilized as its supervised classifier. Furthermore, considering Twitter’s massive size, we collected over 3.6 million tweets and analyzed various dataset sizes as these are related to the model’s learning process. Lastly, Grey Wolf Optimizer parameter tuning was conducted to optimize the classifier’s performance. The results show that 1) HyVADRF Model returned an accuracy of 75.29 %, precision of 70.22%, recall of 87.70%, and F1-score of 78%. 2) The most ideal percentage of dataset size is 90% of the total collected tweets (n=1,249,060). 3) With standard deviations of 0.0008 for accuracy and F1-score and 0.0011 for precision and recall. Hence, HyVADRF Model consistently delivers stable results.
Blockchain has widespread applications in the financial field but has also attracted increasing cybercrimes. Recently, phishing fraud has emerged as a major threat to blockchain security, calling for the development of effective regulatory strategies. Nowadays network science has been widely used in modeling Ethereum transaction data, further introducing the network representation learning technology to analyze the transaction patterns. In this paper, we consider phishing detection as a graph classification task and propose an end-to-end Phishing Detection Graph Neural Network framework (PDGNN). Specifically, we first construct a lightweight Ethereum transaction network and extract transaction subgraphs of collected phishing accounts. Then we propose an end-to-end detection model based on Chebyshev-GCN to precisely distinguish between normal and phishing accounts. Extensive experiments on five Ethereum datasets demonstrate that our PDGNN significantly outperforms general phishing detection methods and scales well in large transaction networks.
Arkan Hammoodi Hasan Kabla, Mohammed Anbar, Selvakumar Manickam, Taief Alaa Al-Amiedy · 7 authors
Ethereum attracts more investors, researchers, and even scammers for many reasons; this is the first platform that enables the new Decentralized Applications (DApps) to run on top of the blockchain network. However, the rich semantics and applications of DApps inevitably introduce many security issues that have grabbed significant attention from industry and academics due to their destructive impact on DApps in recent years. Therefore, there is a vital need to study the applicability of Intrusion Detection System in detecting Ethereum-based attacks. Hence, this paper is among the first comprehensive review that studies the applicability of IDS in detecting Ethereum-based attacks. In addition, this paper lists all the potential attacks on Ethereum passing through the vulnerabilities that cause those attacks and ending with the consequences of each attack. Besides, this paper analyses all the IDS-based related works of Ethereum attacks detection since the Ethereum platform was launched in 2015. Finally, this paper discusses the open issues regarding vulnerabilities and attacks, challenges, and future directions.
Arkan Hammoodi Hasan Kabla, Mohammed Anbar, Selvakumar Manickam, Shankar Karupayah
Recently, the rapid flourish of blockchain technology in the financial field has attracted many cybercriminals’ attention to launch blockchain-based attacks such as Ponzi schemes, Scam wallets, and phishing scams. Currently, Ethereum is the most prominent blockchain-based platform and the first that supports smart contracts. However, the number of phishing scam accounts are reportedly more than 50% of all cybercrimes in Ethereum. In contrast, this paper proposes a detection mechanism called Ethereum Phishing Scam Detection (Eth-PSD) that attempts to detect phishing scam-related transactions using a novel machine learning-based approach. Eth-PSD tackles some of the limitations in the existing works, such as the use of imbalanced datasets, complex feature engineering, and lower detection accuracy. We also investigated the aspects of constructing a new updated and balanced dataset that can be used for evaluating Eth-PSD effectively. Our experimental results indicate that Eth-PSD could efficiently detect the phishing scam on Ethereum with a detection accuracy of 98.11%, with a very low False Positive Rate of 0.01. Taken together, Eth-PSD showed a superior advantage compared to the existing works in reducing the dimensionality of the dataset by feature engineering and achieved an overall detection accuracy with an improvement of at least 6% compared to other existing solutions from the related work.
Blockchain kripto paraların arkasındaki teknoloji olarak sistemi değiştirmeyi, hacklemeyi, hile yapmayı zorlaştıracak ve hatta imkânsız hale getirecek şekilde bilgi kaydetme sistemidir. İş yönetimi için çok önemli olan yeniliklerin örneklerinden biridir ve işletmelerin işleyişi üzerinde önemli bir etkiye sahip, gelişmekte olan ve faydacı bir teknolojidir. Bu çalışmanın amacı blockchain teknolojisinin mevcut ve muhtemel kullanım alanlarını analiz etmektir. Bu amaçla literatür taraması yapılarak elde edilen bulgular değerlendirilmiştir. Araştırma bulguları blockchain teknolojisinin işletmelerde, üretim, insan kaynakları, tedarik zinciri, pazarlama, turizm, kamu, sağlık, tarım, finans, muhasebe denetim, enerji, eğlence sektörlerinde kullanım imkanı olduğunu göstermektedir. Elde edilen sonuçlara göre blockchain özellikle muhasebe, finans, denetim ve bankacılık alanlarında önemli değişimlere ve gelişmelere yol açacak bir teknoloji olarak kabul edilmektedir.
Kripto para birimleri 2009 yılında ilk Bitcoin'in ortaya çıkışından bu yana finansal sistemin önemli bir parçası haline gelmiştir. Özellikle de son zamanlarda finansal sistem içerisinde potansiyel değişiklikler meydana getirerek, toplumsal karşılığı ve gelecekteki beklentileri hakkında daha çok gündemi meşgul etmeye başlamıştır. Bu gündem sosyal medya sitelerinde daha çok görülmektedir. Bu çalışmada da Twitter’da #Bitcoin olarak atılan Tweetlerin duygu analizi incelenmiştir. Bunun için Orange Data Mining programı kullanılmıştır. Sonuç olarak; Bitcoin konusunda baskın bir sevinç duygusunun olduğu ve yatırımcıların Bitcoin aldıklarında kendilerini mutlu hissettikleri görülmüştür.
Kai Wang, Jun Pang, Ding-Jie Chen, Yu Zhao · 7 authors
Exploiting the anonymous mechanism of Bitcoin, ransomware activities demanding ransom in bitcoins have become rampant in recent years. Several existing studies quantify the impact of ransomware activities, mostly focusing on the amount of ransom. However, victims’ reactions in Bitcoin that can well reflect the impact of ransomware activities are somehow largely neglected. Besides, existing studies track ransom transfers at the Bitcoin address level, making it difficult for them to uncover the patterns of ransom transfers from a macro perspective beyond Bitcoin addresses. In this article, we conduct a large-scale analysis of ransom payments, ransom transfers, and victim migrations in Bitcoin from 2012 to 2021. First, we develop a fine-grained address clustering method to cluster Bitcoin addresses into users, which enables us to identify more addresses controlled by ransomware criminals. Second, motivated by the fact that Bitcoin activities and their participants already formed stable industries, such as Darknet and Miner , we train a multi-label classification model to identify the industry identifiers of users. Third, we identify ransom payment transactions and then quantify the amount of ransom and the number of victims in 63 ransomware activities. Finally, after we analyze the trajectories of ransom transferred across different industries and track victims’ migrations across industries, we find out that to obscure the purposes of their transfer trajectories, most ransomware criminals (e.g., operators of Locky and Wannacry) prefer to spread ransom into multiple industries instead of utilizing the services of Bitcoin mixers. Compared with other industries, Investment is highly resilient to ransomware activities in the sense that the number of users in Investment remains relatively stable. Moreover, we also observe that a few victims become active in the Darknet after paying ransom. Our findings in this work can help authorities deeply understand ransomware activities in Bitcoin. While our study focuses on ransomware, our methods are potentially applicable to other cybercriminal activities that have similarly adopted bitcoins as their payments.
This paper studies a fundamental problem regarding the security of blockchain PoW consensus on how the existence of multiple misbehaving miners influences the profitability of selfish mining. Each selfish miner (or attacker interchangeably) maintains a private chain and makes it public opportunistically for acquiring more rewards incommensurate to his Hash power. We first establish a general Markov chain model to characterize the state transition of public and private chains for Basic Selfish Mining (BSM), and derive the stationary profitable threshold of Hash power in closed-form. It reduces from 25% for a single attacker to below 21.48% for two symmetric attackers theoretically, and further reduces to around 10% with eight symmetric attackers experimentally. We next explore the profitable threshold when one of the attackers performs strategic mining based on Partially Observable Markov Decision Process (POMDP) that only half of the attributes pertinent to a mining state are observable to him. An online algorithm is presented to compute the nearly optimal policy efficiently despite the large state space and high dimensional belief space. The strategic attacker mines selfishly and more agilely than BSM attacker when his Hash power is relatively high, and mines honestly otherwise, thus leading to a much lower profitable threshold. Last, we formulate a simple model of absolute mining revenue that yields an interesting observation: selfish mining is never profitable at the first difficulty adjustment period, but replying on the reimbursement of stationary selfish mining gains in the future periods. The delay till being profitable of an attacker increases with the decrease of his Hash power, making blockchain miners more cautious on performing selfish mining.
Abdul Razaque, Bandar Alotaibi, Munif Alotaibi, Fathi Amsaad · 8 authors
When people use social networks, they often fall prey to a clickbait scam. The scammer attempts to create a striking headline that attracts the majority of users and attaches a link. The user follows the link and can be redirected to a fraudulent resource where the user easily loses personal data. To solve this problem, a Blockchain-enabled deep recurrent neural network (BDRNN) is proposed to detect the nature safe and malicious clickbait from the contents. The proposed BDRNN consists of three phases: analysis of clickbait and source rating, clickbait search process and multi-layered clickbait detection. The analysis of clickbait and source rating phase helps to analyze different sources to detect the clickbait and also rating the content-sources. To achieve the clickbait analysis and source rating, the detection of blocklisted/allowlisted source and source rating check algorithms are introduced. The clickbait search process is accomplished by incorporating the binary search features for a faster and more efficient search process for malicious content-detection. The multi-layered clickbait detection is main phase of the proposed BDRNN that consists of three models: content-to-vector model (layer-1), deep neural network model(layer-2), and Blockchain-enabled malicious content detection model (layer-3). These models collectively detect the malicious and safe clickbait from the contents. The extensive experiments are conducted to determine the effectiveness of the proposed BDRNN model and compared with the existing state-of-the-art neural network models designed for clickbait detection, and the result demonstrates that the proposed BDRNN model outperforms the counterparts from the, accuracy, link detection, memory usage, analogous perspectives, and attacker’s successful content capturing rate.
The emergence of the pandemic, Covid-19, impacted the worldwide economy. The daily scientific development helped in creating a vaccine against the virus. In order to limit the spread of the virus, government authorities are making it mandatory for vaccination certificates for people to run businesses or access public facilities like theaters, restaurants, etc. The government mandate of vaccine certificates compelled people to purchase fake certificates and fake entities to provide fake certificates. This paper provides an application-based blockchain solution for registering vaccinating authorities to vaccinate and provides relevant vaccine certificates that anyone can verify in no time. Additionally, analysis of data retrieving from the blockchain is provided because the data reading will be happening by thousands of authorities. The code for the prototype application is available on Github.
Now a days, people spend most of their times in social media. Due to availability of news and also for the free scope of sharing, most of the time rumors are being extensive in a short period of time. Detecting and preventing rumors and false information remains a significant challenge for social network. The introduction of blockchain technology has paved the way for the development of decentralized apps in order to address this issue. In this technology any information is recorded permanently. We will explore a strategy to eliminate bogus news on social media by utilizing the benefits of peer-to-peer network ideas. By issuing non-fungible token content rating we can detect and ensure appropriate news. The findings revealed that the suggested technique has a satisfactory performance and efficiency in recognizing rumors and preventing their spread.
Yourong Chen, Hao Chen, Yang Zhang, Meng Han · 6 authors
Owing to the incremental and diverse applications of cryptocurrencies and the continuous development of distributed system technology, blockchain has been broadly used in fintech, smart homes, public health, and intelligent transportation due to its properties of decentralization, collective maintenance, and immutability. Although the dynamism of blockchain abounds in various fields, concerns in terms of network communication interference and privacy leakage are gradually increasing. Because of the lack of reliable attack analysis systems, fully understanding some attacks on the blockchain, such as mining, network communication, smart contract, and privacy theft attacks, has remained challenging. Therefore, in this study, we examine the security and privacy of the blockchain and analyze possible solutions. We systematical classify the blockchain attack techniques into three categories, then discuss the corresponding attack and defense methods based on these categories. We focus on (1) the attack and defense methods of mining pool attacks for blockchain security issues, such as block withholding, 51%, pool hopping, selfish mining, and fork after withholding attacks, in the attack type of consensus excitation; (2) the attack and defense methods of network communication and smart contracts for blockchain security issues, such as distributed denial-of-service, Sybil, eclipse, and reentrancy attacks, in the attack type of middle protocol; and (3) the attack and defense methods of privacy thefts for blockchain privacy issues, such as identity privacy and transaction information attacks, in the attack type of application service. Finally, we discuss future research directions for blockchain security.
P. Lavanya, N. Ananthi, K Kumaran, M. Abinaya · 7 authors
The availability of fake product in the Market is one of the biggest challenges of the online retail industry. These products appear to be genuine but they are imitations of the original branded products. Almost 20% of the products sold on online websites are fake. In recent times, block chain is receiving more engagement and various applications are been emerged from this technology. In this paper, to ensure that consumers need not depend on the distributers to know whether their products are authentic or not, we are using the decentralized Block chain technology approach. We describe a decentralization Block chain network with anti-counterfeiting items, which allows producers to deliver items without having to run clear outlets, lowering product quality assurance costs dramatically.
Razieh Nokhbeh Zaeem, Kai Chih Chang, Teng-Chieh Huang, David Liau · 10 authors
Identity is at the heart of digital transformation. Successful digital transformation requires confidence in and protection of digital identities. On the Internet, however, there is no unique and standard identity layer. Consequently, a variety of digital identities have emerged over years, leading to privacy risks, security vulnerabilities, risks for identity owners, and liability for identity issuers and those relying on digital identities to grant access to goods and services. Self-Sovereign Identity (SSI) and similar forms of identity management on the blockchain distributed ledger are novel technologies that recognize the need to keep user identity privately stored in user-owned devices, securely verified by identity issuers, and only revealed to verifiers as needed. There is limited academic literature defining the prerequisite SSI functional and non-functional requirements and comparing SSI technologies. Often those SSI technologies reviewed in the literature lack behind current advances. We present the first work that compiles a comprehensive list of functional and non-functional requirements of SSI and compares an extensive number of existing SSI/blockchain-based identity management solutions with respect to these requirements. Our work sheds light on the state-of-the-art SSI development and paves the way for future, more informed analysis and development of novel identity management and SSI solutions.
In this article, we present a Social Network Analysis–based approach to investigate user behaviour during a cryptocurrency speculative bubble in order to extract knowledge patterns about it. Our approach is general and can be applied to any past, present and future cryptocurrency speculative bubble. To verify its potential, we apply it to investigate the Ethereum speculative bubble happened in the years 2017 and 2018. We also describe several interesting knowledge patterns about the behaviour of specific categories of users that we obtained from this investigation. Furthermore, we describe how our approach can support the construction of an identikit of the speculators who maneuvered behind the Ethereum bubble analysed. Finally, we show that this capability of supporting the hunting for speculators is intrinsic of our approach and can cover past, present and future bubbles.
Muneeb Ul Hassan, Mubashir Husain Rehmani, Jinjun Chen
Over the past decade, blockchain technology has attracted a huge attention from both industry and academia because it can be integrated with a large number of everyday applications of modern information and communication technologies (ICT). Peer-to-peer (P2P) architecture of blockchain enhances these applications by providing strong security and trust-oriented guarantees, such as immutability, verifiability, and decentralization. Despite these incredible features that blockchain technology brings to these ICT applications, recent research has indicated that the strong guarantees are not sufficient enough and blockchain networks may still be prone to various security, privacy, and reliability issues. In order to overcome these issues, it is important to identify the anomalous behaviour within the actionable time frame. In this article, we provide an in-depth survey regarding integration of anomaly detection models in blockchain technology. For this, we first discuss how anomaly detection can aid in ensuring security of blockchain based applications. Then, we demonstrate certain fundamental evaluation metrics and key requirements that can play a critical role while developing anomaly detection models for blockchain. Afterwards, we present a thorough survey of various anomaly detection models from the perspective of each layer of blockchain. Finally, we conclude the article by highlighting certain important challenges alongside discussing how they can serve as future research directions for new researchers in the field.
Tan Hui Yang Zen, Chin Bing Hong, P. Mohan, Vivek Balachandran
The propagation of misinformation has become prevalent in recent years and is one of the predominant factors for social media myths and conspiracy theories. This paper proposes and develops a solution to detect fake news and hence control misinformation broadcasting in social media. Existing solutions for detecting fake news involve either using Machine learning/AI or employing a crowdsourcing-based fact-checker to evaluate the reliability of the information. In our proposed solution - ABC-verify - we designed and developed an integrated framework combining both AI and a Proof-of-stake (PoS) smart contract algorithm for crowdsourcing to achieve better accuracy than AI-only or pure crowdsourcing. The advantage of the proposed solution is two-fold. Firstly, the AI model can continuously learn from the output of the smart contract algorithm. Secondly, the validated news that is added to the blockchain is immutable. The validators from the public Ethereum blockchain stake ERC721 tokens in exchange for a reward if the information reliability were accurate. The prediction from the AI classification model is based on a pre-trained BERT model on a dataset of 10,000 labelled Twitter datasets. The AI classification model proxies as one of the validators in the PoS algorithm. The final verdict from the smart contract is then fed back into the training dataset to improve the AI classification model and achieve better overall accuracy of 93%. Unlike traditional crowdsourcing platforms, news stored within the blockchain is immutable. Furthermore, the Ethereum blockchain is transparent, and every transaction is recorded within the blockchain, hence enabling authenticity and trust between peer-to-peer transactions.
This article proposes a SaTya scheme that leverages a blockchain (BC)-based deep learning (DL)-assisted classifier model that forms a trusted chronology in fake news classification. The news collected from newspapers, social handles, and e-mails are web-scrapped, prepossessed, and sent to a proposed Q-global vector for word representations (Q-GloVe) model that captures the fine-grained linguistic semantics in the data. Based on the Q-GloVe output, the data are trained through a proposed bi-directional long short-term memory (Bi-LSTM) model, and the news is classified as real-or-fake news. This reduces the vanishing gradient problem, which optimizes the weights of the model and reduces bias. Once the news is classified, it is stored as a transaction, and the news stakeholders can execute smart contracts (SCs) and trace the news origin. However, only verified trusted news sources are added to the BC network, ensuring credibility in the system. For security evaluation, we propose the associated cost of the Bi-LSTM classifier and propose vulnerability analysis through the smart check tool for potential vulnerabilities. The scheme is compared against discourse-structure analysis, linguistic natural language framework, and entity-based recognition for different performance metrics. The scheme achieves an accuracy of 99.55% compared to 93.62% against discourse structure analysis. Also, it shows an average improvement of 18.76% against other approaches, which indicates its viability against fake-classifier-based models.
While Bitcoin is legal, hackers, narcotics smugglers, and other dubious persons that have to be prosecuted are still utilizing it. Bitcoin is used in various industries due to its wide range of applications but it is also on the radar of malicious people and they are performing various types of cybercrimes in the dark web. Future conflicts will be cyber wars, with crimes combining cryptography and malware to manipulate information technology and compromise their security. Cyber-attacks are made easier by the rapid development of the Internet. Loss of private information and degradation of customer trust in e-commerce are two examples of web threats. In this paper, the authors have implemented an automated process for investigating the bitcoins balances and wallet addresses. The authors have also highlighted the use of bitcoin in various cybercrimes. The tool used in investigating the Bitcoin balances and the bitcoin wallets is SpiderFoot. The results are generated in our paper are the form of hashes of bitcoin balances and wallet addresses that are investigated properly to check for any cyber fraud in the dark web.
A smart contract cannot be modified once deployed. Bugs in deployed smart contracts may cause devastating consequences. For example, the infamous reentrancy bug in the DAO contract allows attackers to arbitrarily withdraw ethers, which caused millions of dollars loss. Currently, the main countermeasure against contract bugs is to thoroughly detect and verify contracts before deployment, which, however, cannot defend against unknown bugs. These detection methods also suffer from possible false negative results.