Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

13,493 papersLast indexed Aug 31, 2026
Search papers

Paper index

13,493 results · page 378 of 563

Clear filters
Oct 22, 2021·Lecture notes in computer science
33 cites
Formal Verification of the Ethereum 2.0 Beacon Chain

Franck Cassez, Joanne Fuller, Aditya Asgaonkar

Abstract We report our experience in the formal verification of the reference implementation of the Beacon Chain. The Beacon Chain is the backbone component of the new Proof-of-Stake Ethereum 2.0 network: it is in charge of tracking information about the validators , their stakes , their attestations (votes) and if some validators are found to be dishonest, to slash them (they lose some of their stakes). The Beacon Chain is mission-critical and any bug in it could compromise the whole network. The Beacon Chain reference implementation developed by the Ethereum Foundation is written in Python, and provides a detailed operational description of the state machine each Beacon Chain’s network participant (node) must implement. We have formally specified and verified the absence of runtime errors in (a large and critical part of) the Beacon Chain reference implementation using the verification-friendly language Dafny. During the course of this work, we have uncovered several issues, proposed verified fixes. We have also synthesised functional correctness specifications that enable us to provide guarantees beyond runtime errors. Our software artefact with the code and proofs in Dafny is available at https://github.com/ConsenSys/eth2.0-dafny .

Open access
3 source records
Security and Verification in Computing
Advanced Malware Detection Techniques
Software Engineering Research
Original source
Oct 21, 2021·arXiv
14 cites
Decentralised Trustworthy Collaborative Intrusion Detection System for IoT

Guntur Dharma Putra, Volkan Dedeoglu, Abhinav Pathak, Salil S. Kanhere · 5 authors

Intrusion Detection Systems (IDS) have been the industry standard for securing IoT networks against known attacks. To increase the capability of an IDS, researchers proposed the concept of blockchain-based Collaborative-IDS (CIDS), wherein blockchain acts as a decentralised platform allowing collaboration between CIDS nodes to share intrusion related information, such as intrusion alarms and detection rules. However, proposals in blockchain-based CIDS overlook the importance of continuous evaluation of the trustworthiness of each node and generally work based on the assumption that the nodes are always honest. In this paper, we propose a decentralised CIDS that emphasises the importance of building trust between CIDS nodes. In our proposed solution, each CIDS node exchanges detection rules to help other nodes detect new types of intrusion. Our architecture offloads the trust computation to the blockchain and utilises a decentralised storage to host the shared trustworthy detection rules, ensuring scalability. Our implementation in a lab-scale testbed shows that the our solution is feasible and performs within the expected benchmarks of the Ethereum platform.

Open access
2 source records
cs.CR
Network Security and Intrusion Detection
Distributed systems and fault tolerance
Original source
Oct 21, 2021·Ingeniería y Desarrollo
1 cites
CyberDrone: una plataforma de ciberseguridad para detección de ataques a drones

Germán Zapata, Rodolfo García-Sierra

Se presentó el desarrollo de una plataforma de ciberseguridad para vehículos aéreos no tripulados (UAV, por sus siglas en inglés) o drones según la tecnología cyber-deception. Esta tecnología tiene como fundamento la creación deliberada de señuelos (honeypots) de fácil acceso y detección para detectar potenciales intrusos en el perímetro de una infraestructura crítica. Se explicó el modelo conceptual de la solución propuesta y la descripción detallada de cada uno de los procedimientos desarrollados, se implementó una metodología de desarrollo tecnológico, se llevaron a cabo procedimientos para la creación de señuelos en redes inalámbricas wifi y en bandas de radiofrecuencia (RF), y se incluyó la aproximación al desarrollo de un procedimiento de GPS Spoofing. Este último fue explorado usando un equipo de radio definido por software (SDR, por sus siglas en inglés) para la suplantación de señales GPS que permite la implementación de estrategias de defensa contra drones atacantes. Finalmente, se describe la plataforma web para monitorear los señuelos activos y para registrar los intentos de penetración. Estos registros de intento de penetración se almacenan en una blockchain desarrollada según la tecnología Ethereum. Se encontró que las redes inalámbricas wifi y de RF poseen vulnerabilidades que pueden ser explotadas por potenciales atacantes. También que el procedimiento GPS Spoofing es mucho más complejo que los procedimientos por redes inalámbricas, pero que permitiría tomar acción sobre drones atacantes.

Open access
Conflict, Peace, and Violence in Colombia
War, Law, and Justice
European and Russian Geopolitical Military Strategies
Original source
Oct 21, 2021·Symmetry
11 cites
A Proposed Framework for Secure Data Storage in a Big Data Environment Based on Blockchain and Mobile Agent

Khalil al-Sulbi, Maher Khemakhem, Abdullah Ahamd Basuhail, Fathy Eassa Eassa · 6 authors

The sum of Big Data generated from different sources is increasing significantly with each passing day to extent that it is becoming challenging for traditional storage methods to store this massive amount of data. For this reason, most organizations have resolved to use third-party cloud storage to store data. Cloud storage has advanced in recent times, but it still faces numerous challenges with regard to security and privacy. This paper discusses Big Data security and privacy challenges and the minimum requirements that must be provided by future solutions. The main objective of this paper is to propose a new technical framework to control and manage Big Data security and privacy risks. A design science research methodology is used to carry out this project. The proposed framework takes advantage of Blockchain technology to provide secure storage of Big Data by managing its metadata and policies and eliminating external parties to maintain data security and privacy. Additionally, it uses mobile agent technology to take advantage of the benefits related to system performance in general. We present a prototype implementation for our proposed framework using the Ethereum Blockchain in a real data storage scenario. The empirical results and framework evaluation show that our proposed framework provides an effective solution for secure data storage in a Big Data environment.

Open access
Blockchain Technology Applications and Security
Cloud Data Security Solutions
IoT and Edge/Fog Computing
Original source
Oct 20, 2021·Blockchain and the Digital Twin
0 cites
Blockchain and Smart Contracts for Know Your Customer (KYC)

PricewaterhouseCoopers, Patrick Osborne

Distributed Ledger Technology (DLT) and Blockchain Technology (BCT) are options for introducing smart and transitive energy trading via a Know Your Customer or Know Your Client (KYC) system using an Ethereum Blockchain. The most significant context in which BCT can create transformative change is in the verification of other parties in an energy trading system. Currently the KYC trade mostly relies on internal controls to send and receive KYC information across the globe, resulting in slower and error prone data management and governance. BCT can solve this by providing immutable and verifiable data sources. Implementing smart contract addressing, the issue of storing critical data necessary at different stages of KYC and making it verifiable by all stakeholders is of critical importance. The literature review looks at the current research in BCT, programming languages used in BCT, Game Theory, Zero-Knowledge Proofs and energy trading in context to KYC. Having a foundational concept mathematically by creating game theoretic models and a simple computer programming simulation is the first step in the task of creating a true BCT platform that can be used in energy trading for KYC. Simulating the scenarios of n-player games is important to the advancement of this platform. The key result of these games and interaction between traders will help change the trading systems regionally and internationally. This can deliver new ways of working and brings visibility and control to each energy trade. The researcher analyses the strength of the system through the decisions of the traders using infinite games. New trading strategies and BCT resources with different parameters gain a larger market presence in international trade with these proofs, codifications and simulations. A gap exists in the literature in BCT in the creation of game theory algorithms as well as using simulation tools and software and using these methods to create forecasted energy trading scenarios with the implementation of KYC. Looking at an infinite game mathematically and presenting a simple codified computer simulation using Ethereum via Solidity involving a supplier, operator and regulator will give new implications in game theory and conflict-resolution scenarios within context to energy trading and KYC via BCT.

Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Original source
Oct 20, 2021·2021 International Conference on Information and Communication Technology Convergence (ICTC)
2 cites
A Feasibility Study of An Intelligent Environmental Monitoring System Based On The Ethereum Blockchains

Cheng Yiyang, Kazunori Takashio

In today's era, the security and authenticity of information have always received extensive attention, especially when people have doubts about the authenticity of data. Hence, a traceable data storage platform with the feature that theoretically cannot be tampered with becomes extremely important. Under such demands, the deployment of smart contracts can effectively trace the source and discover problems. This article introduces an environmental data detection platform based on blockchain technology and smart contracts. It aims to record the data continuously and verify the authority of each transaction.

Blockchain Technology Applications and Security
Currency Recognition and Detection
Original source
Oct 20, 2021·2021 13th International Conference on Information & Communication Technology and System (ICTS)
9 cites
News Verification using Ethereum Smart Contract and Inter Planetary File System (IPFS)

Haekal Febriansyah Ramadhan, Fandi Aditya Putra, Riri Fitri Sari

News is a form of information sharing that tells the people about current event that is happening. With the advancement of technologies, the rate of spreading of the news is also increasing. One of the most popular places to read news is through the Internet. However, most of the people that read news from the Internet is not aware about the news sources. This leads to the spread of some fake news in society. In this paper, we suggest a way to verify a news using Ethereum smart contract and IPFS. There are four entities that involved in the system, such as Journalist as the one that provides the news, Validator as the one that will rate the news, Ethereum Smart Contract that will store the data inside the blockchain, and IPFS that will store the news and giving hash code to be stored inside the blockchain. This paper also analyzed the cost required to run the function of the smart contract deployed. The result is that all of the Rating Functions cost the same. However, the News Submit Function is not. The difference is the bigger the news stored in the IPFS, the more expensive the cost required to run the function.

Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Advanced Data Storage Technologies
Original source
Oct 20, 2021·Environmental Science and Pollution Research
80 cites
Analyzing asymmetric effects of cryptocurrency demand on environmental sustainability

Sinan Erdoğan, Maruf Yakubu Ahmed, Samuel Asumadu Sarkodie

Abstract When Bitcoin (BTC), the first pioneering cryptocurrency was released in 2009, it was considered as an apolitical currency. Besides, the possible effect of BTC and other cryptocurrencies on either financial markets or transactions has been widely discussed. However, the environmental effects of cryptocurrency demand have been ignored. Here, this study examines the nexus between cryptocurrencies and environmental degradation by employing standard and asymmetric causality methods. The Toda-Yamamoto and bootstrap-augmented Toda-Yamamoto test results reveal Bitcoin and Ethereum (ETH) excluding Ripple (XRP) have causal effects on environmental degradation. The Fourier-augmented Toda-Yamamoto test results show causal effects running from Bitcoin and Ripple to environmental degradation, whereas no causal effect runs from Ethereum to environmental degradation. The asymmetric causality shows causal effects from the positive shock of Bitcoin demand, negative shocks of Ripple and Ethereum demands to positive shocks of environmental degradation. Further discussions and policy implications are provided in the relevant sections of this study.

Open access
3 source records
Blockchain Technology Applications and Security
Energy, Environment, Economic Growth
Market Dynamics and Volatility
Original source
Oct 19, 2021·Proceedings of the ACM SIGOPS 28th Symposium on Operating Systems Principles
22 cites
Forerunner

Chen Yang, Zhongxin Guo, Runhuai Li, Shuo Chen · 7 authors

Ethereum is an emerging distributed computing platform that supports a decentralized replicated virtual machine at a large scale. Transactions in Ethereum are specified in smart contracts, disseminated through broadcast, accepted into the chain of blocks, and then executed on each node. In this new Dissemination-Consensus-Execution (DiCE) paradigm, the time interval between when a transaction is known (during the dissemination phase) to when the transaction is executed (after the consensus phase) offers a window of opportunity to accelerate transaction processing through speculative execution. However, the traditional speculative execution, which hinges on the ability to predict the future accurately, is inadequate because of DiCE's many-future nature.

2 source records
Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Cloud Computing and Resource Management
Original source
Oct 19, 2021·IEEE Transactions on Network and Service Management
31 cites
Decentralized On-Chain Data Access via Smart Contracts in Ethereum Blockchain

R. Sivasankari, R. Akila, S. Revathi, J. Brindha Merin

Smart contracts in Ethereum blockchain network are self-executable scripts used for managing tokenized assets and access rights between different entities on the blockchain network. They are significant addition to blockchain technology for achieving data transparency and reliability in maintaining the digital relationship between two or more entities. However, the smart contract is in its nascent stage and suffers from various limitations, including immutability and code secrecy. In this paper, we address the inability of smart contracts to access the on-chain data. The smart contract currently fetches the on-chain data by taking external oracle assistance, which can be compromised to influence the customers. To address the issue, we propose a decentralized mechanism for accessing the blockchain data directly from the smart contracts by indexing single or multiple parameters of a transaction in each block using the Merkle-Patricia Trie (MPT). The idea is to increase the data transparency of blockchain applications. The paper provides a sequential search methodology that can retrieve transactions from${N}$blocks, satisfying specific conditions, in${O}$(${N}$). The complexity is further reduced to${O}$(N/k) by partitioning the blockchain data into${k}$disjoint subsets to achieve parallelism in the search procedure. We experimentally verify the effectiveness of the proposed methodology with a case study on the Ethereum blockchain data.

2 source records
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Steganography and Watermarking Techniques
Original source
Oct 19, 2021·Lecture notes in computer science
57 cites
Three Attacks on Proof-of-Stake Ethereum

Caspar Schwarz-Schilling, Joachim Neu, Barnabé Monnot, Aditya Asgaonkar · 6 authors

Recently, two attacks were presented against Proof-of-Stake (PoS) Ethereum: one where short-range reorganizations of the underlying consensus chain are used to increase individual validators' profits and delay consensus decisions, and one where adversarial network delay is leveraged to stall consensus decisions indefinitely. We provide refined variants of these attacks, considerably relaxing the requirements on adversarial stake and network timing, and thus rendering the attacks more severe. Combining techniques from both refined attacks, we obtain a third attack which allows an adversary with vanishingly small fraction of stake and no control over network message propagation (assuming instead probabilistic message propagation) to cause even long-range consensus chain reorganizations. Honest-but-rational or ideologically motivated validators could use this attack to increase their profits or stall the protocol, threatening incentive alignment and security of PoS Ethereum. The attack can also lead to destabilization of consensus from congestion in vote processing.

Open access
3 source records
Distributed systems and fault tolerance
Internet Traffic Analysis and Secure E-voting
Security and Verification in Computing
Original source
Oct 19, 2021·2021 20th International Symposium on Communications and Information Technologies (ISCIT)
10 cites
A Comparison of Distributed Ledger Technologies in IoT: IOTA versus Ethereum

Xuan Chen, Ryota Nakada, Kien Nguyen, Hiroo Sekiya

There is an increasing interest in adopting distributed ledger technologies (DLTs) to IoT applications that enable secured interaction between IoT devices without third-party involvement. Among recent advanced DLTs, Ethereum blockchain and IOTA Tangle are emerging as promising candidates for various IoT use cases. Both offer various IoT-friendly features such as lightweight crypto, open-source implementations, energy-efficient operations, etc. So far, the two technologies have only been qualitatively evaluated together in the literature. There has not yet been a performance comparison between IOTA and Ethereum in an IoT application. To address the issue, we build an IoT environment that can run both DLTs and compare their performance. We thoroughly investigate the DLTs' three layers (i.e., Consensus, Network, and Storage layers). In the first layer, we evaluate the CPU utilization and number of transaction; in the second one, the DLTs' network performance is compared. Meanwhile, disk and memory usage are derived in the third layer. The results show that IOTA performs better with most performance metrics.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Caching and Content Delivery
Original source
Oct 18, 2021·arXiv (Cornell University)
0 cites
An Empirical Study of Protocols in Smart Contracts

Timothy Mou, Michael Coblenz, Jonathan Aldrich

Smart contracts are programs that are executed on a blockhain. They have been used for applications in voting, decentralized finance, and supply chain management. However, vulnerabilities in smart contracts have been abused by hackers, leading to financial losses. Understanding state machine protocols in smart contracts has been identified as important to catching common bugs, improving documentation, and optimizing smart contracts. We analyze Solidity smart contracts deployed on the Ethereum blockchain and study the prevalence of protocols and protocol-based bugs, as well as opportunities for gas optimizations.

Open access
2 source records
cs.PL
cs.CR
Blockchain Technology Applications and Security
Original source
Oct 17, 2021·MULTINETICS
3 cites
Implementasi Ethereum Blockchain dan Smart Contract Pada Jaringan Smart Energy Meter

Anggun Mugi Mabruroh, Favian Dewanta, Aulia Arif Wardana

Pada penelitian ini mengusulkan pembuatan perangkat Internet of Things yaitu smart energy meter dengan menerapkan sistem blockchain sebagai database. Internet of Things memiliki sistem penyimpanan secara terpusat pada database server, jika server down maka database tidak dapat digunakan dan data kemungkinan akan hilang. Terdapat sistem penyimpanan yang memiliki jaringan desentralisasi dan terdistribusi yaitu blockchain. Sistem blockchain pribadi dibuat menggunakan framework Ethereum. Data sensor akan dibaca oleh Raspberry Pi 4B dan dikirimkan ke node 1 melalui MQTT. Node 1 akan menyimpan data ke blok. Dua node akun Ethereum akan memvalidasi blok tersebut. Jika diterima maka blok akan disimpan pada blockchain dan membuat rantai blok baru. Dalam proses penyimpanan memiliki smart contract antar akun Ethereum yang dibuat menggunakan solidity dan diakses menggunakan web3 API. Data yang berhasil disimpan akan ditampilkan ke web pengguna. Berdasarkan hasil pengukuran performa protokol MQTT dan sistem blockchain jika dibandingkan dengan database tradisional, maka blockchain kurang cepat dalam proses penyimpanan karena terdapat proses transaksi dan verifikasi data. Namun jika diterapkan pada data smart energy meter tidak masalah karena waktu yang diperlukan untuk proses penyimpanan maksimal 1 menit saja cukup. Jumlah node dan ukuran data atau blok tidak mempengaruhi kinerja algoritma konsensus proof of authority.

Open access
Blockchain Technology in Education and Learning
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Original source
Oct 15, 2021·International Journal of Finance & Banking Studies (2147-4486)
3 cites
Value at Risk estimation using GAS models with heavy tailed distributions for cryptocurrencies

Stephanie Danielle Subramoney, Knowledge Chinhamu, Retius Chifurira

Risk management and prediction of market losses of cryptocurrencies are of notable value to risk managers, portfolio managers, financial market researchers and academics. One of the most common measures of an asset’s risk is Value-at-Risk (VaR). This paper evaluates and compares the performance of generalized autoregressive score (GAS) combined with heavy-tailed distributions, in estimating the VaR of two well-known cryptocurrencies’ returns, namely Bitcoin returns and Ethereum returns. In this paper, we proposed a VaR model for Bitcoin and Ethereum returns, namely the GAS model combined with the generalized lambda distribution (GLD), referred to as the GAS-GLD model. The relative performance of the GAS-GLD models was compared to the models proposed by Troster et al. (2018), in other words, GAS models combined with asymmetric Laplace distribution (ALD), the asymmetric Student’s t-distribution (AST) and the skew Student’s t-distribution (SSTD). The Kupiec likelihood ratio test was used to assess the adequacy of the proposed models. The principal findings suggest that the GAS models with heavy-tailed innovation distributions are, in fact, appropriate for modelling cryptocurrency returns, with the GAS-GLD being the most adequate for the Bitcoin returns at various VaR levels, and both GAS-SSTD, GAS-ALD and GAS-GLD models being the most appropriate for the Ethereum returns at the VaR levels used in this study.

Open access
Financial Risk and Volatility Modeling
Complex Systems and Time Series Analysis
Market Dynamics and Volatility
Original source
Oct 15, 2021·Digital Threats Research and Practice
27 cites
On Secure E-Voting over Blockchain

Patrick McCorry, Maryam Mehrnezhad, Ehsan Toreini, Siamak F. Shahandashti · 5 authors

This article discusses secure methods to conduct e-voting over a blockchain in three different settings: decentralized voting, centralized remote voting, and centralized polling station voting. These settings cover almost all voting scenarios that occur in practice. A proof-of-concept implementation for decentralized voting over Ethereum’s blockchain is presented. This work demonstrates the suitable use of a blockchain not just as a public bulletin board but, more importantly, as a trustworthy computing platform that enforces the correct execution of the voting protocol in a publicly verifiable manner. We also discuss scaling up a blockchain-based voting application for national elections. We show that for national-scale elections the major verifiability problems can be addressed without having to depend on any blockchain. However, a blockchain remains a viable option to realize a public bulletin board, which has the advantage of being a “preventive” measure to stop retrospective changes on previously published records as opposed to a “detective” measure like the use of mirror websites. CCS Concepts: • Security and privacy ;

Open access
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Oct 15, 2021·Applied Aspects of Information Technology
4 cites
Smart contract sharding with proof of execution

Igor Mazurok, Yevhen Leonchyk, Oleksandr S. Antonenko, Kyrylo S. Volkov

Nowadays, Decentralized Networks based on Blockchain technology are actively researched. A special place in these researches is occupied by Smart Contracts that are widely used in many areas, such as Decentralized Finance (DeFi), real estate, gambling, electoral process, etc. Nevertheless, the possibility of their widespread adoption is still not a solved problem. This is caused by the fact of their limited flexibility and scalability. In other words, Smart Contracts cannot process a large number of contract calls per second, lack of direct Internet access, inability to operate with a large amount of data, etc. This article is devoted to the development of the Sharding Concept for Decentralized Applications (DApps) that are expressed in form of Smart Contracts written in WebAssembly. The aim of the research is to offer a new Concept of Smart Contract that will increase the scaling due to applying the idea of Sharding that allows avoiding doing the same work by all nodes on the Network and flexibility due to the possibility of interaction with the Internet without special Oracles. During the research, decentralized 0ata storages with the possibility of collective decision-making were developed. The scheme of forming Drives that assumes that each Contract is executed by a set of randomly selected nodes that allows avoiding cahoots and prevents Sybil Attack is offered. Such an approach allowed using Drives as a base layer for Smart Contracts. Moreover, Drives can be used as a standalone solution for decentralized data storing. The features of coordination of results of Contracts execution that greatly expands the possibilities of the Contracts compared to Ethereum Smart Contracts, and, in particular, allow the Contracts to interact with the Internet are described. The Rewards Concept that incentivizes all nodes that honestly execute the Contracts, unlike other systems where only the block producer is rewarded, is developed. It is based on the specially developed Proof of Executiona special algorithm that allows detecting all the nodes that honestly execute the Contracts. In order to make the Proof of Execution more compact, an extension for the existing discrete logarithm zero-knowledge proofs that makes it possible to consistently prove knowledge of dynamically expanding set of values with minimal computational and memory complexity so-called Cumulative Discrete Logarithm Zero-Knowledge Proof is developed. Thus, in this article, the new concept of Smart Contracts Sharding empowered by economic leverages is researched. The main advantages of the proposed approach are the possibility of interaction with the Internet and big data processing. Moreover, the mechanism of incentivizing nodes to honestly execute the Smart Contracts is developed. In addition, the Cumulative Proof that is necessary for the cryptographic strength of the specified mechanism is offered and its correctness is proven. The obtained results can be used to implement Smart Contracts in decentralized systems, in particular, working on the basis of Blockchain technology, especially in the case of demanding high bandwidth and performance.

Open access
Blockchain Technology Applications and Security
Economic and Technological Systems Analysis
Digital Transformation in Law
Original source
Oct 15, 2021·Proceedings of the ACM on Programming Languages
17 cites
Symbolic value-flow static analysis: deep, precise, complete modeling of Ethereum smart contracts

Yannis Smaragdakis, Neville Grech, Sifis Lagouvardos, Κonstantinos Τriantafyllou · 5 authors

We present a static analysis approach that combines concrete values and symbolic expressions. This symbolic value-flow (“symvalic”) analysis models program behavior with high precision, e.g., full path sensitivity. To achieve deep modeling of program semantics, the analysis relies on a symbiotic relationship between a traditional static analysis fixpoint computation and a symbolic solver: the solver does not merely receive a complex “path condition” to solve, but is instead invoked repeatedly (often tens or hundreds of thousands of times), in close cooperation with the flow computation of the analysis. The result of the symvalic analysis architecture is a static modeling of program behavior that is much more complete than symbolic execution, much more precise than conventional static analysis, and domain-agnostic: no special-purpose definition of anti-patterns is necessary in order to compute violations of safety conditions with high precision. We apply the analysis to the domain of Ethereum smart contracts. This domain represents a fundamental challenge for program analysis approaches: despite numerous publications, research work has not been effective at uncovering vulnerabilities of high real-world value. In systematic comparison of symvalic analysis with past tools, we find significantly increased completeness (shown as 83-96% statement coverage and more true error reports) combined with much higher precision, as measured by rate of true positive reports. In terms of real-world impact, since the beginning of 2021, the analysis has resulted in the discovery and disclosure of several critical vulnerabilities, over funds in the many millions of dollars. Six separate bug bounties totaling over $350K have been awarded for these disclosures.

Open access
2 source records
Advanced Malware Detection Techniques
Security and Verification in Computing
Software Engineering Research
Original source
Oct 14, 2021·3rd International Scientific Conference on Innovations in Digital Economy
7 cites
A Blockchain-Based BIM Model for the Smart Building Planning Process

Mohammed Ali Berawi, Teuku Yuri M. Zagloel, Muhammad Naufal Ariq, Mustika Sari

Players in the building and construction industry have progressively adopted building Information Modelling (BIM) to improve the efficiency of building information management through its rich digital building models used at all building life cycle stages. However, there are still several constraints in the BIM collaboration process and data management regarding data security, accountability, and transparency. On the other hand, blockchain, a distributed ledger technology, is considered a solution to address those constraints. Therefore, this paper aims to integrate blockchain technology into the BIM workflow, focusing on the smart building planning process that holds most data generation of the activities in the whole construction project. To obtain the objectives of this study, literature review, benchmarking study, and expert interviews were conducted in two stages, firstly to identify the characteristics and components of a smart building and then to develop further the blockchain-based framework for smart building planning in the BIM model. By developing the framework that utilizes Ethereum blockchain and InterPlanetary File System (IPFS) peer-to-peer storage in Revit BIM client, the results of this study showed that the integration of blockchain in BIM workflow provides an improved platform in terms of data security, accountability, transparency, in which digital signature can be created, and authorization for the models is provided for the planning process of a smart building.

BIM and Construction Integration
Digital Transformation in Industry
IoT and Edge/Fog Computing
Original source
Oct 14, 2021·JMIR Publications Inc.
0 cites
Improving Diagnosis Through Digital Pathology: Proof-of-Concept Implementation Using Smart Contracts and Decentralized File Storage (Preprint)

Hemang Subramanian, Susmitha Subramanian

BACKGROUND Recent advancements in digital pathology resulting from advances in imaging and digitization have increased the convenience and usability of pathology for disease diagnosis, especially in oncology, urology, and gastroenteric diagnosis. However, despite the possibilities to include low-cost diagnosis and viable telemedicine, digital pathology is not yet accessible owing to expensive storage, data security requirements, and network bandwidth limitations to transfer high-resolution images and associated data. The increase in storage, transmission, and security complexity concerning data collection and diagnosis makes it even more challenging to use artificial intelligence algorithms for machine-assisted disease diagnosis. We designed and prototyped a digital pathology system that uses blockchain-based smart contracts using the nonfungible token (NFT) standard and the Interplanetary File System for data storage. Our design remediates shortcomings in the existing digital pathology systems infrastructure, which is centralized. The proposed design is extendable to other fields of medicine that require high-fidelity image and data storage. Our solution is implemented in data systems that can improve access quality of care and reduce the cost of access to specialized pathological diagnosis, reducing cycle times for diagnosis. OBJECTIVE The main objectives of this study are to highlight the issues in digital pathology and suggest that a software architecture–based blockchain and the Interplanetary File System create a low-cost data storage and transmission technology. METHODS We used the design science research method consisting of 6 stages to inform our design overall. We innovated over existing public-private designs for blockchains but using a 2-layered approach that separates actual file storage from metadata and data persistence. RESULTS Here, we identified key challenges to adopting digital pathology, including challenges concerning long-term storage and the transmission of information. Next, using accepted frameworks in NFT-based intelligent contracts and recent innovations in distributed secure storage, we proposed a decentralized, secure, and privacy-preserving digital pathology system. Our design and prototype implementation using Solidity, web3.js, Ethereum, and node.js helped us address several challenges facing digital pathology. We demonstrated how our solution, which combines NFT smart contract standard with persistent decentralized file storage, solves most of the challenges of digital pathology and sets the stage for reducing costs and improving patient care and speed of diagnosis. CONCLUSIONS We identified technical limitations that increase costs and reduce the mass adoption of digital pathology. We presented several design innovations using NFT decentralized storage standards to prototype a system. We also presented the implementation details of a unique security architecture for a digital pathology system. We illustrated how this design can overcome privacy, security, network-based storage, and data transmission limitations. We illustrated how improving these factors sets the stage for improving data quality and standardized application of machine learning and artificial intelligence to such data.

Open access
AI in cancer detection
Original source
Oct 14, 2021·arXiv (Cornell University)
2 cites
Understanding the Evolution of Blockchain Ecosystems: A Longitudinal Measurement Study of Bitcoin, Ethereum, and EOSIO

Ningyu He, Weihang Su, Zhou Yu, Xinyu Liu · 10 authors

The continuing expansion of the blockchain ecosystems has attracted much attention from the research community. However, although a large number of research studies have been proposed to understand the diverse characteristics of individual blockchain systems (e.g., Bitcoin or Ethereum), little is known at a comprehensive level on the evolution of blockchain ecosystems at scale, longitudinally, and across multiple blockchains. We argue that understanding the dynamics of blockchain ecosystems could provide unique insights that cannot be achieved through studying a single static snapshot or a single blockchain network alone. Based on billions of transaction records collected from three representative and popular blockchain systems (Bitcoin, Ethereum and EOSIO) over 10 years, we conduct the first study on the evolution of multiple blockchain ecosystems from different perspectives. Our exploration suggests that, although the overall blockchain ecosystem shows promising growth over the last decade, a number of worrying outliers exist that have disrupted its evolution.

Open access
2 source records
Blockchain Technology Applications and Security
Complex Network Analysis Techniques
Data Stream Mining Techniques
Original source
Oct 14, 2021·arXiv
8 cites
An Effective Framework of Private Ethereum Blockchain Networks for Smart Grid

Do Hai Son, Tran Thi Thuy Quynh, Tran Viet Khoa, Dinh Thai Hoang · 9 authors

A smart grid is an important application in Industry 4.0 with a lot of new technologies and equipment working together. Hence, sensitive data stored in the smart grid is vulnerable to malicious modification and theft. This paper proposes a framework to build a smart grid based on a highly effective private Ethereum network. Our framework provides a real smart grid that includes modern hardware and a smart contract to secure data in the blockchain network. To obtain high throughput but a low uncle rate, the difficulty calculation method used in the mining process of the Ethereum consensus mechanism is modified to adapt to the practical smart grid setup. The performance in terms of throughput and latency are evaluated by simulation and verified by the real smart grid setup. The enhanced private Ethereum-based smart grid has significantly better performance than the public one. Moreover, this framework can be applied to any system used to store data in the Ethereum network.

Open access
2 source records
Blockchain Technology Applications and Security
Smart Grid Security and Resilience
IoT and Edge/Fog Computing
Original source