Ethereum is one of the popular Blockchain platform. The key component in the Ethereum Blockchain is the smart contract. Smart contracts (SC) are like normal computer programs which are written mostly in solidity high-level object-oriented programming language. Smart contracts allow completing transactions directly between two parties in the network without any middle man or mediator. Modification of the smart contracts are not possible once deployed into the Blockchain. Thus smart contract has to be vulnerable free before deploying into the Blockchain. In this paper, Bayesian Network Model was designed and constructed based on Bayesian learning concept to detect smart contract security vulnerabilities which are Reentrancy, Tx.origin and DOS. The results showed that the proposed BNMC (Bayesian Network Model Construction) design is able to detect the severity of each vulnerability and also suggest the reasons for the vulnerability. The accuracy of the proposed BNMC results are improved (accuracy 8% increased for both Reentracy and Tx.origin, 6% increased for DOS), compared with traditional method LSTM. This proposed BNMS design and implementation is the first attempt to detect smart contract vulnerabilities using Bayesian Networks.
The use of computers is becoming more and more common. The power and maliciousness of powerful attackers are increasing. Organizations must improve their ability to mitigate information security threats. Adequate protection is more critical than ever. With websites and social media platforms holding a wealth of personal information and potentially damaging content, attackers use the internet's sophisticated hacking tools to cause harm to individuals and organizations. Attacks have become stealthier, with more significant economic damage and broader damage. Blockchain must be the solution to the security problem of financial transactions. However, judging from the results and expected answers from the industry and organization, it is crucial to understand how financial institutions deal with these issues by looking at blockchain deployments in cybersecurity. A blockchain is a digital database that records all mentoring transactions. This technology supports many different exchanges that are currently in use. The authors also believe that blockchain should be integrated into many parts of cybersecurity. The primary goal of this chapter is to review relevant research papers and book chapters over the past 10 years to understand how successful cybersecurity and blockchain implementations have been in the enterprise and to identify the different challenges and concerns that enterprise personnel face. They also provide suggestions and solutions to problems.
Distributed ledger technology benefits society by enabling an ecosystem of decentralised finance. However the pseudo-anonymised nature of transactions has also been an enabler of new routes for illicit activities ranging from individual scams to organised crimes. Current solutions for identifying addresses involved in illicit activities (illicit addresses) rely on commercial intelligence services, which are costly due to the intensive investigative efforts required. We propose Ledgit, an automatic real-time service for diagnosing illicit addresses on the Bitcoin blockchain. Ledgit is based solely on publicly available data, and uses an unsupervised clustering method that combines information from textual reports and the blockchain graph to assign a risk score that a Bitcoin address is involved in illicit activities. We verify the system with labeled addresses, showing high performance in identifying illicit addresses. Finally, we provide an intuitive user interface that provides accessible risk assessment with graph and report analytics.
The article analyses a foreign practice of the criminal legal measures for counteracting cyberterrorism. An analysis of the US Code chapter 18 1030(a)(5), amended by USA PATRIOT Act 2001 (a response to the terrorist attack of September 11, 2001), is presented. The substantial features of cyberthreats on the part of terrorist organizations, stated in annual threat assessments of the U.S. Intelligence Community, are marked out. The experience of the Western European countries in the field is also summarized. Particularly, the routine activity of the secret services and law-enforcement authorities which rarely involves the criminal responsibility. A special attention is drawn to the legal acts of the People's Republic of China which ground counteracting cyberterrorism on the general conception of the digital sovereignty. In PRC the measures of counteracting to modern cyberthreats are arranged in three main blocks: development of own technologies, ideological propaganda, state policy. As a result of technological progress the structure of terrorist organizations and the tactics of criminal actions are changed. The use of networking model has resulted in emergence of the "single person terrorists", multi-integration of various organizations, frequently committing their operations in distance one of another, self-radicalization as a key model of involving to the criminal activity,decentralization in management while lacking of the "command centres", making use of the blockchain in the financing model. The article also proposes general positions for the criminalization of the cyberterrorism in the Russian Federation. The recommendations for amendment of criminal legislation are made.
Smart contracts are decentralized applications running on blockchain platforms and have been widely used in a variety of scenarios in recent years. However, frequent smart contract security incidents have focused more and more attention on their security and reliability, and smart contract vulnerability detection has become an urgent problem in blockchain security. Most of the existing methods rely on fixed rules defined by experts, which have the disadvantages of single detection type, poor scalability, and high false alarm rate. To solve the above problems, this paper proposes a method that combines Bi-LSTM and an attention mechanism for multiple vulnerability detection of smart contract opcodes. First, we preprocessed the data to convert the opcodes into a feature matrix suitable as the input of the neural network and then used the Bi-LSTM model based on the attention mechanism to classify smart contracts with multiple labels. The experimental results show that the model can detect multiple vulnerabilities at the same time, and all evaluation indicators exceeded 85%, which proves the effectiveness of the method proposed in this paper for multiple vulnerability detection tasks in smart contracts.
In recent years, counterfeit luxury products have become a major concern for consumers worldwide. The reason for the proliferation of counterfeit products is that the manufacturing and distribution process is not transparent to consumers and this information can be easily falsified or altered by others. To solve this problem, this paper proposes the development of a management system using blockchain and smart contract technology to solve the problems of data forgery and data tampering, while tracking the information related to luxury products and ensuring the accuracy and authenticity of the relevant data, to achieve the purpose of luxury product anti-counterfeiting. When using Hyperledger Fabric to deploy the blockchain and execute smart contracts, all information related to the production and logistics process of luxury goods will be uploaded to the blockchain. No human intervention is required to create a complete, traceable, tamper-proof, and trusted repository. Compared to previous work, this paper combines blockchain technology with specific processes in the supply chain, employing a variety of security methods to secure the communication process. Moreover, our proposed solution is more flexible in transmission, with more secure protocols also making data harder to tamper with and falsify, thereby solving the problem of forgery and tracking of luxury products.
Blockchain technology was created with security in mind. However, in recent years, there has been various confirmed cases of breach, worth billions of dollars loss in Blockchain associated to smart contracts. In order to address this growing concern, it is crucial to investigate detection and mitigation of vulnerabilities in smart contract, and this paper critically reviews and analyses key approaches for detecting vulnerabilities in smart contract within Blockchain. In order to achieve the purpose of this paper, five key approaches, notably the application of OWASP Top 10, SCSVS, vulnerability detection tools, fuzz testing and the AI-driven approaches are critically reviewed and compared. As part of the comparison performed, a penetration testing quality model was applied to study six quality metrics, notably extensibility, maintainability, domain coverage, usability, availability and reliability. Results revealed limitations of the studied vulnerability detection approaches and findings are expected to help in decision making especially when selecting approaches to be used during security analysis and pen-testing.
Digital forensic examiners and stakeholders face increasing challenges during the investigation of Internet of Things (IoT) environments due to the heterogeneous nature of the IoT infrastructure. These challenges include guaranteeing the integrity of forensic evidence collected and stored during the investigation process. Similarly, they also encounter challenges in ensuring the transparency of the investigation process which includes the chain-of-custody and evidence chain. In recent years, some blockchain-based secure evidence models have been proposed especially for IoT forensic investigations. These proof-of-concept models apply the inherent properties of blockchain to secure the evidence chain of custody, maintain privacy, integrity, provenance, traceability, and verification of evidence collected and stored during the investigation process. Although there have been few prototypes to demonstrate the practical implementation of some of these proposed models, there is a lack of descriptive review of these blockchain-based IoT forensic models. In this paper, we report a comprehensive Systematic Literature Review (SLR) of the latest blockchain-based IoT forensic investigation process models. Particularly, we systematically review how blockchain is being used to securely improve the forensic investigation process and discuss the efficiency of these proposed models. Finally, the paper highlights challenges, open issues, and future research directions of blockchain technology in the field of IoT forensic investigations.
Tin Tironsakkul, Manuel Maarek, Andrea Eross, Mike Just
Bitcoin and other cryptocurrencies are well-known for their privacy properties that allow for the “anonymous” exchange of money. Bitcoin tracking with taint analysis remains challenging as it does not account for the change in Bitcoins' ownership or the usage of Privacy-Enhancing Technologies (PETs) to obscure Bitcoins' movement, and often produces unessential incidents with transactions unlikely to be related to the targeted activity. In this paper, we propose to improve the Bitcoin taint analysis tracking process that adapts to the context of address ownership and avoid following unrelated transactions. First, we introduce an approach in which we incorporate Bitcoin taint analysis with address profiling. Second, we propose two context-based taint analysis strategies. Third, we introduce a set of metrics using hypothesised behaviours related to illegal Bitcoins and recognisable patterns within the blockchain. We conducted an experiment using sample data from known Bitcoin theft cases to illustrate and evaluate the approach. The results on address profile integration reveal distinct transaction behaviours in tracking theft cases following all the metrics, such as address reuse, address size and transaction fee payment. One of the context-based tracking strategies, Dirty-First, shows positive potential for illustrating illegal Bitcoins’ spending and obscuring strategies. The majority of the six metrics we defined give distinct results in transaction behaviours between the theft cases and the control groups. Our context-based tracking methodology provides a solution for one of the shortcomings in the current Bitcoin tracking methodology and the next step for future cryptocurrency and cybercrime forensic research.
Smart contracts are computer programs running on the blockchain, and their security issues have received widespread attentions. However, existing vulnerability detection techniques such as static analysis, symbol execution, and fuzz testing could be unable to expose new types of vulnerabilities in time because they rely on extracting vulnerability features manually. On the other hand, vulnerability detection techniques based on machine learning do not require experts to define features manually and can learn vulnerability patterns automatically. In this paper, we propose a vulnerability detection technique for smart contracts, which extracts smart contract features based on the abstract syntax tree (AST) and trains the model to detect smart contract vulnerabilities. Experiment results show that the model achieves an average accuracy of 98.7% and F1-value of 0.885 in detecting three kinds of security vulnerabilities.
In this paper, we address the problems of fraud and anomalies in the Bitcoin network. These are common problems in e-banking and online transactions. However, as the financial sector evolves, so do the methods for fraud and anomalies. Moreover, blockchain technology is being introduced as the most secure method integrated into finance. However, along with these advanced technologies, many frauds are also increasing every year. Therefore, we propose a secure fraud detection model based on machine learning and blockchain. There are two machine learning algorithms-XGboost and random forest (RF)-used for transaction classification. The machine learning techniques train the dataset based on the fraudulent and integrated transaction patterns and predict the new incoming transactions. The blockchain technology is integrated with machine learning algorithms to detect fraudulent transactions in the Bitcoin network. In the proposed model, XGboost and random forest (RF) algorithms are used to classify transactions and predict transaction patterns. We also calculate the precision and AUC of the models to measure the accuracy. A security analysis of the proposed smart contract is also performed to show the robustness of our system. In addition, an attacker model is also proposed to protect the proposed system from attacks and vulnerabilities.
Blockchain smart contracts are prevalent nowadays as numerous applications are developed based on this feature. Though smart contracts are important and widely used, they contain certain vulnerabilities. This paper discusses various security issues that arise in smart contract applications. They are categorized in the smart contract platform, the applications that integrate with the Blockchain, and the vulnerabilities in smart contract code. A detailed study of smart contract-specific vulnerabilities and the defense against those vulnerabilities are presented in this article. Because of certain limitations of platforms or programming language used to write smart contract, there are possibilities of attacks on smart contracts. Hence different security measures or precautions to be taken while writing the smart contract code is discussed in this article. This will prevent the potential attacks happening on Blockchain distributed applications.
In recent years, cryptocurrencies' economic application and speculative value have soared. Cryptocurrency is being used as a means of trade, even in Pakistan. The government does not legalize it, but it is traded like many other states. Globally it causes fraudulent investment schemes. Cryptocurrencies are speculative, as the dot-com boom of the 1990s. Even though these organizations lacked a product, business plan, and profit potential, the stock market was eager to invest heavily in internet-related companies. A few years later, a dot-com catastrophe ended an era of unjustified and speculative online firms. The gold rush occurred much earlier. In the 1800s, people worldwide sought their fortune in the U.S., Canada, and Australia. They rapidly understood that mining a significant gold stake was dangerous and unlikely to succeed. In 2021, cryptocurrencies will become the dominant form of money. 2021 was the landmark year. Bitcoin became the new gold rush and caused online fraud, known as cryptocurrency fraud. We will examine cryptocurrency, crimes, laws, and regulations to combat crypto crimes.
Muhammad Umar Nasir, Safiullah Khan, Shahid Mehmood, Muhammad Adnan Khan · 6 authors
The study presents a framework to analyze and detect meddling in real-time network data and identify numerous meddling patterns that may be harmful to various communication means, academic institutes, and other industries. The major challenge was to develop a non-faulty framework to detect meddling (to overcome the traditional ways). With the development of machine learning technology, detecting and stopping the meddling process in the early stages is much easier. In this study, the proposed framework uses numerous data collection and processing techniques and machine learning techniques to train the meddling data and detect anomalies. The proposed framework uses support vector machine (SVM) and K-nearest neighbor (KNN) machine learning algorithms to detect the meddling in a network entangled with blockchain technology to ensure the privacy and protection of models as well as communication data. SVM achieves the highest training detection accuracy (DA) and misclassification rate (MCR) of 99.59% and 0.41%, respectively, and SVM achieves the highest-testing DA and MCR of 99.05% and 0.95%, respectively. The presented framework portrays the best meddling detection results, which are very helpful for various communication and transaction processes.
Crypto crimes peaked in 2021, and recent years have shown that blockchain is not going to die but will stay with us. In addition, blockchain transaction throughputs are expected to rise, which will make the manual investigation of crimes next to impossible in the future. We need effective and automated solutions to monitor and detect fraudulent activities happening on blockchains. In this paper, we propose a system to detect the blacklisted addresses in the Ethereum blockchain. First, we collected Ethereum blockchain transaction data and blacklisted addresses. Then, we constructed the transaction graph of Ethereum and extracted features of addresses, including some global features like pagerank. Finally, we trained the models of standard machine learning algorithms and predicted the class of the addresses. Our results show that with more than 97% accuracy we can predict blacklisted addresses.
Detecting malicious activity in advance has become increasingly important for public safety, economic stability, and national security. However, the disparity in living standards incites the minds of certain undesirable members of society to commit crimes, which may disrupt society’s stability and mental calm. Breakthroughs in deep learning (DL) make it feasible to address such challenges and construct a complete intelligent framework that automatically detects such malicious behaviors. Motivated by this, we propose a convolutional neural network (CNN)-based Xception model, i.e., BlockCrime, to detect crimes and improve public safety. Furthermore, we integrate blockchain technology to securely store the detected crime scene locations and alert the nearest law enforcement authorities. Due to the scarcity of the dataset, transfer learning has been preferred, in which a CNN-based Xception model is used. The redesigned Xception architecture is evaluated against various assessment measures, including accuracy, F1 score, precision, and recall, where it outperforms existing CNN architectures in terms of train accuracy, i.e., 96.57%.
Ethereum smart contract and the agreements contained therein exist across a distributed, decentralized blockchain network, which controls the execution of Dapps, and transactions are trackable and irreversible. Since the amount of smart contracts on Ethereum has a rapid growth, which also lead to a large number of security vulnerabilities. However, the traditional method such as static symbolic analysis requires manual analysis in advance with high false detection rate. In this paper, we propose a GVD-net model for smart contract vulnerability detection. GVD-net consists of preprocessing section,backbone-net and detection section.We prepossess the source code and gain a weight matrix in the first section. In backbone-net, we generate a CFG graph according to the variables and function calling relationships of the solidity code, and use the CFG graph to build the corresponding relationship of nodes and generate a non-Euclidean graph. Then we use the adjacent search algorithm to generate a non-complete random walk sequence, and use the graph embedding algorithm Node2Vec to generate a 256-dimensional vector and gain another weight matrix. We input the test code into GVD-net to generate the threshold ϑ in the final section and will classify the smart contract as danger code if the ϑ is bigger than 0.75. Moreover, GVD-net will confirm the type of vulnerability according to weight matrix. We conduct comprehensive experiments on GVD-net with the SBcurated data-set, and the experiment results show that (1) GVD-net can classify a smart contract as safe or danger code, with the accuracy of 90.2% (2) GVD-net can detect three types of vulnerability (arithmetic issues, access control and asset frozen) and attain good performance within 1s.
Anokye Acheampong Amponsah, Adebayo Felix Adekoya, Benjamin Asubam Weyori
Healthcare fraud is a global problem affecting both developing and developed countries. It is the deliberate attempt of the perpetrators to take undue advantage of the inefficiencies in current healthcare systems. Fraud tends to deny legitimate beneficiaries of universal health coverage, especially those under health insurance protection. In this work, we propose using machine learning techniques and blockchain technology to detect and prevent fraud in healthcare, especially in claims processing. A decision tree classification algorithm is adopted to classify the original claims dataset. The extracted knowledge is programmed in the Ethereum blockchain smart contract to detect and prevent healthcare fraud. The comparative experimental results show that the best performing tool achieves a classification accuracy of 97.96% and a sensitivity of 98.09%. This means that the proposed system enhances the blockchain smart contract’s ability to detect fraud with an accuracy of 97.96%.
Traditional ways of distributing and verifying academic certificates are not efficient. Certificates are distributed as hard copy. Verifying the integrity of the certificate is a time and resource consuming process. As a result, forged certificates have become common. It is very difficult to differentiate between a real and a forged certificate. Through our system, we intend to make the certificate generation, distribution, and verification process seamless. Any student can enter his or her personal details, academic coursework details, and the university code, and thus submit a certificate request to the university. University admins can verify the certificate requests, and approve or reject the requests as per their policy. Any student or third party could verify the integrity of the certificate by entering the details of the certificate under scrutiny into the system.
With the development of decentralized networks, smart contracts, especially those for ERC tokens, are attracting more and more Dapp users to implement their applications. There are some functions in ERC token contracts that only a specific group of accounts could invoke. Among those functions, some even can influence other accounts or the whole system without prior notice or permission. These functions are referred to as contract backdoors. Once exploited by an attacker, they can cause property losses and harm users’ privacy. In this work, we propose Pied-Piper, a hybrid analysis method that integrates datalog analysis and directed fuzzing to detect backdoor threats in Ethereum ERC token contracts. First, datalog analysis is applied to abstract the data structures and identification rules related to the threats for preliminary static detection. Then, directed fuzzing is applied to eliminate false positives caused by the static analysis. We first evaluated Pied-Piper on 200 smart contracts, which are injected with different types of backdoors. It reported all problems without false positives, and none of the injected problems was missed. Then, we applied Pied-Piper on 13,484 real token contracts deployed on Ethereum. Pied-Piper reported 189 confirmed problems, four of which have been assigned unique CVE ids while others are still in the review process. Each contract takes 8.03 seconds for datalog analysis on average, and the fuzzing engine can eliminate the false positives within one minute.
Blockchain, the technology infrastructure behind the famous cryptocurrency bitcoin, can take away the notion of trust from centralized organizations to a decentralized platform that is mathematically verifiable and cryptographically secure. It is gaining more significant momentum exponentially and disrupts the way businesses function beyond the digital currency aspects. This work presents a text mining literature analysis of research articles published in major digital libraries on blockchain technology and cybersecurity. This literature analysis employs automated text mining approaches such as topic modeling and keyphrase extraction for unearthing the themes from a vast body of literature. This analysis highlights the multidisciplinary nature of blockchain technology within the cybersecurity domain. The findings also show the cyber threats and vulnerabilities that evolve with blockchain technology developments. This analysis also showcases the computer security research community’s vulnerabilities and provides future research dimensions that are crucial for designing secure blockchain applications and platforms.