Social media is becoming one of the dominant ways to communicate. Before social media, people were extremely limited in their means to interact with others, and they were limited largely to the people that they knew in person. However, this impact on people in real life has damaged privacy. Alternative solutions have been proposed in order to overcome current social media issues. In this direction, blockchain is one of the most promising, and several blockchain-based social media have been proposed. In this paper, we analyze blockchain online social media from the technical point of view in order to understand the current trend of social DApps and to describe which characteristics are important in a blockchain-based social media scenario. We analyze real data by exploiting one of the most well-known DApps sites, and we compare current technologies in order to highlight which ones can be better applied to a real social scenario, such as Facebook.
Social bots can cause social, political, and economical disruptions by spreading rumours. The state-of-the-art methods to prevent social bots from spreading rumours are centralised and such solutions may not be accepted by users who may not trust a centralised solution being biased. In this paper, we developed a decentralised method to prevent social bots. In this solution, the users of a social network create a secure and privacy-preserving decentralised social network and may accept social media content if it is sent by its neighbour in the decentralised social network. As users only choose their trustworthy neighbours from the social network to be part of its neighbourhood in the decentralised social network, it prevents the social bots to influence a user to accept and share a rumour. We prove that the proposed solution can significantly reduce the number of users who are share rumour.
Raja Wasim Ahmad, Khaled Salah, Raja Jayaraman, Ibrar Yaqoob · 5 authors
Today's systems, approaches, and technologies leveraged for managing oil and gas supply chain operations fall short in providing operational transparency, traceability, audit, security, and trusted data provenance features. Also, a large portion of the existing systems is centralized, manual, and highly disintegrated which make them vulnerable to manipulation and the single point of failure problem. In this survey, we explore the potential opportunities and applications of blockchain technology in managing the exploration, production, and supply chain and logistics operations in the oil and gas industry as it can offer traceability, immutability, transparency, and audit features in a decentralized, trusted, and secure manner. We discuss state-of-the-art blockchain-based schemes, research projects, business initiatives, and case studies to highlight the practicability of blockchain in the oil and gas industry. We present the potential opportunities brought about by blockchain technology in various use cases and application scenarios. We introduce several systems that leverage blockchain-based smart contracts to automate the important services in terms of tracking and tracing of petroleum products, protection of international trade documents, and coordination of purchasing and bidding activities for granting oil exploration rights to petroleum exploration and development companies. Finally, we present open challenges acting as future research directions.
This study examined the characteristics of internet rumors in the user-generated content (UGC) mode, analysed the advantages of using the blockchain technology to curb internet rumors, and proposed a framework of the internet rumor reporting system based on the blockchain incentive mechanism. With Truffle as a development framework, intelligent contracts such as create, read, update, and delete were created using Solidity. The end users were connected to the blockchain using the MetaMask plugin. Finally, rewards were obtained by the participants, and the decentralizing program Dapp was created. The results showed that the TRUES could support multiuser reporting and execute intelligent contracts automatically and efficiently in a complex internet rumor environment; for the range of 1–2896 participants, virtual currency rewards could be obtained in 0.5–2.5 d. The conclusion showed that the internet rumor reporting system under the blockchain incentive mechanism had the characteristics of multilevel management, and distributed ledger and digital signatures contributed to the retention and traceability of rumors. Intelligent contracts and consensus mechanisms have obvious advantages in dealing with the complex forms of internet rumors.
Mwrwan Abubakar, Zakwan Jaroucheh, Ahmed Al Dubai, Bill Buchanan
The Session Initiation Protocol (SIP) is the principal signalling protocol in Voice over IP (VoIP) systems, responsible for initialising, terminating, and maintaining sessions amongst call parties. However, the problem with the SIP protocol is that it was not designed to be secure by nature as the HTTP digest authentication used in SIP is insecure, making it vulnerable to a variety of attacks. The current solutions rely on several standardised encryption protocols, such as TLS and IPsec, to protect SIP registration messages. However, the current centralised solutions do not scale well and cause algorithm overload when encoding and decoding SIP messages. In trying to rectify this issue, we propose in this paper a blockchain-based lightweight authentication mechanism, which involves a decentralised identity model to authenticate the SIP client to the SIP server. Our mechanism uses a smart contract on the Ethereum blockchain to ensure trust, accountability and preserves user privacy. We provided a proof-of-concept implementation to demonstrate our work. Further analysis of this approach's usability, mainly CPU and memory usage, was conducted comparing to IPsec and TLS. Then we discussed our system's security and presented a security analysis. Our analysis proves that our approach satisfies the SIP protocol security requirements.
Elnaz Rabieinejad, Abbas Yazdinejad, Reza M. Parizi
Blockchain technology has found extensive applications in recent years, especially in financial and currency exchange applications, due to improved trustworthiness and security. Although blockchain technology improves security by design, it is not immune to security threats and vulnerabilities. Ethereum, as a decentralized, open-source blockchain, has shown high growth and widespread adoption in recent years, however, there is a wide range of vulnerability, security risks, and also attacks around it. To tackle such issues, machine learning could be a viable solution for threat hunting in the Ethereum blockchain. Machine learning algorithms, by analyzing the behav-ioral patterns, can achieve an insight for threat hunting. In this paper, we proposed a deep learning-based model for Ethereum threat hunting. The model applies a deep neural network for attack detection and uses a combination of machine learning algorithms (unsupervised with supervised algorithms) for attack classification. The performance evolution of the proposed model in terms of accuracy presents 97.72 % in Ethereum attack detection and 99.4% in attack classification.
Ballots are often hold for fair decisions such as party theme selecting, however, the existing traditional ballot has some problems involving amount of human resources, cost of places, equipment, time and traffic, and repeated procedures. In order to solve the issues aforementioned, a ballot blockchain system is designed and implemented based on the smart contract of Ethereum. It is designed on the core blockchain technologies of the decentralized ledger technology, using a secure hash algorithm, anonymous user, incorruptible data, and adopting a public blockchain. The ballot blockchain system is implemented based on the MetaMask verification and the Remix interface development environment. The smart contract plays the role of the decision-maker for controlling ballot activities instead of numerous human tasks. All ballot transactions are recorded in the ballot blockchain permanently when the ballot completed. The aim of the ballot blockchain system is to achieve a fair, less time-consuming, secured, and transparent environment.
Riri Fitri Sari, Asri Samsiar Ilmananda, Daniela M. Romano
In the current digital era, information exchanges can be done easily through the Internet and social media. However, the actual truth of the news on social media platforms is hard to prove, and social media platforms are susceptible to the spreading of hoaxes. As a remedy, Blockchain technology can be used to ensure the reliability of shared information and can create a trusted communications environment. In this study, we propose a social media news spreading model by adapting an epidemic methodology and a scale-free network. A Blockchain-based news verification system is implemented to identify the credibility of the news and its sources. The effectiveness of the model is investigated by utilizing agent-based modelling using NetLogo software. In the simulations, fake news with a truth level of 20% are assigned a low News Credibility Indicator (NCI ± -0.637) value for all of the different network dimensions. Moreover, the Producer Reputation Credit is also decreased (PRC ± 0.213) so that the trust factor value is reduced. Our epidemic approach for news verification has also been implemented using Ethereum Smart Contract and several tools such as React with Solidity, IPFS, Web3.js, and Metamask. By showing the measurements of the credibility indicator and reputation credit to the user during the news dissemination process, this proposed smart contract can effectively limit user behaviour in spreading fake news and improve the content quality on social media.
Blockchain-based crowdfunding is one of the new, upcoming alternatives to the traditional centralized approach to crowdfunding. Traditional crowdfunding platforms are vulnerable to data leaks, high transaction and platform fees, and rampant frauds which happens due to the anonymity of user’s identity i.e., users cannot be identified when they commit cybercrimes. As blockchain is immutable and decentralized, it can reduce the possibility of data breaches. This brings in transparency as there is no central authority over the blockchain-based crowdfunding system. This paper attempts to solve these existing issues with the aid of a digital identity management system with an underlying Blockchain system. By implementing blockchain in a digital identity management system, malicious users can be identified and action can be taken against them. This paper explores donation-based crowdfunding using Ethereum as a framework and has been tested on the Rinkeby Test Network. This system can conduct several crowdfunding campaigns simultaneously. This paper explains the smart contract written in Solidity language in detail.
With the increasing popularity of blockchain technology, Merkle trees (or hash trees) are playing significant roles in verifying and retrieving data for the implementation of blockchain for allowing efficient and secure verification of the contents of large data structures. This article gives systematical insights into Merkle trees with respect to their principles, properties, advantages, and applications.
Philipp Winter, Anna Harbluk Lorimer, Peter J. Snyder, Benjamin Livshits
Much of the recent excitement around decentralized finance (DeFi) comes from hopes that DeFi can be a secure, private, less centralized alternative to traditional finance systems. However, people moving to DeFi sites in hopes of improving their security and privacy may end up with less of both as recent attacks have demonstrated. In this work, we improve the understanding of DeFi by conducting the first Web measurements of the security, privacy, and decentralization properties of popular DeFi front ends. We find that DeFi applications -- or dapps -- suffer from the same security and privacy risks that frequent other parts of the Web but those risks are greatly exacerbated considering the money that is involved in DeFi. Our results show that a common tracker can observe user behavior on over 56% of websites we analyzed and many trackers on DeFi sites can trivially link a user's Ethereum address with PII (e.g., user name or demographic information), or phish users by initiating fake Ethereum transactions. Lastly, we establish that despite claims to the opposite, because of companies like Amazon and Cloudflare operating significant Web infrastructure, DeFi as a whole is considerably less decentralized than previously believed.
Hye-Yeong Shin, Meryam Essaid, Sejin Park, Hongtaek Ju
Bitcoin is the most representative UTXO-based blockchain platform, and many studies have been conducted related to it. However, account-based blockchains such as Ethereum are not yet profoundly analyzed. There is an urgent need to track all cryptocurrency transactions involved with illegal activities to deanonymize and identify malicious users. To link users' accounts to real identities in both networks, we first need to examine the differences between Ethereum and Bitcoin to propose an efficient deanonymizing method. Therefore, this paper compares and analyzes the wallet address clustering method of Bitcoin and Ethereum.
Ali Raheem, Rand Raheem, Tom Chen, Ahmed Alkhayyat
Ransomware is one of the malicious software that is designed to prevent access to computer system until a sum of money is paid by the victim to the attacker. During the infection, the computer will either be locked, or the data will be encrypted. Ransoms are often demanded in Bitcoin, a largely anonymous Cryptocurrency. All transactions are recorded in the blockchain and verified by peer-to-peer networks. This paper investigation collects ten recent ransomware families, which use bitcoin as a payment for their ransom. In conjunction, we identified, collected and analysed Bitcoin addresses of users combining information from a clustering model and the blockchain. We used a heuristic clustering algorithm to reveal the hidden node’s payment of ransomware. Finally, we demonstrated the characteristics of ransomware encryption mechanisms that include a view of the infected process and its execution, and the distinctive demands of ransom.
Tong Cao, Jérémie Decouchant, Jiangshan Yu, Paulo Esteves-Veríssimo
While previous works have discussed the network delay upper bound that guarantees the consistency of Nakamoto consensus, measuring the actual network latencies and evaluating their impact on miners/pools in Bitcoin remain open questions. This paper fills this gap by: (1) defining metrics that quantify the impact of network latency on the mining network; (2) developing a tool, named miner entanglement (ME), to experimentally evaluate these metrics with a focus on the network latency of the top mining pools; and (3) quantifying the impact of the current network delays on Bitcoin's mining network. For example, we evaluated that Poolin, a Bitcoin mining pool, was able to gain between 0.5% and 1.9% of blocks in addition (i.e., from 36.27 BTC to 137.83 BTC) per week thanks to its low network latency. Moreover, as pools are rational in Bitcoin, we model the strategy a pool would follow to improve its network latency (e.g., by leveraging our ME tool) as a two party game. We show that a Bitcoin mining pool could improve its effective hash rate by up to 4.5%. For a multi-party game, we use a state-of-the-art Bitcoin mining simulator to study the situation where all pools attempt to improve their network latency and show that the largest mining pools would improve their revenue and reach a Nash equilibrium while the smaller mining pools would suffer from a decreased access to the network, and therefore a decreased revenue. These conclusions further incentivize the centralisation of the mining network in Bitcoin, and provide an empirical explanation for the observed tendency of pools to design and rely on low latency private networks.
Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Steganography and Watermarking Techniques
This paper explores how cryptocurrency affects Nigeria’s socio-economic and digital landscape, highlighting both its potential as an instrument of economic leveraging and its use in cybercrime. It explores how the decentralized characteristics of cryptocurrencies facilitate innovation and financial inclusion — and allow for anonymity, too, that enables cybercriminal activities. Today, cryptocurrency is a hot topic around the world. Nigeria, which registers some of the highest cryptocurrency adoption rates in the world, has used this class of digital asset as a key enabler of both breaking with traditional banking constraints and promoting economic resilience. But its decentralized and anonymous design also stands as a superpower to various forms of cybercrimes, from fraud and ransomware to money laundering. Such duality offers serious challenges to policymakers, law enforcement agencies, and financial institutions. The paper explores Nigeria’s regulatory experiences, technological barriers, and ethical dilemmas through in-depth analysis and case studies. This paper analyzes the phenomenon of cryptocurrency and cybercriminality in Nigeria, a phenomenon in which innovative technologies can be used as a vehicle for socioeconomic empowerment but also as a space for illegal activities. It examines case studies and statistical analyses revealing the systemic exploitation of cryptocurrency by cybercriminals and assessing the effectiveness of current legal and regulatory frameworks. This is against international best practices that expose Nigeria to grave dangers in tackling cybercrime linked to cryptocurrencies. We make sure that both the opportunities and threats it offers become bearable in how we balance the opportunities with threats this technology presents. Prescribing solutions for these challenges, the report highlights the importance of improving the regulatory environment, enhancing law enforcement capability in cyberspace, and developing a partnership between the private and public sectors to strike an appropriate balance between innovation and security. The research sent a clear message that articulated an approach to policy that would make the most of the potential of cryptocurrency while mitigating its weaknesses. Addressing these matters will allow Nigeria to seize the opportunities presented by cryptocurrency without compromising its frontier of digital security.
Intrusion detection systems that have emerged in recent decades can identify a variety of malicious attacks that target networks by employing several detection approaches. However, the current approaches have challenges in detecting intrusions, which may affect the performance of the overall detection system as well as network performance. For the time being, one of the most important creative technological advancements that plays a significant role in the professional world today is blockchain technology. Blockchain technology moves in the direction of persistent revolution and change. It is a chain of blocks that covers information and maintains trust between individuals no matter how far apart they are. Recently, blockchain was integrated into intrusion detection systems to enhance their overall performance. Blockchain has also been adopted in healthcare, supply chain management, and the Internet of Things. Blockchain uses robust cryptography with private and public keys, and it has numerous properties that have leveraged security’s performance over peer-to-peer networks without the need for a third party. To explore and highlight the importance of integrating blockchain with intrusion detection systems, this paper provides a comprehensive background of intrusion detection systems and blockchain technology. Furthermore, a comprehensive review of emerging intrusion detection systems based on blockchain technology is presented. Finally, this paper suggests important future research directions and trending topics in intrusion detection systems based on blockchain technology.