Rachit Agarwal, Tanmay Thapliyal, Sandeep K. Shukla
Smart Contracts (SCs) in Ethereum can automate tasks and provide different functionalities to a user. Such automation is enabled by the `Turing-complete' nature of the programming language (Solidity) in which SCs are written. This also opens up different vulnerabilities and bugs in SCs that malicious actors exploit to carry out malicious or illegal activities on the cryptocurrency platform. In this work, we study the correlation between malicious activities and the vulnerabilities present in SCs and find that some malicious activities are correlated with certain types of vulnerabilities. We then develop and study the feasibility of a scoring mechanism that corresponds to the severity of the vulnerabilities present in SCs to determine if it is a relevant feature to identify suspicious SCs. We analyze the utility of severity score towards detection of suspicious SCs using unsupervised machine learning (ML) algorithms across different temporal granularities and identify behavioral changes. In our experiments with on-chain SCs, we were able to find a total of 1094 benign SCs across different granularities which behave similar to malicious SCs, with the inclusion of the smart contract vulnerability scores in the feature set.
Rohit Kumar Sachan, Rachit Agarwal, Sandeep K. Shukla
The rise in the adoption of blockchain technology has led to increased illegal activities by cybercriminals costing billions of dollars. Many machine learning algorithms are applied to detect such illegal behavior. These algorithms are often trained on the transaction behavior and, in some cases, trained on the vulnerabilities that exist in the system. In our approach, we study the feasibility of using the Domain Name (DN) associated with the account in the blockchain and identify whether an account should be tagged malicious or not. Here, we leverage the temporal aspects attached to the DN. Our approach achieves 89.53% balanced-accuracy in detecting malicious blockchain DNs. While our results identify 73769 blockchain DNs that show malicious behavior at least once, out of these, 34171 blockchain DNs show persistent malicious behavior, resulting in 2479 malicious blockchain DNs over time. Nonetheless, none of these identified malicious DNs were reported in new officially tagged malicious blockchain DNs.
Rachit Agarwal, Tanmay Thapliyal, Sandeep K. Shukla
Smart Contracts (SCs) in Ethereum can automate tasks and provide different\nfunctionalities to a user. Such automation is enabled by the `Turing-complete'\nnature of the programming language (Solidity) in which SCs are written. This\nalso opens up different vulnerabilities and bugs in SCs that malicious actors\nexploit to carry out malicious or illegal activities on the cryptocurrency\nplatform. In this work, we study the correlation between malicious activities\nand the vulnerabilities present in SCs and find that some malicious activities\nare correlated with certain types of vulnerabilities. We then develop and study\nthe feasibility of a scoring mechanism that corresponds to the severity of the\nvulnerabilities present in SCs to determine if it is a relevant feature to\nidentify suspicious SCs. We analyze the utility of severity score towards\ndetection of suspicious SCs using unsupervised machine learning (ML) algorithms\nacross different temporal granularities and identify behavioral changes. In our\nexperiments with on-chain SCs, we were able to find a total of 1094 benign SCs\nacross different granularities which behave similar to malicious SCs, with the\ninclusion of the smart contract vulnerability scores in the feature set.\n
Android mobile devices are a prime target for a huge number of cyber-criminals as they aim to create malware for disrupting and damaging the servers, clients, or networks. Android malware are in the form of malicious apps, that get downloaded on mobile devices via the Play Store or third-party app markets. Such malicious apps pose serious threats like system damage, information leakage, financial loss to user, etc. Thus, predicting which apps contain malicious behavior will help in preventing malware attacks on mobile devices. Identifying Android malware has become a major challenge because of the ever-increasing number of permissions that applications ask for, to enhance the experience of the users. And most of the times, permissions and other features defined in normal and malicious apps are generally the same. In this paper, we aim to detect Android malware using machine learning, deep learning, and natural language processing techniques. To delve into the problem, we use the Android manifest files which provide us with features like permissions which become the basis for detecting Android malware. We have used the concept of information value for ranking permissions. Further, we have proposed a consensus-based blockchain framework for making more concrete predictions as blockchain have high reliability and low cost. The experimental results demonstrate that the proposed model gives the detection accuracy of 95.44% with the Random Forest classifier. This accuracy is achieved with top 45 permissions ranked according to Information Value.
In recent years, phishing scams have become the crime type with the largest money involved on Ethereum, the second-largest blockchain platform. Meanwhile, graph neural network (GNN) has shown promising performance in various node classification tasks. However, for Ethereum transaction data, which could be naturally abstracted to a real-world complex graph, the scarcity of labels and the huge volume of transaction data make it difficult to take advantage of GNN methods. Here in this paper, to address the two challenges, we propose a Self-supervised Incremental deep Graph learning model (SIEGE), for the phishing scam detection problem on Ethereum. In our model, two pretext tasks designed from spatial and temporal perspectives help us effectively learn useful node embedding from the huge amount of unlabelled transaction data. And the incremental paradigm allows us to efficiently handle large-scale transaction data and help the model maintain good performance when the data distribution is drastically changing. We collect transaction records about half a year from Ethereum and our extensive experiments show that our model consistently outperforms strong baselines in both transductive and inductive settings.
Over the past few years, there has been an alarming rise in the cyber attacks which are being carried out by Social Engineering Technique. Email is widely used for communication purposes and thus Spam Email Attacks are found to be the most common social engineering technique used by attackers to intrude into the system and perform malicious operations. Almost 85% of the overall email traffic is found to be spam (122.3 billion spam e-mails transmitted per day), which causes severe damage like, data loss, account compromise, ransomware attack, malware infection into the organization/personal systems. Various Artificial Intelligence-based methods (based on reviewing the content of an email) are created to identify spam emails, still, the count of hacks and loss due to spam emails is increasing on daily basis. On the other hand, blockchain being one of the cutting edges and disruptive technology has gained attention in the past few years. In this literature, authors have proposed a blockchain-based system to counter, prevent and identify spam emails. Authors have integrated the wallet-to-wallet transaction in Ethereum, with an existing email system to identify spam and legitimate email. The proposed framework is not based on verifying the content of an email at mailing servers instead the server verifies or check if or not the Cryptocurrency is paid, and thus the proposed framework is supposed to have small workloads and better performance throughput in terms of sending and receiving emails. The authors were able to create a Proof of Concept of the proposed methodology. All the endpoints created to achieve the same were executed in less than 1.5 sec of Elapse Time Average. The proposed framework will act as a Single Source of truth in identifying the Spam E-Mail.
Despite the fact that it is publicly available, collecting and processing the full bitcoin blockchain data is not trivial. Its mere size, history, and other features indeed raise quite specific challenges, that we address in this paper. The strengths of our approach are the following: it relies on very basic and standard tools, which makes the procedure reliable and easily reproducible; it is a purely lossless procedure ensuring that we catch and preserve all existing data; it provides additional indexing that makes it easy to further process the whole data and select appropriate subsets of it. We present our procedure in details and illustrate its added value on large-scale use cases, like address clustering. We provide an implementation online, as well as the obtained dataset.
Coronavirus 2019, called COVID-19, is a transmissible disease caused by severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2). It earlier impacted the citizens of China alone. However, it has rapidly spread all over the world. The COVID-19 supply chain system aims to facilitate access to several critical items, such as personal protective equipment (PPE), biomedical equipment, diagnostics supplies, and vaccines. In this article, we discuss a robust security framework for vaccine distribution and tracking in an Internet of Medical Things (IoMT)-based cloud-assisted COVID-19 environment by considering both intra-country and inter-country scenarios. Various transactions related to vaccine requests, orders, distribution, and tracking are put into the blockchain in the form of blocks. Since blockchain technology offers immutability, transparency, and decentralization, the security of the proposed framework has been improved significantly. The proposed framework also supports artificial intelligence(AI)-based big data analytics on the information stored into the blocks in the blockchain. Furthermore, a practical demonstration of the proposed framework has been done through a blockchain simulation study.
Abstract Miners in various blockchain-backed cryptocurrency networks compete to maintain the validity of the underlying distributed ledgers to earn the bootstrapped cryptocurrencies. With limited hashing power, each miner needs to decide how to allocate their resource to different cryptocurrencies so as to achieve the best overall payoff. Together all the miners form a hashing power allocation game. We consider two settings of the game, depending on whether each miner can allocate their fund to a risk-free asset or not. We show that this game admits unique pure Nash equilibrium in closed-form for both settings.
Saeideh G. Motlagh, Jelena Mišić, Vojislav B. Mišić
Selfish mining is a recognized misbehaving attack in Bitcoin. Selfish miners intentionally delay the release of newly mined blocks with the goal of gaining more revenue. While several studies have been devoted to analyzing the selfish miner behavior, the impact of selfish behavior on Bitcoin network performance has received little to no attention at all. In this work, we focus on that impact using a Markov chain that models selfish behavior both from the aspect of mining and form the aspect of block distribution time. We find that blocks mined by honest miners undergo longer distribution time compared to blocks mined by selfish miners. This delay results in intentional forking and the resulting network inconsistency provides more opportunity for selfish miners to gain unfair revenue.
Ponzi schemes are financial scams that lure users under the promise of high profits. With the prosperity of Bitcoin and blockchain technologies, there has been growing anecdotal evidence that this classic fraud has emerged in the blockchain ecosystem. Existing studies have proposed machine-learning based approaches for detecting Ponzi schemes, i.e., either based on the operation codes (opcodes) of the smart contract binaries or the transaction patterns of addresses. However, state-of-the-art approaches face several major limitations, including lacking interpretability and high false positive rates. Moreover, machine-learning based methods are susceptible to evasion techniques, and transaction-based techniques do not work on smart contracts that have a small number of transactions. These limitations render existing methods for detecting Ponzi schemes ineffective. In this paper, we propose SADPonzi, a semantic-aware detection approach for identifying Ponzi schemes in Ethereum smart contracts. Specifically, by strictly following the definition of Ponzi schemes, we propose a heuristic-guided symbolic execution technique to first generate the semantic information for each feasible path in smart contracts and then identify investor-related transfer behaviors and the distribution strategies adopted. Experimental result on a well-labelled benchmark suggests that SADPonzi can achieve 100% precision and recall, outperforming all existing machine-learning based techniques. We further apply SADPonzi to all 3.4 million smart contracts deployed by EOAs in Ethereum and identify 835 Ponzi scheme contracts, with over 17 million US Dollars invested by victims. Our observations confirm the urgency of identifying and mitigating Ponzi schemes in the blockchain ecosystem.
3 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Steganography and Watermarking Techniques
The existing supply chain for the pharmaceutical industry is obsolete and lacks clear visibility over the entire system. Moreover, the circulation of counterfeit drugs in the market has increased over the years. According to the WHO report, around 10.5% of the medicinal drugs in lower / middle income countries are fake and such drugs may pose serious threats to public health, sometimes leading to death. Keeping these threats in mind, in this paper, we propose a blockchain-based model to track the movement of drugs from the industry to the patient and to minimize the chances of a drug being counterfeit. The reasons for using blockchain technology in our work include its immutability property and easy tracking of an entity in the blockchain. Through this proposed model, the manufacturer would be able to upload the details corresponding to a drug, after which it will be sent for approval to the Government. Thereafter, hospitals and pharmacies, based upon their requirements, can request the approved drugs. In the future, if a patient wants some medication, then he or she has to request it on the blockchain network. The request will be sent to the nearest hospital/pharmacy and thereafter, the patient can collect the medication. To implement this model, we have used Hyperledger fabric due to the presence of many auto-implemented features in it. Our implementation of the proposed blockchain based model highlights that the model can successfully detect any drug being counterfeit. This will be beneficial for the users getting affected with counterfeit drugs. Moreover, with the proposed model, we can also track the movement of the drug beginning from the manufacturer right up to the patient consuming that drug. Index Terms: Blockchain, Counterfeit Drugs, Drugs Tracking, Fake Medicines, Health Care.
Bütün sektörler dahilinde finans sektöründe de müşterilere ait fikir ve düşüncelerinin belirlenmesi, firma ve kurumların ileriki dönemler için sunacağı hizmetleri etkilemektedir. Kripto para birimlerinin (Bitcoin, Ethereum, Ripple vb.) ekonomik ve sosyal etkileri hızla artmaya devam ettikçe, ilgili haber makalelerinin ve sosyal medya yayınlarının, özellikle de tweetlerin yaygınlığı da artmaktadır. Bu çalışmada, Twitter kullanıcılarının finans sektörü konularından biri olan Bitcoin ile ilgili yorumları derlenerek bir duygu analizi çalışması yapılmıştır. Kullanıcı yorumları, Twitter’ın sunmuş olduğu API hizmeti vasıtasıyla Python Programlama Dili kullanılarak alınmış; yorumlar olumlu, nötr ve olumsuz etiketler ile ayrıştırılmış, etiket bulutunda toplanmıştır. Naïve Bayes ve Lojistik Regresyon algoritmaları kullanılarak oluşturulan modellerde başarı oranları karşılaştırılmıştır. Naïve Bayes uygulamasının tweetlerin duygularını tahmin etmedeki başarı oranı %72,19 olurken, Lojistik Regresyon uygulamasında bu oran %75,53 olmuştur. Çalışmanın ikinci aşamasında ise, duygu analizinden sonra “Bitcoin” anahtar kelimesi içeren günlük pozitif tweet oranı ile Bitcoin günlük açılış değeri beraber kullanılarak Bitcoin kapanış değeri tahminlemesi yapılmıştır. Finans verileri Yahoo Finance web sitesi üzerinden alınmış; Doğrusal Regresyon ve Rastgele Orman Regresyon yöntemleri ile modeller oluşturulmuştur. Doğrusal Regresyon için r² değeri %88,97 çıkarken, Rastgele Orman Regresyonu için ise %94,16 olmuştur.Anahtar Kelimeler: Duygu analizi, Twitter, Bitcoin, Makine öğrenmesi, Veri madenciliği, Finans
One of the most important discoveries and creative developments that is playing a vital role in the professional world today is blockchain technology. A blockchain is a distributed, digitized and consensus-based secure information storage mechanism. Blockchain technology moves in the direction of persistent revolution and change. In the last couple of years, the upsurge in blockchain technology has obliged scholars and specialists to scrutinize new ways to apply blockchain technology with a wide range of domains. The dramatic increase in blockchain technology has provided many new application opportunities, including e-voting application. The present article provides a systematic review of emerging blockchain-based e-voting systems. In this paper, we call attention to the open research matters in this fast-growing field, explaining them in some details. It was concluded that frameworks needed enhancements in order to be used in voting systems due to these reservations. KEYWORDS: blockchain, e-voting, cloud computing, ethereum; ballot
Every second a large amount of news is exchanged amongst people with Internet as its driving force. Cheap and easily accessible Internet services across the world have made it even easier for the fake news to spread quickly than the real ones. Moreover, in order to gain TRP (Television Rating Point), many of the news agencies and media houses themselves indulge in malpractices, contributing towards the spread of false news. This sometimes results in riots and political as well as communal instability. Thus, in order to stop the spread of false news, blockchain technology integrated with artificial intelligence and machine learning techniques can be used. In this paper, we have proposed a model based on the above stated technologies named as Reliable News Sharing Platform (RNSP) that aims at ensuring that only real news is communicated and false news is not only detected but is also stopped from being communicated. Anonymous news publication, no central governance, no external interference, credit system are some of the salient features of our proposed model.
Swarna Madhuri Pichikala, G Rachana, H Sanjanapatel, Saumya Shanu · 5 authors
Any software or file that we download from the internet has no way to verify if it is legit and does not contain a malware. An anti-virus just uses a centralised database. Building a blockchain solution around this which allows people who download any file from the internet to verify and approve that it is malicious or not is the need of the hour.In recent years, blockchain technology stands as some solution to everything due to its features like decentralization, persistency, anonymity, and auditability. The antivirus softwares detects whether a file is malicious or not and removes whichever file found malicious. These softwares try to be effective as much as their virus database allows them to be. These virus databases usually will have signatures of malicious behaviour. When a file is checked for maliciousness, its signature is checked if it matches or not with any of the existing signatures. If it is, then it is declared malicious and not allowed to download else file is quarantine or sent to lab analysis. Regarding the lab analysis and report, it depends on that particular antivirus software. Whatever can be the method of deciding whether a file is malicious or not but it takes time to analyse it, decide and add that particular file's signature to antivirus software's database within which any person would have downloaded that file. Here is where distributed and decentralized feature of blockchain is used to update the blockchain with the new malicious file's signature. By doing this every node in the network will be able to decide on whether the particular file from internet is malicious or not.
Smart contract is the building block of blockchain systems that enables automated peer-to-peer transactions and decentralized services. With the increasing popularity of smart contracts, blockchain systems, in particular Ethereum, have been the "paradise" of versatile fraud activities in which Ponzi, Honeypot and Phishing are the prominent ones. Formal verification and symbolic analysis have been employed to combat these destructive scams by analyzing the codes and function calls, yet the vulnerability of each \emph{individual} scam should be predefined discreetly. In this work, we present SCSGuard, a novel deep learning scam detection framework that harnesses the automatically extractable bytecodes of smart contracts as their new features. We design a GRU network with attention mechanism to learn from the \emph{N-gram bytecode} patterns, and determines whether a smart contract is fraudulent or not. Our framework is advantageous over the baseline algorithms in three aspects. Firstly, SCSGuard provides a unified solution to different scam genres, thus relieving the need of code analysis skills. Secondly, the inference of SCSGuard is faster than the code analysis by several order of magnitudes. Thirdly, experimental results manifest that SCSGuard achieves high accuracy (0.92$\sim$0.94), precision (0.94$\sim$0.96\%) and recall (0.97$\sim$0.98) for both Ponzi and Honeypot scams under similar settings, and is potentially useful to detect new Phishing smart contracts.
Jose Eduardo A. Sousa, Vinícius Cunha Oliveira, Júlia Almeida Valadares, Alex Borges Vieira · 7 authors
Ethereum is one of the most popular cryptocurrency currently and it has been facing security threats and attacks. As a consequence, Ethereum users may experience long periods to validate transactions. Despite the maintenance on the Ethereum mechanisms, there are still indications that it remains susceptible to a sort of attacks. In this work, we analyze the Ethereum network behavior during an under-priced DoS attack, where malicious users try to perform denial-of-service attacks that exploit flaws in the fee mechanism of this cryptocurrency. We propose the application of machine learning techniques and ensemble methods to detect this attack, using the available transaction attributes. The proposals present notable performance as the Decision Tree models, with AUC-ROC, F-score and recall larger than 0.94, 0.82, and 0.98, respectively.
Vinícius Cunha Oliveira, Júlia Almeida Valadares, Jose Eduardo A. Sousa, Alex Borges Vieira · 7 authors
Ethereum has emerged as one of the most important cryptocurrencies in terms of the number of transactions. Given the recent growth of Ethereum, the cryptocurrency community and researchers are interested in understanding the Ethereum transactions behavior. In this work, we investigate a key aspect of Ethereum: the prediction of a transaction confirmation or failure based on its features. This is a challenging issue due to the small, but still relevant, fraction of failures in millions of recorded transactions and the complexity of the distributed mechanism to execute transactions in Ethereum. To conduct this investigation, we train machine learning models for this prediction, taking into consideration carefully balanced sets of confirmed and failed transactions. The results show high-performance models for classification of transactions with the best values of F1-score and area under the ROC curve approximately equal to 0.67 and 0.87, respectively. Also, we identified the gas used as the most relevant feature for the prediction.
Ethereum Smart Contracts based on Blockchain Technology (BT)enables monetary transactions among peers on a blockchain network independent of a central authorizing agency. Ethereum smart contracts are programs that are deployed as decentralized applications, having the building blocks of the blockchain consensus protocol. This enables consumers to make agreements in a transparent and conflict-free environment. However, there exist some security vulnerabilities within these smart contracts that are a potential threat to the applications and their consumers and have shown in the past to cause huge financial losses. In this study, we review the existing literature and broadly classify the BT applications. As Ethereum smart contracts find their application mostly in e-commerce applications, we believe these are more commonly vulnerable to attacks. In these smart contracts, we mainly focus on identifying vulnerabilities that programmers and users of smart contracts must avoid. This paper aims at explaining eight vulnerabilities that are specific to the application level of BT by analyzing the past exploitation case scenarios of these security vulnerabilities. We also review some of the available tools and applications that detect these vulnerabilities in terms of their approach and effectiveness. We also investigated the availability of detection tools for identifying these security vulnerabilities and lack thereof to identify some of them
For proof-of-work blockchains such as Ethereum, the mining power decentralization is an important discussion point in the community. Previous studies mostly focus on the aggregated power of the mining pools, neglecting the pool participants who are the source of the pools' power. In this paper, we present the first large-scale study of the pool participants in Ethereum's mining pools. Pool participants are not directly observable because they communicate with their pools via private channels. However, they leave "footprints" on chain as they use Ethereum accounts to anonymously receive rewards from mining pools. For this study, we combine several data sources to identify 62,358,646 pool reward transactions sent by 47 pools to their participants over Ethereum's entire near 5-year history. Our analyses about these transactions reveal interesting insights about three aspects of pool participants: the power decentralization at the participant level, their pool-switching behavior, and why they participate in pools. Our results provide a complementary and more balanced view about Ethereum's mining power decentralization at a deeper level.