In current IPv6 networks, the increasing number of network devices also boosts the widespread DDoS attacks. Meanwhile, Intrusion Detection System (IDS) is evolved from the individual defense pattern to a distributed and collaborative mode, and Cooperative IDS (CIDS) becomes the mainstream technique. How to improve the overall defense capability through the coordination of information becomes worth studying. In this paper, we propose a DDoS blacklist mechanism with smart contract for IPv6-SAVI (Source Address Validation Improvements) network. In SAVI environment, DDoS source information detected by IDS is considered to be credible. Based on this observation, we design a dynamic update strategy for the reputation of trusted addresses based on the detection results and form a blacklist. Furthermore, we combine CIDS deployment with blockchain to design a blacklist sharing strategy based on smart contract, so that the individual IDS distributed on the chain can realize safe and reliable sharing and updating of the blacklist. Finally, extensive experiments evaluate the performance of our mechanism in terms of latency, overhead, reputation change accuracy, etc., which demonstrates that the blacklist can provide DDoS traffic filtering reference to improve the DDoS mitigation capability.
Votingis a basic element of running a country. Voting will continue to take place by physically entering the voting booth. No security is guaranteed for this operation, and several cases of tampering have been noted. In order to eliminate this type of problem, the paper proposes an online voting process with blockchain technology. With encryption and hashing, the security of each vote is ensured. The votes will be stored as transactions. A peer-to-peer network is leveraged to share this distributed ledger with voting transactions. The application is designed to hide the complexities of the architecture from the user. With the QR code, each student is uniquely identified. This ensures that each voter has only one chance to vote. With the public and private key, each node will have the ability to securely encrypt, hash, and add transactions to the blockchain. Votes cannot be traced back to the voters. This paper creates a peer-to-peer network with at least three peers. This paper plans to increase voter turnout through online voting. The scalability of blockchain applications depends on the secondary storage limits of peers.
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
The data in the blockchain cannot be tampered with and the users are anonymous, which enables the blockchain to be a natural carrier for covert communication. However, the existing methods of covert communication in blockchain suffer from the predefined channel structure, the capacity of a single transaction is not high, and the fixed transaction behaviors will lower the concealment of the communication channel. Therefore, this paper proposes a derivation matrix-based covert communication method in blockchain. It uses dual-key to derive two types of blockchain addresses and then constructs an address matrix by dividing addresses into multiple layers to make full use of the redundancy of addresses. Subsequently, to solve the problem of the lack of concealment caused by the fixed transaction behaviors, divide the rectangular matrix into square blocks with overlapping regions and then encrypt different blocks sequentially to make the transaction behaviors of the channel addresses match better with those of the real addresses. Further, the linear congruence algorithm is used to generate random sequence, which provides a random order for blocks encryption, and thus enhances the security of the encryption algorithm. Experimental results show that this method can effectively reduce the abnormal transaction behaviors of addresses while ensuring the channel transmission efficiency.
Open access
Advanced Steganography and Watermarking Techniques
Amit Kumar Goel, Aditi Rai, Anushree Narain, Ashish Richard · 5 authors
Voting is the essential element for each nation to express one’s choice. Nowadays, Electronic Voting Machines (EVMs) are used to poll which may be tampered resulting in incorrect election results. Therefore, an online voting system has been introduced in this research. An Electronic Voting (E-Voting) machine is a balloting machine wherein the election opinions are notated, saved, stored, and processed digitally, which makes the balloting control project complicated than the conventional paper based method. The Election Commission forms elections and enlist party candidates along with the parties for contesting the election. This paper works with the following ideas by having the two different sets of modules: election commission and the voters. An election’s REST API is arranged on Ethereum’s Blockchain, which is the front end. The votes are then stored on the blockchain architecture, to which the Election Commission grants the number of votes. However, there are some limitations due to the fact that the blockchain architecture cannot run on the main net as it must be hosted, and a separate web3 provider must be used for interacting with it due to the lack of public API availability.
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Coin mixing services allow users to mix their cryptocurrency coins and thus enable unlinkable payments in a way that prevents tracking of honest users' coins by both the service provider and the users themselves. The easy bootstrapping of new users and backwards compatibility with cryptocurrencies (such as Bitcoin) with limited support for scripts are attractive features of this architecture, which has recently gained considerable attention in both academia and industry.
Chábeli Castaño Arango, Roberto Luna-Garcia, Steve Cutchin, Gaby G. Dagher
Bitcoin transactions are pseudonymous, which means that even when addresses or addresses can be connected one to another, it is really hard to connect them with outside entities. On top of that there have been a proliferation of bitcoins mixing sites in recent years. These sites operate mostly on the dark web and their main mission is launder bitcoins by making vast amounts of complex transactions with them and to make their association with a single owner even harder. Our mission is to make that distinction easier. In this paper we plan to introduce two novel heuristics. Our OI heuristic is designed to parse blockchain data in a way where we only receive information we deem is of interest. We introduce HOLO which aims to taint bitcoin addresses in reference to a fixed output. We also visualize the blockchain and our heuristic in an easily digestible manner.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Yukun Niu, Lingbo Wei, Chi Zhang, Jianqing Liu · 5 authors
Anonymous yet accountable authentication can protect users' privacy and security and prevent users from misbehaving when they access public Wi-Fi hotspots. However, most existing privacy-enhanced authentication schemes either do not meet the accountability requirements in public Wi-Fi hotspot access or they are inherently dependent on trusted third parties, and therefore are undeployable in practical settings. In this paper, we design and implement an access authentication scheme to simultaneously and efficiently provide anonymity and accountability without relying on any trusted third party by utilizing a permissionless blockchain (e.g., Bitcoin or Ethereum) and Intel SGX. Inspired by the recent progress on Bitcoin techniques such as Colored Coins, we utilize the unmodified Bitcoin blockchain as the powerful platform to manage access credentials without introducing any trusted third party. We leverage SGX-based mixer to allow users to anonymously exchange their access credentials and design the verification path of access credentials to support blacklisting misbehaving access credentials without compromising users' anonymity. By integrating with the anti-double-spending property of the Bitcoin blockchain, our scheme can simultaneously provide users' accountability and anonymity without involving any trusted third party. Finally, we demonstrate that our proposed scheme is compatible with the current Bitcoin system or other permissionless blockchains, and is highly effective and practical for public Wi-Fi hotspot access control systems.
In the recent development of the online cryptocurrency mining platform, Coinhive, numerous websites have employed “Cryptojacking.” They may need the unauthorized use of CPU resources to mine cryptocurrency and replace advertising income. Web cryptojacking technologies are the most recent attack in information security. Security teams have suggested blocking Cryptojacking scripts by using a blacklist as a strategy. However, the updating procedure of the static blacklist has not been able to promptly safeguard consumers because of the sharp rise in “Cryptojacking kidnapping”. Therefore, we propose a Cryptojacking identification technique based on analyzing the user's computer resources to combat the assault technology known as “Cryptojacking kidnapping.” Machine learning techniques are used to monitor changes in computer resources such as CPU changes. The experiment results indicate that this method is more accurate than the blacklist system and, in contrast to the blacklist system, manually updates the blacklist regularly. The misuse of online Cryptojacking programs and the unlawful hijacking of users' machines for Cryptojacking are becoming worse. In the future, information security undoubtedly addresses the issue of how to prevent Cryptojacking and abduction. The result of this study helps to save individuals from unintentionally becoming miners.
In order to analyze real-time power data without revealing users’ privacy, privacy-preserving data aggregation schemes have been extensively researched in smart grid. However, most of the existing schemes either can only allow stationary users, or require a trusted center. In this paper, we propose an efficient and robust multidimensional data aggregation scheme based on blockchain. In our scheme, a leader election algorithm in Raft protocol is used to select a mining node from all smart meters to aggregate data. A dynamically verifiable secret sharing homomorphism scheme is adopted to realize flexible dynamic user management. In addition, our scheme can not only resist internal and external attacks but also support multidimensional data aggregation and fault tolerance. The security analysis shows that our proposed scheme is IND-CPA secure and can meet stronger security features. The experimental results show that compared with other schemes, our scheme can be implemented with lower computation and communication overhead.
Manish Kumar, B Annappa, Likewin Thomas, Sourav Kanti Addya · 5 authors
The ability to voice one&s;s opinion is the strong foothold which Democracy declares to provide. Amongst all the other mechanisms, Voting constitutes the major tool to gather and summarize people&s;s opinion. Numerous schemes and protocols based on strong cryptography and using the advantages of the prevalent technologies have been proposed and implemented. The inherent lack of a strong framework or consolidated building block to support the same has not been addressed or is in its infancy. Many alternatives are being considered, and in our opinion, the most promising technology in this regard is the evolution of Blockchain. Using blockchain technology we have proposed a scheme for an E-voting process. This would help to overcome the limitations of transparent voting process, votes summarization/counting. All these are at a low workload on the admin in the voting process. Our proposed scheme provides Anonymity to Voters wherein no other person will be able to link the voters vote to a voter. This unlikability is provided using the concept of Non-Interactive Zero Knowledge Proofs on the Blockchain. A public-key cryptosystem is what provides votes privacy. The proposed protocol aims to provide Anonymity of voters, with privacy of votes and results in a transparent and secure Election
Christina Ovezik, Dimitris Karakostas, Aggelos Kiayias
Decentralization has been touted as the principal security advantage which propelled blockchain systems at the forefront of developments in the financial technology space. Its exact semantics nevertheless remain highly contested and ambiguous, with proponents and critics disagreeing widely on the level of decentralization offered by existing systems. To address this, we put forth a systematization of the current landscape with respect to decentralization and we derive a methodology that can help direct future research towards defining and measuring decentralization. Our approach dissects blockchain systems into multiple layers, or strata, each possibly encapsulating multiple categories, and it enables a unified method for measuring decentralization in each one. Our layers are (1) hardware, (2) software, (3) network, (4) consensus, (5) economics ("tokenomics"), (6) client API, (7) governance, and (8) geography. Armed with this stratification, we examine for each layer which pertinent properties of distributed ledgers (safety, liveness, privacy, stability) can be at risk due to centralization and in what way. We also introduce a practical test, the "Minimum Decentralization Test" which can provide quick insights about the decentralization state of a blockchain system. To demonstrate how our stratified methodology can be used in practice, we apply it fully (layer by layer) to Bitcoin, and we provide examples of systems which comprise one or more "problematic" layers that cause them to fail the MDT. Our work highlights the challenges in measuring and achieving decentralization, and suggests various potential directions where future research is needed.
With the development of the Internet of Things (IoT) and its applications, a large amount of data is generated regularly. If this information is used by malicious attackers, it will be a great disaster for the relevant users. In this regard, this article focuses on the user’s identity privacy issues involved in the IoT. By protecting the user’s identity privacy, the attacker cannot associate the obtained data with the user’s real identity, and so achieve the purpose of protecting the user. This article uses the features of blockchain that cannot be tampered with nor forged to strengthen the reliability of the system. The proposed scheme saves the transaction information of user information through the Hyperledger and uses the ring signature method to obscure the real identity. A key generator is used to generate system public parameters and ring membership information required for signature. Users can use this information to hide their identity in a ring group of n users so that other users can only guess the true identity of the user with a probability of 1/n. Additionally, the method of aggregated signature is used to shorten the time and space required for k signature verification to 1/k, which greatly improves the efficiency. Finally, this article also uses an accountability mechanism to punish some attackers who attempt to waste system resources by revealing the real identity of the attacker and refusing to serve him. In this paper, GO language is used to write chain code to realize the proposed algorithm, and a prototype system is built through HyperLeger Fabric blockchain network, and the prototype system is verified by experiment. The correctness and efficiency of the above scheme are also proved through theoretical analysis and experiments.
Saba Abdulbaqi Salman, Sufyan Al-Janabi, Ali Makki Sagheer
Improving the voting system has become a widely discussed issue. Paper-based elections are not safe because of the possibility of changing and adding ballots. Consequently, many countries use e-voting systems to ensure security, authenticity and time efficiency. Blockchain e-voting systems can be adopted to reduce fraud and increase voting access from home, especially in pandemics. This paper suggests a blockchain e-voting system that tackles two security and authentication issues. The security has been ensured using hybrid public-key cryptography; the voter information is encrypted using the regional election office elliptic public key, while the homomorphic public supreme election authority encrypts the vote. Using homomorphic encryption for voice enables the calculations of results as the authority encrypts it without revealing the vote itself. Authentication has been improved for home voting by a robust login system. This login system consists of two steps. In the first step, the voter enters the site using his unique QR code number scanned by webcam; in the second step, the system checks the voter's face using a face recognition system by web camera to be routed to the voting page. Voting public keys are also authenticated using a digital certificate schema. The system has been tested to show its efficiency and suitability in block establishment time and the encryption and key generator randomness using NIST tests.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Voting is one of the most fundamental components of a democratic society. In 2021 Iraq held the Council of Representatives (CoR) elections in 83 electoral constituencies in 19 governorates. Nonetheless, several significant issues arose during this election, including the problem of logistics distribution, the excessively long period of ballot counting, voters can't know if their votes were counted or if their ballots were tampered with, and the inconsistent regulation of vote counting. Blockchain technology, which was just invented, may offer a solution to these problems. This paper introduces an electronic voting system for the Iraq Council of Representatives elections that is based on a prototype of the permission hyperledger fabric blockchain. An immutable, distributed ledger maintained by all members of a network is what blockchain technology is all about. By authenticating each voter, the system can prevent voting fraud by making votes traceable and verifiable, hence decreasing the chance of unlawful activities and fraudulent ballots. This work investigates the influence of E-voting, specifically the voting phase workload, on the performance of the hyperledger fabric blockchain platform in terms of latency and throughput by altering transaction send rates (tps), block size, and block timeout.
The second revolution in blockchain technology is smart contracts. Smart contracts are used in most of the blockchain applications like cryptocurrency, Health care, banking sectors, supply chain and IOT with different platforms like Fabric, Ethereum, Corda etc. In Ethereum blockchain, due to lack of inefficiency of the knowledge of technical developers and insecure programming languages for smart contracts, the attackers have exploited the smart contracts and the end users have lost millions of dollars like re-entrancy, king of ether throne attack, DoS, forcefully send ethers, multisig wallet, unexpected ether and poly network attack etc. In the year 2016, the attackers have exploited approximately $289 million US dollars with the help of re-entrancy vulnerability. The attackers have also attacked the smart contracts and broke the execution of that particular contracts through king of ether throne attack. In this paper, we propose a novel prevention and detection mechanisms for re-entrancy and king of ether throne attacks using time mechanisms and also implementing the same with proof of concepts for these vulnerabilities.
Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
With the development of 5G and the Internet of things (IoT), the multi-domain access of massive devices brings serious data security and privacy issues. At the same time, most access systems lack the ability to identify network attacks and cannot adopt dynamic and timely defenses against various security threats. To this end, we propose a blockchain-based access control and behavior regulation system for IoT. Relying on the attribute-based access control model, this system deploys smart contracts on the blockchain to achieve distributed and fine-grained access control and ensures that the identity and authority of access users can be trusted. At the same time, an inter-domain communication mechanism is designed based on the locator/identifier separation protocol and ensures the traffic of access users are authorized. A feedback module that combines traffic detection and credit evaluation is proposed, ensuring real-time detection and fast, proactive responses against malicious behavior. Ultimately, all modules are linked together through workflows to form an integrated security model. Experiments and analysis show that the system can effectively provide comprehensive security protection in IoT scenarios.
Ethereum has received increasing attention as the first blockchain platform to support smart contracts. Data mining has become an important tool for analyzing Ethereum transactions. However, existing methods have the disadvantage of covering partial transactions and being vulnerable to privacy-enhancing techniques. In this paper, we propose a scheme for transaction correlation with the node as an entity, which can cover all transactions while being resistant to privacy-enhancing techniques. Utilizing timestamps relayed from N fixed nodes to describe the network properties of transactions, we cluster transactions that enter the network from the same source node. Experimental results show that our method can determine with 97% precision whether two transactions enter the network from the same source node.
Francisco Assis Moreira do Nascimento, Fabiano Hessel
Internet of Things-based systems are typically distributed systems and thus inherit all issues related to the need to guarantee confidentiality, integrity, and availability. Moreover, IoT-based systems are vulnerable to several attacks, mainly due to the weakness of IoT devices, which have little computational and memory power, necessary for more sophisticated security features. To build robust infrastructures, one of the traditional strategies to deal with these problems involves intrusion detection and prevention techniques. Implementing them in a centralized way is usual, which leads to not being scalable for IoT systems with an increasing number of devices. Moreover, it implies an unacceptable single point of failure. Besides, sending all collected data to a centralized server in the cloud poses a significant risk to the privacy of information. Recently, machine learning techniques, as decentralized federated learning, combined with distributed ledger technologies, have been used to implement more robust and privacy-preserving intrusion detection systems for IoT-based systems. However most current decentralized federated learning approaches depend on a centralized server, and so have a single point of failure. The centralized server is used to aggregate the local trained models obtained by means of deep learning algorithms performed on edge and fog devices. This paper reviews state of the art on intrusion detection based on totally decentralized federated learning and distributed ledger techniques applied to minimize IoT security threats, identifies open problems, and recommends future research directions to cope with them.
We study the problem of simultaneously addressing both ballot stuffing and participation privacy for pollsite voting systems. Ballot stuffing is the attack where fake ballots (not cast by any eligible voter) are inserted into the system. Participation privacy is about hiding which eligible voters have actually cast their vote. So far, the combination of ballot stuffing and participation privacy has been mostly studied for internet voting, where voters are assumed to own trusted computing devices. Such approaches are inapplicable to pollsite voting where voters typically vote bare handed. We present an eligibility audit protocol to detect ballot stuffing in pollsite voting protocols. This is done while protecting participation privacy from a remote observer - one who does not physically observe voters during voting. Our protocol can be instantiated as an additional layer on top of most existing pollsite E2E-V voting protocols. To achieve our guarantees, we develop an efficient zero-knowledge proof (ZKP), that, given a value $v$ and a set $Φ$ of commitments, proves $v$ is committed by some commitment in $Φ$, without revealing which one. We call this a ZKP of reverse set membership because of its relationship to the popular ZKPs of set membership. This ZKP may be of independent interest.
Miguel Díaz Montiel, Rachid Guerraoui, Pierre-Louis Roman
Blockchain intercommunication systems enable the exchanges of messages between blockchains. This interoperability promotes innovation, unlocks liquidity and access to assets. However, blockchains are isolated systems that originally were not designed for interoperability. This makes cross-chain communication, or bridges for short, insecure by nature. More precisely, cross-chain systems face security challenges in terms of selfish rational players such as maximal extractable value (MEV) and censorship. We propose to solve these challenges using zero knowledge proofs (ZKPs) for cross-chain communication. Securing cross-chain communication is remarkably more complex than securing single-chain events as such a system must preserve user security against both on- and off-chain analysis. To achieve this goal, we propose the following pair of contributions: the DACT protocol and the SurferMonkey infrastructure that supports the DACT protocol. The DACT protocol is a global solution for the anonymity and security challenges of agnostic blockchain intercommunication. DACT breaks on- and off-chain analysis thanks to the use of ZKPs. SurferMonkey is a decentralized infrastructure that implements DACT in practice. Since SurferMonkey works at the blockchain application layer, any decentralized application (dApp) can use SurferMonkey to send any type of message to a dApp on another blockchain. With SurferMonkey, users can neither be censored nor be exposed to MEV. By applying decentralized proactive security, we obtain resilience against selfish rational players, and raise the security bar against cyberattacks. We have implemented a proof of concept (PoC) of SurferMonkey by reverse engineering Tornado Cash and by applying IDEN3 ZKP circuits. SurferMonkey enables new usecases, ranging from anonymous voting and gaming, to a new phase of anonymous decentralized finance (aDeFi).
DNS has often been criticized for inherent design flaws, which make the system vulnerable to attack. Further, domain names are not fully controlled by users, meaning that they can easily be taken down by authorities and registrars. Due to this, there have been efforts to build a decentralized name service that gives greater control to domain owners. The Ethereum Name Service (ENS) is a major example. Yet, no existing work has systematically studied this emerging system, particularly regarding security and misbehavior. To address this gap, we present the first large-scale measurement study of ENS. Our findings suggest that ENS has shown growth during its four years' evolution. We identify several security issues, including traditional name system problems, as well as new issues introduced by the unique properties of ENS. We find that attackers are abusing the system with thousands of squatting ENS names, a number of scam blockchain addresses and indexing of malicious websites. We further develop a new record persistence attack, to find that 22,716 .eth names (3.7% of all names) are vulnerable to name hijacking. Our exploration suggests that our community should invest more effort into the detection and mitigation of issues in decentralized name services.
V Srinadh, Chetan Sai Pyla, Desaraju Sri Rama Ganesh, Borra Kiran Kumar · 5 authors
<strong>Abstract:</strong> Modern digital technology has enhanced the lives of several people. Unlike to the election system, it makes heavy use of printed paper. Elections using the traditional method risk the security aspects and openness. The institution that oversees general elections continues to adopt a centralized approach. With an organization having complete control over the database and system, it is feasible to tamper with the database of significant opportunities. This is one of the issues that might arise in traditional election systems. Because it adopts a decentralized structure and the full database is held by multiple people, blockchain technology has been one of the solutions. The methodology outlined in this work examines the usefulness of hashing algorithms, the construction and sealing of blocks, the accumulation of data, and the declaration of results using an adaptable blockchain approach. Electronic voting or e-voting has fundamental benefits over paper-based systems such as increased efficiency and reduced errors. The electronic voting system tends to maximize user participation, by allowing them to vote from anywhere and from any device that has an internet connection. The blockchain is an emerging, decentralized, and distributed technology with strong cryptographic foundations that promises to improve different aspects of many industries. Expanding e-voting into blockchain technology could be the solution to alleviate the present concerns in e-voting. Here we propose a blockchain-based voting system that will limit the voting fraud and make the voting process simple, secure and efficient. <strong>Keywords:</strong> Blockchain, Online voting, Decentralization, Privacy, Security, Ethereum. <strong>Title:</strong> Online Voting System using Ethereum in Blockchain Technology <strong>Author:</strong> V Srinadh, Chetan Sai Pyla, Desaraju Sri Rama Ganesh, Borra Kiran Kumar, Bheemerasetty Divya Sai <strong>International Journal of Recent Research in Mathematics Computer Science and Information Technology</strong> <strong>ISSN 2350-1022</strong> <strong>Vol. 9, Issue 2, October 2022 - March 2023</strong> <strong>Page No: 1-10</strong> <strong>Paper Publications</strong> <strong>Website: www.paperpublications.org</strong> <strong>Published Date: 21-October-2022</strong> <strong>DOI: https://doi.org/10.5281/zenodo.7233830</strong> <strong>Paper Download Link (Source)</strong> <strong>https://www.paperpublications.org/upload/book/Online%20Voting%20System%20using%20Ethereum-21102022-2.pdf</strong>