Sarah Khadijah Taylor, Aswami Ariffin, Khairul Akram Zainol Ariffin, Siti Norul Huda Sheikh Abdullah
The steady growth of cryptowallets users and the widespread of cryptocurrencies adoption has inadvertently risen the numbers of cybercrime. The decentralized and pseudo-anonymous nature of cryptocurrencies impose a unique challenge to the investigators. Unlike investigation on fiat currency where banks can be contacted to freeze account, cryptocurrencies do not have a centralized entity that can be contacted. On top of that, studies have shown that using a generic digital forensics methodology to collect and preserve cryptowallets, which often involves imaging and seizing, are ineffective for cryptocurrencies investigation. This is because criminals can recover his seized cryptowallets into other devices and thus continue to make transactions for illegal activities. This defeats the purpose of halting the criminals from conducting further crimes. Hence in this study we propose a methodology for preserving cryptowallets at crime scene. We then conducted evaluation on the methodology by using real case and simulation exercise on different types of cryptowallets. The result shows that our methodology can be used to properly preserve cryptocurrencies evidence. This study aims to identify gaps in cryptocurrencies investigation and address them by proposing a proper methodology.
Blockchain technology is increasingly finding traction in diverse areas such as finance, supply-chain management, and cloud services because of its ability to provide robust cybersecurity inherent in its system of having decentralized data storage. The rising complexity in the architecture of popular blockchain platforms create barriers to correct adoption of the technology. It becomes imperative that pedagogical tools are inducted in the blockchain ecosystem to address this perceived or real impediments for the uptake of the technology. We propose one of the first such pedagogical tool for training in blockchain using an adversarial sandbox adaptive serious game approach for students and technology professionals. We further propose use of AI to enhance NPC interactivity based on player’s responses. We plan to evaluate this serious game on a subjective metrics that is based on a game experience questionnaire.
Pei Xu, Joonghee Lee, James R. Barth, R. Glenn Richey
Purpose This paper discusses how the features of blockchain technology impact supply chain transparency through the lens of the information security triad (confidentiality, integrity and availability). Ultimately, propositions are developed to encourage future research in supply chain applications of blockchain technology. Design/methodology/approach Propositions are developed based on a synthesis of the information security and supply chain transparency literature. Findings from text mining of Twitter data and a discussion of three major blockchain use cases support the development of the propositions. Findings The authors note that confidentiality limits supply chain transparency, which causes tension between transparency and security. Integrity and availability promote supply chain transparency. Blockchain features can preserve security and increase transparency at the same time, despite the tension between confidentiality and transparency. Research limitations/implications The research was conducted at a time when most blockchain applications were still in pilot stages. The propositions developed should therefore be revisited as blockchain applications become more widely adopted and mature. Originality/value This study is among the first to examine the way blockchain technology eases the tension between supply chain transparency and security. Unlike other studies that have suggested only positive impacts of blockchain technology on transparency, this study demonstrates that blockchain features can influence transparency both positively and negatively.
The paper-based certification is prone to manipulation and vulnerable to fraud. Instances of fraudulent degrees, manipulation of academic records, or compromised academic programs adversely impact and damage an academic institution's credibility. It also affects the Indian universities’ mission and prospects of the students graduating from such a university. What makes reputational risk a unique risk is that it may arise both from the university or institution's failure or the action outside the university. It is, therefore, essential to take an enterprise risk management approach to mitigate reputational risk. Robust credential verification and validation protocols are the most important protections against fake certifications. The legacy certificate verification solutions are highly centralized, i.e., utterly dependent on the issuing authority for certificates. Despite the University Grants Commission (UGC) taking strict measures against individuals, Indian universities, colleges, and associations, we do come across several acts of torts. Some of the technology-savvy institutions have moved to digital certificates and digital signatures. However, this has an inherent weakness, i.e., they still need to rely on a trusted third party. Blockchain technology has three foundational components, data structures based on cryptography that make it secure and tamperproof, consensus protocols that allow it to function truthfully and without any central authority or a third party smart contracts, which provide efficiency and business value transactions. These key features of blockchain, if implemented appropriately, effectively has the potential to mitigate the inherent reputational risk arising from fraudulent academic certificate matters. Niti Ayog is currently developing a blockchain-based proof of concepts to solve traditional educational qualifications related to identity misrepresentation and document forgery. The immutability attribute of the blockchain ensures that tampering and manipulation of the record are not attainable. This paper focuses on the reputational risk Indian universities and institution may face when its certifications are not easily verifiable. Therefore, it becomes easy targets for bad actors to exploit vulnerabilities by issuing counterfeit certificates. Secondary published data, including various scholarly journals, reports, industry publications, and website sources, are utilized to develop this case study. The paper also explores how blockchain technology with specific reference to the proof of concept SuperCert proposed by Niti Ayog for Indian academic institutions may provide effective preventive control to overcome such reputational risk using the ABCD analysis framework as a research case study.
The financial and legal aspects of alternative payment systems from the anti-money laundering prespective Abstract The aim of this thesis is to provide a general overview of the current state of alternative payment systems with regard to their inclusion in the financial market, their properties and potentials for wider use, and to evaluate their possibilities to more effectively combat money laundering, terrorist financing and the proliferation of weapons of mass destruction. In the first chapter, the thesis explains the broader context with regard to financial systems, especially within the money market systems focusing on retail, while providing a deeper explanation of the context of European law and Czech law. The second chapter is focused on closer analysis of alternative payment systems with regard to their use. Alternative payment systems are divided into two basic categories for centralized alternative payment systems and decentralized alternative payment systems. The category of centralized alternative payment systems corresponds to the current conventional financial market, taking into account the innovations that have emerged in recent years. Decentralized alternative payment systems are based on the DLT Blockchain technology and the Islamic Hawala payment system is analyzed as a purely informal,...
Raúl Riesco Granadino, Xavier Larriva-Novo, Víctor A. Villagrá
Although cyber threat intelligence (CTI) exchange is a theoretically useful technique for improving security of a society, the potential participants are often reluctant to share \ntheir CTI and prefer to consume only, at least in voluntary based approaches. Such behavior destroys the idea of information exchange. On the other hand, governments are forcing specific entities and operators to report them specific incidents depending \non their impact. Obligations and sanctions are usually discouraging participants to share information voluntarily. We propose a paradigm shift of cybersecurity information exchange by ntroducing a new way to encourage all participants involved, at \nall levels, to share relevant information dynamically. Participants will have new and specific incentives to share, invest and consume threat intelligence and risk intelligence information depending on their different roles (producers, consumers, investors, donors and owner). Our proposal leverages from standards like Structured Threat Information Exchange (STIX™), W3C semantic web standards and from the Ethereum Blockchain to enable a workspace of knowledge related to behavioral threat intelligence patterning to characterize tactics, techniques and procedures (TTP) introducing new type of incentives.
Alex Hoffman, Phillipe Austria, Chol Hyun Park, Yoohwan Kim
A C TBug Bounty Programs (BBPs) play an important role in providing and maintaining security in software applications.These programs allow testers to discover and resolve bugs before the general public is aware of them, preventing incidents of widespread abuse.However, they have shown problems such as organizations providing accountability of reporting bugs and nonrecognition of testers.In this paper, we discuss Bountychain, a decentralized application using Ethereum-based Smart Contracts (SCs) and the Interplanetary File System (IPFS), a distributed file storage system.Blockchain and SCs provide a safe, secure and transparent platform for a BBP.Testers can submit bug reports and organizations can accept or reject the defect via the SCs.Transactions on the blockchain serve as a persistent and transparent record of software bugs, while IPFS serves as a long-term storage system for bug details.Thus, Bountychain ensures organization accountability and allows testers to gain irrefutable recognition.
This research work, a study was carried out on blockchain technology and its types, as well as the creation of new models of government and governance from the scope of an organization, infrastructure and platform. Governance and commercial models were addressed, based on standardization of data and legal frameworks. On the other hand, it showed how operational governance causes consequences in business models, whether with transactions, multi-signature, forks, consensus mechanism, smart contracts, tokenization, online dispute resolution and decentralized application (World Economic Forum, 2020, pp. 97 196). It was discovered that at least in current business models, private blockchain networks are more useful than public networks because they have greater operational flexibility and data governance, without exempting that public networks must also have mechanisms of governance since sometimes a human consensus must be reached to make updates to protocols and technical rules (The Law Society, 2020, pp. 24-61). This paper shows the basic principles that must be observed about governance and regulation in the implementation of blockchain technologies in systems created by governments, corporations and/or organized civil societies.
The advantages and disadvantages of blockchain technology in cryptocurrency attacks will be explained in this article. Digital currency has been widely used around the world. The soaring value of digital currencies has also led to an increase in the use of cryptocurrency. Cryptocurrency is a form of payment that can be exchanged online for goods and services. The increasingly popular use of cryptocurrency around the world is causing criminals, and hackers are starting to attack cryptocurrency on an ongoing basis. With the advent of blockchain technology, it managed to save the digital currency system with the availability of a decentralized database. Each block has many transactions, and for new transactions will be recorded and added to a decentralized database with a cryptographic signature that does not change making it difficult for abuse and theft. The authors have examined the strengths and weaknesses of the blockchain in cryptocurrency attacks. As a result, the authors support that this blockchain technology can help deal with cryptocurrency attacks that occur.
Maitha Al Ketbi, Khaled Shuaib, Ezedin Barka, Marton Gergely
Aim/Purpose: The aim of this paper is to propose a new information security controls framework for blockchain technology, which is currently absent from the National and International Information Security Standards. Background: Blockchain technology is a secure and relatively new technology of distributed digital ledgers, which is based on inter-linked blocks of transactions, providing great benefits such as decentralization, transparency, immutability, and automation. There is a rapid growth in the adoption of blockchain technology in different solutions and applications and within different industries throughout the world, such as finance, supply chain, digital identity, energy, healthcare, real estate, and the government sector. Methodology: Risk assessment and treatments were performed on five blockchain use cases to determine their associated risks with respect to security controls. Contribution: The significance of the proposed security controls is manifested in complementing the frameworks that were already established by the International and National Information Security Standards in order to keep pace with the emerging blockchain technology and prevent/reduce its associated information security risks. Findings: The analysis results showed that the proposed security controls herein can mitigate relevant information security risks in blockchain-based solutions and applications and, consequently, protect information and assets from unauthorized disclosure, modification, and destruction. Recommendations for Practitioners: The performed risk assessment on the blockchain use cases herein demonstrates that blockchain can involve security risks that require the establishment of certain measures in order to avoid them. As such, practitioners should not blindly assume that through the use of blockchain all security threats are mitigated. Recommendation for Researchers: The results from our study show that some security risks not covered by existing Standards can be mitigated and reduced when applying our proposed security controls. In addition, researchers should further justify the need for such additional controls and encourage the standardization bodies to incorporate them in their future editions. Impact on Society: Similar to any other emerging technology, blockchain has several drawbacks that, in turn, could have negative impacts on society (e.g., individuals, entities and/or countries). This is mainly due to the lack of a solid national and international standards for managing and mitigating risks associated with such technology. Future Research: The majority of the blockchain use cases in this study are publicly published papers. Therefore, one limitation of this study is the lack of technical details about these respective solutions, resulting in the inability to perform a comprehensive risk identification properly. Hence, this area will be expanded upon in our future work. In addition, covering other standardization bodies in the area of distributed ledger in blockchain technology would also prove fruitful, along with respective future design of relevant security architectures.