Inspired from the iForest algorithmic scheme, we propose an iForest-based blockchain social media anomaly behavior detection method via the improved tree algorithm, for the purpose of isolating the anomalous behaviors as an outlier. The model is integrated with the smart contract structure of blockchain. In the overall system, the user data is sent to the intelligent contract for a period of time. After the identification of the abnormal behavior of social media users, the abnormal behavior in blockchain is marked and stored in the abnormal chain. To a certain extent, the scheme protects users' privacy, improves the efficiency and accuracy of iForest anomaly detection, and is more suitable for multi-dimensional heterogenous data-centric social media user behavior detection.
Suhani Jattan, Vineeth Kumar, R Akhilesh, Rachith R Naik · 5 authors
In today's world, more importance is given on the availability of the applications and various websites available in the digital market. People will manage their daily work on time, precisely, very fast, and with satisfaction. So various technologies are used to fulfil daily work. In India, there is no direct and efficient way of communication between the government and the public, for solving a problem i.e for getting a problem solved at any place, people may have to wait for three months, but it can probably be solved sooner. Nowadays, the scenario has changed. Many applications are available, which allow users to register their complaints. But there are some problems related to its transparency. This paper proposes an Ethereum blockchain application that will help people to register their complaints and get updates about the complaint. Adoption of blockchain technology makes the application more secure, transparent and immutable.
In agreements among anonymous users, smart contracts eliminate the need for a trusted intermediary and enforce its terms when the conditions set by the parties are met. Although smart contracts are mostly used for positive purposes, they have also been used for illegal activities due to their appealing characteristics in the criminal context. More specifically, a smart contract stimulates new forms of trustless collaboration among cybercriminals and the trend toward criminal use of smart contract can be more dangerous in collaborative attacks in terms of attacks' destructive power and sophistication.
In this paper, we present an architecture for real-world collaborative attacks based on criminal smart contracts (CSCs). We propose a CSC for the case of a collaborative distributed denial of service attack. In order to explore the feasibility and capture the characteristic of the attack-result, we formulate the attackers' interaction as an incomplete information game and prove that it has a unique dominant strategy equilibrium. We also model the proposed CSC as an incentive mechanism and prove that it is a strategy-proof and budget-balanced mechanism. Our numerical simulations show that the proposed incentive mechanism provides individual rationality and fairness to the collaborating attackers in its equilibrium.
Ikra Afzal Chesti, Mamoona Humayun, Najm Us Sama, N. Z. Jhanjhi
Tremendous growth of ransom malware demands valuable security methods to protect individuals and organizations. Ransomware or ransom malware is a type of malware that restricts users from accessing their files or system and demands a ransom payment to get back access to files. The hacked files are encrypted and asked for payment to decrypt and redeliver the files back to the user. To regain access back to hacked files one has to make digital payment. Ransomware of this type is dangerous as it hacks all the files and fails all the security methods available on the system also the possibility for retrieving your file is zero percent. Even if the payment is done still one cannot be sure that files will be delivered back to the user. The earliest ransomware came into existence in 1980, at that time one has to pay through snail mail. Ransomware is considered as the most widespread malware since 1989 and had caused global financial losses both to individuals and big organizations. Every year this loss is increasing. Therefore, protection of our data from ransomware is necessary. Today, originators of ransomware demand for payment via bitcoins or cryptocurrency. This paper provides the detailed overview about ransomware, its evolution, the reasons for paying or not paying a ransom, the existing approaches to avoid this problem, and the recovery techniques in case of infection.
Cryptocurrencies have revolutionized the process of trading in the digital world. Roughly one decade since the induction of the first bitcoin block, thousands of cryptocurrencies have been introduced. The anonymity offered by the cryptocurrencies also attracted the perpetuators of cybercrime. This paper attempts to examine the different machine learning approaches for efficiently identifying ransomware payments made to the operators using bitcoin transactions. Machine learning models may be developed based on patterns differentiating such cybercrime operations from normal bitcoin transactions in order to identify and report attacks. The machine learning approaches are evaluated on bitcoin ransomware dataset. Experimental results show that Gradient Boosting and XGBoost algorithms achieved better detection rate with respect to precision, recall and F-measure rates when compared with k-Nearest Neighbor, Random Forest, Naïve Bayes and Multilayer Perceptron approaches
The Modern Slavery Act of the UK has failed in reducing modern slavery significantly in UK organizations and their supply chains. One of the critical reasons for the failure is that these organizations utilize human-centered modern slavery due diligence processes, which have significant weaknesses in identifying modern slavery offenses. This paper aims to propose modern slavery due diligence process which leverages the self-sovereign digital identity component, an AI-based modern slavery offense monitoring component, and a modern slavery offense blockchain component designed to help improve the identification of modern slavery offenses which would otherwise remain hidden. This process enables managers to identify and act on more modern slavery offenses due to low-cost continuous monitoring instead of high-cost sample-based monitoring. This proposed solution can significantly reduce modern slavery offenses and generate tangible business benefits.
Cilj ovog završnog rada je egzaktno opisati izradu kriptovalute zasnovanu na tehnologiji blockchain. Za izradu kriptovalute korišten je izvorni kôd postojeće kriptovalute Litecoin te su kroz postupak izrade izmijenjeni određeni parametri u izvornom kôdu kao i dijelovi kôda kako bi se uspješno izradila nova kriptovaluta. U radu je opisan postupak izgradnje kriptovalute i opisane su tehnologije koje su pri tom korištene. Prilikom izgradnje korišten je operativni sustav Linux u virtualnom okruženju te su testirane sve funkcionalnosti neophodne za rad s kriptovalutom.
The insider threats have always been one of the most severe challenges to cybersecurity. It can lead to the destruction of the organisation's internal network system and information leakage, which seriously threaten the confidentiality, integrity and availability of data. To make matters worse, since the attacker has authorized access to the internal network, they can launch the attack from the inside and erase their attack trace, which makes it challenging to track and forensics. A blockchain traceability system for insider threats is proposed in this paper to mitigate the issue. First, this paper constructs an insider threat model of the internal network from a different perspective: insider attack forensics and prevent insider attacker from escaping. Then, we analyze why it is difficult to track attackers and obtain evidence when an insider threat has occurred. After that, the blockchain traceability system is designed in terms of data structure, transaction structure, block structure, consensus algorithm, data storage algorithm, and query algorithm, while using differential privacy to protect user privacy. We deployed this blockchain traceability system and conducted experiments, and the results show that it can achieve the goal of mitigating insider threats.
This article defines and exemplifies the primary information security goals when organisations use, operate or develop blockchain technology solutions. The proposed goals extend the well-known CIA-triad Confidentiality, integrity, Availability) to account for the increased complexity in securing software solutions and organisations. The understanding of these goals can help information security practitioners design and implement more effective security controls for protecting blockchain solutions and organisations. Non-security professionals in the blockchain field can also benefit from the concepts in this article, as security is a core component in all blockchains.
Emad Badawi, Guy-Vincent Jourdan, Gregor von Bochmann, Iosif-Viorel Onut
We investigate what we call the "Bitcoin Generator Scam" (BGS), a simple system in which the scammers promise to "generate" new bitcoins using the ones that were sent to them. A typical offer will suggest that, for a small fee, one could receive within minutes twice the amount of bitcoins submitted. BGS is clearly not a very sophisticated attack. The modus operandi is simply to put up some web page on which to find the address to send the money and wait for the payback. The pages are then indexed by search engines, and ready to find for victims looking for free bitcoins. We describe here a generic system to find and analyze scams such as BGS. We have trained a classifier to detect these pages, and we have a crawler searching for instances using a series of search engines. We then monitor the instances that we find to trace payments and bitcoin addresses that are being used over time. Unlike most bitcoin-based scam monitoring systems, we do not rely on analyzing transactions on the blockchain to find scam instances. Instead, we proactively find these instances through the web pages advertising the scam. Thus our system is able to find addresses with very few transactions, or even none at all. Indeed, over half of the addresses that have eventually received funds were detected before receiving any transactions. The data for this paper was collected over four months, from November 2019 to February 2020. We have found more than 1,300 addresses directly associated with the scam, hosted on over 500 domains. Overall, these addresses have received (at least) over 5 million USD to the scam, with an average of 47.3 USD per transaction.
Malicious activities such as scams and frauds have imposed high costs for financial systems. The advent of blockchain-based cryptocurrencies such as Ethereum provides unprecedented characteristics. On one hand, the pseudonymity of the blockchain allows criminals to hide their actual identities, which is an appealing feature for conducting malicious activities. On the other hand, the public data of blockchain sets forth the opportunity for comprehensive forensic analysis. In this paper, we present a novel framework to identify malicious entities in the Ethereum blockchain network. The proposed framework composes of an efficient method for extracting a set of features from the Ethereum blockchain data to represent transactional behavior of entities. Our proposed solutions for detecting malicious entities employ variations of Logistic Regression, Support Vector Machine, Random Forest, and other ensemble methods such as Stacking and AdaBoost Classifier. The ensemble methods show high performance with F1score of 0.996 in average. The results also imply that the proposed method of feature extraction is fairly efficient in presenting the network characteristics.
Amsterdam Law Forum (ALF) is the student-run 'International Law Journal' of VU University. Every year ALF publishes a winter, spring, and summer issue. The journal consists of three sections; scientific articles, opinion articles, and commentaries. As of this year, ALF also creates a section for inaugural speeches. In addition, ALF hosts a conference in spring with a relevant legal theme, where renowned speakers are invited to share their perspectives. Overall, ALF is a topical journal that provides a platform for established scholars and young academics to share knowledge, opinions and experiences and to make contributions to the international law discourse. Staff, PhD students and master students who have written a very good thesis are invited to submit an article to ALF. What is learned in the cradle is carried to the tomb: we are looking forward to sharing your articles on our website!
Kripto paralar ekonomi ve finans dünyasında etkili bir rol oynamaya başladığından beri bu varlıklarla işlem yapan kişi ve kuruluşların ekonomik değeri haiz bu varlıkları koruması zorlaşmıştır. Merkezi bir otoriteye bağlı olmayan kripto paraların avantajları olduğu gibi dezavantajları da vardır. Kripto para birimleri normal bir banka kartı veya kredi kartı ile aynı yasal korumaya sahip olmadığından bu sistemin güvenlik zafiyetlerini bilen kötü niyetli kişiler teknolojinin yardımıyla kripto para dolandırıcılığı yapabilmektedir. Kripto para birimlerinin kendine özgü bir varlık değerinin bulunması ve uçtan uca şifreleme yöntemi ile aracı olmaksızın transfer edilebilme imkanı, kişilere önemli avantajlar sağlarken sanal para arzlarıyla, fidye yazılımlarla, phishing tuzakları ile ponzi şeması yöntemi veya internet ve sosyal medya reklamları ile kripto para dolandırıcılığı işlenebilmektedir. Çalışmamızda kripto para dolandırıcılığı suçuyla nasıl mücadele edileceği ve mevcut düzenlemelerle mukayese edildiğinde sanal ortamda icra edilen fiillerin hangi suçlara sebebiyet vereceği tartışılarak kripto para dolandırıcılığının ne şekilde işlendiği ve bu konuda nelere dikkat edilmesi gerektiği üzerinde durulacaktır.
Blockchain systems afford new privacy capabilities. This threatens to create conflict, as different social groups involved in blockchain development often disagree on which capabilities specific systems should enact. This article adopts a boundary object perspective to make sense of disagreements between collaborating social worlds. We perform a case study of privacy attitudes among collaborating actors in Monero, a cryptocurrency community that emphasises privacy and decentralisation alongside a set of values sometimes described as anti-establishment, crypto-anarchist, and/or cypherpunk. The case study performs a series of interviews with users, developers, cryptographic researchers, corporate architects, and government regulators. Three novel and important findings emerge. The first is that none of the social worlds express a desire to monitor routine transactions, despite the obvious business and tax-collection value of such data. The second is that regulators are happy to postpone active involvement, based on the flawed assumption they can impose privacy-related regulation later, once risks have become clear. Such regulation may not be possible as protocols and rulesets currently being coded into the system may be impossible to amend in the future (unless they can obtain either developer or network consensus). The third is that regulators assume methods for overseeing extraordinary transaction are necessary to avoid widespread, near-effortless money laundering. Yet, each of the other social worlds is operating under the assumption that this trade-off has already been accepted. These findings demonstrate subtle power transitions and changes in privacy attitudes that have implications for research on blockchain, management, and boundary objects in general.
The immutability of blockchains and the transparency of their transaction records would appear to limit the benefit of exploiting them for criminal activity. However, blockchains also offer a high degree of anonymity, similar to fiat paper currency; the technology was intended to facilitate trustless transactions. Coupled with a global, borderless reach, blockchains have become an enabler of cybercrime. They are a new class of assets that, like all other assets, possess security risks and become potential targets of attack. In particular, cryptocurrencies, which depend on blockchain technology, provide significant incentives for attack because of their value. The goals of this chapter are to identify and classify blockchain-based cybercrimes and to explore the avenues for protecting against them at individual, organizational, and policy levels.
The financial crime landscape is evolving along with the digitization in financial services. In this context, laws and regulations cannot efficiently cope with a fast-moving industry such as finance, which translates in late adoption of measures and legal voids, providing a fruitful landscape for malicious actors. In parallel, blockchain technology and its promising features such as immutability, verifiability, and authentication, enhance the opportunities of financial forensics. In this paper, we focus on an embezzlement scheme and we provide a forensic-by-design methodology for its investigation. In addition, the feasibility and adaptability of our approach can be extended and embrace digital investigations on other types of schemes. We provide a functional implementation based on smart contracts and we integrate standardised forensic flows and chain of custody preservation mechanisms. Finally, we discuss the benefits and challenges of the symbiotic relationship between blockchain and financial investigations, along with future research directions.
Today, people are going to senior managers in almost all industries pitching about their “I have a new product” thing. Disruptive technology transforms a differentiated product that was so expensive and sometimes complicated or sophisticated into a simplified implementation with the applicability of APIs. APIs provide a platform where startup companies can be nitrated to a giant and established companies. Secondly, it changes the business ecosystem to suit all kinds of players small or big. In previous years, only major companies with a lot of resources had access to such technologies. This selfish access to new technologies would make such giants flourish like Amazon, eBay, Google. Blockchain is a form of distributed ledger technology gaining significant research devotion in numerous areas cutting across e-commerce, cryptocurrency, cryptography, logistics, security, finance, and now it is gaining grounds in e-commerce, big data, and internet of things. This chapter introduces the concept of blockchain, applications, and benefits it possesses in various fields related to e-commerce.
Since its inception in 2009, Bitcoin has been mired in controversies for providing a haven for illegal activities. Several types of illicit users hide behind the blanket of anonymity. Uncovering these entities is key for forensic investigations. Current methods utilize machine learning for identifying these illicit entities. However, the existing approaches only focus on a limited category of illicit users. The current paper proposes to address the issue by implementing an ensemble of decision trees for supervised learning. More parameters allow the ensemble model to learn discriminating features that can categorize multiple groups of illicit users from licit users. To evaluate the model, a dataset of 2059 real-life entities on Bitcoin was extracted from the Blockchain. Nine features were engineered to train the model for segregating 28 different licit-illicit categories of users. The proposed model provided a reliable tool for forensic study. Empirical evaluation of the proposed model vis-a-vis three existing benchmark models was performed to highlight its efficacy. Experiments showed that the specificity and sensitivity of the proposed model were comparable to other models.
Purpose The purpose of this study is to describe the opportunities and limitations of cryptocurrencies as a tool for money laundering through six currently available “open doors” (exchange mechanisms). The authors link the regulatory dialectic paradigm to know your customer and anti-money laundering evasion techniques, highlight six tactics to launder funds with virtual assets and investigate potential law enforcement and regulatory alternates used to reduce the incidence of money laundering with digital coins. Design/methodology/approach The methodology used is the analysis of significant recent events and the availability of “fintech” crime-fighting tools and a literature review focusing on the application of the regulatory dialectic to innovations in existing crypto-asset markets that make them compelling to money launderers. Findings The authors examine the illicit use of cryptocurrency through Kane’s regulatory dialectic paradigm, identify a number of avenues for crypto to fiat exchange that are still available for those seeking to launder money using digital coins, review recently “closed doors” and make recommendations regarding the regulation of crypto-related markets that may assist in making them less desirable for potential criminals. Research limitations/implications The research is constrained by the state of the market for crypto to fiat exchange as of time of writing; the technology and products to launder money using these open doors is continually changing (as predicted by the regulatory dialectic). Social implications The regulatory dialectic predicts that regulatory response is reactive and often increasingly burdensome or oppressive. There is continuous innovation in the cryptocurrency market, which seeks to preserve privacy and anonymity with which regulators seek to keep up. From a social perspective, the response of bank regulators worldwide to existing open doors for crypto to fiat exchange used for money laundering may prove costly to individuals engaging in legitimate transactions, as well as financial criminals and may also erode the ability of individuals to maintain privacy regarding their financial information. Originality/value To the authors’ knowledge, there are yet no broad overview regarding the feasibility of money laundering across crypto-related assets within the paradigm of the regulatory dialectic.
In Proof-of-Work Blockchain-based systems, the ledger is kept consistent through some participants solving cryptopuzzles, usually referred to as block mining. Conventional wisdom asserts that the mining protocol is incentive-compatible. However, whether some strategic mining behaviors occur in practice or not, has been the subject of extensive debate. In this paper, we target this question by detecting anomalies in the statistics of consecutive blocks among several popular cryptocurrency systems. Firstly, we measure the inequality of mining revenue distribution in each system. Secondly, we propose a statistical method to identify the selfish mining (SM) behavior, a mining attack strategy posited by Eyal and Sirer in 2014. Our method is based on abnormal (statistically significant) high probability of continuously mining blocks. Finally, we extend our method to detect the mining cartels, in which miners secretly get together and share information about newly mined blocks. Our analysis will contribute to the research of fairness in cryptocurrency mining by providing evidence that the aforementioned strategic mining behaviors do take place in practice.
Summary Blockchain users are identified by addresses (public keys), which cannot be easily linked back to them without out‐of‐network information. This provides pseudo‐anonymity, which is amplified when the user generates a new address for each transaction. Since all transaction history is visible to all users in public blockchains, finding affiliation between related addresses undermines pseudo‐anonymity. Such affiliation information can be used to discriminate against addresses linked with undesired activities or can lead to de‐anonymization if out‐of‐network information becomes available. In this work, we propose an approach to undermine pseudo‐anonymity of blockchain transactions by linking together addresses that were used to deploy smart contracts, which were produced by the same authors. In our approach, we leverage stylometry techniques, widely used in the social science field for attribution of literary texts to their corresponding authors. The assumption underlying authorship attribution is the existence of a distinctive writing style, unique to an author and easily distinguishable from others. Drawing an analogy between literary text and smart contracts' source code, we explore the extent to which unique features of source code and byte code of Ethereum smart contracts can represent the coding style of smart contract developers. We show that even a small number of representative features leads to a sufficiently high accuracy in attributing smart contracts' code to its deployer's address. We further validate our approach on real‐world scammers' data and Ponzi scheme‐related contracts. Additionally, we provide an algorithm to extract distinctly contributing features per an entire dataset or per specific authors. We use this algorithm to extract and explore such features in our dataset and in the Ponzi scheme‐related dataset.