Emre Ateş, Ozan Tuncer, Ata Türk, Vitus J. Leung · 7 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,265 results · page 51 of 53
Emre Ateş, Ozan Tuncer, Ata Türk, Vitus J. Leung · 7 authors
No abstract is available for this record.
Yuan Cao, Yuan Gao, Rongjun Tan, Qingbang Han · 5 authors
Defending against distributed denial of service (DDoS) attacks in the Internet is a fundamental problem. One practical approach to addressing DDoS attacks is to redirect all destination (e.g., via DNS or BGP) to a third-party, DDoS protection-as-a-service provider (e.g., Cloudflare and Akamai), which is well provisioned and equipped with proprietary filtering mechanisms to remove attack traffic before passing the remaining traffic to the destination. Although such an approach is appealing, as it requires no modification to the existing Internet infrastructure and can scale to handle very large attacks, recent industrial interviews with more than 100 interviewees from over 10 industry segments reveal that this approach alone is not sufficient, especially for large organizations (e.g., Web hosting companies and government) that cannot afford to allow third-parity security-service providers to terminate their network connections. Instead, these organizations have to rely on their ISPs to filter attack traffic. In this paper, we discuss the challenges faced by the ISPs in order to disrupt the Internet security-service market and sketch our solutions, powered by smart contracts.
Hoang-Long Nguyen, Jean-Philippe Eisenbarth, Claudia‐Lavinia Ignat, Olivier Perrin
No abstract is available for this record.
Léo Mendiboure, Mohamed Aymen Chalouf, Francine Krief
No abstract is available for this record.
Hoang-Long Nguyen, Claudia‐Lavinia Ignat, Olivier Perrin
Public key server is a simple yet effective way of key management in secure end-to-end communication. To ensure the trustworthiness of a public key server, transparent log systems such as CONIKS employ a tamper-evident data structure on the server and a gossiping protocol among clients in order to detect compromised servers. However, due to lack of incentive and vulnerability to malicious clients, a gossiping protocol is hard to implement in practice. Meanwhile, alternative solutions such as EthIKS are not scalable. This paper presents Trusternity, an auditing scheme relying on Ethereum blockchain that is easy to implement, scalable and inexpensive to operate.
Song Li, Scott A Wu
No abstract is available for this record.
Oleh Stanislavovych Savenko
The work out the developed method of interaction of components of distributed multi-level system of detection of malicious software on the basis of decentralized and self-organized architecture in local networks. Its feature is the synthesis of its requirements of distribution, decentralization, multilevel and self-organization. This allows you to use it autonomously. The basis of the distributed distributed system is its structural components, which are represented by autonomous software modules that can be in different states. The transition between module states is based on a defined set of transitions. Interaction and communication between autonomous software modules is based on their presence in certain states during operation and is determined by the rules of the developed method. Distributed system is a responsive system that will monitor selected events. Each program module places a resident mechanism, the motive mechanisms for the transition between states, the transitions between which are given by subsets of transitions, the data for which will be formed using the technologies of artificial intelligence. In addition, the feature of the components of the system is the same organization, which allows the exchange of knowledge in the middle of the system, which, unlike the known systems, allows us to use the knowledge gained by separate parts of our system in other parts. The developed system allows to fill it with subsystems of detection of various types of malicious software in local area networks. The method of interaction of components of a distributed multilevel detection system of malicious software provides a procedure for communication between parts of the system and the exchange of knowledge between them. It will be used to organize the interaction of system components and maintain its integrity. In order to solve the problem of the direct detection of malicious software in local area networks, methods will be applied that will be applied to the lower level of the system, which will include the architectural features of the distributed system and the technology of detecting the malicious software-based software. However, the developed method of interaction includes the ability to determine the state of a distributed multi-level system, depending on the states of individual modules, and on its basis, in accordance with it will be decided on the further operation of the system as a whole and its configuration. The method regulates the actions of the part of the system that relates to the bundling software of the distributed system. The conducted experiments on the use of the developed distributed system showed the possibility of attracting to the detection of the malicious software of computing power of 78 # 24 (2018) other hosts of the local network. The obtained results of experiments show an increase in the reliability of the detection of malicious software.
Tomer Golomb, Yisroel Mirsky, Yuval Elovici
Due to their rapid growth and deployment, Internet of things (IoT) devices have become a central aspect of our daily lives. However, they tend to have many vulnerabilities which can be exploited by an attacker. Unsupervised techniques, such as anomaly detection, can help us secure the IoT devices. However, an anomaly detection model must be trained for a long time in order to capture all benign behaviors. This approach is vulnerable to adversarial attacks since all observations are assumed to be benign while training the anomaly detection model.
Baokun Zheng, Liehuang Zhu, Meng Shen, Xiaojiang Du · 10 authors
No abstract is available for this record.
Indra Deep Mastan, Souradyuti Paul
Mounting deanonymization attacks on the unreachable Bitcoin nodes – these nodes do not accept incoming connections – residing behind the NAT is a challenging task. Such an attack was first given by Biryukov, Khovratovich and Pustogarov based on their observation that a node can be uniquely identified in a single session by their directly-connected neighbouring nodes (ACM CCS’15). However, the BKP15 attack is less effective across multiple sessions. To address this issue, Biryukov and Pustogarov later on devised a new strategy exploiting certain properties of address-cookies (IEEE S&P’15). Unfortunately, the BP15 attack is also rendered ineffective by the present modification to the Bitcoin client.
Νικόλαος Αλεξόπουλος, Emmanouil Vasilomanolakis, Natália Réka Ivánkó, Max Mühlhäuser
No abstract is available for this record.
Chul‐Jin Kim
No abstract is available for this record.
Jingjing Gu, Binglin Sun, Xiaojiang Du, Jun Wang · 6 authors
To address the problem of detecting malicious codes in malware and extracting the corresponding evidences in mobile devices, we construct a consortium blockchain framework, which is composed of a detecting consortium chain shared by test members and a public chain shared by users. Specifically, in view of different malware families in Android-based system, we perform feature modeling by utilizing statistical analysis method, so as to extract malware family features, including software package feature, permission and application feature, and function call feature. Moreover, for reducing false-positive rate and improving the detecting ability of malware variants, we design a multi-feature detection method of Android-based system for detecting and classifying malware. In addition, we establish a fact-base of distributed Android malicious codes by blockchain technology. The experimental results show that, compared with the previously published algorithms, the new proposed method can achieve higher detection accuracy in limited time with lower false-positive and false-negative rates.
Ralph Deters
No abstract is available for this record.
Weizhi Meng, Elmar Tischhauser, Qingju Wang, Yu Wang · 5 authors
With the purpose of identifying cyber threats and possible incidents, intrusion detection systems (IDSs) are widely deployed in various computer networks. In order to enhance the detection capability of a single IDS, collaborative intrusion detection networks (or collaborative IDSs) have been developed, which allow IDS nodes to exchange data with each other. However, data and trust management still remain two challenges for current detection architectures, which may degrade the effectiveness of such detection systems. In recent years, blockchain technology has shown its adaptability in many fields, such as supply chain management, international payment, interbanking, and so on. As blockchain can protect the integrity of data storage and ensure process transparency, it has a potential to be applied to intrusion detection domain. Motivated by this, this paper provides a review regarding the intersection of IDSs and blockchains. In particular, we introduce the background of intrusion detection and blockchain, discuss the applicability of blockchain to intrusion detection, and identify open challenges in this direction.
Arif Sarı, Seyfullah Kilic
Collection of intelligence is one of the key elements to organize more sophisticated methods of attacks. Open Source Intelligence (OSINT) is a technique used by attackers for reconnaissance purposes to gather information about specific targets. The accessibility to critical information about emerging systems through OSINT leads exposure of vulnerabilities and exploitation of these vulnerabilities to form widespread attack. Blockchain is one of the emerging technologies that exposed the use of crypto currencies such as Bitcoin and Ethereum. This research paper explains the use of OSINT to gather critical information about cryptocurrency miners such as Bitcoin Antminer and Ethereum Claymore and expose the vulnerabilities to exploit the configuration file of the miner manager. The research outcomes expose the vulnerability of the existing crypto currencies and use of OSINT for detection and analysis of cyberthreat in crypto currency market.
Abdellah Ouaguid, Noreddine Abghour, Mohammed Ouzzif
This article presents a new framework named ANDROSCANREG (Android Permissions Scan Registry) that allows to extract and analyze the requested permissions in an Android application via a decentralized and distributed system. This framework is based on the emerging technology Blockchain whose potential is approved in the matter of transparency, reliability, security and availability without resorting to a central processing unit judged of trust. ANDROSCANREG consists of two Blockchains, the first one (PERMBC) will handle analysis, validation and preparation of the raw results so that they will persist in the second Blockchain of Bitcoin already existing (BTCBC), which will assume the role of a Registry of recovered permissions and will save the permissions history of each version of the applications being scanned via financial transactions, whose wallet source, recipient wallet and transaction value have a precise meaning. An example of a simulation will be presented to describe the different steps, actors, interactions and messages generated by the different entity of ANDROSCANREG.
A. Cimitile, Francesco Mercaldo, Vittoria Nardone, Antonella Santone · 5 authors
No abstract is available for this record.
Beltran Fiz, Stefan Hommes, Radu State
No abstract is available for this record.
J.A. Gómez-Hernández, L. Álvarez-González, Pedro García‐Teodoro
No abstract is available for this record.
Christos Tselios, Ilias Politis, Stavros Kotsopoulos
The majority of business activity of our integrated and connected world takes place in networks based on cloud computing infrastructure that cross national, geographic and jurisdictional boundaries. Such an efficient entity interconnection is made possible through an emerging networking paradigm, Software Defined Networking (SDN) that intends to vastly simplify policy enforcement and network reconfiguration in a dynamic manner. However, despite the obvious advantages this novel networking paradigm introduces, its increased attack surface compared to traditional networking deployments proved to be a thorny issue that creates skepticism when safety-critical applications are considered. Especially when SDN is used to support Internet-of-Things (IoT)-related networking elements, additional security concerns rise, due to the elevated vulnerability of such deployments to specific types of attacks and the necessity of inter-cloud communication any IoT application would require. The overall number of connected nodes makes the efficient monitoring of all entities a real challenge, that must be tackled to prevent system degradation and service outage. This position paper provides an overview of common security issues of SDN when linked to IoT clouds, describes the design principals of the recently introduced Blockchain paradigm and advocates the reasons that render Blockchain as a significant security factor for solutions where SDN and IoT are involved.
Ramiro Daniel Camino, Radu State, Leandro Montero, Petko Valtchev
Banks and financial institutions around the world must comply with several policies for the prevention of money laundering and in order to combat the financing of terrorism. Nowadays, there is a raise in the popularity of novel financial technologies such as digital currencies, social trading platforms and distributed ledger payments, but there is a lack of approaches to enforce the aforementioned regulations accordingly. Software tools are developed to detect suspicious transactions usually based on knowledge from experts in the domain, but as new criminal tactics emerge, detection mechanisms must be updated. Suspicious activity examples are scarce or nonexistent, hindering the use of supervised machine learning methods. In this paper, we describe a methodology for analyzing financial information without the use of ground truth. A user suspicion ranking is generated in order to facilitate human expert validation using an ensemble of anomaly detection algorithms. We apply our procedure over two case studies: one related to bank fund movements from a private company and the other concerning Ripple network transactions. We illustrate how both examples share interesting similarities and that the resulting user ranking leads to suspicious findings, showing that anomaly detection is a must in both traditional and modern payment systems.
Bruno Rodrigues, Thomas Bocek, Burkhard Stiller
No abstract is available for this record.
Andrea Pinna, Roberto Tonelli, Matteo Orrù, Michele Marchesi
A Blockchain is a global shared infrastructure where cryptocurrency transactions among addresses are recorded, validated and made publicly available in a peer-to-peer network. To date, the best known and important cryptocurrency is the bitcoin. In this paper, we focus on this cryptocurrency and in particular on the modeling of the Bitcoin Blockchain by using the Petri Nets formalism. The proposed model allows us to quickly collect information about identities owning Bitcoin addresses and to recover measures and statistics on the Bitcoin network. By exploiting algebraic formalism, we reconstructed an Entities network associated to Blockchain transactions gathering together Bitcoin addresses into the single entity holding permits to manage Bitcoins held by those addresses. The model allows also to identify a set of behaviors typical of Bitcoin owners, like that of using an address only once, and to reconstruct chains for this behavior together with the rate of firing. Our model is highly flexible and can easily be adapted to include different features of the Bitcoin cryptocurrency system. By exploiting algebraic formalism, we reconstructed an Entities network associated to Blockchain transactions gathering together Bitcoin addresses into the single entity holding permits to manage Bitcoins held by those addresses. The model allows also to identify a set of behaviors typical of Bitcoin owners, like that of using an address only once, and to reconstruct chains for this behavior together with the rate of firing. Our model is highly flexible and can easily be adapted to include different features of the Bitcoin cryptocurrency system.