Bitcoin-NG, a scalable blockchain protocol, divides each block into a key block and many micro blocks to effectively improve the transaction processing capacity. Bitcoin-NG has a special incentive mechanism (i.e. splitting transaction fees to the current and the next leader) to maintain its security. However, this design of the incentive mechanism ignores the joint effect of transaction fees, mint coins and mining duration lengths on the expected mining reward. In this paper, we identify the advanced mining attack that deliberately ignores micro blocks to enlarge the mining duration length to increase the likelihood of winning the mining race. We first show that an advanced mining attacker can maximize its expected reward by optimizing its mining duration length. We then formulate a game-theoretical model in which multiple mining players perform advanced mining to compete with each other. We analyze the Nash equilibrium for the mining game. Our analytical and simulation results indicate that all mining players in the mining game converge to having advanced mining at the equilibrium and have no incentives for deviating from the equilibrium; the transaction processing capability of the Bitcoin-NG network at the equilibrium is decreased by advanced mining. Therefore, we conclude that the Bitcoin-NG blockchain protocol is vulnerable to advanced mining attack. We discuss how to reduce the negative impact of advanced mining for Bitcoin-NG.
In last decades' web application security has become one of the most important case study of information security studies. Business processes are transferred to web platforms. So web application usage is increased very fast. Web-based attacks have also increased due to the increased use of web applications. In order to ensure the security of web applications, intrusion detection and prevention systems and web application firewalls are used against web based attacks. Blockchain technology, which has become popular in recent years, enables reliable and transparent sharing of data with all stakeholders. In this study, in order to detect web-based attacks, a blockchain based web attack detection model that uses the signature based detection method is proposed. The signature based detection refers to the detection of attacks by looking for specific patterns against known web based attack types, such as Structured Query Language (SQL) Injection, Cross Site Scripting (XSS), Command Injection. Three web servers were used for the experimental study. A blockchain node has been installed with the MultiChain application for each server. Attacks on web applications are detected using the signature list found in the web application as well as detected using the signature list updated on the blockchain. According to the experimental results, the attacks signature detected and defined by a web application are updated in the blockchain lists and used by all web applications.
Cybercriminals exploit cryptocurrencies, such as Bitcoin, to carry out
various illicit activities. In this paper, we focus on Ponzi schemes that
operate on Bitcoin and perform an in-depth analysis of MMM, one of the oldest
and most popular Ponzi schemes. Based on 423K transactions involving 16K
addresses, we show that: (1) Starting Sep 2014, the scheme goes through three
phases over three years. At its peak, MMM circulated more than 150M dollars a
day, after which it collapsed by the end of Jun 2016. (2) There is a high
income inequality among MMM members, with the daily Gini index reaching more
than 0.9. The scheme also exhibits a zero-sum investment model, in which one
member's loss is another member's gain. The percentage of victims who never
made any profit has grown from 0% to 41% in five months, during which the
top-earning scammer has made 765K dollars in profit. (3) The scheme has a
global reach with 80 different member countries, but a highly-asymmetrical flow
of money between them. While India and Indonesia have the largest pairwise flow
in MMM, members in Indonesia have received 12x more money than they have sent
to their counterparts in India.
Maurantonio Caprolu, Simone Raponi, Gabriele Oligeri, Roberto Di Pietro
Cryptojacking occurs when an adversary illicitly runs crypto-mining software over the devices of unaware users. This novel cybersecurity attack, that is emerging in both the literature and in the wild, has proved to be very effective given the simplicity of running a crypto-client into a target device. Several countermeasures have recently been proposed, with different features and performance, but all characterized by a host-based architecture. The cited solutions, designed to protect the individual user, are not suitable for efficiently protecting a corporate network, especially against insiders. In this paper, we propose a network-based approach to detect and identify crypto-clients activities by solely relying on the network traffic, even when encrypted and mixed with non-malicious traces. First, we provide a detailed analysis of the real network traces generated by three major cryptocurrencies, Bitcoin, Monero, and Bytecoin, considering both the normal traffic and the one shaped by a VPN. Then, we propose Crypto-Aegis, a Machine Learning (ML) based framework built over the results of our investigation, aimed at detecting cryptocurrencies related activities, e.g., pool mining, solo mining, and active full nodes. Our solution achieves a striking 0.96 of F1-score and 0.99 of AUC for the ROC, while enjoying a few other properties, such as device and infrastructure independence. Given the extent and novelty of the addressed threat we believe that our approach, supported by its excellent results, pave the way for further research in this area.
Masarah Paquet-Clouston, Matteo Romiti, Bernhard Haslhofer, Thomas Charvat
In the past year, a new spamming scheme has emerged: sexual extortion messages requiring payments in the cryptocurrency Bitcoin, also known as sextortion. This scheme represents a first integration of the use of cryptocurrencies by members of the spamming industry. Using a dataset of 4,340,736 sextortion spams, this research aims at understanding such new amalgamation by uncovering spammers' operations. To do so, a simple, yet effective method for projecting Bitcoin addresses mentioned in sextortion spams onto transaction graph abstractions is computed over the entire Bitcoin blockchain. This allows us to track and investigate monetary flows between involved actors and gain insights into the financial structure of sextortion campaigns. We find that sextortion spammers are somewhat sophisticated, following pricing strategies and benefiting from cost reductions as their operations cut the upper-tail of the spamming supply chain. We discover that one single entity is likely controlling the financial backbone of the majority of the sextortion campaigns and that the 11-month operation studied yielded a lower-bound revenue between $1,300,620 and $1,352,266. We conclude that sextortion spamming is a lucrative business and spammers will likely continue to send bulk emails that try to extort money through cryptocurrencies.
Illicit crypto-mining leverages resources stolen from victims to mine cryptocurrencies on behalf of criminals. While recent works have analyzed one side of this threat, i.e.: web-browser cryptojacking, only commercial reports have partially covered binary-based crypto-mining malware.
Cryptocurrencies have embraced Twitter as a major channel of communication. Employing social network analysis and sentiment analysis, this study investigates the Twitter-mediated communication behaviors among cryptocurrencies. This study determines whether a significant association exists between cryptocurrencies' Twitter networks and their credit scores. Data were drawn from the Twitter pages of several top cryptocurrencies. The results indicate that reply-mention networks had the densest structure, that the following-follower network structure was correlated with the reply-mention structure, and that the reply-mention and co-tweet networks were positively correlated. The results also indicate that cryptocurrencies' active networking strategies affected their credit scores and more importantly, that cryptocurrencies frequently linked with fellow currencies tended to have high credit scores.
Rima Rana, Razieh Nokhbeh Zaeem, K. Suzanne Barber
Personally Identifiable Information (PII) is often used to perform authentication and acts as a gateway to personal and organizational information. One weak link in the architecture of identity management services is sufficient to cause exposure and risk identity. Recently, we have witnessed a shift in identity management solutions with the growth of blockchain. Blockchainâthe decentralized ledger systemâprovides a unique answer addressing security and privacy with its embedded immutability. In a blockchain-based identity solution, the user is given the control of his/her identity by storing personal information on his/her device and having the choice of identity verification document used later to create blockchain attestations. Yet, the blockchain technology alone is not enough to produce a better identity solution. The user cannot make informed decisions as to which identity verification document to choose if he/she is not presented with tangible guidelines. In the absence of scientifically created practical guidelines, these solutions and the choices they offer may become overwhelming and even defeat the purpose of providing a more secure identity solution.
Kirsten Cremona, Donald Tabone, Clifford De Raffaele
The fight against child pornography on the Internet is difficult due to the inability of controlling the dissemination of content. While the cryptocurrency applications of a blockchain, such as Bitcoin, primarily store financial data in blockchain transactions, numerous approaches to arbitrarily insert other types of data are possible, including content in the form of readable text and images. Thus, considering the blockchain principles of decentralization, immutability, censorship resistance, and net neutrality, we are suddenly presented with a set of new challenges for mitigating the storage and distribution of illicit and potentially illegal data. Such a novel cybersecurity threat requires an adequate solution within a decentralized paradigm. In stark contrast to the countermeasures proposed in literature for filtering out illicit content from other legitimate data, this study proposes the first appropriately designed solution for effectively mitigating these threats whilst maintaining fidelity to the underlying core principles of the blockchain. Through the designed approach, arbitrary images in blockchain transactions are detected, and whilst leveraging an off-chain content filtering service, successful discrimination is achieved between clean and illicit embedded data. The proposed methodology was evaluated directly on the Bitcoin blockchain, successfully demonstrating a pioneering and viable approach for thwarting the insertion of child pornography images. The presented solution within this research is made available on GitHub [1] for open-source use.
A blockchain database containing files regarding transactions of cryptocurrency is sometime vulnerable to double spending attack. This type of attack pertains to a coin being spent more in more that one transaction in the network. This paper is motivated by a goal to create a blockchain that can withstand double spending attacks. This way, honest miners will be able to safely and securely exchange cryptocurrency. There currently lack valuable prevention methods in the network therefore we designed a novel countermeasure to combat double spending attacks on the blockchain system. We proposed the MSP (Multistage Secure Pool) framework in order to address the vulnerabilities on the blockchain. This was designed to handle both discrete and general issues that affect the overall security of the blockchain. Our evaluation using this application shows that there was a decrease in the amount of attacks propagating through the system based on our system's robustness and capabilities. We also present machine learning capabilities of the system in our study in order to enable a progressive aspect to the design. Providing our application with the ability to analyze data in order to recognize and classify distinct actions will enable for greater comprehension. An application that learns, updates and configures to meet specified defensive standards present key design features which enables for greater understanding and future analysis of the overall blockchain network.
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Steganography and Watermarking Techniques
Chinnapong Angsuchotmetee, Pisal Setthawong, Sapjarern Udomviriyalanon
Voting is an essential activity in the modern democracy. To facilitate the voting process, there are several attempts on proposing an electronic voting system such that, the voting and tallying processes can be done efficiently and the results would be accountable to the public. To date, however, an online electronic voting system has been rarely adopted in practice due to the possibility of having the voting result tampered through vote-rigging or cyber-attacking. In 2009, the blockchain algorithm was proposed by Satoshi Nakamoto. Blockchain is a technique for recording transactions between self-auditing ledgers in an open, distributed, permanent, and verifiable manner. Even though blockchain was originally designed for a financial applications, it is possible to apply blockchain to other domains, including in the implementation of an online decentralized-based electronic voting system. In this study, the architecture of a blockchain-based electronic voting system, named \textit{BlockVOTE}, is proposed. The architecture design and all related formal definitions are given. To validate the proposal, two BlockVOTE prototypes were implemented using two different blockchain application frameworks. The performance analysis of both versions of the prototypes are given. The analysis of both technical and management aspects on the possibility of adopting the proposed decentralized voting system in an actual voting scenario is also given at the end of this study.
Internet is a common method of trading business today. The usage of cryptocurrencies has increased these days and it has become a trend to utilize them. Cryptocurrency exchange servicers provide different smartphone apps that unfortunately may become the target of malicious attacks. This paper focuses on how it achieves highest security and proposes the multiple layered security analyses method for cryptocurrency exchange servicers.
Blockchain users are identified by addresses (public keys), which cannot be easily linked back to them without out-of-network information. This provides pseudo-anonymity, which is amplified when the user generates a new address for each transaction. Since all transaction history is visible to all users in public blockchains, finding affiliation between related addresses can hurt pseudo-anonymity. Such affiliation information can be used to discriminate against addresses that were found to be related to a specific group, or can even lead to the de-anonymization of all addresses in the associated group, if out-of-network information is available on a few addresses in that group. In this work we propose to leverage a stylometry approach on Ethereum's deployed smart contracts' bytecode and high level source code, which is publicly available by third party platforms. We explore the extent to which a deployed smart contract's source code can contribute to the affiliation of addresses. To address this, we prepare a dataset of real-world Ethereum smart contracts data, which we make publicly available; design and implement feature selection, extraction techniques, data refinement heuristics, and examine their effect on attribution accuracy. We further use these techniques to test the classification of real-world scammers data.
In recent years, illegal activities such as money laundering using cryptocurrency represented by bitcoin have been emerging. The anonymity, two-way convertibility and transnational of bitcoin are used to "launder" illegal income. Some bitcoin theft incidents are also associated with money laundering. Hackers "launder" the stolen bitcoins and eventually convert them into legal property. In this paper, we explore whether these illegal activities can be detected. First, we mine the user characteristics from the original transaction data of bitcoin. Second, the user characteristics are classified to distinguish normal users from abnormal users. Third, Gaussian Mixture Model is used to cluster users to find suspicious users. Finally, we detect the abnormal transactions among the suspicious users.
Jianwei Liao, Tsung-Ta Tsai, Chia-Kang He, ChinâWei Tien
Blockchain has flourished in recent years. As a decentralized system architecture, smart contracts give the blockchain a user-defined logical concept. The smart contract is an executable program that can be used for automatic transactions on the Ethereum blockchain. In 2016, the DAO attack resulted in the theft of 60M USD due to unsafe smart contracts. Smart contracts are vulnerable to hacking because they are difficult to patch and there is a lack of assessment standards for ensuring their quality. Hackers can exploit the vulnerabilities in smart contracts when they have been published on Ethereum. Thus, this study presents SoliAudit (Solidity Audit), which uses machine learning and fuzz testing for smart contract vulnerability assessment. SoliAudit employs machine learning technology using Solidity machine code as learning features to verify 13 kinds of vulnerabilities, which have been listed as Top 10 threats by an open security organization. We also created a gray-box fuzz testing mechanism, which consists of a fuzzer contract and a simulated blockchain environment for on-line transaction verification. Different from previous research systems, SoliAudit can detect vulnerabilities without expert knowledge or predefined patterns. We subjected SoliAudit to real-world evaluation by using near 18k smart contracts from the Ethereum blockchain and Capture-the-Flag samples. The results show that the accuracy of SoliAudit can reach to 90% and the fuzzing can help identify potential weaknesses, including reentrancy and arithmetic overflow problems.
The term âsmart contractsâ has become ubiquitous to describe an enormous number of programs uploaded to the popular Ethereum blockchain system. Despite rapid growth of the smart contract ecosystem, errors and exploitations have been constantly reported from online contract systems, which has put financial stability at risk with losses totaling millions of US dollars. Most existing research focuses on pinpointing specific types of vulnerabilities using known patterns. However, due to the lack of awareness of the inherent nondeterminism in the Ethereum blockchain system and how it affects the funds transfer of smart contracts, there can be unknown vulnerabilities that may be exploited by attackers to access numerous online smart contracts. \n \nIn this paper, we introduce a methodical approach to understanding the inherent nondeterminism in the Ethereum blockchain system and its (unwanted) influence on contract payments. We show that our new focus on nondeterminism-related smart contract payment bugs captures the root causes of many common vulnerabilities without relying on any known patterns and also encompasses recently disclosed issues that are not handled by existing research. To do so, we introduce techniques to systematically model components in the contract execution context and to expose various nondeterministic factors that are not yet fully understood. We further study how these nondeterministic factors impact contract funds transfer using information flow tracking. The technical challenge of detecting nondeterministic payments lies in discovering the contract global variables subtly affected by read-write hazards because of unpredictable transaction scheduling and external callee behavior. We show how to augment and instrument a contract program into a representation that simulates the execution of a large subset of the contract behavior. The instrumented code is then analyzed to flag nondeterministic global variables using off-the-shelf model checkers. \n \nWe implement the proposed techniques as a practical tool named NPChecker (Nondeterministic Payment Checker) and evaluate it on 30K online contracts (3,075 distinct) collected from the Ethereum mainnet. NPChecker has successfully detected nondeterministic payments in 1,111 online contracts with reasonable cost. Further investigation reports high precision of NPChecker (only four false positives in a manual study of 50 contracts). We also show that NPChecker unveils contracts vulnerable to recently-disclosed attack vectors. NPChecker can identify all six new vulnerabilities or variants of common smart contract vulnerabilities that are missed by existing research relying on a âcontract vulnerability checklist.â
Crowdfunding has revolutionized the way of raising funds for not only start-ups but for all traditional or existing businesses. Crowdfunding made it easy for fundraisers to raise funds as they donât have to knock on doors of banks and financers and get the desired amount in return of interest or offering equity or even through donation, or reward. Blockchain, on the hand, is decentralizing the system of records and control which makes crowdfunding more transparent and secure. Though a number of blockchain-based crowdfunding platforms are already doing good business and they vary in crypto, model and type of crowdfunding. The study is conducted on a very new blockchain-based crowdfunding platform, WHIRL. The unique and different in this model is the model, âpay-it-forwardâ itself. The model assures that members will get their legit project funded after they help other projects succeed. The study also highlights some thoughts from the Executive Board of Directors and co-founders after doing a brief discussion with them.
Proof of work and proof of stake (PoS) are commonly used in the current permissionless blockchains. These consensus protocols can be abstracted into a random process of selecting a node for accounting in a blockchain ledger. However, they are generally faced with resource consumption and vulnerability issues. We present proof of credit (PoC), a fair blockchain protocol based on the PoC blockchain protocol. It is a special PoS protocol where the credit is a special kind of stake quantifying whether the node's activity is beneficial to the system. Any nodes cannot change their credits arbitrarily. We demonstrate that our PoC protocol satisfies the security properties, including common prefix, chain quality, and chain growth, under the assumption that the total credit the honest held is majority. In addition, we propose a self-audit mechanism and a hybrid incentive mechanism to enhance the security and stability. Finally, we explain the method by which the PoC protocol resists the double-spending attacks and the selfish mining attacks.
This chapter explores the threats that malware, specifically, botnets pose to the mining of cryptocurrencies. The reader will be introduced to the history of botnet-inspired threats, operational mechanisms of botnets, and an in-depth look at significant botnets that have attacked cryptocurrencies. The chapter looks at countermeasures in terms of detection, prevention, and thwarting. It presents implications for growing cryptocurrency usage and therefore, increasing exposure to various security threats, both organized and unintentional, on botnet black markets, Internet-of-thing devices and from unsuspecting users. The chapter describes a general overview of the consensus operation in cryptomining and shows how threats to the consensus mechanisms could affect the cryptocurrency mining process. It provides an overview of the consensus mechanism in cryptomining and significant threats posed by botnets to the consensus mechanism.
Public software repositories such as GitHub make transparent the development history of an open source software system. Source code commits, discussions about new features and bugs, and code reviews are stored and carefully attributed to the appropriate developers. However, sometimes governments may seek to analyze these repositories, to identify citizens who contribute to projects they disapprove of, such as those involving cryptography or social media. While developers who seek anonymity may contribute under assumed identities, their body of public work may be characteristic enough to betray who they really are. The ability to contribute anonymously to public bodies of knowledge is extremely important to the future of technological and intellectual freedoms. Just as in security hacking, the only way to protect vulnerable individuals is by demonstrating the means and strength of available attacks so that those concerned may know of the need and develop the means to protect themselves. \n \nIn this work, we present a method to de-anonymize source code contributors based on the authors' intrinsic programming style. First, we present a partial replication study wherein we attempt to de-anonymize a large number of entries into the Google Code Jam competition. We base our approach on Caliskan-Islam et al. 2015, but with modifications to the feature set and modelling strategy for scalability and feature-selection robustness. We did not achieve 0.98 F1 achieved in this prior work, but managed a still reasonable 0.71 F1 under identical experimental conditions, and a 0.88 F1 given more data from the same set. \n \nSecond, we present an exploratory study focused on de-anonymizing programmers who have contributed to a repository, using other commits from the same repository as training data. We train random-forest classifiers using programmer data collected from 37 medium to large open-source repositories. Given a choice between active developers in a project, we were able to correctly determine authorship of a given function about 75% of the time, without the use of identifying meta-data or comments. We were also able to correctly validate a contributor as the author of a questioned function with 80\\% recall and 65\\% precision. This exploratory study provides empirical support for our approach. \n \nFinally, we present the results of a similar, but more difficult study wherein we attempt de-anonymize a repository in the same manner, but without using the target repository as training data. To do this, we gather as much training data as possible from the repository's contributors through the Github API. We evaluate our technique over 3 repositories: Bitcoin, Ethereum (crypto-currencies) and TrinityCore (a game engine). Our results in this experiment starkly contrast our results in the intra-repository study showing accuracies of 35% for Bitcoin, 22% for Ethereum, and 21% for TrinityCore which had candidate set sizes of 6, 5, and 7 respectively. \n \nOur results indicate that we can do somewhat better than random guessing, even under difficult experimental conditions, but they also indicate some fundamental issues with the state of the art of Code Stylometry. In this work we present our methodology, results, and some comments on past empirical studies, the difficulties we faced, and likely hurdles for future work in the area.
Ayman Alkhalifah, Alex Ng, A. S. M. Kayes, Jabed Chowdhury ¡ 6 authors
Blockchain technology has become one of the most popular technologies for maintaining digital transactions. From the foundation of Bitcoin to the now-predominant smart contract, blockchain technology promises to induce a shift in thought-about digital transactions in many fields, such as energy, healthcare, Internet of Things, cybersecurity, financial services, and the supply chain. Despite blockchain technology offering many cryptography advantages such as immutability, digital signature, and hashing, it has suffered from several critical cybersecurity threats and vulnerabilities. In this chapter, we build upon the previous studies on vulnerabilities and investigate over 60 real cybersecurity incidents that have been happening on the blockchain networks between 2009 and 2019. We categorize those incidents against the key cybersecurity vulnerabilities in blockchain technologies and have developed a taxonomy that captures five types of cybersecurity threats and vulnerabilities based on five main players in blockchain. The outcome of this research prompted concerns and research direction in developing countermeasures to alleviate these risks. Blockchain; Cybersecurity; Attack; Threat; Vulnerability; Taxonomy.
Dimitrios G. Kogias, Helen C. Leligou, Michael G. Xevgenis, Maria Polychronaki ¡ 8 authors
Crowdsourcing has been pursued as a way to leverage the power of the crowd for many different purposes in diverse sectors from collecting information, aggregating funds, and gathering employees to perform tasks of different sizes among other targets. Data integrity and nonrepudiation are of utmost importance in these systems and are currently not guaranteed. Blockchain technology has been proven to improve on these aspects. In this article, we investigate the benefits that the adoption of Blockchain technology can bring in crowdsourcing systems. To this end, we provide examples of real-life crowdsourcing use cases and explore the benefits of using Blockchain, mainly as a database.
Klitos Christodoulou, Elias Iosif, Soulla Louca, Marinos Themistocleous
Blockchain-based systems such as the one proposed to support the Bitcoin protocol are primarily used to enable the execution of financial transactions in a decentralized manner. The characteristics of blockchains have inspired the development of new types of applications that are shifting from its original purpose. Besides supporting the recording of crypto-currency transactions blockchains are also being exploited as mediums of recording arbitrary chunks of data. One technique for embedding such data on the public Bitcoin blockchain is using the OP_RETURN opcode creating an unspendable transaction.
Advanced Steganography and Watermarking Techniques