Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,600 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,600 results · page 54 of 67

Clear filters
Aug 26, 2019·Proceedings of the 3rd International Conference on Vision, Image and Signal Processing
3 cites
Adaptive Security for Smart Contracts using High Granularity Metrics

Venkata Siva Vijayendra Bhamidipati, Michael Chan, Derek Chamorro, Arpit Jain · 5 authors

In this work, we present a systems centric approach towards implementing security in Blockchain ecosystems. First, we detail the motivation for our security approach. Then, we detail the foundation of this approach by describing the concept of inline, Non-invasive High Granularity Metrics (HGMs). Following this, we outline how such metrics can be used effectively to monitor Blockchain ecosystems to detect behavior that is not deemed secure. We describe how they can be used to build whitelist and blacklist access controls in an adaptive manner, and then describe how they can be effectively used to detect potentially malicious behavior that is not yet baked into the access control structures. Finally, we discuss scalability and potential improvements for future work.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Original source
Aug 13, 2019·Frontiers in Blockchain
22 cites
An Analysis of Non-standard Transactions

Stefano Bistarelli, Ivan Mercanti, Francesco Santini

In Bitcoin, the most common kind of transactions is in the form “Bob pays Alice”, and it is based on the Pay to-Public Key Hash(P2PKH) script, which are resolved by sending the public key and a digital signature created by the corresponding private key. P2PKH transactions are just one among many standard classes: a transaction is standard if it passes Bitcoin Core’s IsStandard() and IsStandardTx() tests. However, the creation of ad-hoc scripts to lock (and unlock) transactions allows for also generating non-standard transactions, which can be nevertheless broadcast and mined as well. In this work, we explore the Bitcoin block-chain with the purpose to analyze and classify standard and non-standard transactions, understanding how much the standard behaviour is respected.

Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Original source
Aug 13, 2019·arXiv (Cornell University)
115 cites
A Survey on Ethereum Systems Security: Vulnerabilities, Attacks and Defenses

Huashan Chen, Marcus Pendleton, Laurent Njilla, Shouhuai Xu

The blockchain technology is believed by many to be a game changer in many application domains, especially financial applications. While the first generation of blockchain technology (i.e., Blockchain 1.0) is almost exclusively used for cryptocurrency purposes, the second generation (i.e., Blockchain 2.0), as represented by Ethereum, is an open and decentralized platform enabling a new paradigm of computing --- Decentralized Applications (DApps) running on top of blockchains. The rich applications and semantics of DApps inevitably introduce many security vulnerabilities, which have no counterparts in pure cryptocurrency systems like Bitcoin. Since Ethereum is a new, yet complex, system, it is imperative to have a systematic and comprehensive understanding on its security from a holistic perspective, which is unavailable. To the best of our knowledge, the present survey, which can also be used as a tutorial, fills this void. In particular, we systematize three aspects of Ethereum systems security: vulnerabilities, attacks, and defenses. We draw insights into, among other things, vulnerability root causes, attack consequences, and defense capabilities, which shed light on future research directions.

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Aug 9, 2019·Proceedings of the 14th International Conference on Availability, Reliability and Security
36 cites
Thieves in the Browser

Marius Musch, Christian Wressnegger, Martin Johns, Konrad Rieck

With the introduction of memory-bound cryptocurrencies, such as Monero, the implementation of mining code in browser-based JavaScript has become a worthwhile alternative to dedicated mining rigs. Based on this technology, a new form of parasitic computing, widely called cryptojacking or drive-by mining, has gained momentum in the web. A cryptojacking site abuses the computing resources of its visitors to covertly mine for cryptocurrencies. In this paper, we systematically explore this phenomenon. For this, we propose a 3-phase analysis approach, which enables us to identify mining scripts and conduct a large-scale study on the prevalence of cryptojacking in the Alexa 1 million websites. We find that cryptojacking is common, with currently 1 out of 500 sites hosting a mining script. Moreover, we perform several secondary analyses to gain insight into the cryptojacking landscape, including a measurement of code characteristics, an estimate of expected mining revenue, and an evaluation of current blacklist-based countermeasures.

Advanced Malware Detection Techniques
Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Original source
Aug 2, 2019·arXiv (Cornell University)
2 cites
Spams meet Cryptocurrencies: Sextortion in the Bitcoin Ecosystem

Masarah Paquet-Clouston, Matteo Romiti, Bernhard Haslhofer, Thomas Charvat

In the past year, a new spamming scheme has emerged: sexual extortion messages requiring payments in the cryptocurrency Bitcoin, also known as sextortion. This scheme represents a first integration of the use of cryptocurrencies by members of the spamming industry. Using a dataset of 4,340,736 sextortion spams, this research aims at understanding such new amalgamation by uncovering spammers' operations. To do so, a simple, yet effective method for projecting Bitcoin addresses mentioned in sextortion spams onto transaction graph abstractions is computed over the entire Bitcoin blockchain. This allows us to track and investigate monetary flows between involved actors and gain insights into the financial structure of sextortion campaigns. We find that sextortion spammers are somewhat sophisticated, following pricing strategies and benefiting from cost reductions as their operations cut the upper-tail of the spamming supply chain. We discover that one single entity is likely controlling the financial backbone of the majority of the sextortion campaigns and that the 11-month operation studied yielded a lower-bound revenue between \$1,300,620 and \$1,352,266. We conclude that sextortion spamming is a lucrative business and spammers will likely continue to send bulk emails that try to extort money through cryptocurrencies.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Aug 1, 2019·2019 16th International ISC (Iranian Society of Cryptology) Conference on Information Security and Cryptology (ISCISC)
9 cites
SANUB: A new method for Sharing and Analyzing News Using Blockchain

Arian Balouchestani, Mojtaba Mahdavi, Yeganeh Hallaj, Delaram Javdani

Millions of news are being exchanged daily among people. With the appearance of the Internet, the way of broadcasting news has changed and become faster, however it caused many problems. For instance, the increase in the speed of broadcasting news leads to an increase in the speed of fake news creation. Fake news can have a huge impression on societies. Additionally, the existence of a central entity, such as news agencies, could lead to fraud in the news broadcasting process, e.g. generating fake news and publishing them for their benefits. Since Blockchain technology provides a reliable decentralized network, it can be used to publish news. In addition, Blockchain with the help of decentralized applications and smart contracts can provide a platform in which fake news can be detected through public participation. In this paper, we proposed a new method for sharing and analyzing news to detect fake news using Blockchain, called SANUB. SANUB provides features such as publishing news anonymously, news evaluation, reporter validation, fake news detection and proof of news ownership. The results of our analysis show that SANUB outperformed the existing methods.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Caching and Content Delivery
Original source
Aug 1, 2019·2019 17th International Conference on Privacy, Security and Trust (PST)
18 cites
Competitive Selfish Mining

Hamid Azimy, Ali A. Ghorbani

Bitcoin mining is the process of generating new blocks in Bitcoin blockchain. This process is vulnerable to different types of attacks. One of the most famous attacks in this category is Selfish Mining, introduced by Eyal and Sirer [1] in 2014. This attack is essentially a strategy that a sufficiently powerful mining pool can follow to obtain more revenue than its fair share. This is a tempting attack to deploy because every pool is trying to increase its revenue and this is an excellent opportunity. However, in most of the works to date, the effect of only one selfish pool has been studied. This is an attempt to analyze selfish mining in a competitive environment, where there are more than one selfish miners in play. To do so, we created a Bitcoin network simulator and used it to simulate different configurations of miners to be able to address this problem. In short, our finding shows that in almost all of the configurations, with the presence of a more powerful selfish miner, selfish mining actually decreases the revenue of the weaker selfish miners and also helps the stronger selfish miner.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Caching and Content Delivery
Original source
Aug 1, 2019·2019 Twelfth International Conference on Contemporary Computing (IC3)
1 cites
User Reputation Analysis for effective Trading on Bitcoin Network

Divya Singh, Lakshay Kumar, Somya Jain

Signed network is a refined form of social network where connections or relationships between people are defined with strength. An edge in this network can contain a positive, negative or neutral sign to define friendly, foe or neutral relationship respectively. This paper aims to utilize the properties of signed network and hence builds a Bitcoin alpha (whom-trust-whom) network. This trading network is further scrutinized to estimate user's reputation i.e. predicting ranks of participating actors. Thus, we are able to provide score to individual user to recommend whether he is safe to make transactions with. In addition, novel method for link prediction by calculating strength of path between two unconnected nodes is proposed. This strength value considers all the features of the nodes, edges and neighbors giving results that have higher accuracy over previously defined methods.

Blockchain Technology Applications and Security
Complex Network Analysis Techniques
Spam and Phishing Detection
Original source
Aug 1, 2019·2019 IEEE International Conference on Computational Science and Engineering (CSE) and IEEE International Conference on Embedded and Ubiquitous Computing (EUC)
20 cites
Secured Cyber-Attack Signatures Distribution using Blockchain Technology

Oluwaseyi Ajayi, Melvin Cherian, Tarek Saadawi

The proliferation of cloud database has increased its vulnerability to cyberattacks. Despite several proposed methods of securing databases, malicious intruders find ways to exploit their vulnerabilities and gain access to data. This is because cyberattacks are becoming more sophisticated and harder to detect. As a result, it is becoming very difficult for a single or isolated intrusion detection system (IDS) node to detect all attacks. With the adoption of cooperative intrusion detection system, all attacks can be detected by an IDS node with the help of other IDS nodes. In cooperative intrusion detection, IDS nodes exchange attack signatures with the view of promptly detecting any attack that has been detected by other IDS. Therefore, the security of the database that houses these shared attack signatures becomes a huge problem. More specifically, detecting and/or preventing malicious signature injection, manipulation or deletion becomes important. This paper proposed an architecture that securely stores and distribute these attack signatures in real time for the purpose of prompt detection. Our proposed architecture leverages the distributed ledger technology, data immutability and tamper-proof abilities of blockchain technology. The performance of our system was examined by using the latency of the blockchain network.

Network Security and Intrusion Detection
Spam and Phishing Detection
Blockchain Technology Applications and Security
Original source
Aug 1, 2019·2019 Twelfth International Conference on Contemporary Computing (IC3)
60 cites
Short-Term Bitcoin Price Fluctuation Prediction Using Social Media and Web Search Data

Aditi Mittal, Vipasha Dhiman, Ashi Singh, Chandra Prakash

In recent years, the social network has been widely used among the public to share their views and for communication as well. Further, sentiments of the text used in emails, blogs, and social media posts affect human decision making and behavior. Bitcoin being a decentralized and peer-to-peer cryptocurrency has attracted a large number of users on the web search and social media. The goal of this paper is to correlation among Bitcoin price and Twitter and Google search patterns. Linear regression, polynomial regression, Recurrent Neural Network, and Long Short Term Memory based analysis concludes that there is a relevant degree of correlation of Google Trends and Tweet volume data with the price of Bitcoin, and with no significant relation with the sentiments of tweets.

Blockchain Technology Applications and Security
Sentiment Analysis and Opinion Mining
Spam and Phishing Detection
Original source
Jul 19, 2019·Symmetry
38 cites
Smart Contract-Based Pool Hopping Attack Prevention for Blockchain Networks

Sushil Kumar Singh, Mikail Mohammed Salim, Minjeong Cho, Jeonghun Cha · 6 authors

Pool hopping attack is the result of miners leaving the pool when it offers fewer financial rewards and joining back when the rewards of mining yield higher rewards in blockchain networks. This act of leaving and rejoining the pool only during the good times results in the miner receiving more rewards than the computational power they contribute. Miners exiting the pool deprive it of its collective hash power, which leaves the pool unable to mine the block successfully. This results in its competitors mining the block before they can finish mining. Existing research shows pool hopping resistant measures and detection strategies; however, they do not offer any robust preventive solution to discourage miners from leaving the mining pool. To prevent pool hopping attacks, a smart contract-based pool hopping attack prevention model is proposed. The main objective of our research is maintaining the symmetrical relationship between the miners by requiring them all to continually contribute their computational power to successfully mine a block. We implement a ledger containing records of all miners, in the form of a miner certificate, which tracks the history of the miner’s earlier behavior. The certificate enables a pool manager to better initiate terms of the smart contract, which safeguards the interests of existing mining pool members. The model prevents frequent mine hoppers from pool hopping as they submit coins in the form of an escrow and risk losing them if they abandon the pool before completing mining of the block. The key critical factors that every pool hopping attack prevention solution must address and a study of comparative analysis with existing solutions are presented in the paper.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Crime, Illicit Activities, and Governance
Original source
Jul 11, 2019·IEEE Transactions on Information Forensics and Security
245 cites
SDTE: A Secure Blockchain-Based Data Trading Ecosystem

Weiqi Dai, Chunkai Dai, Kim‐Kwang Raymond Choo, Changze Cui · 6 authors

Data, a key asset in our data-driven economy, has fueled the emergence of a new data trading industry. However, there are a number of limitations in conventional data trading platforms due to the existence of dishonest buyer/data broker. To mitigate these limitations, we posit the importance of a data processing-as-a-service model, which complements the conventional data hosting/exchange-as-a-service model. Specifically, in this paper, we introduce a secure data trading ecosystem and present a new blockchain-based data trading ecosystem (hereafter referred to as SDTE). In the ecosystem, both data broker and buyer are not able to obtain access to the seller's raw data, as they are only getting access to the analysis findings that they require. In other words, we reduce the challenge of securing the dataset to the challenge to secure the data processing. We also build a security model to analyze the data trading market and describe a new set of trading protocols for the entire data trading market. To demonstrate utility, we implement our proposed secure data trading platform (SDTP) on Ethereum & Intel's Software Guard Extensions (SGX) and perform an in-depth analysis.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Cryptography and Data Security
Original source
Jul 1, 2019·IEEE Xplore 29 August 2019
9 cites
Blockchain Security by Design Framework for Trust and Adoption in IoT Environment

Gohar Sargsyan, Nicolas Castellon, Raymond Binnendijk, Peter Cozijnsen

With the recent advances of IoT (Internet of Things) new and more robust security frameworks are needed to detect and mitigate new forms of cyber-attacks, which exploit complex and heterogeneity IoT networks, as well as, the existence of many vulnerabilities in IoT devices. With the rise of block chain technologies service providers pay considerable attention to better understand and adopt blockchain technologies in order to have better secure and trusted systems for own organisations and their customers. The present paper introduces a high level guide for the senior officials and decision makers in the organisations and technology managers for blockchain security framework by design principle for trust and adoption in IoT environments. The paper discusses Cyber-Trust project's blockchain technology development as a representative case study for offered security framework. Security and privacy by design approach is introduced as an important consideration in setting up the framework.

Open access
2 source records
cs.CR
Network Security and Intrusion Detection
Blockchain Technology Applications and Security
Original source
Jul 1, 2019·2019 10th International Conference on Computing, Communication and Networking Technologies (ICCCNT)
78 cites
Preventing Sybil Attack in Blockchain using Distributed Behavior Monitoring of Miners

P. Swathi, Chirag Modi, Dhiren Patel

Blockchain technology is useful with the record keeping of digital transactions, IoT, supply chain management etc. However, we have observed that the traditional attacks are possible on blockchain due to lack of robust identity management. We found that Sybil attack can cause severe impact in public/permissionless blockchain, in which an attacker can subvert the blockchain by creating a large number of pseudonymous identities (i.e. Fake user accounts) and push legitimate entities in the minority. Such virtual nodes can act like genuine nodes to create disproportionately large influence on the network. This may lead to several other attacks like DoS, DDoS etc. In this paper, a Sybil attack is demonstrated on a blockchain test bed with its impact on the throughput of the system. We propose a solution directive, in which each node monitors the behavior of other nodes and checks for the nodes which are forwarding the blocks of only particular user. Such nodes are quickly identified, blacklisted and notified to other nodes, and thus the Sybil attack can be restricted. We analyze experimental results of the proposed solution.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Original source
Jul 1, 2019·2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS)
60 cites
AI Blockchain Platform for Trusting News

Zon‐Yin Shae, Jeffrey J. P. Tsai

An interdisciplinary effort is needed for solving the fake news crisis, because the solutions depend not only on AI, but also on social mechanisms. In this paper, we propose an AI blockchain platform to build a strong collaboration among AI blockchain researchers and news media to advance the research fighting against fake news. This platform will provide journalists with blockchain crowd-sourced and AI validated factual data on emerging news. This platform will gather blockchain traced data and AI tools that can provide pointers to the original data sources, news propagation path, AI analyzed experts to consult on a given topic. This will provide journalists with cheaper and reliable sources of information in the Internet social media age. So that factual-sourced reporting can outpace the spread of fake news on social media which will encourage factual news sources as a way to value and promote truth for society. The technical contributions of this paper are (1) mechanism building the factual news database, (2) mechanism generating the news blockchain supply chain graph, and (3) AI blockchain based crowd sourcing fake news ranking mechanisms (4) AI blockchain platform for trusting news ecosystem. (5) reviewing the state of fake news research from the technology and social aspects, and providing list of key research issues and technical challenges.

Misinformation and Its Impacts
Spam and Phishing Detection
Blockchain Technology Applications and Security
Original source
Jul 1, 2019·2019 IEEE International Conference on Blockchain (Blockchain)
116 cites
Effective Scheme against 51% Attack on Proof-of-Work Blockchain with History Weighted Information

Yang Xinle, Yang Chen, Xiaohu Chen

Proof-of-Work (PoW) is a popular protocol used in Blockchain systems to resolve double-spending problems. However, if an attacker has access to calculation hash power greater than half of the total hash power, this attacker can create a double-spending attack or 51% attack. The cost of creating a 51% attack is surprisingly low if hash power is abundantly available. That posts a great threat to lots of PoW blockchains. We propose a technique to combine history weighted information of miners with the total calculation difficulty to alleviate the 51% attack problem. Analysis indicates that with the new technique, the cost of a traditional attack is increased by two orders of magnitude.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Jul 1, 2019·2019 IEEE International Conference on Intelligence and Security Informatics (ISI)
22 cites
Targeted Addresses Identification for Bitcoin with Network Representation Learning

Jiaqi Liang, Linjing Li, Weiyun Chen, Daniel Zeng

The anonymity and decentralization of Bitcoin make it widely accepted in illegal transactions, such as money laundering, drug and weapon trafficking, gambling, to name a few, which has already caused significant security risk all around the world. The obvious de-anonymity approach that matches transaction addresses and users is not possible in practice due to limited annotated data set. In this paper, we divide addresses into four types, exchange, gambling, service, and general, and propose targeted addresses identification algorithms with high fault tolerance which may be employed in a wide range of applications. We use network representation learning to extract features and train imbalanced multi-classifiers. Experimental results validated the effectiveness of the proposed method.

Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Crime, Illicit Activities, and Governance
Original source
Jul 1, 2019·2019 IEEE International Conference on Blockchain (Blockchain)
22 cites
Enhancing Blockchain Traceability with DAG-Based Tokens

Hiroki Watanabe, Tatsuro Ishida, Shigenori Ohashi, Shigeru Fujimura · 7 authors

Blockchain technology has positively impacted traceability across various industries such as logistics and shipping. By overcoming the problem of data silos among organizations and concentration of authority, this innovative approach allows a decentralized and tamper-resistant ledger to be built. On the other hand, the use of non-fungible tokens, a new concept for projecting digital and physical goods on a blockchain, is expected to be able to represent complicated operations in traceability systems. However, the existing token design lacks an efficient model for retrieval of past histories. The most popular way to retrieve past information on tokens is to use blockchain explorers, which are centralized trusted parties. Otherwise, so far there is only a naive way to examine all block headers, and it takes a vast amount of time. Our preliminary study shows that the processing time for retrieving all histories of 1,030 tokens on the Ethereum mainnet takes approximately 57 minutes. We propose a new token design based on a directed acyclic graph (DAG) that allows token histories to be efficiently explored without examining the whole blockchain. The model associates each state of the token from past to latest and covers expressions of relationships between tokens, such as merge and split. Our implementation and evaluation reveal that the DAG-based token design significantly improves the efficiency of exploring token transfer histories. The results show that our method can complete the exploration for 1,030 tokens in a matter of seconds and maintains performance over the long term even if the blockchain grows.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Halal products and consumer behavior
Original source
Jul 1, 2019·2019 IEEE International Conference on Blockchain (Blockchain)
18 cites
Deterministic Sub-Wallet for Cryptocurrencies

Hossein Rezaeighaleh, Cliff C. Zou

A big challenge in cryptocurrency is securing a user key from potential hackers because nobody can rollback a transaction made by an attacker with a stolen key once the blockchain network confirms it. One solution to protect users is splitting the money between super-wallet and sub-wallet. The user stores a large amount of money on her super-wallet and keeps it safe; she refills the sub-wallet when she needs while using the sub-wallet for her daily purchases. In this paper, we propose a new scheme to create sub-wallet that we call deterministic sub-wallet. In this scheme, the seed of the sub-wallet keys is derived from the super-wallet master seed, and therefore the super-wallet can build many sub-wallet addresses and refill them in a single blockchain transaction. Compared to existing approaches, our mechanism is cheaper, real-time, more secure against man-in-the-middle attack and easier for backup and recovery. We implement a proof-of-concept on a hardware wallet and evaluate its performance. In addition, we analyze the attacks and defenses of this design to demonstrate that our proposed method has a higher level of security than existing models.

Blockchain Technology Applications and Security
Cryptography and Data Security
Spam and Phishing Detection
Original source
Jul 1, 2019·arXiv
39 cites
Cascading Machine Learning to Attack Bitcoin Anonymity

Francesco Zola, Maria Eguimendia, Jan Lukas Bruse, Raul Orduna Urrutia

Bitcoin is a decentralized, pseudonymous cryptocurrency that is one of the most used digital assets to date. Its unregulated nature and inherent anonymity of users have led to a dramatic increase in its use for illicit activities. This calls for the development of novel methods capable of characterizing different entities in the Bitcoin network. In this paper, a method to attack Bitcoin anonymity is presented, leveraging a novel cascading machine learning approach that requires only a few features directly extracted from Bitcoin blockchain data. Cascading, used to enrich entities information with data from previous classifications, led to considerably improved multi-class classification performance with excellent values of Precision close to 1.0 for each considered class. Final models were implemented and compared using different machine learning models and showed significantly higher accuracy compared to their baseline implementation. Our approach can contribute to the development of effective tools for Bitcoin entity characterization, which may assist in uncovering illegal activities.

Open access
2 source records
Cybercrime and Law Enforcement Studies
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Jul 1, 2019·2019 IEEE International Conference on Blockchain (Blockchain)
62 cites
Traceability in Permissioned Blockchain

Tatsuo Mitani, Akira Otsuka

In this paper, we have achieved privacy protection and high transparency in a permissioned blockchain. There is a sidechain that connects the permissionless blockchain and the permissioned blockchain. The behavior in the permissioned blockchain is almost a black box from the perspective of the permissionless blockchain. While this fact is useful for privacy protection, there is room for improvement in terms of transparency. To improve the transparency of the permissioned blockchain under privacy protection, we consider traceability in the permissioned blockchain consisting of the following three properties: trade privacy (who trades with whom and at what asset amount), preservation (the total amount inside the permissioned blockchain, including deposits and withdrawals to the permissionless blockchain, is immutable), and noninvolvement (some members in the permissioned blockchain are not involved in some trades, and it is possible to prove that specified members performed the transaction). To the best of our knowledge, we are the first to achieve both preservation and noninvolvement while protecting the privacy of transactions. Our approach is as follows. We model traceability based on the hidden Markov model. Because the proof of traceability requires the calculation of more than quadratic degrees, we encrypt this model by homomorphic encryption. The number of participants in the permissioned blockchain corresponds to the number of additions in the model. Then, we can construct the encrypted model by employing somewhat homomorphic encryption. The establishment of the original model is verifiable by applying the noninteractive zero-knowledge proof of the knowledge that the plaintext is equal to zero. This is an adaptation of Benhamouda et al. (Asiacrypt 2014).

Open access
3 source records
Blockchain Technology Applications and Security
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Original source
Jul 1, 2019·2019 IEEE 19th International Conference on Software Quality, Reliability and Security Companion (QRS-C)
27 cites
Security Smells in Smart Contracts

Mehmet Demir, Manar H. Alalfi, Ozgur Turetken, Alexander Ferworn

The popularity of blockchain technology encourages organizations to use more blockchain features in mission-critical processes such as trading, access control, and computational public safety. Automation of processes with smart contracts is one of these features that significantly enlarge the scope of a blockchain implementation. Smart contracts help automate business processes by modeling business activities on the distributed ledger. Smart contracts are significantly different from other programs from a defect fixing and security issue handling perspective. The opportunity of fixing such issues is only available in the narrow window before registering the contract on to the blockchain. After a smart contract becomes a part of the chain, it is not possible to update or fix any issues. This distinct nature of smart contracts makes it essential to detect the program issues early on by paying attention to security smells. Security smells are clues that point to a deeper problem in the programming space. In this study, we review the literature and identify vulnerabilities that programmers and beneficiaries of smart contracts must avoid. We explain these security smells and categorize them based on their nature. We also review the applications that detect these vulnerabilities and provide information about their approach and coverage. Our main contribution is the evaluation of smart contracts as a platform or aid for mission-critical applications such as access control platforms. We conducted this evaluation by identifying the issues related to smart contracts and informing the reader about the problem, challenges, and techniques. We conclude by defining future directions for our research.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Jul 1, 2019·2019 IEEE International Conference on Blockchain (Blockchain)
100 cites
Data Mining-Based Ethereum Fraud Detection

Eunjin Jung, Marion Le Tilly, Ashish Gehani, Yunjie Ge

The popularity of blockchain-based currencies, such as Bitcoin and Ethereum, has grown among enthusiasts since 2009. Relying on the anonymity provided by the blockchain, hustlers have adapted offline scams to this new ecosystem. As a result, Ponzi schemes are proliferating on Ethereum, dressed up as secure investment schemes. They reward early investors with funds from the later ones before collapsing, leaving the last investors empty handed. Illegal in the offline world, they are creating thousands of victims on Ethereum, while stealing millions of dollars worth of ether. We use data mining to provide a detection model for Ponzi schemes on Ethereum, improving over prior work. We built a dataset of likely benign Ethereum smart contracts, in addition to known Ponzi scheme smart contracts, and designed features based on their compiled code and transactions. Using Weka to benchmark several classification algorithms, we obtained models that achieve both high precision and high recall. Our 0-day model can be used as soon as a smart contract is uploaded on the blockchain. The full-feature model continued to show high performance for almost 250 days. A detailed analysis on top-strength features provides novel perspectives on Ponzi scheme behavior.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source