Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

2,015 papersLast indexed Aug 31, 2026
Search papers

Paper index

2,015 results · page 57 of 84

Clear filters
Jan 1, 2021·IACR Cryptology ePrint Archive
21 cites
A Security Framework for Distributed Ledgers

Christoph Egger, Mike Graf, Ralf Küsters, Daniel Rausch · 6 authors

In the past few years blockchains have been a major focus for security research, resulting in significant progress in the design, formalization, and analysis of blockchain protocols. However, the more general class of distributed ledgers, which includes not just blockchains but also prominent non-blockchain protocols, such as Corda and OmniLedger, cannot be covered by the state-of-the-art in the security literature yet. These distributed ledgers often break with traditional blockchain paradigms, such as block structures to store data, system-wide consensus, or global consistency. In this paper, we close this gap by proposing the first framework for defining and analyzing the security of general distributed ledgers, with an ideal distributed ledger functionality, called Fledger, at the core of our contribution. This functionality covers not only classical blockchains but also non-blockchain distributed ledgers in a unified way. To illustrate Fledger, we first show that the prominent ideal block-chain functionalities Gledger and GPL realize (suitable instantiations of) Fledger, which captures their security properties. This implies that their respective implementations, including Bitcoin, Ouroboros Genesis, and Ouroboros Crypsinous, realize Fledger as well. Secondly, we demonstrate that Fledger is capable of precisely modeling also non-blockchain distributed ledgers by performing the first formal security analysis of such a distributed ledger, namely the prominent Corda protocol. Due to the wide spread use of Corda in industry, in particular the financial sector, this analysis is of independent interest. These results also illustrate that Fledger not just generalizes the modular treatment of blockchains to distributed ledgers, but moreover helps to unify existing results.

2 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Vehicular Ad Hoc Networks (VANETs)
Original source
Dec 30, 2020·IEEE Access
145 cites
Tight Arms Race: Overview of Current Malware Threats and Trends in Their Detection

Luca Caviglione, Michał Choraś, Igino Corona, Artur Janicki · 7 authors

Cyber attacks are currently blooming, as the attackers reap significant profits from them and face a limited risk when compared to committing the “classical” crimes. One of the major components that leads to the successful compromising of the targeted system is malicious software. It allows using the victim’s machine for various nefarious purposes, e.g., making it a part of the botnet, mining cryptocurrencies, or holding hostage the data stored there. At present, the complexity, proliferation, and variety of malware pose a real challenge for the existing countermeasures and require their constant improvements. That is why, in this paper we first perform a detailed meta-review of the existing surveys related to malware and its detection techniques, showing an arms race between these two sides of a barricade. On this basis, we review the evolution of modern threats in the communication networks, with a particular focus on the techniques employing information hiding. Next, we present the bird’s eye view portraying the main development trends in detection methods with a special emphasis on the machine learning techniques. The survey is concluded with the description of potential future research directions in the field of malware detection.

Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Digital and Cyber Forensics
Original source
Dec 29, 2020·Computer Systems Science and Engineering
16 cites
Data Security Storage Model of the Internet of Things Based on Blockchain

Pingshui Wang, Willy Susilo

With the development of information technology, the Internet of Things (IoT) has gradually become the third wave of the worldwide information industry revolution after the computer and the Internet. The application of the IoT has brought great convenience to people’s production and life. However, the potential information security problems in various IoT applications are gradually exposed and people pay more attention to them. The traditional centralized data storage and management model of the IoT is easy to cause transmission delay, single point of failure, privacy disclosure and other problems, and eventually leads to unpredictable behavior of the system. Blockchain technology can effectively improve the operation and data security status of the IoT. Referring to the storage model of the Fabric blockchain project, this paper designs a data security storage model suitable for the IoT system. The simulation results show that the model is not only effective and extensible, but also can better protect the data security of the Internet of Things.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Malware Detection Techniques
Original source
Dec 28, 2020·arXiv (Cornell University)
3 cites
A Survey on Vulnerabilities of Ethereum Smart Contracts

Zulfiqar Ali Khan, Akbar Siami Namin

Smart contract (SC) is an extension of BlockChain technology. Ethereum BlockChain was the first to incorporate SC and thus started a new era of crypto-currencies and electronic transactions. Solidity helps to program the SCs. Still, soon after Solidity's emergence in 2014, Solidity-based SCs suffered many attacks that deprived the SC account holders of their precious funds. The main reason for these attacks was the presence of vulnerabilities in SC. This paper discusses SC vulnerabilities and classifies them according to the domain knowledge of the faulty operations. This classification is a source of reminding developers and software engineers that for SC's safety, each SC requires proper testing with effective tools to catch those classes' vulnerabilities.

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Security and Verification in Computing
Original source
Dec 28, 2020·Journal of Systems and Software
240 cites
A systematic literature review of blockchain and smart contract development: Techniques, tools, and open challenges

Anna Vacca, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora

The International Conference on Software Maintenance and Evolution is the premier international forum for researchers and practitioners from academia, industry, and government to present, discuss, and debate the most recent ideas, experiences, and challenges in software maintenance and evolution.

3 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
IoT and Edge/Fog Computing
Original source
Dec 25, 2020·IEEE Access
67 cites
Blockchain System Defensive Overview for Double-Spend and Selfish Mining Attacks: A Systematic Approach

Kervins Nicolas, Yi Wang, George C. Giakos, Bingyang Wei · 5 authors

Blockchain is a technology that ensures data security by verifying database of records established in a decentralized and distributed network. Blockchain-based approaches have been applied to secure data in the fields of the Internet of Things, software engineering, healthcare systems, financial services, and smart power grids. However, the security of the blockchain system is still a major concern. We took the initiative to present a systematic study which sheds light on what defensive strategies are used to secure the blockchain system effectively. Specifically, we focus on blockchain data security that aims to mitigate the two data consistency attacks: double-spend attack and selfish mining attack. We employed the systematic approach to analyze a total of 40 selected studies using the proposed taxonomy of defensive strategies: monitoring, alert forwarding, alert broadcasting, inform, detection, and conceptual research design. It presents a comparison framework for existing and future research on blockchain security. Finally, some recommendations are proposed for blockchain researchers and developers.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Malware Detection Techniques
Original source
Dec 22, 2020·Sensors
59 cites
A Blockchain-Based Multi-Mobile Code-Driven Trust Mechanism for Detecting Internal Attacks in Internet of Things

Noshina Tariq, Muhammad Asim, Farrukh Aslam Khan, Thar Baker · 6 authors

A multitude of smart things and wirelessly connected Sensor Nodes (SNs) have pervasively facilitated the use of smart applications in every domain of life. Along with the bounties of smart things and applications, there are hazards of external and internal attacks. Unfortunately, mitigating internal attacks is quite challenging, where network lifespan (w.r.t. energy consumption at node level), latency, and scalability are the three main factors that influence the efficacy of security measures. Furthermore, most of the security measures provide centralized solutions, ignoring the decentralized nature of SN-powered Internet of Things (IoT) deployments. This paper presents an energy-efficient decentralized trust mechanism using a blockchain-based multi-mobile code-driven solution for detecting internal attacks in sensor node-powered IoT. The results validate the better performance of the proposed solution over existing solutions with 43.94% and 2.67% less message overhead in blackhole and greyhole attack scenarios, respectively. Similarly, the malicious node detection time is reduced by 20.35% and 11.35% in both blackhole and greyhole attacks. Both of these factors play a vital role in improving network lifetime.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Malware Detection Techniques
Original source
Dec 21, 2020·Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering
16 cites
Summary-based symbolic evaluation for smart contracts

Yu Feng, Emina Torlak, Rastislav Bodík

This paper presents Solar, a system for automatic synthesis of adversarial contracts that exploit vulnerabilities in a victim smart contract. To make the synthesis tractable, we introduce a query language as well as summary-based symbolic evaluation, which significantly reduces the number of instructions that our synthesizer needs to evaluate symbolically, without compromising the precision of the vulnerability query. We encoded common vulnerabilities of smart contracts and evaluated Solar on the entire data set from Etherscan. Our experiments demonstrate the benefits of summary-based symbolic evaluation and show that Solar outperforms state-of-the-art smart contracts analyzers, teether, Mythril, and ContractFuzzer, in terms of running time and precision.

Open access
Blockchain Technology Applications and Security
Adversarial Robustness in Machine Learning
Advanced Malware Detection Techniques
Original source
Dec 21, 2020·Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering
20 cites
Demystifying loops in smart contracts

Benjamin Mariano, Yanju Chen, Yu Feng, Shuvendu K. Lahiri · 5 authors

This paper aims to shed light on how loops are used in smart contracts. Towards this goal, we study various syntactic and semantic characteristics of loops used in over 20,000 Solidity contracts deployed on the Ethereum blockchain, with the goal of informing future research on program analysis for smart contracts. Based on our findings, we propose a small domain-specific language (DSL) that can be used to summarize common looping patterns in Solidity. To evaluate what percentage of smart contract loops can be expressed in our proposed DSL, we also design and implement a program synthesis toolchain called Solis that can synthesize loop summaries in our DSL. Our evaluation shows that at least 56% of the analyzed loops can be summarized in our DSL, and 81% of these summaries are exactly equivalent to the original loop.

Open access
Advanced Malware Detection Techniques
Logic, programming, and type systems
Digital Rights Management and Security
Original source
Dec 21, 2020·Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering
79 cites
Cross-contract static analysis for detecting practical reentrancy vulnerabilities in smart contracts

Yinxing Xue, Mingliang Ma, Yun Lin, Yulei Sui · 6 authors

Reentrancy bugs, one of the most severe vulnerabilities in smart contracts, have caused huge financial loss in recent years. Researchers have proposed many approaches to detecting them. However, empirical studies have shown that these approaches suffer from undesirable false positives and false negatives, when the code under detection involves the interaction between multiple smart contracts.

2 source records
Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Security and Verification in Computing
Original source
Dec 19, 2020·2020 2nd International Conference on Sustainable Technologies for Industry 4.0 (STI)
12 cites
Towards SDN and Blockchain based IoT Countermeasures: A Survey

Shakila Zaman, M. Shamim Kaiser, Risala Tasin Khan, Mufti Mahmud

Security vulnerabilities have become significant concerns due to growing demand of Internet of Things (IoT) not only for home automation systems, but also for various industrial applications. Central security technologies are vulnerable to single-point failure that could reduce attack handling technology efficiency. Distributed security frameworks are used in resource-constrained heterogeneous IoT networks. Conventional security strategies are insufficient to protect the distributed and dynamic existence of IoT networks. Conversely, Software Define Network (SDN) and Blockchain are two emerging techniques expected to solve heterogeneous IoT network security. This analysis work therefore mainly seeks to examine IoT network features, security specifications, and challenges. Thereafter, well-known threats or attacks are analyzed in IoT. SDN and blockchain-based countermeasures are addressed for IoT network security with a case study. Finally, to enhance security and privacy , numerous open issues are discussed.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
IoT and Edge/Fog Computing
Original source
Dec 19, 2020·2020 23rd International Conference on Computer and Information Technology (ICCIT)
24 cites
Securing Medical Forensic System Using Hyperledger Based Private Blockchain

Mamun Ahmed, Saha Reno, Nelofa Akter, Fahmida Haque

Forensic pathology applies medical skills and knowledge to a criminal inquiry that recognizes or develops the information regarding the accidental or unlawful death of an innocent person or the victims of significant physical injury. It is a legal process which collects, examines, analyzes and reports the evidence. Hyperledger Fabric is a permissioned and private blockchain structure which includes the present estimation of the element's property and the historical backdrop of transactions. In forensic department, every piece of evidence should be properly identified, collected, preserved, analyzed and finally admitted to the proper authority. But in reality assembling, evaluating, storing evidence is not secured enough. So in this paper, we are focused on creating a blockchain based medical forensic system using Hyperledger. The system can track any unauthorized access and modification by retrieving the Historian Record and Asset Registries and thus guarantees the impartiality of evidence, secrecy and validity of transactions.

Digital and Cyber Forensics
Advanced Malware Detection Techniques
User Authentication and Security Systems
Original source
Dec 14, 2020·2020 IEEE 17th International Conference on Smart Communities: Improving Quality of Life Using ICT, IoT and AI (HONET)
1 cites
A Methodological Framework for Validating ZKP Authentication Process

Jeffrey A. Young, Amar Rasheed, Ray R. Heshemi, Ayman Bagabas

The Internet of Things (IoT) is completely transforming the way network-connected devices are made. Manufacturers and intelligent transportation systems are using thousands of IoT devices and machine-to-machine communication to drive industrial automation. Existing access control schemes for IoT authentication fail to support user anonymity. They rely on the surrendering of the device/user authentication parameters to the trusted server, which hence can be utilized by the IoT infrastructure to track users' behavioral patterns. Furthermore, existing access control mechanisms lack the support of run-time integrity assessment capabilities that are used to verify the authenticity of an authentication process during execution. This paper presents a parametrized crypto-based privacy-preserving authentication protocol that support anonymity, it is based on Zero Knowledge Proof (ZKP). Without the loss of anonymity, a methodological framework for bootstrapping a parametrized authentication process's integrity is introduced herein. We show that run-time integrity assessment of an authentication process running on an IoT device can be achieved through the utilization of the IoT device's physical characteristics, specifically energy consumption and computation time. Behavioral patterns based on the device's power/energy consumption for the ZKP-based protocol were captured and recorded during this effort. In addition, fine-grained behavioral patterns that capture the authentication protocol's processing time were collected and analyzed. To validate the proposed scheme, it was fully implemented and deployed on an IoT testbed. We have tested the performance of the proposed scheme in terms of power consumption and computation time.

User Authentication and Security Systems
IoT and Edge/Fog Computing
Advanced Malware Detection Techniques
Original source
Dec 11, 2020·2020 IEEE 6th International Conference on Computer and Communications (ICCC)
10 cites
Multilayered Defense-in-Depth Architecture for Cryptocurrency Wallet

Hossein Rezaeighaleh, Cliff C. Zou

A significant challenge in blockchain and cryptocurrencies is protecting private keys from potential hackers because nobody can rollback a transaction made with a stolen key once the blockchain network confirms the transaction. The technical solution to protect private keys is cryptocurrency wallets, a piece of software, hardware, or a combination of them to manage the keys. In this paper, we propose a multilayered architecture for cryptocurrency wallets based on a Defense-in-Depth strategy to protect private keys with a balance between convenience and security. The user protects the private keys in three restricted layers with different protection mechanisms. So, a single breach cannot threaten the entire fund, and it saves time for the user to respond. We implement a proof-of-concept of our proposed architecture on both a smart card hardware wallet and an Android smartphone wallet with no performance penalty. Furthermore, we analyze the security of our proposed architecture with two adversary models.

Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
User Authentication and Security Systems
Original source
Dec 11, 2020·2020 IEEE 6th International Conference on Computer and Communications (ICCC)
2 cites
Dynamic Array Double-Access Attack in Ethereum

Xiangyang Chang, Junhu Zhu, Shibin Zhao

We propose a new type of variable coverage method called Dynamic Array Double-Access Attack (DADA Attack) in Ethereum Virtual Machine (EVM). Such attack can read and write operations anywhere in the storage area, resulting in abnormal execution of contract and out of control. Vulnerable contracts with such attacks will directly lead to the loss of a large amount of property. To evaluate the effectiveness of such Double-Access Attack, we conducted theoretical analysis and experimental verification, finding attack success rate is 100% under the condition that dynamic array length is controllable.

Blockchain Technology Applications and Security
Security and Verification in Computing
Advanced Malware Detection Techniques
Original source
Dec 10, 2020·2020 3rd International Seminar on Research of Information Technology and Intelligent Systems (ISRITI)
5 cites
TwoChain: Leveraging Blockchain and Smart Contract for Two Factor Authentication

Yustus Eko Oktian, Sang-Gon Lee, Hoon Jae Lee

User identity and personal information remain to be hot targets for attackers. From recent surveys, we can categorize that 65.5% of all cyberattacks in 2018 target user information. Sadly, most of the time, the system's security depends on how secure it is the implementation from the provider-side. One defense technique that the user can take part in is applying a two-factor authentication (2FA) system for their account. However, we observe that state-of-the-art 2FAs have several weaknesses and limitations. In this paper, we propose TwoChain, a blockchain-based 2FA system for web services to overcome those issues. Our implementation facilitates an alternative 2FA system that is more secure, disposable, and decentralized. Finally, we release TwoChain for public use.

User Authentication and Security Systems
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Original source
Dec 10, 2020·2020 IEEE International Conference on Big Data (Big Data)
29 cites
Ethereum Smart Contracts: Vulnerabilities and their Classifications

Zulfiqar Ali Khan, Akbar Siami Namin

Smart contract (SC) is an extension of BlockChain technology. Ethereum BlockChain was the first to incorporate SC and thus started a new era of crypto-currencies and electronic transactions. Solidity helps to program the SCs. Still, soon after Solidity's emergence in 2014, Solidity-based SCs suffered many attacks that deprived the SC account holders of their precious funds. The main reason for these attacks was the presence of vulnerabilities in SC. This paper discusses SC vulnerabilities and classifies them according to the domain knowledge of the faulty operations. This classification is a source of reminding developers and software engineers that for SC's safety, each SC requires proper testing with effective tools to catch those classes' vulnerabilities.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Security and Verification in Computing
Original source
Dec 6, 2020·ACM Computing Surveys
162 cites
Security and Privacy in IoT Using Machine Learning and Blockchain

Nazar Waheed, Xiangjian He, Muhammad Ikram, Muhammad Usman · 6 authors

Security and privacy of users have become significant concerns due to the involvement of the Internet of Things (IoT) devices in numerous applications. Cyber threats are growing at an explosive pace making the existing security and privacy measures inadequate. Hence, everyone on the Internet is a product for hackers. Consequently, Machine Learning (ML) algorithms are used to produce accurate outputs from large complex databases, where the generated outputs can be used to predict and detect vulnerabilities in IoT-based systems. Furthermore, Blockchain (BC) techniques are becoming popular in modern IoT applications to solve security and privacy issues. Several studies have been conducted on either ML algorithms or BC techniques. However, these studies target either security or privacy issues using ML algorithms or BC techniques, thus posing a need for a combined survey on efforts made in recent years addressing both security and privacy issues using ML algorithms and BC techniques. In this article, we provide a summary of research efforts made in the past few years, from 2008 to 2019, addressing security and privacy issues using ML algorithms and BC techniques in the IoT domain. First, we discuss and categorize various security and privacy threats reported in the past 12 years in the IoT domain. We then classify the literature on security and privacy efforts based on ML algorithms and BC techniques in the IoT domain. Finally, we identify and illuminate several challenges and future research directions using ML algorithms and BC techniques to address security and privacy issues in the IoT domain.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Malware Detection Techniques
Original source
Dec 1, 2020·2020 IEEE 14th International Conference on Big Data Science and Engineering (BigDataSE)
19 cites
Blockchain-based Multi-Levels Trust Mechanism Against Sybil Attacks for Vehicular Networks

Achref Haddaji, Samiha Ayed, Lamia Chaari Fourati

Vehicular ad hoc networks (VANET) authorize the vehicles to communicate and exchange data among themselves and with the Road-Side Unit (RSU). However, with the increase of the vehicles number, the VANET become vulnerable to many attacks. One serious attack is the Sybil attack which threats the functionalities of VANET by generating a high number of fake identities. In this paper, we present a Multi-Levels Trust Mechanism solution (BMLT-SA) based on the blockchain to detect the Sybil attack. Our approach is divided into three main parts : (1) A Horizontal Trust Management mechanism (HTM) is introduced as vehicle to vehicle (V2V) scheme to detect a malicious vehicle. In this level, each vehicle runs a Local Machine Learning (LML) algorithm to classify their neighbors as normal and malicious ones. All the decisions made by the vehicles are broadcasted to the RSUs; (2) A Vertical Trust Management mechanism (VTM) is used to launch a verification algorithm by the RSU. This algorithm takes as input all the LML results and gives a Vehicular Trust list as output; (3) All the RSUs belonging to the same region are collaborating to form a Distributed Trust Management mechanism (DTM) based on the use of the blockchain to share the Vehicular Trust List and to identify the class of each vehicle crossing the network. Simulations and experiments demonstrate that the proposed model based on the collaboration of different VANET components is an effective method for Sybil attack detection.

Vehicular Ad Hoc Networks (VANETs)
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Original source
Dec 1, 2020·2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)
15 cites
FPGA Based Blockchain System for Industrial IoT

Lei Xu, Lin Chen, Zhimin Gao, Hanyee Kim · 6 authors

Industrial IoT (IIoT) is critical for industrial infrastructure modernization and digitalization. Therefore, it is of utmost importance to provide adequate protection of the IIoT system. A modern IIoT system usually consists of a large number of devices that are deployed in multiple locations and owned/managed by different entities who do not fully trust each other. These features make it harder to manage the system in a coherent manner and utilize existing security mechanisms to offer adequate protection. The emerging blockchain technology provides a powerful tool for IIoT system management and protection because the IIoT nature of distributed deployment and involvement of multiple stakeholders fits the design philosophy of blockchain well. Most existing blockchain construction mechanisms are not scalable enough and too heavy for an IIoT system. One promising way to overcome these limitations is utilizing hardware based trusted execution environment (TEE) in blockchain construction. However, most of the existing works on this direction do not consider the characteristics of IIoT devices (e.g., fixed functionality and limited supply) and face several limitations when they are applied for IIoT system management and protection, such as high energy consumption, single root-of-trust, and low decentralization level. To mitigate these challenges, we propose a novel field programmable gate array (FPGA) based blockchain system. It leverages the FPGA to build a simple but efficient TEE for IIoT devices, and removes the single root-of-trust by allowing all stakeholders to participate in the management of the devices. The FPGA based blockchain system shifts the computation/storage intensive part of blockchain management to more powerful computers but still involves the IIoT devices in the block construction to achieve a high level of decentralization. We implement the major FPGA components of the design and evaluate the performance of the whole system with a simulation tool to demonstrate its feasibility for IIoT applications.

Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Advanced Malware Detection Techniques
Original source
Dec 1, 2020·2020 IEEE 20th International Conference on Software Quality, Reliability and Security (QRS)
25 cites
Early Detection of Smart Ponzi Scheme Contracts Based on Behavior Forest Similarity

Weisong Sun, Guangyao Xu, Zijiang Yang, Zhenyu Chen

Smart contracts empowered by blockchains often manage digital assets in a distributed and decentralized environment. People believe in smart contracts based on these new technologies. Unfortunately, malicious smart contacts, such as smart Ponzi scheme contracts (ponzitracts, for short), pose risk. Existing techniques detect ponzitracts by analyzing the code as well as a large amount of transaction data after time-consuming deployment. However, a conclusion based on transaction data can only be gotten after the damage has been caused. This paper proposes PonziDetector, a ponzitract detection technique that does not rely on transaction data. Behavior forest is introduced into PonziDetector to capture dynamic behaviors of smart contracts during interacting with them, which makes it possible to early detect ponzitracts. The empirical study demonstrates that PonziDetector, without transaction data, can improve the precision and the recall of the state-of-the-art to 94.6% and 93.0% respectively. This means that PonziDetector can avoid potential losses by early detecting ponzitracts.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
Dec 1, 2020·2020 27th Asia-Pacific Software Engineering Conference (APSEC)
16 cites
Source Code Obfuscation for Smart Contracts

Meng Zhang, Pengcheng Zhang, Xiapu Luo, Feng Xiao

State-of-the-art work of evaluating smart contract static analysis tools faces a major problem: most test cases (i.e., labeled buggy contracts) are too simple and lack complexity, which makes the evaluation unable to show the real performance of the analysis tools when complex contracts are analyzed. To fill the gap, we propose a novel source code obfuscation approach for Ethereum smart contracts. We use the buggy contracts in the public dataset11https://github.com/smartbugs/smartbugs/tree/master/dataset to evaluate our approach. The evaluation result shows that our approach can effectively increase the complexity of a contract. Besides, we use obfuscated contracts to evaluate the static analysis tools. The evaluation result shows that the performance of most smart contract static analysis tools decreases in different degree when the original contracts are obfuscated.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Adversarial Robustness in Machine Learning
Original source
Nov 30, 2020·Frontiers in Computer Science
28 cites
Analysis Techniques for Illicit Bitcoin Transactions

Adam Turner, Stephen McCombie, Allon J. Uhlmann

This comprehensive overview of analysis techniques for illicit Bitcoin transactions addresses both technical, machine learning approaches as well as a non-technical, legal, and governance considerations. We focus on the field of ransomware countermeasures to illustrate our points.

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source