Hyochang Baek, Junhyoung Oh, Chang Yeon Kim, Kyungho Lee
The perpetration of financial fraud progresses parallel with the innovation in the field of finance. Consequently, the emergence of the blockchain technology has also manifested financial transaction obfuscation through the use of de-anonymization of the blockchain technology. This study identifies the suspicious transaction from Binance, an open-source cryptocurrency, through the means of defining and detecting the cryptocurrency wallets. By drawing the metadata of 38,526 wallets from etherscan.io, this study investigates the transactions with discernible purpose. This study performed an unsupervised learning expectation maximization (EM) algorithm to cluster the data set. Based on the features engineered from the unsupervised learning, we performed an anomaly detection using Random Forest (RF). In this study, we offered an insight into labeling the cryptocurrency wallets by providing a model for detecting the cryptocurrency with anomalous transactions. We advocate that labeling the wallets with discernible transactions may help financial institutions, private sectors, financial intelligence, and government agencies identify and detect the transactions with illicit activities.
Eunjin Jung, Marion Le Tilly, Ashish Gehani, Yunjie Ge
The popularity of blockchain-based currencies, such as Bitcoin and Ethereum, has grown among enthusiasts since 2009. Relying on the anonymity provided by the blockchain, hustlers have adapted offline scams to this new ecosystem. As a result, Ponzi schemes are proliferating on Ethereum, dressed up as secure investment schemes. They reward early investors with funds from the later ones before collapsing, leaving the last investors empty handed. Illegal in the offline world, they are creating thousands of victims on Ethereum, while stealing millions of dollars worth of ether. We use data mining to provide a detection model for Ponzi schemes on Ethereum, improving over prior work. We built a dataset of likely benign Ethereum smart contracts, in addition to known Ponzi scheme smart contracts, and designed features based on their compiled code and transactions. Using Weka to benchmark several classification algorithms, we obtained models that achieve both high precision and high recall. Our 0-day model can be used as soon as a smart contract is uploaded on the blockchain. The full-feature model continued to show high performance for almost 250 days. A detailed analysis on top-strength features provides novel perspectives on Ponzi scheme behavior.
Michael Fröwis, Thilo Gottschalk, Bernhard Haslhofer, Christian Rückert · 5 authors
Analyzing cryptocurrency payment flows has become a key forensic method in law enforcement and is nowadays used to investigate a wide spectrum of criminal activities. However, despite its widespread adoption, the evidential value of obtained findings in court is still largely unclear. In this paper, we focus on the key ingredients of modern cryptocurrency analytics techniques, which are clustering heuristics and attribution tags. We identify internationally accepted standards and rules for substantiating suspicions and providing evidence in court and project them onto current cryptocurrency forensics practices. By providing an empirical analysis of CoinJoin transactions, we illustrate possible sources of misinterpretation in algorithmic clustering heuristics. Eventually, we derive a set of legal key requirements and translate them into a technical data sharing framework that fosters compliance with existing legal and technical standards in the realm of cryptocurrency forensics. Integrating the proposed framework in modern cryptocurrency analytics tools could allow more efficient and effective investigations, while safeguarding the evidential value of the analysis and the fundamental rights of affected persons.
Michael Fröwis, Thilo Gottschalk, Bernhard Haslhofer, Christian Rückert · 5 authors
Analyzing cryptocurrency payment flows has become a key forensic method in\nlaw enforcement and is nowadays used to investigate a wide spectrum of criminal\nactivities. However, despite its widespread adoption, the evidential value of\nobtained findings in court is still largely unclear. In this paper, we focus on\nthe key ingredients of modern cryptocurrency analytics techniques, which are\nclustering heuristics and attribution tags. We identify internationally\naccepted standards and rules for substantiating suspicions and providing\nevidence in court and project them onto current cryptocurrency forensics\npractices. By providing an empirical analysis of CoinJoin transactions, we\nillustrate possible sources of misinterpretation in algorithmic clustering\nheuristics. Eventually, we derive a set of legal key requirements and translate\nthem into a technical data sharing framework that fosters compliance with\nexisting legal and technical standards in the realm of cryptocurrency\nforensics. Integrating the proposed framework in modern cryptocurrency\nanalytics tools could allow more efficient and effective investigations, while\nsafeguarding the evidential value of the analysis and the fundamental rights of\naffected persons.\n
Tin Tironsakkul, Manuel Maarek, Andrea Eross, Mike Just
Since the creation of Bitcoin, transaction tracking is one of the prominent means for following the movement of Bitcoins involved in illegal activities. Although every Bitcoin transaction is recorded in the blockchain database, which is transparent for anyone to observe and analyse, Bitcoin's pseudonymity system and transaction obscuring techniques still allow criminals to disguise their transaction trail. While there have been a few attempts to develop tracking methods, there is no accepted evaluation method to measure their accuracy. Therefore, this paper investigates strategies for transaction tracking by introducing two new tainting methods, and proposes an address profiling approach with a metrics-based evaluation framework. We use our approach and framework to compare the accuracy of our new tainting methods with the previous tainting techniques, using data from two real Bitcoin theft transactions and several related control transactions.
Blockchain and cybersecurity are two current themes in Information Technology that have evolved and gained tremendous attention over the past few years. In this paper authors aim to structure existing and potential use of blockchain-based cybersecurity solutions from the perspective of attackers and defenders to assess whether the intersection will tip the scales in favor of one of these groups. Historically blockchain has been mainly associated with innovative financial services (including crypto-currencies) but it has other emerging use cases within e-government, supply chain management as well as security (e.g. encryption, identity and authentication, data security). On the other hand, blockchain-based platforms are increasingly a target of malicious actors and could be used as an initial attack vector. Therefore, there is a case to be made weather further adoption of blockchain-based solutions should be encouraged or not from a security standpoint and if the overall potential for change could be net positive.
The aim of this research is to propose a new blockchain network model that facilitates the secure dissemination of Cyber Threat Intelligence (CTI) data. The primary motivations for this study are based around the recent changes to information security legislation in the European Union and the challenges that Computer Security and Incident Response Teams (CSIRT) face when trying to share actionable and highly sensitive data within systems where participants do not always share the same interests or motivations. We discuss the common problems within the domain of CTI sharing and we propose a new model, that leverages the security properties of blockchain. Our model provides a more effective and efficient framework for a CTI sharing network that has the potential to overcome the trust barriers and data privacy issues inherent in this domain. We implemented a testbed using Hyperledger Fabric and the STIX 2.0 protocol and validated the efficacy of the segmentation, implemented using smart contracts and Fabric channels.
João Antônio Aparecido Cardoso, Felipe Takeshi Ishizu, Jeferson Tadeu De Lima, Jefferson de Souza Pinto
Goal: The present work aims to present how the use of a blockchain two-factor authentication solution 2FA on a page developed on WordPress can contribute to the information security regarding user authentication. Design/Methodology/Approach: The research method employed is characterized as an exploratory research, since all the analysis is based on the theoretical reference data available on the subject. A field research was carried out in relation to the implementation of the multi-factor authentication plugin Hydro Raindrop MFA, which uses blockchain technology offered by The Hydrogen Technology Corporation and the Project Hydro platform over the Ethereum network. Thus, this paper sought to present and conceptualize some of the technologies used, pointing out their contribution to information security. Results: The main results showed that the use of decentralized technology, such as blockchain and the Hydro Raindrop Plugin, can contribute considerably in the process of user authentication, which may strengthen the safeguard of the information and assets of individuals and organizations by inhibiting or reducing the possibility of successful a hacker attack. This solution is at the forefront of innovation with regard to data security because it uses advanced blockchain technology. It might contribute in a satisfactory way to the preservation of critical data and information that are the core value of many organizations of the industry 4.0. Limitations of the investigation: This research was limited to analyzing how the implementation of the Hydro Raindrop multi-factor authentication solution on a WordPress page can be beneficial to ensure information security. Practical implications: This study’s findings can contribute to entities interested in cybersecurity. As a suggestion for future works, analyses of plugins or similar solutions available on the market in distinct types of websites, or performance comparisons between them, may be relevant to contribute to scientific research. Originality/Value: This work can contribute in an innovative way to scientific research, since it addresses a recently created solution that uses blockchain technology as its basis for a safer method of authentication.
Purpose This paper aims to explore the implications of the 2014 Financial Action Task Force (FATF) publication and guidelines on virtual currency definitions and the overall impact of blockchain technology on anti-money laundering (AML) compliance and regulation. The report cites three case study examples, which the FATF paper uses and which this paper questions as to their relevance, especially to the formal banking sector. Design/methodology/approach The paper has provided a critical analysis of a FATF publication and guideline document. Additional secondary data has been used on blockchain technology and to analyse the relevance and implications of the case studies used in the FATF document. Findings The main findings are that virtual currency technology has the potential to support AML frameworks within banking when and if they are better understood. However, generic case examples of virtual currency legal cases are not necessarily useful when developing AML risk assessment frameworks within the banking sector. Practical implications The implications from the research affect any financial organisation undertaking AML risk analysis or compliance especially for virtual currencies. It applies to the banking, insurance and auditing professions and is of interest to academics working on virtual and digital currencies. Social implications The social implications are that virtual currency technology can be used to add protection to banking transactions and could also be considered for client identity information such as beneficial ownership. Originality/value The originality of this paper is the topic of blockchain technology being considered in AML frameworks and the critical analysis of the FATF cases.
Purpose The purpose of this paper is to present the findings from a literature review, which aimed to identify previous studies evaluating cryptolaundering from a systems thinking perspective. The aim of this paper is to first confirm that cryptolaundering systems can indeed be defined as complex socio-technical systems and second to present the findings from a systematic review of the literature to determine the extent to which previous research has adopted a systems thinking perspective. Design/methodology/approach The study involved a SLR of studies published in the peer-reviewed literature between 2009 and 2018. Rasmussen’s risk management framework (Rasmussen, 1997) was used to evaluate the extent to which a systems thinking perspective had been adopted. Findings The cryptolaundering process is considered to be a complex socio-technical system. The review demonstrates that no previous studies have defined cryptolaundering as a complex socio-technical system or used systems thinking framework approach to evaluate how criminals, regulatory bodies or law enforcement entities understand processes and assess risk within cryptolaundering systems. It is argued that using such an approach to the cryptolaundering process would likely improve assessing criminal risk analyses of cryptolaundering and assist law enforcement and regulatory bodies with understanding risk management during the laundering of cryptocurrencies. Originality/value Future assessments of cryptolaundering using socio-technical system analytical processes may afford law enforcement and regulatory bodies the opportunity to improve intervention techniques and identify gaps in regulations and enforcement.
Blockchain technology has an enormous scope to revamp the healthcare system in many ways as it improves the quality of healthcare by data sharing among all the participants, selective privacy and ensuring data safety. This paper explores the basics of blockchain, its applications, quality of experience and advantages in disease surveillance over the other widely used real-time and machine learning techniques. The other real-time surveillance systems lack scalability, security, interoperability, thus making blockchain as a choice for surveillance. Blockchain offers the capability of enhancing global health security and also can ensure the anonymity of patient data thereby aiding in healthcare research. The recent epidemics of re-emerging infections such as Ebola and Zika have raised many concerns regarding health security which resulted in strengthening the surveillance systems. We also discuss how blockchains can help in identifying the threats early and reporting them to health authorities for taking early preventive measures. Since the Global Health Security Agenda addresses global public health threats (both infectious and NCDs); strengthen the workforce and the systems; detect and respond rapidly and effectively to the disease threats; and elevate global health security as a priority. The blockchain has enormous potential to disrupt many current practices in traditional disease surveillance and health care research.
Following Bitcoin's Nakamoto Consensus protocol (NC), hundreds of cryptocurrencies utilize proofs of work (PoW) to maintain their ledgers. However, research shows that NC fails to achieve perfect chain quality, allowing malicious miners to alter the public ledger in order to launch several attacks, i.e., selfish mining, double-spending and feather-forking. Some later designs, represented by Ethereum, Bitcoin-NG, DECOR+, Byzcoin and Publish or Perish, aim to solve the problem by raising the chain quality; other designs, represented by Fruitchains, DECOR+ and Subchains, claim to successfully defend against the attacks in the absence of perfect chain quality. As their effectiveness remains self-claimed, the community is divided on whether a secure PoW protocol is possible. In order to resolve this ambiguity and to lay down the foundation of a common body of knowledge, this paper introduces a multi-metric evaluation framework to quantitatively analyze PoW protocols' chain quality and attack resistance. Subsequently we use this framework to evaluate the security of these improved designs through Markov decision processes. We conclude that to date, no PoW protocol achieves ideal chain quality or is resistant against all three attacks. We attribute existing PoW protocols' imperfect chain quality to their unrealistic security assumptions, and their unsatisfactory attack resistance to a dilemma between "rewarding the bad" and "punishing the good". Moreover, our analysis reveals various new protocol-specific attack strategies. Based on our analysis, we propose future directions toward more secure PoW protocols and indicate several common pitfalls in PoW security analyses.
In the past decade, online crime has begun to emerge, owing to Bitcoin what was released in 2009 [1], which was an excellent tool for cybercriminals to launder their income from illegal sources. In our research, we investigate the relationship between Bitcoin as cryptocurrency and cybercrime through theoretical examples and real crimes. Besides blockchain - registry and inventory system for the recording, tracking, monitoring, and transacting - various cyber-attack modes are presented, and solution and protection suggestions are also introduced that make the cyberspace more protected.
Bitcoin is a decentralized digital currency whose transactions are recorded in a common ledger, so called blockchain. Due to the anonymity and lack of law enforcement, Bitcoin has been misused in darknet markets which deal with illegal products, such as drugs and weapons. Therefore from the security forensics aspect, it is demanded to establish an approach to identify newly emerged darknet markets' transactions and addresses. In this paper, we thoroughly analyze Bitcoin transactions and addresses related to darknet markets and propose a novel identification method of darknet markets' addresses. To improve the identification performance, we propose a voting based method which decides the labels of multiple addresses controlled by the same user based on the number of the majority label. Through the computer simulation with more than 200K Bitcoin addresses, it was shown that our voting based method outperforms the nonvoting based one in terms of precision, recal, and F1 score. We also found that DNM's addresses pay higher fees than others, which significantly improves the classification.
Bitcoin is a popular cryptocurrency that records all transactions in an allotted append-handiest public ledger referred to as a blockchain. The security of Bitcoin heavily relies on the motivation-suitable proof-of-work (PoW) founded dispensed consensus protocol, which is run with the aid of the community nodes known as miners. Because of its inception, blockchain technological know-how has proven promising application possibilities. The spectrum of blockchain functions stages from financial, healthcare, automobile, hazard administration, internet of matters (IoT) to public and social offerings. Several reports focal point on utilizing the blockchain information structure in various applications. These vulnerabilities result in the execution of different security threats to the ordinary functionality of Bitcoin. We then examine the feasibility and robustness of the brand new safety solutions. Moreover, we discuss the current anonymity concerns in Bitcoin and the privatenessrelated threats to Bitcoin customers together with the evaluation of the comprehensive privacy-keeping solutions.
Chad Albrecht, Kristopher McKay Duffin, Steven R. Hawkins, Víctor Morales-Rocha
Purpose This paper aims to analyze the money laundering process itself, how cryptocurrencies have been integrated into this process, and how regulatory and government bodies are responding to this new form of currency. Design/methodology/approach This paper is a theoretical paper that discusses cryptocurrencies and their role in the money laundering process. Findings Cryptocurrencies eliminate the need for intermediary financial institutions and allow direct peer-to-peer financial transactions. Because of the anonymity introduced through blockchain, cryptocurrencies have been favored by the darknet and other criminal networks. Originality/value Cryptocurrencies are a nascent form of money that first arose with the creation of bitcoin in 2009. This form of purely digital currency was meant as a direct competitor to government-backed fiat currency that are controlled by the central banking system. The paper adds to the recent discussions and debate on cryptocurrencies by suggesting additional regulation to prevent their use in money laundering and corruption schemes.
Muhammad Saad, Jeffrey Spaulding, Laurent Njilla, Charles Kamhoua · 7 authors
In this paper, we systematically explore the attack surface of the Blockchain technology, with an emphasis on public Blockchains. Towards this goal, we attribute attack viability in the attack surface to 1) the Blockchain cryptographic constructs, 2) the distributed architecture of the systems using Blockchain, and 3) the Blockchain application context. To each of those contributing factors, we outline several attacks, including selfish mining, the 51% attack, Domain Name System (DNS) attacks, distributed denial-of-service (DDoS) attacks, consensus delay (due to selfish behavior or distributed denial-of-service attacks), Blockchain forks, orphaned and stale blocks, block ingestion, wallet thefts, smart contract attacks, and privacy attacks. We also explore the causal relationships between these attacks to demonstrate how various attack vectors are connected to one another. A secondary contribution of this work is outlining effective defense measures taken by the Blockchain technology or proposed by researchers to mitigate the effects of these attacks and patch associated vulnerabilities
This article identifies the many risk factors an investor should consider before adding cryptocurrencies to their investment portfolio. The returns yielded by these digital assets can in some cases be high, but an investor should seek to understand what risks exist as well. There are numerous factors to consider when investing in any asset. Traditional assets may prompt a fundamental analysis of an industry, company (business plan, financials, leadership) and other considerations. However, cryptocurrencies are not traditional assets. This investment/speculative environment contains: extremely volatile assets, a largely unregulated crowd funding mechanism, chronic theft and loss, money laundering, high transaction processing latency, potential market manipulation, and an overhanging ethical question. This article is not meant as investment advice, but points to many risk factors that are not generally present when investing in traditional assets/companies, and highlights the fact that the data needed to perform due diligence is often lacking. <b>TOPICS:</b>Currency, portfolio construction, wealth management
Christopher Copeland, Mikaela Wallin, Thomas J. Holt
The development of the Darknet as a parallel network to the Web in the 21st century has facilitated illegal trafficking in small arms, as defined by the United Nations. The authors have used investigative research methodologies to observe six weapon sale sites on the Darknet over a six-month period to identify sellers of firearms, the type and caliber of weapons for sale, manufacturer, price in Bitcoin, and the principle national origins of the firearms. This is the first study of its type to explore the illegal sale of firearms on the Darknet. This evidence can be used by law enforcement to intercept and shut down said sites and provide insight to the nature of the illegal arms trade on the Darknet.
21. yüzyıl bilgi ve iletişim teknolojilerinde önemli gelişmelere sahne olmuştur. Özellikle iletişim teknolojilerinde yaşanan kayda değer gelişmeler sonucu akıllı telefonların ortaya çıkması, interneti insanların günlük yaşantılarında sürekli kullandıkları bir teknoloji haline getirmiştir. Bu gelişmeler hayatın pek çok alanını değiştirdiği gibi ekonomik faaliyetleri de değiştirmiş ve bu faaliyetleri internet ortamına taşımıştır. Günümüzde bankacılık işlemlerinden, alışverişe kadar pek çok faaliyet internet üzerinden kolaylıkla yapılabilmektedir. Ancak internetin sunduğu bu kolaylıklar, güvenlik açıkları, verilerin çalınması gibi pek çok sorunu da beraberinde getirmektedir. Bu noktada blockchain teknolojisinin güvenlik açıklarına karşı korumalı ve bir ağ üzerinde şifrelenen verilerin yönetimini sağlayan dağınık bir veri tabanı oluşu, bu kronikleşmiş sorunların çözülmesinin yanı sıra günümüz ekonomilerinde yaşanan pek çok soruna da çözümler sunmaktadır. Bu çerçevede blockchain tabanlı ekosistemlerin oluşturulması amacıyla kamu/özel destekli pek çok platform hali hazırda çalışmalar yürütmektedir. Bu çalışmada, Blockchain’in altyapısını oluşturan teknoloji hakkında bilgi verilmiş ve bu teknolojinin kullanım alanları doğrultusunda uygulama alanları incelenmiştir.
With the development of Internet technologies, the number of threats and attacks directed at networks and systems is increasing. Attackers invent new ways of attack or improve old ones. One of the most common serious threats is "Phishing", in which cybercriminals attempt to steal user credentials using fake emails or websites or both. Blockchain projects increasingly becomes the target of attacks by intruders due to high investments and gaps in national legislation. After a series of attacks on blockchain projects around the world, the issue of cybersecurity of blockchain became particularly relevant. The article classifies the main types and schemes of phishing attacks on the blockchain, suggests methods of protection against them, examines the development of blockchain protection against phishing attacks.