Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,600 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,600 results · page 57 of 67

Clear filters
Mar 5, 2019·Concurrency and Computation Practice and Experience
45 cites
A new product anti‐counterfeiting blockchain using a truly decentralized dynamic consensus protocol

Naif Alzahrani, Nirupama Bulusu

Summary The growth of counterfeit goods has plagued the international community for decades. Nowadays, the battle against counterfeiting remains a significant challenge. Most of the current anti‐counterfeiting systems are centralized. Motivated by the evolution of blockchain technology, we propose (Block‐Supply), a decentralized anti‐counterfeiting supply chain that exploits NFC and blockchain technologies. This paper also proposes a new truly decentralized consensus protocol that, unlike most of the existing protocols, does not require PoW and randomly employs a different set of different size of validators each time a new block is proposed. Our protocol utilizes a game theoretical model to analyze the risk likelihood of the block's proposing nodes. This risk likelihood is used to determine the number of validators involved in the consensus process. Additionally, the game model enforces the honest consensus nodes' behavior by rewarding honest players and penalizing dishonest ones. Our protocol utilizes a novel, decentralized, dynamic mapping between the nodes that participate in the consensus process. This mapping ensures that the interaction between these nodes is executed anonymously and blindly. This way of mapping withstands many attacks that require knowing the identities of the participating nodes in advance, such as DDoS, Bribery, and Eclipse attacks.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Mobile Crowdsensing and Crowdsourcing
Original source
Mar 1, 2019·2019 International Conference on Recent Advances in Energy-efficient Computing and Communication (ICRAECC)
10 cites
A Survey on Data Security using Blockchain: Merits, Demerits and Applications

Manisha Nehe, Shitalkumar A. Jain

Network security is consequential prospect while working over the internet, LAN or other networks. Data security must be high precedence when it comes to network setup. Data security assures that shared data is kept secure. In the network, data security is crucial against attackers and hackers. The data security is all about first to secure the information from pirated access and the second one is to protect from thwart hackers. The objective of network security is to keep the network running and safe for all legitimate users. The target of this paper is to present the merits and demerits of blockchain over data security in different sectors. The blockchain technology is used in various applications to store exchanges of values via transactions. All transactions made by nodes are signed digitally with the preceding transaction hash and the public key of the destination node; this scheme guarantees that transactions are tamper-proof. A block containing transactions will be approved by specific blockchain nodes. In block-chain technology, each page in a ledger of transactions forms a block. That block affects the next block or page through cryptographic hashing. In other words, when a block is finally completed, it creates a special secure code, that links to the next page or block, creating a chain of blocks, or block-chain. Data security can be accomplished using the block-chain concept. The hash tables of raw data files are stored on the blockchain, and other copies are validated by a hashing technique. Thus any interference with the data will be instantly found because the initial hash tables are stored on thousands of nodes.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Spam and Phishing Detection
Original source
Mar 1, 2019·2019 5th International Conference on Advanced Computing & Communication Systems (ICACCS)
40 cites
Securing Blockchain based Electronic Health Record using Multilevel Authentication

B. Radhakrishnan, A. Sam Joseph, S. Sudhakar

Electronic health records possess the patient's medication details and their health history. The health records attract the attention of the attackers' as it possesses invaluable information. Loss of electronic health record leads to a wrong medication or surgery. Healthcare systems provide fewer security measures to secure the health records. Blockchain is a distributed and decentralized ledger that plays a vital role in securing the data and transactions. Introduction of blockchain in the healthcare systems protects the health records from the attackers. However, the blockchain faces phishing, dictionary-based, cold wallets, and hot wallets attacks. This paper proposes a multilevel authentication-based scheme to protect the blockchain from the attacks mentioned above.

Blockchain Technology Applications and Security
User Authentication and Security Systems
Spam and Phishing Detection
Original source
Mar 1, 2019·2019 International Conference on Engineering Technologies and Computer Science (EnT)
54 cites
Phishing Attacks and Preventions in Blockchain Based Projects

A.A. Andryukhin

With the development of Internet technologies, the number of threats and attacks directed at networks and systems is increasing. Attackers invent new ways of attack or improve old ones. One of the most common serious threats is "Phishing", in which cybercriminals attempt to steal user credentials using fake emails or websites or both. Blockchain projects increasingly becomes the target of attacks by intruders due to high investments and gaps in national legislation. After a series of attacks on blockchain projects around the world, the issue of cybersecurity of blockchain became particularly relevant. The article classifies the main types and schemes of phishing attacks on the blockchain, suggests methods of protection against them, examines the development of blockchain protection against phishing attacks.

Spam and Phishing Detection
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Mar 1, 2019·2019 International Conference on Vision Towards Emerging Trends in Communication and Networking (ViTECoN)
46 cites
An Overview of Blockchain Applications and Attacks

Rahul Rao Vokerla, Bharanidharan Shanmugam, Sami Azam, Asif Karim · 7 authors

In recent decades, Information Technology has contributed fundamentally to the development of financial markets, reforming the way in which financial institutions interact with each other. However, the established practices and norms of this sector may face an all-out overhaul as remarkable innovations such as Blockchain are maturing. The essence of Blockchain is that it is a public, shared and carefully designed record that allows mutually unknown individuals and institutions to share data in a reliable ledger and carry out all kinds of transactions. This ground-breaking technology is developed from cryptography and peer-to-peer network technologies. It is nearly immune to the majority of today's digital threats. Besides financial institutions, Blockchain based solutions have made it into other industries such as real estate, health care, the media as well as Government bodies. This paper will explain how Blockchain works, what it really is, types, its applications and threats and will offer a few ideas for prospective expansion of this technology.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Mar 1, 2019·2019 Fifth Conference on Mobile and Secure Services (MobiSecServ)
37 cites
Privacy and Security Analysis of Cryptocurrency Mobile Applications

Ashish Rajendra Sai, Jim Buckley, Andrew Le Gear

Subsequent to the introduction of Bitcoin, the field of cryptocurrency has seen unprecedented growth. Mobile applications known as wallets often facilitate user interaction to these cryptocurrencies. With a perceived real world value these wallets are a target for attackers. Unlike mainstream financial services applications, cryptocurrency wallets are not subject to the same stringent security requirements of their regulated counterparts. In this paper, we examine the security profiles of commonly used Android cryptocurrency applications. We examine these applications for common vulnerabilities outlined by OWASP mobile top 10. We establish a baseline for our tests by evaluating commonly used banking and trading applications. We compare the results from our baseline test and establish the state of security provided by cryptocurrency wallet applications. The paper also examines the possible privacy implications of mobile applications. We report that the conventional financial services applications are only marginally better than cryptocurrency application in security provisions but they provide greater privacy.

Advanced Malware Detection Techniques
Spam and Phishing Detection
Network Security and Intrusion Detection
Original source
Mar 1, 2019·2019 International Conference on Vision Towards Emerging Trends in Communication and Networking (ViTECoN)
29 cites
DAuth: A Decentralized Web Authentication System using Ethereum based Blockchain

Shibasis Patel, Anisha Sahoo, Bhabendu Kumar Mohanta, Soumyashree S. Panda · 5 authors

Over the past decade, a lot of evolution has happened in the field of security specifically authentication system. The most commonly used authentication service we use now is OAuth 2.0 based authentication. In this method, we are dependent on a 3rd party authentication service provider to which we need to trust. Though this model is used extensively nowadays, studies show that it is still vulnerable to several hacks. In addition to that, the 3rd party authentication provider has total control over the user data to which they can leak or modify at their will. Thus the use of OAuth 2.0 based protocol has raised security and privacy concerns. In this paper, blockchain and its use cases are studied and an alternative way of authentication service has been proposed based on Ethereum Blockchain called DAuth. Furthermore, a prototype has been developed which enables user authentication on the site. DAuth proposes to enhance transparency and user control in transactions which involves identity management.

User Authentication and Security Systems
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Feb 28, 2019·International Journal of Computer Sciences and Engineering
5 cites
Bitcoin Movement Prediction Using Sentimental Analysis of Twitter Feeds

Atharva Thanekar, Sanket Shelar, Aditya Thakare, Vivek Yadav

International Journal of Computer Sciences and Engineering (A UGC Approved and indexed with DOI, ICI and Approved, DPI Digital Library) is one of the leading and growing open access, peer-reviewed, monthly, and scientific research journal for scientists, engineers, research scholars, and academicians, which gains a foothold in Asia and opens to the world, aims to publish original, theoretical and practical advances in Computer Science,Information Technology, Engineering (Software, Mechanical, Civil, Electronics & Electrical), and all interdisciplinary streams of Computing Sciences. It intends to disseminate original, scientific, theoretical or applied research in the field of Computer Sciences and allied fields. It provides a platform for publishing results and research with a strong empirical component. It aims to bridge the significant gap between research and practice by promoting the publication of original, novel, industry-relevant research.

Open access
Sentiment Analysis and Opinion Mining
Human Mobility and Location-Based Analysis
Spam and Phishing Detection
Original source
Feb 22, 2019·Proceedings of the 20th International Workshop on Mobile Computing Systems and Applications
5 cites
CryptoCurrency Mining on Mobile as an Alternative Monetization Approach

Sinh Huynh, Kenny Tsu Wei Choo, Rajesh Krishna Balan, Youngki Lee

Can cryptocurrency mining (crypto-mining) be a practical ad-free monetization approach for mobile app developers? We conducted a lab experiment and a user study with 228 real Android users to investigate different aspects of mobile crypto-mining. In particular, we show that mobile devices have computational resources to spare and that these can be utilized for crypto-mining with minimal impact on the mobile user experience. We also examined the profitability of mobile crypto-mining and its stability as compared to mobile advertising. In many cases, the profit of mining can exceed mobile advertising's. Most importantly, our study shows that the majority (72%) of the participants are willing to allow crypto-mining as means to replace ads to trade-off for benefits such as a better user experience.

Open access
Big Data and Business Intelligence
Customer churn and segmentation
Spam and Phishing Detection
Original source
Feb 19, 2019·arXiv (Cornell University)
51 cites
The Art of The Scam: Demystifying Honeypots in Ethereum Smart Contracts

Christof Ferreira Torres, Mathis Steichen, Radu State

Modern blockchains, such as Ethereum, enable the execution of so-called smart contracts - programs that are executed across a decentralised network of nodes. As smart contracts become more popular and carry more value, they become more of an interesting target for attackers. In the past few years, several smart contracts have been exploited by attackers. However, a new trend towards a more proactive approach seems to be on the rise, where attackers do not search for vulnerable contracts anymore. Instead, they try to lure their victims into traps by deploying seemingly vulnerable contracts that contain hidden traps. This new type of contracts is commonly referred to as honeypots. In this paper, we present the first systematic analysis of honeypot smart contracts, by investigating their prevalence, behaviour and impact on the Ethereum blockchain. We develop a taxonomy of honeypot techniques and use this to build HoneyBadger - a tool that employs symbolic execution and well defined heuristics to expose honeypots. We perform a large-scale analysis on more than 2 million smart contracts and show that our tool not only achieves high precision, but is also highly efficient. We identify 690 honeypot smart contracts as well as 240 victims in the wild, with an accumulated profit of more than $90,000 for the honeypot creators. Our manual validation shows that 87% of the reported contracts are indeed honeypots.

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Feb 13, 2019·FC: International Conference on Financial Cryptography 2019
42 cites
SoK: Transparent Dishonesty: front-running attacks on Blockchain

Shayan Eskandari, Seyedehmahsa Moosavi, Jeremy Clark

We consider front-running to be a course of action where an entity benefits from prior access to privileged market information about upcoming transactions and trades. Front-running has been an issue in financial instrument markets since the 1970s. With the advent of the blockchain technology, front-running has resurfaced in new forms we explore here, instigated by blockchains decentralized and transparent nature. In this paper, we draw from a scattered body of knowledge and instances of front-running across the top 25 most active decentral applications (DApps) deployed on Ethereum blockchain. Additionally, we carry out a detailed analysis of Status.im initial coin offering (ICO) and show evidence of abnormal miners behavior indicative of front-running token purchases. Finally, we map the proposed solutions to front-running into useful categories.

Open access
2 source records
cs.CR
cs.CY
cs.SI
Original source
Feb 11, 2019·arXiv
32 cites
Mind the Mining

Guy Goren, Alexander Spiegelman

In this paper we revisit the mining strategies in proof of work based cryptocurrencies and propose two strategies, we call smart and smarter mining, that in many cases strictly dominate honest mining. In contrast to other known attacks, like selfish mining, which induce zero-sum games among the miners, the strategies proposed in this paper increase miners' profit by reducing their variable costs (i.e., electricity). Moreover, the proposed strategies are viable for much smaller miners than previously known attacks, and surprisingly, an attack performed by one miner is profitable for all other miners as well. While saving electricity power is very encouraging for the environment, it is less so for the coin's security. The smart/smarter strategies expose the coin to under 50\% attacks and this vulnerability might only grow when new miners join the coin as a response to the increase in profit margins induced by these strategies.

Open access
2 source records
cs.CR
cs.DC
cs.GT
Original source
Feb 2, 2019·arXiv (Cornell University)
73 cites
Identifying and Analyzing Cryptocurrency Manipulations in Social Media

Mehrnoosh Mirtaheri, Sami Abu-El-Haija, Fred Morstatter, Greg Ver Steeg · 5 authors

Interest surrounding cryptocurrencies, digital or virtual currencies that are used as a medium for financial transactions, has grown tremendously in recent years. The anonymity surrounding these currencies makes investors particularly susceptible to fraud---such as ``pump and dump'' scams---where the goal is to artificially inflate the perceived worth of a currency, luring victims into investing before the fraudsters can sell their holdings. Because of the speed and relative anonymity offered by social platforms such as Twitter and Telegram, social media has become a preferred platform for scammers who wish to spread false hype about the cryptocurrency they are trying to pump. In this work we propose and evaluate a computational approach that can automatically identify pump and dump scams as they unfold by combining information across social media platforms. We also develop a multi-modal approach for predicting whether a particular pump attempt will succeed or not. Finally, we analyze the prevalence of bots in cryptocurrency related tweets, and observe a significant increase in bot activity during the pump attempts.

Open access
4 source records
Spam and Phishing Detection
Blockchain Technology Applications and Security
Misinformation and Its Impacts
Original source
Feb 1, 2019·2019 IEEE 4th International Conference on Computer and Communication Systems (ICCCS)
2 cites
Optimal Selection of Cryptographic Algorithms in Blockchain Based on Fuzzy Analytic Hierarchy Process

Junji Qiu, Xianglin Lu, Jiayi Lin

As a collection of innovative technologies, blockchain has solved the problem of reliable transmission and exchange of information on untrusted networks. The underlying implementation is the basis for the reliability of blockchain, which consists of various cryptographic algorithms for the use of identity authentication and privacy protection of distributed ledgers. The cryptographic algorithm plays a vital role in the blockchain, which guarantees the confidentiality, integrity, verifiability and non-repudiation of the blockchain. In order to get the most suitable cryptographic algorithm for the blockchain system, this paper proposed a method using Fuzzy Analytic Hierarchy Process (FAHP) to evaluate and score the comprehensive performance of the three types of cryptographic algorithms applied in the blockchain, including symmetric cryptographic algorithms, asymmetric cryptographic algorithms and hash algorithms. This paper weighs the performance differences of cryptographic algorithms considering the aspects of security, operational efficiency, language and hardware support and resource consumption. Finally, three cryptographic algorithms are selected that are considered to be the most suitable ones for block-chain systems, namely ECDSA, sha256 and AES. This result is also consistent with the most commonly used cryptographic algorithms in the current blockchain development direction. Therefore, the reliability and practicability of the algorithm evaluation pro-posed in this paper has been proved.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Steganography and Watermarking Techniques
Original source
Feb 1, 2019·2019 21st International Conference on Advanced Communication Technology (ICACT)
12 cites
Analysis of Bitcoin Exchange Using Relationship of Transactions and Addresses

Seongho Hong, Heeyoul Kim

This bitcoin system is a system made to support transactions between users without the help of any financial institution. The Bitcoin Exchange is a service that enables exchanges of bitcoins mined by others with cash. To use this service, the miner should send bitcoins from his bitcoin wallet to the deposit address provided by the Exchange. The bitcoins delivered to the deposit address are automatically moved to one of the Exchange's bitcoin addresses by the Exchange system. Since what is known to the user is only the deposit address for the user, the user can only guess that the Exchange has taken the bitcoins from his deposit address when he/she sees the transfer of his/her bitcoins to another address. We will present a method to find out a few bitcoin addresses through preliminary work and find out the associated Exchange addresses using the characteristics of the deposit addresses and system addresses of the Exchange through transactions with the relevant addresses on the blockchain.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Imbalanced Data Classification Techniques
Original source
Jan 15, 2019·arXiv (Cornell University)
81 cites
Selfish Mining in Ethereum

Jianyu Niu, Chen Feng

We study selfish mining in Ethereum. The problem is combinato-rially more complex than in Bitcoin because of major differences in the reward system and a different difficulty adjustment formula. Equivalent strategies in Bitcoin do have different profitabilities in Ethereum. The attacker can either broadcast his fork one block by one, or keep them secret as long as possible and publish them all at once at the end of an attack cycle. The first strategy is damaging for substantial hashrates, and we show that the second strategy is even worse. This confirms what we already proved for Bitcoin: Selfish mining is most of all an attack on the difficulty adjustment formula. We show that the current reward for signaling uncle blocks is a weak incentive for the attacker to signal blocks. We compute the profitabilities of different strategies and find out that for a large parameter space values, strategies that do not signal blocks are the best ones. We compute closed-form formulas for the apparent hashrates for these strategies and compare them. We use a direct combinatorics analysis with Dyck words to find these closed-form formulas.

Open access
7 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Malware Detection Techniques
Original source
Jan 6, 2019·International Journal of Network Management
180 cites
A survey on blockchain cybersecurity vulnerabilities and possible countermeasures

Huru Hasanova, Ui-Jun Baek, Shin Mu-gon, Kyunghee Cho · 5 authors

Summary Blockchain technology has attracted considerable attention owing to its wide range of potential applications. It first appeared as a cryptocurrency, called Bitcoin, but has since been used in many other business and nonbusiness applications. Unlike most existing systems that are based on centralized frameworks, this new technology utilizes peer‐to‐peer networks and distributed systems which includes blockchain registers to store transactions. Its structure is designed as a digital log file and stored as a series of linked groups, called blocks. Each individual block is locked cryptographically with the previous block. Once a block has been added, it cannot be altered. Many security experts speculate that the inherent cryptographic nature of the blockchain system is sufficient to withstand constant hacking and security threats. However, previous studies on the security and privacy of blockchain technology have shown that many applications have fallen victim to successful cyberattacks. Owing to the increasing demand for cryptocurrency and its current security challenges, previous studies have not focused on blockchain technology cybersecurity vulnerabilities extensively. Here, our study extends upon the previous studies on vulnerabilities and investigates the types of potential attacks. Our study then provides further direction to highlight possible countermeasures against blockchain technology vulnerability to cybersecurity.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source
Jan 2, 2019·Journal of Organizational Computing and Electronic Commerce
26 cites
Cryptojacking injection: A paradigm shift to cryptocurrency-based web-centric internet attacks

Aaron Zimba, Zhaoshun Wang, Mwenge Mulenga

Crypto-mining attacks have emerged as a new generation of web-based attacks which have seen cybercriminals eschew the infamous crypto ransomware. The watering hole attack vector has by far been the most widely employed attack methodology but it faces the task of luring the victim to the infected web resources. However, cryptojacking injection presents a paradigm shift to web-based crypto-mining attacks in that it eliminates the need for a pivotal third-party such as the exploitable web server. Thus, instead of attacking credit card and other private information of e-commerce users, attackers seek to maliciously abuse a victim’s CPU to generate cryptocurrency. In this paper, we investigate and evaluate cryptojacking injection – a state-of-the-art web-centric attack vector in the crypto-mining attacks landscape. We formulate an attack model based on finite state machines which depicts the various breaches of confidentiality, integrity and availability in the web system as the attack progresses. We show how this new attack vector attacks some of the core components of e-commerce (URL, HTTP and HTML) to generate Monero crypto currency from benign web users. We evaluate our modeling approach with a series of experiments with two attack scenarios using different operating systems. Results show that the attack is indeed cross-platform and feasible on any operating system of a browser-capable device. We analyze the generated network traffic during the attack and draw features such as URLs and the parsed files, the associated cryptographic hashes, and the IP addresses of the crypto-mining domains. These, together with host-based features such as exhaustive CPU usage can be used as indicators of compromise and subsequently act as feed into intrusion detection systems.

Spam and Phishing Detection
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Jan 2, 2019·Journal of Management Information Systems
226 cites
Regulating Cryptocurrencies: A Supervised Machine Learning Approach to De-Anonymizing the Bitcoin Blockchain

Hao Hua Sun Yin, Klaus Christian Langenheldt, Mikkel Alexander Harlev, Raghava Rao Mukkamala · 5 authors

Bitcoin is a cryptocurrency whose transactions are recorded on a distributed, openly accessible ledger. On the Bitcoin Blockchain, an owning entity’s real-world identity is hidden behind a pseudonym, a so-called address. Therefore, Bitcoin is widely assumed to provide a high degree of anonymity, which is a driver for its frequent use for illicit activities. This paper presents a novel approach for de-anonymizing the Bitcoin Blockchain by using Supervised Machine Learning to predict the type of yet-unidentified entities. We utilized a sample of 957 entities (with ≈385 million transactions), whose identity and type had been revealed, as training set data and built classifiers differentiating among 12 categories. Our main finding is that we can indeed predict the type of a yet-unidentified entity. Using the Gradient Boosting algorithm with default parameters, we achieve a mean cross-validation accuracy of 80.42% and F1-score of ≈79.64%. We show two examples, one where we predict on a set of 22 clusters that are suspected to be related to cybercriminal activities, and another where we classify 153,293 clusters to provide an estimation of the activity on the Bitcoin ecosystem. We discuss the potential applications of our method for organizational regulation and compliance, societal implications, outline study limitations, and propose future research directions. A prototype implementation of our method for organizational use is included in the appendix.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Jan 1, 2019·UWM Digital Commons (University of Wisconsin–Milwaukee)
0 cites
Zuckerberg Testifies on Facebook Cryptocurrency Libra

Mark Zuckerberg

Mark Zuckerberg testified before congress today on October 23, 2019 regarding Facebook’s cryptocurrency Libra

Big Data Technologies and Applications
Spam and Phishing Detection
Caching and Content Delivery
Original source