Sarah Khadijah Taylor, Aswami Ariffin, Khairul Akram Zainol Ariffin, Siti Norul Huda Sheikh Abdullah
The steady growth of cryptowallets users and the widespread of cryptocurrencies adoption has inadvertently risen the numbers of cybercrime. The decentralized and pseudo-anonymous nature of cryptocurrencies impose a unique challenge to the investigators. Unlike investigation on fiat currency where banks can be contacted to freeze account, cryptocurrencies do not have a centralized entity that can be contacted. On top of that, studies have shown that using a generic digital forensics methodology to collect and preserve cryptowallets, which often involves imaging and seizing, are ineffective for cryptocurrencies investigation. This is because criminals can recover his seized cryptowallets into other devices and thus continue to make transactions for illegal activities. This defeats the purpose of halting the criminals from conducting further crimes. Hence in this study we propose a methodology for preserving cryptowallets at crime scene. We then conducted evaluation on the methodology by using real case and simulation exercise on different types of cryptowallets. The result shows that our methodology can be used to properly preserve cryptocurrencies evidence. This study aims to identify gaps in cryptocurrencies investigation and address them by proposing a proper methodology.
Suat Mercan, Mumin Cebe, Ramazan Aygün, Kemal Akkaya · 6 authors
Abstract A camera footage which is essential for forensic investigations can easily be modified with advanced video tampering techniques. This makes it necessary to employ novel methods to retain and prove the integrity of captured scene in criminal investigations. In this vein, blockchain technology has received a substantial interest in the last decade as it provides trust among users without a trusted third party, which enabled a myriad of applications. To this end, we propose a framework that utilizes blockchain technology to verify integrity of a camera footage recorded by a resource‐constrained wireless Internet of Things (IoT) device. The proposed approach computes the hash of the video data before it leaves the IoT device to ensure the integrity. The hash is then stored on a permissioned blockchain platform that enables detection of tampering in the video. The continuous stream is segmented efficiently to have periodic hash value to minimize the risk of video loss in case of device failure. The system has been implemented on a Raspberry Pi and Hyperledger to validate its efficiency. We are able to process high resolution videos on a resource‐constrained with reasonable amount of delay. The integrity of recorded video is successfully verified by using the digest kept in permissioned blockchain.
Digital Media Forensic Detection
Advanced Steganography and Watermarking Techniques
Physical Unclonable Functions (PUFs) and Hardware Security
Sven-Jannik Wöhnert, Kai Hendrik Wöhnert, Eldar Almamedov, Volker Skwarek
Proof of integrity in produced video data by surveillance cameras requires active forensic methods such as signatures, otherwise authenticity and integrity can be comprised and data becomes unusable e. g. for legal evidence. But a simple file- or stream-signature loses its validity when the stream is cut in parts or by separating data and signature. Using the principles of security in distributed systems similar to those of blockchain and distributed ledger technologies (BC/DLT), a chain which consists of the frames of a video which frame hash values will be distributed among a camera sensor network is presented. The backbone of this Framechain within the camera sensor network will be a camera identity concept to ensure accountability, integrity and authenticity according to the extended CIA triad security concept. Modularity by secure sequences, autarky in proof and robustness against natural modulation of data are the key parameters of this new approach. It allows the standalone data and even parts of it to be used as hard evidence.
Advanced Steganography and Watermarking Techniques
Abbas Yazdinejad, Reza M. Parizi, Gautam Srivastava, Ali Dehghantanha
Deepfakes generally refers to a new breed of adversarial deep learning technology to create non-consensual contents (mostly videos) for nefarious purposes. Most researches focus on the `detection' of deepfakes using AI-assisted approaches to take on this problem. This has been the common method operandi used by researchers thus far. However, there is one missing aspect of the deepfake problem, which is `authentication'. Instead of attempting to detect what content is fake, in this paper, we focus on techniques to provide tamper-proof evidence of what content is real. Blockchain has been advocated to be helpful with the authentication aspect of many real-world scenarios. Despite the scattered efforts around such solutions, there are no studies that can shed light on where it makes sense to adopt blockchain technology to better take on the deepfake problem. This paper aims to provide a one-stop guide to using blockchain to navigate deepfake artificial intelligence. We discuss potential use cases and solutions to tackle deepfakes technology via blockchain functionalities and features.
Sina Rafati Niya, Benjamin Jeffrey, Burkhard Stiller
The integration of Internet-of-Things (IoT) and Blockchains (BC) for trusted and decentralized approaches enabled modern use cases, such as supply chain tracing, smart cities, and IoT data marketplaces. For these it is essential to identify reliably IoT devices, since the producer-consumer trust is not guaranteed by a Trusted Third Party (TTP). Therefore, this work proposes a Know Your IoT device platform (KYoT), which enables the self-sovereign identification of IoT devices on the Ethereum BC. KYoT permits manufacturers and device owners to register and verify IoT devices in a self-sovereign fashion, while data storage security is ensured. KYoT deploys an SRAM-based (Static Random Access Memory) Physically Unclonable Function (PUF), which takes advantage of the manufacturing variability of devices' SRAM chips to derive a unique identifying key for each IoT device. The self-sovereign identification mechanism introduced is based on the ERC 734 and ERC 735 Ethereum identity standards.
Open access
2 source records
Physical Unclonable Functions (PUFs) and Hardware Security
Christopher Chun Ki Chan, Vimal Kumar, Steven Delaney, Munkhjargal Gochoo
Malicious use of deep learning algorithms has allowed the proliferation of high realism fake digital content such as text, images, and videos, to exist on the internet as readily available and accessible consumable content. False information provided through algorithmically modified footage, images, audios, and videos (known as deepfakes), coupled with the virality of social networks, may cause major social unrest. The emergence of misinformation from fabricated digital content suggests the necessity for anti-disinformation methods such as deepfake detection algorithms or immutable metadata in order to verify the validity of digital content. Permissioned blockchain, notably Hyperledger Fabric 2.0, coupled with LSTMs for audio/video/descriptive captioning is a step towards providing a feasible tool for combating deepfake media. Original content would require the original artist attestation of untampered data. The smart contract combines a varied multiple LSTM networks into a process that allows for the tracing and tracking of a digital content's historical provenance. The result is a theoretical framework that enables proof of authenticity (PoA) for digital media using a decentralized blockchain using multiple LSTMs as a deep encoder for creating unique discriminative features; which is then compressed and hashed into a transaction. Our work assumes we trust the video at the point of reception. Our contribution is a decentralized blockchain framework of deep discriminative digital media to combat deepfakes.
Digital Media Forensic Detection
Advanced Steganography and Watermarking Techniques
Generative Adversarial Networks and Image Synthesis
Bitcoin users are guaranteed to be anonymous, increasing the number of cryptocurrency trading related to crimes and fraudulent activities. While most studies about detecting illegal transactions try to distinguish trading patterns and classify them from legitimate ones, classification performance is poor since the class distributions of transaction data are highly imbalanced. In general, the Synthetic Minority Over-sampling TEchnique (SMOTE) is used to deal with class-imbalanced data, but SMOTE has a problem that it does not fully represent the diversity of the data. In this paper, we introduce another oversampling technique using Generative Adversarial Networks (GAN) to generate artificial training data for classification model. In order to verify similarity between artificial data and the actual one, oversampled dataset is evaluated with a classification model using XGBoost algorithm. We show classification performance is improved on average with synthetic data generated by both SMOTE and well-designed GAN model.
In this article, we propose a key secret-sharing technology based on generative adversarial networks (GANs) to address three major problems in the blockchain: 1) low security; 2) hard recovery of lost keys; and 3) low communication efficiency. In our scheme, the proposed network plays the role of a dealer and treats the secret-sharing process as a classification issue. The key idea is to view the secret as an image during the secret-sharing process. If the user's private key is text, we can covert the key text into an image called the original image. Specifically, we first divide the original image into original subimages by the image segmentation. Next, we encode each original subimage by DNA coding. Finally, we train the proposed network to find the key secret-sharing results. Our proposed scheme is not only a significant extension of the GANs but also a new direction for the key secret-sharing technology. The simulation results show that the scheme is secure, and both flexible and efficient in communication.
Advanced Steganography and Watermarking Techniques
Tu Bui, Daniel Cooper, John Collomosse, Mark Bell · 10 authors
We present ARCHANGEL; a novel distributed ledger based system for assuring the long-term integrity of digital video archives. First, we introduce a novel deep network architecture using a hierarchical attention autoencoder (HAAE) to compute temporal content hashes (TCHs) from minutes or hour-long audio-visual streams. Our TCHs are sensitive to accidental or malicious content modification (tampering). The focus of our self-supervised HAAE is to guard against content modification such as frame truncation or corruption but ensure invariance against format shift (i.e. codec change). This is necessary due to the curatorial requirement for archives to format shift video over time to ensure future accessibility. Second, we describe how the TCHs (and the models used to derive them) are secured via a proof-of-authority blockchain distributed across multiple independent archives. We report on the efficacy of ARCHANGEL within the context of a trial deployment in which the national government archives of the United Kingdom, United States of America, Estonia, Australia and Norway participated.
Digital Media Forensic Detection
Advanced Steganography and Watermarking Techniques
Generative Adversarial Networks and Image Synthesis
With new cryptocurrencies being frequently introduced to the market, the demand for cryptomining - a fundamental operation associated with most of the cryptocurrencies - has initiated a new stream of earning financial gains. The cost associated with the lucrative cryptomining has driven general masses to unethically mine cryptocurrencies using “plundered” resources in the public organizations (e.g., universities) as well as in the corporate sector that follows Bring Your Own Device (BYOD) culture. Such exploitation of the resources causes financial detriment to the affected organizations, which often discover the abuse when the damage has already been done. In this paper, we present a novel approach that leverages magnetic side-channel to detect covert cryptomining. Our proposed approach works even when the examiner does not have login-access or root-privileges on the suspect device. It merely requires the physical proximity of the examiner and a magnetic sensor, which is often available on smartphones. The fundamental idea of our approach is to profile the magnetic field emission of a processor for the set of available mining algorithms. We built a complete implementation of our system using advanced machine learning techniques. In our experiments, we included all the cryptocurrencies supported by the top-10 mining pools, which collectively comprise the largest share (84% during Q3 2018) of the cryptomining market. Moreover, we tested our methodology primarily on two different laptops. By using the data recorded from the magnetometer of an ordinary smartphone, our classifier achieved an average precision of over 88% and an average F1 score of 87%. Apart from our primary goal - which is to identify covert cryptomining - we also performed four additional experiments to further evaluate our approach. We found that due to its underlying design, our system is future-ready and can readily adapt even to zero-day cryptocurrencies.
Ui-Jun Baek, Se-Hyun Ji, Jee- Tae Park, Min‐Seob Lee · 6 authors
Since the inception of Bitcoin, the first cryptocurrency to implement blockchain technology, the cryptocurrency market has experienced significant growth.However, this growth has also brought about numerous vulnerabilities and attacks that pose a threat to the Bitcoin ecosystem.These attacks are not only focused on the Bitcoin network itself but also extend to the services that utilize it.Recent surveys have indicated the need to analyze and identify Distributed Denial of Service (DDoS) attacks, considering the interconnectedness between network-level data and service-level DDoS attacks within the Bitcoin system.Typically, the Bitcoin network is considered resilient against DDoS attacks due to the decentralized nature of its ledger.Nevertheless, there are potential vulnerabilities that could be exploited, such as message spoofing using the Transmission Control Protocol (TCP).Additionally, DDoS attacks often target services associated with Bitcoin usage rather than directly impacting the network's performance or stealing currency.Although these service-level attacks may not have an immediate impact, they can ultimately undermine the value of Bitcoin, leading to depreciation.The majority of DDoS attacks on Bitcoin-related services occur on exchanges and mining pools.Our approach involves evaluating experimental outcomes based on proposed metrics to establish a correlation between network-level data and service-level DDoS attacks in the Bitcoin system.By doing so, we aim to detect and analyze these attacks, thereby identifying potential associations.Furthermore, we posit that the methodology employed in this study could be applicable to other blockchain systems, extending its usefulness beyond the Bitcoin network.
Ankit Gangwal, Samuele Giuliano Piazzetta, Gianluca Lain, Mauro Conti
Cybercriminals have been exploiting cryptocurrencies to commit various unique financial frauds. Covert cryptomining - which is defined as an unauthorized harnessing of victims' computational resources to mine cryptocurrencies - is one of the prevalent ways nowadays used by cybercriminals to earn financial benefits. Such exploitation of resources causes financial losses to the victims. In this paper, we present our novel and efficient approach to detect covert cryptomining. Our solution is a generic solution that, unlike currently available solutions to detect covert cryptomining, is not tailored to a specific cryptocurrency or a particular form of cryptomining. In particular, we focus on the core mining algorithms and utilize Hardware Performance Counters (HPC) to create clean signatures that grasp the execution pattern of these algorithms on a processor. We built a complete implementation of our solution employing advanced machine learning techniques. We evaluated our methodology on two different processors through an exhaustive set of experiments. In our experiments, we considered all the cryptocurrencies mined by the top-10 mining pools, which collectively represent the largest share (84% during Q3 2018) of the cryptomining market. Our results show that our classifier can achieve a near-perfect classification with samples of length as low as five seconds. Due to its robust and practical design, our solution can even adapt to zero-day cryptocurrencies. Finally, we believe our solution is scalable and can be deployed to tackle the uprising problem of covert cryptomining.
Images are critical part of investigations, they are referred to and regarded, to gather information, document and create “memory” of a crime scene. Crime scene images are considered as vital criminal evidence in the court of law; hence, it is imperative that the authenticity of such images be maintained and that they be verifiable. The advancement in technology in this digitally proliferated era allows for easy doctoring of crime scene images. Digital watermarking, and blockchain have been used in other research works to authenticate and verify digital content or digital documents. In this paper we propose the use of watermarking and cryptographic blockchain to validate forensic crime scene images.
Advanced Steganography and Watermarking Techniques
A video record plays a crucial role in providing evidence for crime scenes or road accidents. However, the main problem with the video record is that it is often vulnerable to various video tampering attacks. Although visual evidence is required to conduct an integrity verification before investigations, it is still difficult for human vision to detect a forgery. In this paper, we propose a novel video integrity verification method (IVM) that takes advantage of a blockchain framework. The proposed method employs an effective blockchain model in centralized video data, by combining a hash-based message authentication code and elliptic curve cryptography to verify the integrity of a video. In our method, video content with a predetermined size (segments) is key-hashed in a real-time manner and stored in a chronologically chained fashion, thus establishing an irrefutable database. The verification process applies the same procedure to the video segment and generates a hash value that can be compared with the hash in the blockchain. The proposed IVM is implemented on a PC environment, as well as on an accident data recorder-embedded system for verification. The experimental results show that the proposed method has better detection capabilities and robustness toward various kinds of tampering, such as copy–move, insert, and delete, as compared to other state-of-the-art methods. An analysis based on execution time along with an increase in the number of blocks within the blockchain shows a minimal overhead in the proposed method.
Advanced Steganography and Watermarking Techniques
While significant advancements have been made in the field of multimedia forensics to detect altered content, existing techniques mostly focus on enabling the content recipient to verify the content integrity without any inputs from the content creator. In many application scenarios, the creator has a strong incentive to establish the provenance and integrity of the multimedia data created and released by him. Hence, there is a strong need for mechanisms that allow the content creator to prove the authenticity of the released content. Since blockchain technology provides an immutable distributed database, it is an ideal solution for reliably time-stamping content with its creation time and storing an irrefutable signature of the content at the time of its creation. However, a simple digital signature scheme does not allow modification of the content after the initial commitment. Authorized multimedia content alteration by its creator is often necessary (e.g., redaction of faces to protect the privacy of individuals in a video, redaction of sensitive fields in a text document) before the content is distributed. The main contributions of this paper are: (i) a novel sanitizable signature scheme that enables the content creator to prove the integrity of the redacted content, while preventing the recipients from reconstructing the redacted segments based on the published commitment, and (ii) a blockchain-based solution for securely managing the sanitizable signature. The proposed solution employs a robust hashing scheme using chameleon hash function and Merkle tree to generate the initial signature, which is stored on the blockchain. The auxiliary data required for the integrity verification step is retained by the content creator and only a signature of this auxiliary data is stored on the blockchain. Any modifications to the multimedia content requires only updating the signature of the auxiliary data, which is securely recorded on the blockchain. We demonstrate that the proposed approach enables verification of integrity of redacted multimedia content without compromising the content privacy requirements.
Digital Media Forensic Detection
Advanced Steganography and Watermarking Techniques
In our previous study, we found three requirements for digital watermarking. The first is that to prevent watermark information of an image from being diverted to other images, this information must be generated based on the original image. The second is that after the original image is modified/edited, it should still be able to be used the same as the original image. The third is that multiple digital watermarks should be stored and managed without relying on trusted third parties. To meet these requirements, we proposed a digital-copyright-management system based on perceptual hashing and blockchain. However, because we used conventional perceptual hashing in that study, we could not draw sufficient conclusions about the first and second requirements. In this current study, to obtain a stable message digest, we propose a method of improving perceptual hashing based on machine learning. With this method, an image is first modified/edited using various methods to generate an image set. This image set is then input into a convolutional neural network (CNN) to calculate the features of the images, and the data of the CNN intermediate layer are output as machine learning data. Finally, through machine learning, latent stochastic variables are determined that can be used to calculate latent image features, and the perceptual hash value of this image set is calculated using these image features for the blockchain and digital watermarking. The method also records these latent stochastic variables on the blockchain to ensure copyright security by ensuring that these variables cannot be used by those other than the original author.
Advanced Steganography and Watermarking Techniques
This paper examines the way in which blockchain technology can be used to improve the verification of integrity of evidence in digital forensics. Some background into digital forensic practices and blockchain technology are discussed to provide necessary context. A particular scalable method of verifying point-in-time existence of a piece of digital evidence, using the OpenTimestamps (OTS) service, is described, and tests are carried out to independently validate the claims made by the service. The results demonstrate that the OTS service is highly reliable with a zero false positive and false negative error rate for timestamp attestations, but that it is not suitable for timesensitive timestamping due to the variance of the accuracy of timestamps induced by block confirmation times in the Bitcoin blockchain.
Tu Bui, Daniel Cooper, John Collomosse, Mark Bell · 11 authors
We present ARCHANGEL; a novel distributed ledger based system for assuring the long-term integrity of digital video archives. First, we describe a novel deep network architecture for computing compact temporal content hashes (TCHs) from audio-visual streams with durations of minutes or hours. Our TCHs are sensitive to accidental or malicious content modification (tampering) but invariant to the codec used to encode the video. This is necessary due to the curatorial requirement for archives to format shift video over time to ensure future accessibility. Second, we describe how the TCHs (and the models used to derive them) are secured via a proof-of-authority blockchain distributed across multiple independent archives. We report on the efficacy of ARCHANGEL within the context of a trial deployment in which the national government archives of the United Kingdom, Estonia and Norway participated.