Data breaches are an increasingly common part of consumers’ lives. No institution is immune to the possibility of an attack. Each breach inevitably risks the release of consumers’ personally identifiable information and the strong possibility of identity theft. Unfortunately, current solutions for handling these incidents are woefully inadequate. Private litigation like consumer class actions and shareholder lawsuits each face substantive legal and procedural barriers. States have their own data security and breach notification laws, but there is currently no unifying piece of legislation or strong enforcement mechanism. This Note argues that proactive solutions are required. First, a national data security law—setting minimum data security standards, regulating the use and storage of personal information, and expanding the enforcement role of the Federal Trade Commission—is imperative to protect consumers’ data. Second, a proactive solution requires reconsidering how to minimize the problem by going to its source: the collection of personally identifiable information in the first place. This Note suggests regulating companies’ collection of Social Security numbers, and, eventually, using a system based on distributed ledger technology to replace the ubiquity of Social Security numbers.
We propose and compare two approaches to identify smart contracts as token systems by analyzing their public bytecode. The first approach symbolically executes the code in order to detect token systems by their characteristic behavior of updating internal accounts. The second approach serves as a comparison base and exploits the common interface of ERC-20, the most popular token standard. We present quantitative results for the Ethereum blockchain, and validate the effectiveness of both approaches using a set of curated token systems as ground truth. We observe 100% recall for the second approach. Recall rates of 89% (with well explainable missed detections) indicate that the first approach may also be able to identify "hidden" or undocumented token systems that intentionally do not implement the standard. One possible application of the proposed methods is to facilitate regulator' tasks of monitoring and policing the use of token systems and their underlying platforms.
Muhammad Saad, Laurent Njilla, Charles Kamhoua, Aziz Mohaisen
Selfish mining is a well known vulnerability in blockchains exploited by miners to steal block rewards. In this paper, we explore a new form of selfish mining attack that guarantees high rewards with low cost. We show the feasibility of this attack facilitated by recent developments in blockchain technology opening new attack avenues. By outlining the limitations of existing countermeasures, we highlight a need for new defense strategies to counter this attack, and leverage key system parameters in blockchain applications to propose an algorithm that enforces fair mining. We use the expected transaction confirmation height and block publishing height to detect selfish mining behavior and develop a network-wide defense mechanism to disincentivize selfish miners. Our design involves a simple modifications to transactions' data structure in order to obtain a “truth state” used to catch the selfish miners and prevent honest miners from losing block rewards.
We increasingly live in a world where there is a balance between the rights to privacy and the requirements for consent, and the rights of society to protect itself. Within this world, there is an ever-increasing requirement to protect the identities involved within financial transactions, but this makes things increasingly difficult for law enforcement agencies, especially in terms of financial fraud and money laundering. This paper reviews the state-of-the-art in terms of the methods of privacy that are being used within cryptocurrency transactions, and in the challenges that law enforcement face.
Alejandro Tomas Dini, Esteban Gabriel Abete, Marcelo Colombo, Javier Guevara · 6 authors
Blockchain is an innovative technology that allows a untrusted node network to share transactional data consistently while removing the need of a centralized authority. In this paper we propose a system to store citizen criminal records in a decentralized way by using a permissioned blockchain, taking advantage of some of its characteristics to ensure privacy, security, immutability, and disponibility of stored sensitive data. This system would overcome the current one since it can cryptographically guarantee that data, once stored, had not been modified but by a competent authority. It also improves the delivery of the records to its destination which can be geographically spread throughout the territory.
The innovative potential of blockchain technology proves to be convenient and useful in different sectors, but these opportunities may also be disruptive and create challenges. This paper investigates technical, risk and security related challenges of blockchain. The use of this technology is viewed in light of financial crime that pose a threat to security on national and international level as well. Firstly, elements of blockchain technology and the reasons they really matter are explained. Secondly, we focus on national security and how is it affected by the criminal use of cryptocurrencies. Thirdly, we elaborate on the lack of standards and mechanisms in connection with illegal activities, particularly money-laundering and financing terrorism. Finally, we suggest the use of fuzzy methods for security analysis and testing, and compatibility with GDPR for better protection of the recorded data in chain. We conclude that a collaboration of responsible entities in different sectors is needed as well as the investigation of potential ways in which actors can exploit further applications. The convergence of terrorism and cybercrime should be considered, and the necessary preventive actions taken.
Kentaroh Toyoda, Tomoaki Ohtsuki, P. Takis Mathiopoulos
Due to the increased popularity of Bitcoin, many researchers have analyzed how Bitcoin is being used based on the transaction history. However, the existing works analyze the transaction history in a "static" manner and none of them analyzes transaction history "dynamically", i.e. without taking into account the "time variation of how Bitcoin is transferred". The time analysis is in great demand for many practical cases, such as digital forensics tool that infers what was going on behind the scene of a fraudulent scam, and real-time inference of marketplace sales. In this paper, we propose a novel time series analysis for analyzing the history of Bitcoin transactions. In fact the main goal of our research is to detect changing points, namely anomaly detection, against a given (Bitcoin) address's transaction history. To show the effectiveness of the proposed approach, it is tested against the transaction history of Pirate@40's HYIP (High Yielding Investment Program) scheme, which raised 700,000 BTC from his investors and was charged by the Security and Exchange Commission (SEC) in 2013. It is shown that the proposed approach can successfully detect several remarkable points of Pirate@40's HYIP scheme, such as when its program's name was changed to Bitcoin Saving & Trust and when its investment rule was changed.
Bitcoin is the leading cryptocurrency in the world with a total marketcap of nearly USD 33 billion, [1] with 370,000 transactions recorded daily[2]. Pseudo-anonymous, decentralized peer-to-peer electronic cash systems such as Bitcoin have caused a paradigm shift in the way that people conduct financial transactions and purchase goods. Although cryptocurrencies enable users to securely and anonymously exchange money, they can also facilitate illegal criminal activities. Therefore, it is imperative that law enforcement agencies develop appropriate analytical processes that will allow them to identify and investigate criminal activities in the Blockchain (a distributed ledger). In this paper, INTERPOL, through the INTERPOL Global Complex for Innovation, proposes a Bitcoin analytical framework and a software system that will assist law enforcement agencies in the real-time analysis of the Blockchain while providing digital crime analysts with tracing and visualization capabilities. By doing so, it is feasible to render transactions decipherable and comprehensible for law enforcement investigators and prosecutors. The proposed solution is evaluated against three criminal case studies linked to Darknet markets, ransomware and DDoS extortion.
Bitcoin is considered to be the world's first peer-to-peer and unregulated crypto-currency which has received widespread popularity in the last few years. It is issued and controlled by the members of the Bitcoin system. The success of Bitcoin has spurred the launch of many other crypto-currencies. Despite being widely adopted by various large-scale businesses, Bitcoin transactions are still exposed to many known as well as zero-day attacks due to various vulnerabilities being exploited by the malicious entities. In order to achieve reliable and secure transactions, extensive research needs to be carried out to critically examine Bitcoin architecture and its level of security. In this regard, this chapter presents a holistic analysis of Bitcoin architecture and a survey of the attacks prevalent to its transactions. As an evaluation of the Bitcoin system, a comparison of different crypto-currencies has been presented, based on their features, possible attacks, disadvantages, and the advantages which they possess over Bitcoin.
As Bitcoin's popularity has grown over the decade since its creation, it has become an increasingly attractive target for adversaries of all kinds. One of the most powerful potential adversaries is the country of China, which has expressed adversarial positions regarding the cryptocurrency and demonstrated powerful capabilities to influence it. In this paper, we explore how China threatens the security, stability, and viability of Bitcoin through its dominant position in the Bitcoin ecosystem, political and economic control over domestic activity, and control over its domestic Internet infrastructure. We explore the relationship between China and Bitcoin, document China's motivation to undermine Bitcoin, and present a case study to demonstrate the strong influence that China has over Bitcoin. Finally, we systematize the class of attacks that China can deploy against Bitcoin to better understand the threat China poses. We conclude that China has mature capabilities and strong motives for performing a variety of attacks against Bitcoin.
Kriptovalute danas više nisu naznaka daleke budućnosti, nego realno sredstvo plaćanja sa stvarnim posljedicama. Bitcoin je svega u par godina postao nositelj jednog novog vremena za trgovinu u kojoj nije potreban posrednik i čije su transakcije u potpunosti anonimne, što čini veliko odstupanje od uobičajene prakse. Sam cilj ovoga rada je vidjeti koliki je stvarni utjecaj kriptovaluta na poslovnu klimu, odnosno konkretno na međunarodno poslovanje. Kroz ovaj rad upoznat ćemo važnost samih kriptovaluta te kroz primjer bitcoina vidjeti koje poboljšanje kroz samo poslovanje on donosi. U prvom dijelu rada predstavit će se kriptovalute te reći nešto o njihovom podrijetlu te vrstama. Drugo poglavlje donosi detaljniji pogled kako bitcoin funkcionira te će biti riječi o vrstama novčanika koje bitcoin nudi te će se u zadnjem, trećem poglavlju, objasniti primjer kriptovaluta u poslovanju.
Various crimes using Bitcoin are highlighted. Among various crimes using Bitcoin, this paper suggests a method to detect money laundering focusing on mixing service that provides Money Laundering. This is part of the anti-money-laundering (AML) strategy, which can determine whether the mixer service is used in certain transactions by using transaction sample data using mixer. Money laundering using Bitcoin is often used to avoid fund tracking in the underground world and analyzing it is essential in situational awareness of fund tracking.
Marcel C. Ugwu, Izunna Okpala, Collins I. Oham, Cosmas Ifeanyi Nwakanma
In this paper, we present a tiered vehicular forensics framework based on permission BlockChain. We integrate all entities involved in the forensics process and record their interactions in the BlockChain to generate comprehensive evidence for settling disputes and appropriating blame. We incorporate a watchdog entity in our tiered framework to prevent collusive tendencies of potentiality liable entities and to prevent exploitation of evidence. Also, we incorporate a state mechanism to prove the state of a smart vehicle when an accident occurs. Furthermore, we conduct a security analysis to demonstrate the resilience of our framework against identified attacks and describe security mechanisms used to achieve key requirements for vehicular forensics. Finally, we comparatively evaluate our framework against existing proposals.
Yusuf Sani Abubakar, Ahmad Faosiy Ogunbado, Mpawenimana Abdallah Saidi
Bitcoin is a type of cryptocurrency and the most successful in blockchain management. It has become famous in recent years. The critical aspects of cryptocurrency are its legitimacy, source of money laundering, tax evasion, lack of regulation etc. The aim of this study is to explore the view of Muslim scholars on the legality of bitcoin with respect to Shariah. The study adopts doctrinal approach which utilizes descriptive approach of qualitative research methodology which relies on secondary data in form of text books, journals, newspapers, related websites etc. The study found that Muslim scholars are divided on the issue. A part of them completely rejected bitcoin and considered it against Shariah principles. On the other hand, some Muslim scholars believe bitcoin does not contradict Islamic principles and therefore may be used, however with certain conditions. The researchers tend to support the proponents’ view as most of the opponents’ grounds for the rejection are temporary in nature which may be covered through policy regulations.
Anonymity networks and hidden services like those accessible in Tor, also called the "darknet", in combination with cryptocurrencies like bitcoin provide a relatively safe environment for criminal online activities. While this is a challenge for law enforcement, it brings opportunities for researchers to monitor these activities as they are often not really hidden but rather obfuscated and/or anonymized. In this paper we discuss such a monitoring approach for product sales in the darknet. We collect bitcoin addresses and data about product offerings in a number of shops run as hidden services in Tor. We then analyze transactions in the bitcoin blockchain that can be mapped to specific product sales in these shops.
This article presents policing challenges of investigating, evidencing and prosecuting organized cybercriminals for the crimes committed using cryptocurrencies such as Bitcoin. A set of best practices is discussed to tackle these challenges in real world investigations. This work is a result of collaboration with a number of stakeholders the policing and judicial ecosystem with the objective of investigating and prosecuting the new generation of organised cybercriminals. Concrete scenarios of using Bitcoins in a range of cybercrimes were developed as part of this project and the devices were analysed to extract evidence to assist prosecution of organised cybercriminals. We have also presented our return of experience for various stages of digital forensics analysis of devices used in Bitcoin transactions.
In recent years, the Darknet has become one of the most discussed topics in cyber security circles. Current academic studies and media reports tend to highlight how the anonymous nature of the Darknet is used to facilitate criminal activities. This paper reports on a recent research in four Darknet forums that reveals a different aspect of the Darknet. Drawing on our qualitative findings, we suggest that many users of the Darknet might not perceive it as intrinsically criminogenic, despite their acknowledgement of various kinds of criminal activity in this network. Further, our research participants emphasised on the achievement of constructive socio-political values through the use of the Darknet. This achievement is enabled by various characteristics that are rooted in the Darknet’s technological structure, such as anonymity, privacy, and the use of cryptocurrencies. These characteristics provide a wide range of opportunities for good as well as for evil.
Aug 1, 2018·2018 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications/ 12th IEEE International Conference On Big Data Science And Engineering (TrustCom/BigDataSE)
Paul Sarda, Mohammad Jabed Morshed Chowdhury, Alan Colman, Muhammad Ashad Kabir · 5 authors
Current job recruitment process involves a good number of documentations. It is not uncommon for job applicants to misrepresent, overstate or falsify past employment, specifically work experience, and skills. Where this occurs and the applicant is subsequently appointed, a company may be exposed to significant commercial and legal risk. Companies usually employ third party HR recruitment agencies to verify the authenticity of an applicant's listed work experience. However, verification of applicant's past work experience is both time consuming and costly. Moreover, companies have to rely on the third parties, which may not be trustworthy. Therefore, small and medium size companies usually avoid the verification process. In this research, we demonstrate how blockchain technology can provide cost-effective, and real-time work history verification. The proposed approach also ensures trustworthy and privacy-preserving (work-history) data sharing. Furthermore, we have implemented a prototype to demonstrate how individuals can share and verify work history using Ethereum-based public blockchain.
Virtual currencies are on the rise and so is money laundering. While there are efforts to combat money laundering through various intergovernmental bodies, many have expressed concern over the rise of virtual currencies. Some cryptocurrencies such as Bitcoin have played a major role in the proliferation of online money laundering as it possesses characteristics that criminals are fond of. Bitcoin and other cryptocurrencies are decentralised, anonymous/pseudonymous and irreversible. They provide the means to skirt the Anti-Money laundering safeguards that have been put in place. \nThis paper discusses the intersection between Anti-Money Laundering efforts and the challenges that are introduced by cryptocurrencies such as Bitcoin. It also looks at the case of Liberty Reserve to highlight these challenges.