Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,600 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,600 results · page 60 of 67

Clear filters
Nov 26, 2018·Sustainability
26 cites
Blockchain-Based One-Off Address System to Guarantee Transparency and Privacy for a Sustainable Donation Environment

Jaekyu Lee, Aria Seo, Yeichang Kim, Junho Jeong

The problem of transparency in donation systems has long been a topic for discussion. However, the emphasis on transparency raises privacy concerns for donors and recipients, with some people attempting to hide donations or the receipt of money. Therefore, a donation system that guarantees transparency and privacy is required to avoid negative side effects. In this study, we developed a system that protects personal information by using a one-time account address system based on a blockchain while emphasizing transparency. The developed system could contribute to the creation of a sustainable and safe donation environment and culture.

Open access
Caching and Content Delivery
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Nov 16, 2018·arXiv (Cornell University)
75 cites
Towards Safer Smart Contracts: A Sequence Learning Approach to Detecting Security Threats

Wesley Joon-Wie Tann, Xing Han, Sourav Sen Gupta, Yew-Soon Ong

Symbolic analysis of security exploits in smart contracts has demonstrated to be valuable for analyzing predefined vulnerability properties. While some symbolic tools perform complex analysis steps, they require a predetermined invocation depth to search vulnerable execution paths, and the search time increases with depth. The number of contracts on blockchains like Ethereum has increased 176 fold since December 2015. If these symbolic tools fail to analyze the increasingly large number of contracts in time, entire classes of exploits could cause irrevocable damage. In this paper, we aim to have safer smart contracts against emerging threats. We propose the approach of sequential learning of smart contract weaknesses using machine learning---long-short term memory (LSTM)---that allows us to be able to detect new attack trends relatively quickly, leading to safer smart contracts. Our experimental studies on 620,000 smart contracts prove that our model can easily scale to analyze a massive amount of contracts; that is, the LSTM maintains near constant analysis time as contracts increase in complexity. In addition, our approach achieves $99\%$ test accuracy and correctly analyzes contracts that were false positive (FP) errors made by a symbolic tool.

Open access
2 source records
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Spam and Phishing Detection
Original source
Nov 1, 2018·2018 9th IEEE Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON)
20 cites
Probabilistic Blockchains: A Blockchain Paradigm for Collaborative Decision-Making

Tara Salman, Raj Jain, Lav Gupta

A blockchain provides a securedparadigm to achieve consensus using a distributed and peer-to-peer network in which no trusted central party is required. As a result, it has the potential to resolve many challenges that are faced with current centralized controllers in globally distributed applications. To date, the blockchain technology has been used for recording transactions and tracking objects in which multiple participants reach a consensus on whether a transaction is valid or not. This paper introduces the novel paradigm of probabilistic blockchains, an extension of the current blockchains that allows building efficient and distributed risk assessment and decision-making applications in which multiple untrusting parties collaborate but may not completely agree on the outcome. The paradigm is particularly useful for risk assessment, where a group of decision-makersneeds to decide or analyze an event based on imperfect information. The proposed approach can be used in applications like intrusion detections, stock market predictions, insurance, and recommendation systems. The paper presents and analyzes the application of probabilistic blockchains for intrusion detection systems for computer networks. The results show the feasibility and efficiency of the proposed paradigm in making such decisions.

Network Security and Intrusion Detection
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Nov 1, 2018·2018 IEEE 9th Annual Information Technology, Electronics and Mobile Communication Conference (IEMCON)
13 cites
Risks from Spam Attacks on Blockchains for Intemet-of-Things Devices

Santeri Paavolainen, Tommi Elo, Pekka Nikander

There has been increased interest in the use of blockchains to control Internet of Things devices either directly, or through smart contracts. Many blockchains, such as Ethereum and Fabric, have support for smart contracts. The use of public blockchains while attractive due to their decentralization and availability, do pose challenges, such as unpredictable transaction latencies and cryptocurrency price fluctuations. Transactions in the Ethereum network, such as invokations of smart contracts used to control an IoT device, have no fairness or eventuality guarantees. In this work we describe a “spam attack” method available to parties with sufficient cryptocurrency reserves to delay a statistically significant portion of transactions submitted to the Ethereum network. This paper derives estimations on the costs and effects of such an attack, and is based on an analysis of historical transactions.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Spam and Phishing Detection
Original source
Nov 1, 2018·2018 International Seminar on Research of Information Technology and Intelligent Systems (ISRITI)
57 cites
Evaluation of Proof of Work (POW) Blockchains Security Network on Selfish Mining

I Gusti Ayu Kusdiah Gemeliarana, Riri Fitri Sari

Bitcoin is one of the first implementations of cryptocurrency or digital currency. It uses has increased in recent years along with the increasing volume of online transactions that require digital currency A blockchain is a digital ledger that allows parties to transact without use of a central authority as a trusted intermediary. In blockchain, there are a number of consensus protocols proposed including Proof of Stake, Proof of Elapsed Time, but most of the existing blockchain utilizes the computed Proof of Work (PoW) mechanism. Transaction security is secured in Bitcoin by using blocks with a hash-based Proof of Work (PoW) mechanism. PoW is a functional protocol that validates every incoming data to overcome spam attacks and Distributed Denial of Service (DDoS) attacks. Blockchain technology can store historically decentralized transaction data where each connected computer will store exactly the same data. To be able to perform an optimal transaction process, it is necessary to evaluate performance of the POW blockchain and find out what influences the transaction process. In this study, we compare simulation result of different block size and block interval to Block Propagation Time, time setup, and Average upload/download with selfish mining attack using NS3. The experimental results show that the smaller the block interval and block size, the smaller the Block Propagation time. It means that faster transactions are confirmed to peers on the network, and this affects the upload/download speeds.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Steganography and Watermarking Techniques
Original source
Nov 1, 2018·2018 IEEE International Conference on Data Mining Workshops (ICDMW)
50 cites
EGRET: Extortion Graph Exploration Techniques in the Bitcoin Network

Silivanxay Phetsouvanh, Frédérique Oggier, Anwitaman Datta

The Bitcoin network is a complex network that records anonymous financial transactions while encapsulating the relationships among its pseudonymous users. This paper proposes graph mining techniques to explore the relationships among wallet addresses (pseudonyms for Bitcoin users) suspected to be involved in a given extortion racket, exploiting the anonymity of the Bitcoin network to collect and launder money. Starting around Bitcoin addresses of potential interest, neighborhood subgraphs are analyzed in terms of path length and confluence to detect suspicious Bitcoin flow and other wallet addresses controlled by the suspected perpetrators. We show with a dataset of the Ashley Madison blackmail campaign from August 2015 how the mechanisms can be used both to estimate the amount of money that was extorted by the suspected perpetrators under the specific blackmail campaign, and also estimate the amount of money handled by them during the same period of time.

Open access
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Spam and Phishing Detection
Original source
Oct 29, 2018·2018 IEEE International Conference on Data Mining Workshops (ICDMW)
76 cites
Characterizing Entities in the Bitcoin Blockchain

Marc Jourdan, Sébastien Blandin, Laura Wynter, Pralhad Deshpande

Bitcoin has created a new exchange paradigm within which financial transactions can be trusted without an intermediary. This premise of a free decentralized transactional network however requires, in its current implementation, unrestricted access to the ledger for peer-based transaction verification. A number of studies have shown that, in this pseudonymous context, identities can be leaked based on transaction features or off-network information. In this work, we analyze the information revealed by the pattern of transactions in the neighborhood of a given entity transaction. By definition, these features which pertain to an extended network are not directly controllable by the entity, but might enable leakage of information about transacting entities. We define a number of new features relevant to entity characterization on the Bitcoin Blockchain and study their efficacy in practice. We show that even a weak attacker with shallow data mining knowledge is able to leverage these features to characterize the entity properties.

Open access
3 source records
cs.CR
cs.LG
Blockchain Technology Applications and Security
Original source
Oct 29, 2018·Proceedings of the 2018 International Conference on Cloud Computing and Internet of Things
21 cites
Intrusion Detection and Mitigation System Using Blockchain Analysis for Bitcoin Exchange

Suah Kim, Beomjoong Kim, Hyoung Joong Kim

Bitcoin exchanges rely heavily on traditional intrusion detection system to secure their system. However, this reliance has proven to be high risk, since Bitcoin and other blockchain-based transactions are not easily reversible. Many of the attacks have shown that the traditional intrusion detection system is not enough to safeguard against all possible attacks, and most importantly, in some cases, it takes a long time to assess the damage. In this paper, we first describe three types of intrusion models in Bitcoin exchanges and propose a detection and mitigation system using blockchain analysis for each. The proposed detection and mitigation system exploit the decentralized and public nature of Bitcoin blockchain to complement the existing traditional intrusion detection system as a fail-safe. The proposed method provides real-time intrusion detection capability that the existing work cannot provide. Although the proposed method is specifically for Bitcoin blockchain, similar ideas can be extended to other proof-of-work based blockchain cryptocurrencies.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Network Security and Intrusion Detection
Original source
Oct 24, 2018·IEEE Internet of Things Journal
116 cites
NormaChain: A Blockchain-Based Normalized Autonomous Transaction Settlement System for IoT-Based E-Commerce

Chunchi Liu, Yinhao Xiao, Vishesh Javangula, Qin Hu · 6 authors

Internet of Things (IoT)-based E-commerce is a new business model that relies on autonomous transaction management on IoT-devices. The management system toward IoT-based E-commerce demands autonomy, lightweight, and legitimacy. As blockchain is an innovative technology that is competent in governing the decentralized network, we adopt it to design the autonomous transaction management system on IoT E-commerce. However, current blockchain solutions, most namely cryptocurrencies, have fatal drawbacks of nonsupervisability and huge computational overhead, and hence cannot be directly applied on IoT-based E-commerce. In this paper, we propose NormaChain, a blockchain-based normalized autonomous transaction settlement system for IoT-based E-commerce. By designing a special three-layer sharding blockchain network, we can significantly increase transaction efficiency and system scalability. Additionally, by designing an innovative decentralized public key searchable encryption scheme (decentralized public key encryption with keyword search (PEKS) scheme), we can uncover illegal and criminal transactions and achieve crime traceability. Our new decentralized PEKS scheme cryptographically eliminates the dependence of a trusted central authority in the original PEKS scheme and instead expands it to a fully decentralized governance, which distributes the supervision power equally among all parties. More importantly, by proving NormaChain is secure against chosen ciphertext attacks and against the stealing of the secret key, we show that NormaChain prevents a legitimate user’s privacy from being violated by banks, supervisors or malicious adversaries. Finally, we deliver the NormaChain system with design details and full implementations. Experiments show that the average transaction-per-second on IoT devices is around 113, and the supervision accuracy is 100% when proper target illegal keywords are provided.

Blockchain Technology Applications and Security
Cryptography and Data Security
Spam and Phishing Detection
Original source
Oct 15, 2018·Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
115 cites
How You Get Shot in the Back

Geng Hong, Zhemin Yang, Sen Yang, Lei Zhang · 10 authors

As a new mechanism to monetize web content, cryptocurrency mining is becoming increasingly popular. The idea is simple: a webpage delivers extra workload (JavaScript) that consumes computational resources on the client machine to solve cryptographic puzzles, typically without notifying users or having explicit user consent. This new mechanism, often heavily abused and thus considered a threat termed "cryptojacking", is estimated to affect over 10 million web users every month; however, only a few anecdotal reports exist so far and little is known about its severeness, infrastructure, and technical characteristics behind the scene. This is likely due to the lack of effective approaches to detect cryptojacking at a large-scale (e.g., VirusTotal). In this paper, we take a first step towards an in-depth study over cryptojacking. By leveraging a set of inherent characteristics of cryptojacking scripts, we build CMTracker, a behavior-based detector with two runtime profilers for automatically tracking Cryptocurrency Mining scripts and their related domains. Surprisingly, our approach successfully discovered 2,770 unique cryptojacking samples from 853,936 popular web pages, including 868 among top 100K in Alexa list. Leveraging these samples, we gain a more comprehensive picture of the cryptojacking attacks, including their impact, distribution mechanisms, obfuscation, and attempts to evade detection. For instance, a diverse set of organizations benefit from cryptojacking based on the unique wallet ids. In addition, to stay under the radar, they frequently update their attack domains (fastflux) on the order of days. Many attackers also apply evasion techniques, including limiting the CPU usage, obfuscating the code, etc.

Advanced Malware Detection Techniques
Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Original source
Oct 15, 2018·Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
133 cites
MineSweeper

Radhesh Krishnan Konoth, Emanuele Vineti, Veelasha Moonsamy, Martina Lindorfer · 7 authors

A wave of alternative coins that can be effectively mined without specialized hardware, and a surge in cryptocurrencies' market value has led to the development of cryptocurrency mining ( cryptomining ) services, such as Coinhive, which can be easily integrated into websites to monetize the computational power of their visitors. While legitimate website operators are exploring these services as an alternative to advertisements, they have also drawn the attention of cybercriminals: drive-by mining (also known as cryptojacking ) is a new web-based attack, in which an infected website secretly executes JavaScript code and/or a WebAssembly module in the user's browser to mine cryptocurrencies without her consent. In this paper, we perform a comprehensive analysis on Alexa's Top 1 Million websites to shed light on the prevalence and profitability of this attack. We study the websites affected by drive-by mining to understand the techniques being used to evade detection, and the latest web technologies being exploited to efficiently mine cryptocurrency. As a result of our study, which covers 28 Coinhive-like services that are widely being used by drive-by mining websites, we identified 20 active cryptomining campaigns. Motivated by our findings, we investigate possible countermeasures against this type of attack. We discuss how current blacklisting approaches and heuristics based on CPU usage are insufficient, and present MineSweeper, a novel detection technique that is based on the intrinsic characteristics of cryptomining code, and, thus, is resilient to obfuscation. Our approach could be integrated into browsers to warn users about silent cryptomining when visiting websites that do not ask for their consent.

Open access
2 source records
Advanced Malware Detection Techniques
Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Original source
Oct 1, 2018·2018 International Conference on Information and Communication Technology Convergence (ICTC)
14 cites
Reptor: A Model for Deriving Trust and Reputation on Blockchain-based Electronic Payment System

Jaehong Ahn, Mingyu Park, Jeongyeup Paek

E-commerce has become an essential part of our life allowing us to buy products, request services, and transfer money easily with a press of a button. In general, people consider various factors of a product like price, quality, etc. before making purchases. When it comes to choosing one of the sellers having a same product with similar price, customers pay attention to each seller's reputation or the degree of trust to the seller. On the existing online payment systems, however, information such as reputation could be manipulated by the malicious (including the advertisers) giving extremely high or low ratings on purpose. Furthermore, as each individual has different criteria on ways to evaluate, the result value of reputation could be non-objective resulting in unreliability of data.In this paper, we propose Reptor, a model for calculation of trust and reputation with the values stored on blockchain-based payment system's ledger. Reptor is applied on blockchain-based online payment system which has a characteristic of immutability. Reptor normalizes the evaluations given by each user based on personal evaluation criteria changing over time. In addition, Reptor derives reputation of users and trust of one to another by applying psychological factors. Simulation results show that our Reptor is able to derive robust and objective values from immutable transactions on blockchain-based online payment system.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Steganography and Watermarking Techniques
Original source
Oct 1, 2018·2018 Fourth International Conference on Advances in Computing, Communication & Automation (ICACCA)
21 cites
Trust Network, Blockchain and Evolution in Social Media to Build Trust and Prevent Fake News

Wee Jing Tee, Raja Kumar Murugesan

Fake news on major social media platforms has real-world consequences on the sentiments of citizens. For instance, it has the power to influence the election results of a country. The problem statement is fake news detection and prevention on social media presents unique challenges that require novel algorithms. The research methodology is to implement current blockchain technology with advanced Artificial Intelligence in social media platform to prevent fake news. This study aims to provide a substantial review on implementing blockchain on social media in order to build public trust on credible news and prevent spread of fake news via social media. In particular, this paper provides the research problem and discusses state-of-the-art blockchain solutions and technical constraints as well as points out the future research direction in tackling the challenges.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Misinformation and Its Impacts
Original source
Oct 1, 2018·2018 IEEE SmartWorld, Ubiquitous Intelligence & Computing, Advanced & Trusted Computing, Scalable Computing & Communications, Cloud & Big Data Computing, Internet of People and Smart City Innovation (SmartWorld/SCALCOM/UIC/ATC/CBDCom/IOP/SCI)
26 cites
Managing Lifetime Healthcare Data on the Blockchain

Mark Hanley, Hitesh Tewari

The widespread adoption of fax machines in the 1980s revolutionised everyday communications. It was quickly adopted as the standard form of communication across the globe. Since then, the internet has replaced fax as a truly global form of instant communication. However, the fax machine still reigns as the primary form of communication in a number of industries, healthcare being one of them. This paper presents a system that uses a blockchain and an off-chain centralised data storage to give patients and medical professionals instant access to their medical records from anywhere. By assigning each medical record a pseudo anonymous identifier, a second layer "blockchain" for each user can be created allowing for the rapid collection and querying of data. The off-chain pseudo anonymous data storage allows for the data to remain unencrypted enabling the rapid generation of anonymous medical datasets which can be used for machine learning and data mining on the data, potentially bringing many benefits to the healthcare industry.

Open access
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Blockchain Technology Applications and Security
Original source
Oct 1, 2018·2018 13th International Conference on Malicious and Unwanted Software (MALWARE)
3 cites
Unmasking Criminal Enterprises: An Analysis of Bitcoin Transactions

Jonathan Oakley, Carl Worley, Lu Yu, Richard R. Brooks · 5 authors

With the rise of cryptographic ransomware, Bitcoin has found a niche as the standard currency for ransoms. While Bitcoin is pseudonymous, it provides no guarantee of untraceability. As a result, another niche has arisen-Bitcoin money laundering. Hidden Markov Models (HMMs) have previously been used in a number of applications where traditional pattern recognition falls short. In this paper, HMMs are inferred from transactions in the public blockchain in an attempt to link users, events, and enterprises. We introduce a proof-of-concept algorithm to infer HMMs from the Bitcoin blockchain.

Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Spam and Phishing Detection
Original source
Oct 1, 2018·2018 IEEE International Symposium on Technologies for Homeland Security (HST)
6 cites
Blockchain-enhanced Identities for Secure Interaction

Dipto Chakravarty, Tushar Deshpande

Securing identities in online communities like Facebook and Google requires thinking beyond mobility and cloud as federation methods can be gamed. While use of adaptive authentication and biometrics on mobile devices has become the norm, its security can be bolstered lot more with a distributed ledger like blockchain. This paper presents an augmented security model based on the blockchain distributed ledger, depicting how blockchain can help us build decentralized identity ecosystem.

Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Spam and Phishing Detection
Original source
Sep 27, 2018·IEEE Internet of Things Journal
71 cites
Coin Hopping Attack in Blockchain-Based IoT

Saide Zhu, Wei Li, Hong Li, Ling Tian · 6 authors

With dramatic developments of blockchain technology, a number of blockchain-based applications emerge rapidly, among which the incorporation of blockchain into Internet of Things is one of the most valued research direction. Such powerful incorporation is a double-sided sword, i.e., it can benefit both individuals and society but has the vulnerability to coin hopping attack that is a new type of pool mining attack and hard to happen in traditional blockchain networks. In this paper, we theoretically prove the feasibility of coin hopping attack, deeply analyze the conditions of attack implementation, and comprehensively investigate the impacts of coin hopping attack. Moreover, some defense strategies are addressed. To our best knowledge, this paper is the first work targeting coin hopping attack.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Crime, Illicit Activities, and Governance
Original source
Sep 18, 2018·IEEE Transactions on Systems Man and Cybernetics Systems
86 cites
Improving Bitcoin Ownership Identification Using Transaction Patterns Analysis

Tao-Hung Chang, Davor Svetinović

Bitcoin is a cryptocurrency and a financial transaction network implemented using blockchain technology. Users in the Bitcoin network use pseudonymous Bitcoin addresses and conduct transactions with others without revealing their real identities. In order to further enhance their privacy and convenience, users often use a large number of different addresses. In this paper, we analyze different patterns of transactions occurring in the Bitcoin network in order to cluster addresses that share the same ownership. In order to evaluate the proposed clustering approach, Bitcoin addresses belonging to known entities are tagged and these are used in conjunction with the Gini impurity index to test the accuracy of the recovered identity-based clusters. The results show that our heuristic was able to detect relationships between Bitcoin addresses that were missed by the existing heuristics.

2 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Original source
Sep 1, 2018·International Journal of Engineering & Technology
5 cites
Analysis of Spam Transaction on the Blockchain

Tae Kyoung Kim, . ., . .

Background/Objectives: The blockchain has been applied to many fields. Users are concerned about its security. The primary goal of this study is supporting the security service to protect DDoS attack.Methods/Statistical analysis: To provide security service in the blockchain, the security model is suggested. This model can filter out illegitimate traffic and exchange information with other security switches to determine whether a connected node is a normal node or an abnormal node. Each procedure of the proposed model has been described. Also, two different attack types are used to show the operation process of suggested model.Findings: Cyberattacks attempting to impact technology services availability continue to increase. Thus, DDoS is one of the most common type of attacks can also cause the most disruption to internet services. But blockchain has the characteristics of decentralization and peer to peer. This makes it harder to disrupt than conventional distributed application. Nevertheless, DDoS attacks remain a persistent threat. Therefore, a security model is suggested which can effectively block and respond to DDoS attacks.Improvements/Applications: The suggested model makes it possible to protect the spam transaction attacks in blockchain network.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Caching and Content Delivery
Original source
Sep 1, 2018·2018 IEEE 39th Sarnoff Symposium
16 cites
Immutability Measure for Different Blockchain Structures

Hyong S. Kim, Ke Wang

The main advantage of Blockchain technology is the immutability of data maintained by decentralized systems. Earlier studies introduce the probability of attackers succeeding in modifying legitimate data in the blocks. We propose “immutability measure”, a metric that indicates the degree of difficulty in modifying existing data in Blockchain. We propose different blockchain structures that can be more appropriate for different applications. There are several parameters that determine the difficulty of modifying data in Blockchain. We analyze the impact of each of these parameters on the immutability measure of various blockchain structures. We also study the required computational and electrical power as well as the time for a successful attack in various blockchain structures. We demonstrate that our proposed blockchain structures can exponentially improve the immutability measure with a nominal increase in computing resources.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source