A bitcoin node needs to download the full block contents of the entire blockchain, before actually being able to send and receive transactions on bitcoin broadcast network, except simple payment verification clients which require only block headers and bloom filters to sync with others peers available on the network. Transactions/Blocks pass through a complex process at sender and receiver than it apparently looks to be. During transmission transactions/blocks are broken down into smaller chunks of data so that they can be carried on the wire. These chunks are given appropriate headers, encapsulated and then passed through several layers to reach the destination. In this paper we captured Bitcoin packets using Wireshark and deeply investigated and analyzed them. We investigated how bitcoin transaction/block messages work and what values and parameters are considered during this whole process.
Pasu Poonpakdee, Jarotwan Koiwanit, Chumpol Yuangyai, Watchara Chatwiriya
Our global market is emerging transformation strategy that can make the difference between success and failure. Smart contract systems through developments of technological innovations are increasingly seen as alternative technologies to impact transactional processes significantly. Blockchain is a smart contract protocol with trust offering the potential for creating new transaction platforms and thus shows a radical change of the current core value creation in third parties. These results in enormous cost and time savings and the reduced risk for the parties. This study proposed a method to improve the efficiency of distributed consensus in blockchains using epidemic algorithm. The results showed that epidemic protocols can distribute the information similar to blockchain.
A great many cloud users face a difficult challenge in respect of the forthcoming EU General Data Protection Regulation, which comes into effect on 25th May, 2018. While all computer systems are continuously under attack, those who operate conventional distributed network systems stand a far greater chance of being able to demonstrate compliance than those who use cloud based systems. The main reason for this discrepancy between the two approaches is down to the as yet unsolved cloud forensic problem, meaning many cloud users will be completely unable to demonstrate compliance with the new regulation, thus exposing themselves to potentially massive fines after 25th May. We consider the possible use of a crypto-currency based mechanism to address the as yet unsolved cloud forensic problem. Crypto-currencies are becoming a global phenomenon, gaining more attention from media, venture capitalists, financial and government institutions. We focus on the operational risk and the market risk related to crypto-currencies, especially the dominating Bitcoin. Operational risk encompasses the actions that undermine the technological infrastructure and security assumptions of crypto-currencies. We discuss how blockchain technology could improve the efficiency of financial infrastructures, as well as the inevitable vulnerabilities of operational risk of software, open-source governance, and code maintenance. We summarise the literature findings on the co-movement of crypto- currencies with different currencies, indices, and commodities, to show the role of crypto-currency as a commodity, currency, or a speculative investment under portfolio diversification theory. Particularly now that we have seen successful attacks on crypto- currencies in action, it is important to understand where these weaknesses lie, and to endeavour to find out to what extent the use of such technology might expose companies using this technology for GDPR compliance. In the light of the robustness of this approach, we consider whether the underlying blockchain technology could, in turn, be practically applied to addressing the cloud forensic problem. This paper looks at the pros and cons of the blockchain/bitcoin approach, seeking to identify weaknesses, potential benefits offered versus the additional resource costs/latency involved, and considers whether such an approach might be used to secure cloud forensic trails.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
George D. Webster, Ryan Harris, Zachary D. Hanif, Bruce A. Hembree · 6 authors
For decades it has been acknowledged that sharing security information and collaboration between security practitioners are a necessity. Yet, effective sharing and collaboration are rare. A gamut of legislative acts, executive orders, academic works, and private sector initiatives have discussed aspects of the problem and aimed to be the catalyst needed to fix the situation. But almost 30 years since these efforts started, the state of sharing and collaboration is still technically complicated, slow, untrusted, and impeded by bureaucratic woes. This work identifies the challenges of sharing security artifacts and uses real-world examples to illustrate our findings. Based on this knowledge, we propose a new model for sharing and collaboration, CARE. The CARE architecture eases many of the privacy, secrecy, lineage, and structure issues that plague current sharing communities and platforms. We then build upon this foundation to introduce a marketplace based on smart contracts with transactional privacy over a distributed blockchain. Therefore, CARE incentivizes sharing, combats free riding, and provides an immutable ledger for the attribution of events. This paradigm shift, overcomes the challenges of sharing while providing new opportunities for business models, insurance risk assessments, and government backed incentivisation.
Benjamin Johnson, Áron Lászka, Jens Großklags, Tyler Moore
Cryptocurrency exchanges are frequently targeted and compromised by cyber-attacks, which may lead to significant losses for the depositors and closure of the affected exchanges. These risks threaten the viability of the entire public blockchain ecosystem since exchanges serve as major gateways for participation in public blockchain technologies. In this paper, we develop an economic model to capture the short-term incentives of cryptocurrency exchanges with respect to making security investments and establishing transaction fees. Using the model, we derive conclusions regarding an exchange's optimal economic decisions, and illustrate key features of these conclusions using graphs based on real-world data. Our security investment model exhibits horizontal scaling properties with respect to reducing exposure to losses, and may be of special interest to exchanges operating in markets with high price volatility.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Poverty alleviation loan plays an important role in the poverty alleviation strategy of China. To improve the loan service efficiency and reduce service cost, it is necessary to build a management system for this business. However, current management systems for the loan are usually deployed in single service mode, also the transactions are not transparent and traceable to most of the roles participating in the process. Its data privacy protection mechanism is not robust enough facing various cyber attacks. To overcome these challenges, we propose loan on blockchain (LoC), a novel poverty alleviation loan management system based on smart contracts. A digital account model is designed for the transfer of assets between centralized and decentralized ledgers, and locking and unlocking algorithms are introduced for smart contracts. Digital signature and oracle are introduced to protect the data privacy.
The anonymous and decentralized nature of cryptocurrencies has turned them into a powerful weapon in the cyberarsenal of national and international criminal groups by facilitating their illicit activities while evading prosecution. However, despite the numerous challenges that the international law enforcement community faces when investigating cryptocurrencies, a number of investigation opportunities do exist.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Kentaroh Toyoda, Tomoaki Ohtsuki, P. Takis Mathiopoulos
In recent years, Bitcoin has been used for many services and purposes, e.g. gambling, marketplace, but also even as an investment scam. In order to clarify how Bitcoin is used, it is in great importance to identify what kind of services are operated by Bitcoin addresses. In this paper, we propose a multiclass service identification scheme in Bitcoin based on novel transaction history summarization. Our novelty is to propose how transaction history is retrieved and how the retrieved transactions are processed for better identification. When a Bitcoin address is given, the characteristics of its transaction history is calculated as features. Then, the set of calculated features is fed into a supervised classifier and the services operated by the given Bitcoin addresses are identified among seven major services: (i) exchange, (ii) faucet, (iii) gambling, (iv) investment scam, (v) marketplace, (vi) mining pool, and (vii) mixer. To our knowledge, we are the first to propose a multi-class identification. We show that our scheme achieves 72 % of accuracy through performance evaluation with more than 26,000 Bitcoin addresses that have been used for seven services/purposes from Jan. 2009 to Feb. 2017.
Bitcoin mining is a process that serves to both verify sets of transactions and slowly introduce new currency into the system. As a reward for performing this process, miners are paid in bitcoin for the blocks they mine. It was originally thought that there was no incentive in trying to subvert the mining protocol—in other words, there was no reason to believe that miners could be profitable by somehow cheating the system. As it turns out, a specific strategy called “selfish mining” was discovered to increase profitability for miners under certain conditions. This paper presents the selfish mining strategy, traverses a revenue model associated with the strategy, and then simulates the bitcoin network to see how this revenue model holds up under complicated network conditions. Specifically, the selfish mining revenue model typically assumes there is one selfish miner in the network—I simulate the more realistic case of there being many selfish miners in the network. We find that the revenue model can overestimate selfish miner revenues by up to 100% and underestimate them by up to 300% depending on network variables such as the number of selfish miners, the power of those miners, and network latency (the speed of block propagation from one miner to another).
Purpose The purpose of this paper is to highlight the intelligence and investigatory challenges experienced by law enforcement agencies in discovering the identity of illicit Bitcoin users and the transactions that they perform. This paper proposes solutions to assist law enforcement agencies in piecing together the disparate and complex technical, behavioural and criminological elements that make up cybercriminal offending. Design/methodology/approach A literature review was conducted to highlight the main law enforcement challenges and discussions and examine current discourse in the areas of anonymity and attribution. The paper also looked at other research and projects that aim to identify illicit transactions involving cryptocurrencies and the darknet. Findings An optimal solution would be one which has a predictive capability and a machine learning architecture which automatically collects and analyses data from the Bitcoin blockchain and other external data sources and applies search criteria matching, indexing and clustering to identify suspicious behaviours. The implementation of a machine learning architecture would help improve results over time and would be less manpower intensive. Cyber investigators would also receive intelligence in a format and language that they understand and it would allow for intelligence-led and predictive policing rather than reactive policing. The optimal solution would be one which allows for intelligence-led, predictive policing and enables and encourages information sharing between multiple stakeholders from the law enforcement, financial intelligence units, cyber security organisations and fintech industry. This would enable the creation of red flags and behaviour models and the provision of up-to-date intelligence on the threat landscape to form a viable intelligence product for law enforcement agencies so that they can more easily get to the who, what, when and where. Originality/value The development of a functional software architecture that, in theory, could be used to detected suspicious illicit transactions on the Bitcoin network.
Internet is a system of inter-connected computer networks and is today’s significant platform of information & transmission. Its far-flung utilization has led to its entrance in the sphere of trade and commerce, which, in turn, has given escalate to cyber crimes. It is the troubling for parliament as well as law enforcement agencies because of absolute wideness and outreach of cyber space. So to tackle this, cyber security is an essential component to be considered if any person wants to get protected from mischievous people and malicious software from the internet. Internet is the one tool which gives rise to various threats to the computer and often these threats are intentional and developed by people those who are having malicious intention. Before the commencement of Information Technology Act, 2000, the Act which was regulating such crimes was The Indian Penal Code, 1860. But The Indian Penal Code, 1860 was found inadequate to serve and regulate the demands of new crimes that were rising from widespread Internet expansion. Moreover some of the traditional crimes such as fraud, espionage, solicitation, conspiracy, securities etc. are now being performed through Internet which necessitates a new legislation to check them. So this was lead to enactment of I.T Act, 2000 and motive behind this act was prevention and control of cyber crimes. But after commencement of this act, it turned indispensable to institute certain amendments in the various provisions of IPC, 1860 and The Indian Evidence Act, 1872, so that it could meet the prerequisite of the cyber space crimes. The I.T. Act, 2000 is based on UNCITRAL Model on e-commerce, 1996. The methodology used in the research on this study is exploratory-study and case-study approach and input from certain study materials, newspapers and internet.
Bitcoin has introduced a new concept that could feasibly revolutionise the entire Internet as it exists, and positively impact on many types of industries including, but not limited to, banking, public sector and supply chain. This innovation is grounded on pseudo-anonymity and strives on its innovative decentralised architecture based on the blockchain technology. Blockchain is pushing forward a race of transaction-based applications with trust establishment without the need for a centralised authority, promoting accountability and transparency within the business process. However, a blockchain ledger (e.g., Bitcoin) tend to become very complex and specialised tools, collectively called “Blockchain Analytics”, are required to allow individuals, law enforcement agencies and service providers to search, explore and visualise it. Over the last years, several analytical tools have been developed with capabilities that allow, e.g., to map relationships, examine flow of transactions and filter crime instances as a way to enhance forensic investigations. This paper discusses the current state of blockchain analytical tools and presents a thematic taxonomy model based on their applications. It also examines open challenges for future development and research.
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Advanced Steganography and Watermarking Techniques
Manasa Sastry J. K, Astha Pandey, M. S. Dahiya, L Magwa M
Background: From the time immemorial there have been several types of crimes. With the advancement in science and technology, digital crimes have become very prominent. One among which is Bit-Coin crypto-currency frauds which are gaining momentum in the types of frauds encountered by law enforcement agencies. Bit-Coin is a growing form of digital crypto-currency that is created and held electronically that has no centralized control systems, that governs the transactions. It is the most secretive form of money transfer between two anonymous people all over the world. It is on a superficial layer used to purchase or sell goods electronically, similar to the conventional dollars that are traded digitally where individual ledgers are maintained by all the bit coin users to have access to the building block-chain. However, a masked layer consists of a dark-net where enormous amounts of money are concealed in cold storage where illegal websites and illicit commerce like ATM/ Debit/ Credit Card scams subjecting to illegal transactions rule over the deep net by utilizing the innocent public money. Case Presentation: The present study involves a case study where it was noted that innumerable ATM Debit/Credit Cards were skimmed and the illicit money was exchanged with this crypto-currency using an illicit website for bit coin mining and storing huge amounts of anonymous public money that was dictated by a few Nigerian Fraudsters running this racket all over the nation.
Younggee Hong, Hyunsoo Kwon, Jihwan Lee, Junbeom Hur
Bitcoin mixing services improve anonymity by breaking the connection between Bitcoin addresses. In the darkweb environment, many illegal trades, such as in drugs or child pornography, avoid their transactions being traced by exploiting mixing services. Therefore, de-mixing algorithms are needed to identify illegal financial flows and to reduce criminal activity. Unfortunately, to the best of our knowledge, few studies on analyzing mixing services and de-anonymizing transactions have been proposed. In this paper, we conduct an in-depth analysis of real-world mixing services, and propose a de-mixing algorithm for Helix, one of the most widely used Bitcoin mixing services. The proposed algorithm de-anonymizes the relationship between the input and output addresses of mixing services by exploiting the static and dynamic parameters of mixing services. Our experiment showed that, we could identify the relationships between the input and output addresses of the Helix mixing service with a 99.14% accuracy rate.
In the present techno-political moment it is clear that ignoring or dismissing the hype surrounding blockchain is unwise, and certainly for regulatory authorities and governments who must keep a grip on the technology and those promoting it, in order to ensure democratic accountability and regulatory legitimacy within the blockchain ecosystem and beyond. Blockchain is telling (and showing) us something very important about the evolution of capital and neoliberal economic reason, and the likely impact in the near future on forms and patterns of work, social organization, and, crucially, on communities and individuals who lack influence over the technologies and data that increasingly shape and control their lives. In this short essay I introduce some of the problems in the regulation of blockchain and offer counter-narratives aimed at cutting through the hype fuelling the ascendency of this most contemporary of technologies.
Ransomware is a type of malware that encrypts the files of infected hosts and demands payment, often in a crypto-currency like Bitcoin. In this paper, we create a measurement framework that we use to perform a large-scale, two-year, end-to-end measurement of ransomware payments, victims, and operators. By combining an array of data sources, including ransomware binaries, seed ransom payments, victim telemetry from infections, and a large database of bitcoin addresses annotated with their owners, we sketch the outlines of this burgeoning ecosystem and associated third-party infrastructure. In particular, we are able to trace the financial transactions, from the acquisition of bitcoins by victims, through the payment of ransoms, to the cash out of bitcoins by the ransomware operators. We find that many ransomware operators cashed out using BTC-e, a now-defunct Bitcoin exchange. In total we are able to track over $16 million USD in likely ransom payments made by 19,750 potential victims during a two-year period. While our study focuses on ransomware, our methods are potentially applicable to other cybercriminal operations that have similarly adopted Bitcoin as their payment channel.
With the price of Bitcoin ascending to new heights in 2017, the rocketing valuation of cryptocurrencies continues its momentum into 2018. Evidence of the massive growth of these digital assets can be seen in the massive spikes in new clients at companies like Coinbase, adding 100,000 users in a 24-hour period, and Binance, which recently expanded its user base by 240,000 users in just one hour. The financial industry and Silicon Valley are not the only groups who have caught the cryptocurrency fever. Malicious actors have discovered that cryptocurrency newbies are unwitting targets that offer a consistent stream of revenue. Through our global network visibility, Cisco has observed many of these attacks originating from bulletproof hosting infrastructures located in the Eastern European region. This area is a hotbed for crypto theft and other computer crimes such as ransomware, botnets, DDoS services and credit card fraud. Some criminals have even extended beyond the digital world by kidnapping and demanding ransoms in Bitcoin, such as the case in the reported kidnapping and ransom of Pavel Lerner. Lerner was a lead analyst at Ukraine-based digital currency exchange, Exmo, who was released by his kidnappers after a $1 million Bitcoin payment was made. The event illustrates the desperate lengths some criminals will go in order to steal cryptocurrency. Joining the Enterprise Ethereum Alliance in 2017, Cisco is committed to protecting these new crypto technologies. Over the past year Cisco researchers have teamed up with the Ukraine Cyber Police to track a Bitcoin phishing operation dubbed the "Coinhoarder" campaign that has been tied to the theft of tens of millions of dollars worth of Bitcoin. Credential phishing continues to be one of the biggest security challenges for internet users, and cryptocurrency phishers have found it to be a very lucrative form of attack. In 2017, Chainalysis reported Ethereum phishing as being the number one source of theft in that ecosystem with estimates placing the total amount stolen at $115 million. Google also recently published a research paper stating credential phishing is one of their top security challenges. Cisco has been proactive in detecting phishing domains in predictive fashion to help protect our customers. Additionally, we have been working with security personnel at top cryptocurrency wallets and exchanges, such as Blockchain.info and Coinbase, to help protect the cryptocurrency community members from having their tokens stolen.
Jakob Demant, Rasmus Munksgaard, David Décary-Hêtu, Judith Aldridge
Objective: There is broad agreement in the literature on the transformative potential of drug cryptomarkets that allow sourcing on a global market and consequently the circumvention of existing supply chains between producer and end user. We examine whether the transformative potential of drug cryptomarkets has been realized in two ways: Are cryptomarket drug sellers found in production and transit countries? and Do we see the increased use of shipping across international borders over time? Method: Using data collected by the DATACRYPTO software tool between 2013 and 2016, we characterize cryptomarket buyer behavior through the product reviews (i.e., sales transactions) posted on 15 cryptomarkets. Findings: Cryptomarket drug sellers are predominantly based in countries of Europe, North America, and Oceania. For both cannabis resin and cocaine sold on cryptomarkets, we find that known production and transit countries are not the primary sources of supplied drugs but rather key countries of consumption. In the case of 3,4-methylenedioxymethamphetamine, we observe that the Netherlands, a known production country, is the largest supplier. We further observe tendencies over time toward increased localization of cryptomarkets with regard to product destinations. Discussion: Though cryptomarkets offer a potentially global platform for drug distribution, they do not tend to be used as such. We explain our results with reference to buyers’ preferences regarding safety, risk, and convenience, alongside structural limitations for cryptomarket use such as bitcoin availability.
Masarah Paquet-Clouston, Bernhard Haslhofer, Benoît Dupont
Ransomware can prevent a user from accessing a device and its files until a ransom is paid to the attacker, most frequently in Bitcoin. With over 500 known ransomware families, it has become one of the dominant cybercrime threats for law enforcement, security professionals and the public. However, a more comprehensive, evidence-based picture on the global direct financial impact of ransomware attacks is still missing. In this paper, we present a data-driven method for identifying and gathering information on Bitcoin transactions related to illicit activity based on footprints left on the public Bitcoin blockchain. We implement this method on-top-of the GraphSense open-source platform and apply it to empirically analyze transactions related to 35 ransomware families. We estimate the lower bound direct financial impact of each ransomware family and find that, from 2013 to mid-2017, the market for ransomware payments has a minimum worth of USD 12,768,536 (22,967.54 BTC). We also find that the market is highly skewed with only a few number of players responsible for the majority of the payments. Based on these research findings, policy-makers and law enforcement agencies can use the statistics provided to understand the size of the illicit market and make informed decisions on how best to address the threat.
The emergence of block-chain technology in the form known as “cryptocurrency” is an evolution of the global monetary system that is here to stay. The rise of this new variant of distributed ledger technology has been dismissed by some who believe it offers no real value and denigrated by others who believe its prevalence raises national security concerns. Many of these concerns stem from the common misperception that all cryptocurrencies have cryptographic properties which render them anonymous and can be used by terrorists and other undesirables to fund their criminal enterprises. After discussing the basic technical components of blockchain technology, this article distinguishes that, contrary to popular belief, most cryptocurrencies are not what could be classified as “anonymous,” but are instead “pseudonymous.” These pseudonymous cryptocurrencies can actually enhance law enforcement’s ability to track criminal users’ financial activities. It further refines the notion that all cryptocurrencies are the same by noting that some are more anonymous than others, and some are in fact more identifiable than fiat currencies. Instead of resisting cryptocurrencies altogether, this article argues that the United States government should embrace those cryptocurrencies that are pseudonymous and should further study those which are considered anonymous.
Since Bitcoin appeared in 2009, the digital currency has been hailed as an Internet marvel and decried as the preferred transaction vehicle for all manner of criminals. It has left nearly everyone without a computer science degree confused: Just how do you “mine” money from ones and zeros?\nThe answer lies in a technology called blockchain, which can be used for much more than Bitcoin. A general-purpose tool for creating secure, decentralized, peer-to-peer applications, blockchain technology has been compared to the Internet itself in both form and impact. Some have said this tool may change society as we know it. Blockchains are being used to create autonomous computer programs known as “smart contracts,” to expedite payments, to create financial instruments, to organize the exchange of data and information, and to facilitate interactions between humans and machines. The technology could affect governance itself, by supporting new organizational structures that promote more democratic and participatory decision making.\nPrimavera De Filippi and Aaron Wright acknowledge this potential and urge the law to catch up. That is because disintermediation—a blockchain’s greatest asset—subverts critical regulation. By cutting out middlemen, such as large online operators and multinational corporations, blockchains run the risk of undermining the capacity of governmental authorities to supervise activities in banking, commerce, law, and other vital areas. De Filippi and Wright welcome the new possibilities inherent in blockchains. But as Blockchain and the Law makes clear, the technology cannot be harnessed productively without new rules and new approaches to legal thinking.
Bitcoin cryptocurrency system enables users to transact securely and pseudo-anonymously by using an arbitrary number of aliases (Bitcoin addresses). Cybercriminals exploit these characteristics to commit immutable and presumably untraceable monetary fraud, especially via ransomware; a type of malware that encrypts files of the infected system and demands ransom for decryption. In this paper, we present our comprehensive study on all recent ransomware and report the economic impact of such ransomware from the Bitcoin payment perspective. We also present a lightweight framework to identify, collect, and analyze Bitcoin addresses managed by the same user or group of users (cybercriminals, in this case), which includes a novel approach for classifying a payment as ransom. To verify the correctness of our framework, we compared our findings on CryptoLocker ransomware with the results presented in the literature. Our results align with the results found in the previous works except for the final valuation in USD. The reason for this discrepancy is that we used the average Bitcoin price on the day of each ransom payment whereas the authors of the previous studies used the Bitcoin price on the day of their evaluation. Furthermore, for each investigated ransomware, we provide a holistic view of its genesis, development, the process of infection and execution, and characteristic of ransom demands. Finally, we also release our dataset that contains a detailed transaction history of all the Bitcoin addresses we identified for each ransomware.