Cryptocurrency mining is an important process that ensures the reliability of cryptocurrency system. A significant computing power is used in cryptocurrency mining. One of the most important tasks in cryptocurrency mining is to ensure the maximum performance of used computing capacities. In this paper we review the existing Ethereum mining algorithm and search for possibilities for speeding up the mining by applying a new asynchronous mining algorithm.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Smart contracts enable autonomous decentralized organizations (DADs) in large, trustless and open trading networks by specifying conditions for automated transactions of cryptographically secured data. This data could represent cryptocurrencies but also sensor data or commands to Cyber-Physical Systems (CPS) connected to the Internet. To provide reliability, the contract code is enforced by consensus and the transactions it triggers are nonrevertible, even if they were not intended by the programmer, which could lead to dangerous system behavior. In this paper, we conduct a survey over existing smart contract platforms and languages to determine requirements for the design of a safer contract language. Subsequently we propose concepts that enhance the understanding of code by limiting confusing language constructs, such as nesting, arbitrary naming of operations, and unreadable hash identifiers. This enables human reasoning about the contract semantics on a much higher abstraction layer, because a common understanding can be derived from the language specification itself. We implement these concepts in a new domain specific language called SmaCoNat to illustrate the feasibility and show that our concepts are barely covered by existing languages but significantly enhance readability and safety without violating deterministic parsability.
Marius Musch, Christian Wressnegger, Martin Johns, Konrad Rieck
With the introduction of memory-bound cryptocurrencies, such as Monero, the implementation of mining code in browser-based JavaScript has become a worthwhile alternative to dedicated mining rigs. Based on this technology, a new form of parasitic computing, widely called cryptojacking or drive-by mining, has gained momentum in the web. A cryptojacking site abuses the computing resources of its visitors to covertly mine for cryptocurrencies. In this paper, we systematically explore this phenomenon. For this, we propose a 3-phase analysis approach, which enables us to identify mining scripts and conduct a large-scale study on the prevalence of cryptojacking in the Alexa 1 million websites. We find that cryptojacking is common, with currently 1 out of 500 sites hosting a mining script. Moreover, we perform several secondary analyses to gain insight into the cryptojacking landscape, including a measurement of code characteristics, an estimate of expected mining revenue, and an evaluation of current blacklist-based countermeasures.
The exponential growth of wireless-based solutions, such as those related to the mobile smart devices (e.g., smart-phones and tablets) and Internet of Things (IoT) devices, has lead to countless advantages in every area of our society. Such a scenario has transformed the world a few decades back, dominated by latency, into a new world based on an efficient real-time interaction paradigm.Recently, cryptocurrency have contributed to this technological revolution, the fulcrum of which are a decentralization model and a certification function offered by the so-called blockchain infrastructure, which make it possible to certify the financial transactions, anonymously. However, it should be observed how this challenging scenario has generated new security problems directly related to the involved new technologies (e.g., e-commerce frauds, mobile bot-net attacks, blockchain DoS attacks, cryptocurrency scams, etc.). In this context, we can acknowledge that the scientific community efforts are usually oriented toward specific solutions, instead to exploit all the available technologies, synergistically, in order to define more efficient security paradigms. This paper aims to indicate a possible approach able to improve the security of people and things by introducing a novel paradigm to security defined Internet of Entities (IoE). It is a mechanism for the localization of people and things, which exploits both the huge number of existing wireless-based devices and the blockchain-based distributed ledger technology, overcoming the limits of traditional localization approaches, but without jeopardizing the user privacy. Its operation is based on two core elements with interchangeable roles, entities and trackers, which can be very common elements such as smart-phones, tablets, and IoT devices, and its implementation requires minimal efforts thanks to the existing infrastructures and devices.
Anonymity networks and hidden services like those accessible in Tor, also called the "darknet", in combination with cryptocurrencies like bitcoin provide a relatively safe environment for criminal online activities. While this is a challenge for law enforcement, it brings opportunities for researchers to monitor these activities as they are often not really hidden but rather obfuscated and/or anonymized. In this paper we discuss such a monitoring approach for product sales in the darknet. We collect bitcoin addresses and data about product offerings in a number of shops run as hidden services in Tor. We then analyze transactions in the bitcoin blockchain that can be mapped to specific product sales in these shops.
In recent years, the Darknet has become one of the most discussed topics in cyber security circles. Current academic studies and media reports tend to highlight how the anonymous nature of the Darknet is used to facilitate criminal activities. This paper reports on a recent research in four Darknet forums that reveals a different aspect of the Darknet. Drawing on our qualitative findings, we suggest that many users of the Darknet might not perceive it as intrinsically criminogenic, despite their acknowledgement of various kinds of criminal activity in this network. Further, our research participants emphasised on the achievement of constructive socio-political values through the use of the Darknet. This achievement is enabled by various characteristics that are rooted in the Darknet’s technological structure, such as anonymity, privacy, and the use of cryptocurrencies. These characteristics provide a wide range of opportunities for good as well as for evil.
Aug 2, 2018·Jan Rüth, Torsten Zimmermann, Konrad Wolsing, and Oliver Hohlfeld. 2018. Digging into Browser-based Crypto Mining. In IMC '18: Internet Measurement Conference, October 31-November 2, 2018, Boston, MA, USA. ACM, New York, NY, USA, 7 pages
Jan Rüth, Torsten Zimmermann, Konrad Wolsing, Oliver Hohlfeld
Mining is the foundation of blockchain-based cryptocurrencies such as Bitcoin rewarding the miner for finding blocks for new transactions. The Monero currency enables mining with standard hardware in contrast to special hardware (ASICs) as often used in Bitcoin, paving the way for in-browser mining as a new revenue model for website operators. In this work, we study the prevalence of this new phenomenon. We identify and classify mining websites in 138M domains and present a new fingerprinting method which finds up to a factor of 5.7 more miners than publicly available block lists. Our work identifies and dissects Coinhive as the major browser-mining stakeholder. Further, we present a new method to associate mined blocks in the Monero blockchain to mining pools and uncover that Coinhive currently contributes 1.18% of mined blocks having turned over 1293 Moneros in June 2018.
Cryptocurrencies like Bitcoin not only provide a decentralized currency, but also provide a programmatic way to process transactions. Ethereum, the second largest cryptocurrency next to Bitcoin, is the first to provide a Turing-complete language to specify transaction processing, thereby enabling so-called smart contracts. This provides an opportune setting for attackers, as security vulnerabilities are tightly intertwined with financial gain. In this paper, we consider the problem of automatic vulnerability identification and exploit generation for smart contracts. We develop a generic definition of vulnerable contracts and use this to build TEE THER, a tool that allows creating an exploit for a contract given only its binary bytecode. We perform a large-scale analysis of all 38,757 unique Ethereum contracts, 815 out of which our tool finds working exploits for—completely automated.
Banking malware is malicious software that aims to steal money from victims via manipulated bank transfers in online banking. This paper describes how the profits of banking malware are generated and subsequently laundered, with a particular focus on the use of bitcoins and other digital payment methods. Computers are infected with banking malware via phishing emails, in which people are persuaded in various ways to click on links or open attachments, or via exploit kits, programs that try to find weak spots in the security of computer systems. After infection, bank transfers of the online banking accounts of victims are manipulated via fake website screens (web injects). Behind the screens the amounts and beneficiaries of transactions are modified, emptying the victims’ bank accounts. In the next step, the banking malware profits are laundered. In this paper we describe two models that are used in particular (next to more traditional money laundering methods). The first model involves the use of money mules and a quick cash-out. The second model focuses on direct spending via (a) direct purchases of products via online shopping, (b) direct purchases of bitcoins via Bitcoin exchanges or (c) direct purchases of luxury goods. Bitcoins can be further laundered via so-called mixing services. All in all, these methods allow criminals to launder profits in relative anonymity and prevent seizure of the illegal profits.
Lars Brünjes, Aggelos Kiayias, Ηλίας Κουτσουπιάς, Aikaterini-Panagiota Stouka
We introduce and study reward sharing schemes (RSS) that promote the fair formation of {\em stake pools}\ in collaborative projects that involve a large number of stakeholders such as the maintenance of a proof-of-stake (PoS) blockchain. Our mechanisms are parameterized by a target value for the desired number of pools. We show that by properly incentivizing participants, the desired number of stake pools is a Nash equilibrium arising from rational play. Our equilibria also exhibit an efficiency / security tradeoff via a parameter that calibrates between including pools with the smallest cost and providing protection against Sybil attacks, the setting where a single stakeholder creates a large number of pools in the hopes to dominate the collaborative project. We then describe how RSS can be deployed in the PoS setting, mitigating a number of potential deployment attacks and protocol deviations that include censoring transactions, performing Sybil attacks with the objective to control the majority of stake, lying about the actual cost and others. Finally, we experimentally demonstrate fast convergence to equilibria in dynamic environments where players react to each other's strategic moves over an indefinite period of interactive play. We also show how simple reward sharing schemes that are seemingly more "fair", perhaps counterintuitively, converge to centralized equilibria.
A bitcoin node needs to download the full block contents of the entire blockchain, before actually being able to send and receive transactions on bitcoin broadcast network, except simple payment verification clients which require only block headers and bloom filters to sync with others peers available on the network. Transactions/Blocks pass through a complex process at sender and receiver than it apparently looks to be. During transmission transactions/blocks are broken down into smaller chunks of data so that they can be carried on the wire. These chunks are given appropriate headers, encapsulated and then passed through several layers to reach the destination. In this paper we captured Bitcoin packets using Wireshark and deeply investigated and analyzed them. We investigated how bitcoin transaction/block messages work and what values and parameters are considered during this whole process.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
In this paper, we first propose an adaptive strategy for double-spending attack on blockchains. The attacker in our strategy observes the length of the honest branch when a submitted transaction becomes available in the blockchain, and then updates the attack strategy accordingly. This provides a stronger strategy than conventional double-spending attack. We then derive closed-form expressions for the probability of a successful attack and the expected reward of attacker miners. Our analysis shows that the probability of a successful attack by convincing the network nodes to follow the counterfeit branch under the proposed attack strategy is 60% higher than what is expected from the conventional attack strategy when the attackers acquire 40% of the total network processing power. To counter this increase in the probability of attack, the network nodes are required to use a bigger number of confirmation blocks for validating any transaction in the blockchain. We computed the. expected reward of an attacker for mining a counterfeit branch on a blockchain and observed that the expected reward drops to zero after a few number of block confirmations.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Readers' capability to consider and assess sources is imperative. Digital preservation efforts, however, mostly neglected citation provenance, which is a necessity for transparent source verification. We therefore present Webchain, a new system enabling verifiable citations and references on the World Wide Web. Its architecture combines a distributed ledger with secure timestamping to ensure history of creation, ownership, and referential integrity of online resources. With Webchain, readers can independently detect content manipulation by verifying authenticity, integrity, and time consistency. At the same time, authors gain a proof of existence for referenced articles. Web-chain extends a well-known distributed timestamping scheme to handle an open and dynamic network topology by providing a solution for membership management. We examine the security of our approach, particularly regarding forging attacks. Our results show that we are able to render such attacks infeasible, even in the face of a powerful attacker.
Matteo Signorini, Matteo Pontecorvi, Waël Kanoun, Roberto Di Pietro
Anomaly detection tools play a role of paramount importance in protecting networks and systems from unforeseen attacks, usually by automatically recognizing and filtering out anomalous activities. In this paper we present ADvISE: the first Anomaly Detection tool for blockchaIn SystEms which leverages blockchain meta-data, named forks, in order to collect potentially malicious requests in the network/system while being resilient to eclipse attacks. ADvISE collects and analyzes malicious forks to build a threat database that enables detection and prevention of future attacks.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Drug traceability system is essentially important for public drug security and business of pharmaceutical companies, which aims to track or trace where the drug has been and where it has gone along the drug supply chain. Traditional centralized server-client technical solutions have been far from satisfying for their bad performances in data authenticity, privacy, system resilience and flexibility. In this paper, we propose a scenario-oriented blockchain system for drug traceability and regulation called Drugledger, which reconstructs the whole service architecture by separating service provider into three independent service components and ensures the authenticity and privacy of traceability data. Drugledger is more resilient than traditional solutions with its p2p architecture. Furthermore, Drugledger could efficiently prune its storage, achieving a finally stable and acceptable blockchain storage. Besides, algorithms reflecting the real drug supply chain logic (e.g, package, repackage, unpackage, etc.) are designed based on the expanded UTXO workflow in Drugledger. To our knowledge, it is the first systematic work from both a technical and practical perspective on how blockchain system could be designed for drug traceability and regulation.
Blockchain Technology Applications and Security
Spam and Phishing Detection
Innovative Microfluidic and Catalytic Techniques Innovation
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Kentaroh Toyoda, Tomoaki Ohtsuki, P. Takis Mathiopoulos
In recent years, Bitcoin has been used for many services and purposes, e.g. gambling, marketplace, but also even as an investment scam. In order to clarify how Bitcoin is used, it is in great importance to identify what kind of services are operated by Bitcoin addresses. In this paper, we propose a multiclass service identification scheme in Bitcoin based on novel transaction history summarization. Our novelty is to propose how transaction history is retrieved and how the retrieved transactions are processed for better identification. When a Bitcoin address is given, the characteristics of its transaction history is calculated as features. Then, the set of calculated features is fed into a supervised classifier and the services operated by the given Bitcoin addresses are identified among seven major services: (i) exchange, (ii) faucet, (iii) gambling, (iv) investment scam, (v) marketplace, (vi) mining pool, and (vii) mixer. To our knowledge, we are the first to propose a multi-class identification. We show that our scheme achieves 72 % of accuracy through performance evaluation with more than 26,000 Bitcoin addresses that have been used for seven services/purposes from Jan. 2009 to Feb. 2017.
Thanks to the new global order established after the Second World War and the communication networks that have become widespread. Due to this, the electronic payment systems that have started to be used since the second half of the 20th century in the world and the credit cards called plastic money have started to be widely used in our country since the 80 '. From the beginning of 2000's, it is observed that cash-based transactions are lagging e-money-based transactions. Since the beginning of the 90's the Internet and social media emerged with new media technologies and after 2004, it has become a dominant idea that these environments provide freedom and even create disorder. In the last 5-6 years we have seen the trade of crypto currencies like Bitcoin. Bitcoin is a method of payment that people use for their purchases based on mutual trust, without an authority issuing it. It works independently of the state authority and the banking system. From this point of view, it is seen as the reflection of freedom originally envisaged for the internet environment. In this context, the question of how bitcoin systems are perceived, and the level of entrepreneurship are issues that needs to be investigated. In this study, a survey was conducted to measure the level of entrepreneurship of bitcoin miners, buyers and sellers. Twitter users were selected for the sample. The research is designed to examine the impact of entrepreneurship motivated by investors' interest in entering the arena that is said to be quite new and risky, and which sub-factors may dominate, which deals with bitcoin and similar crypto currencies. The findings show that users who are interested in mining, buying-selling and trading have very high level of entrepreneurial points.
Since most of the organizations are going online these days, such organizations have become dependent to their data over the internet. Hence, it has become more critical to secure data by taking adequate security measures. One of the measures that can be taken to secure data from attackers and intruders is access control. Along with the changing trend, even the data used is evolving. `Bitcoin' is the new data that has gained importance in the market. Every third person in the world has Bitcoin to their share. So it becomes important to secure Bitcoin and the information it possesses. Blockchain helps in preventing Bitcoin - the digital currency and therefore stores the information securely. In this paper, we survey and study how the rising of Blockchain technology has affected traditional transactional banking and also outline possible directions for future research.
Transactions in the cryptocurrency market has been extremely hot in recent years, with the price of cryptocurrency climbing all the way. Hackers have turned their attentions to cryptocurrencies, and have used various means to acquire cryptocurrencies illegally, which caused huge losses to the victims. Some browsers block malicious mining activities from the network protocol level, but they do not have the ability to detect mining samples themselves, and it is difficult to make effective detection of homogenous mining samples of the network layer. To solve these problems, based on the attack pattern of browser mining, the browser-based silent mining features are analyzed, and a method to detect browser silent mining behavior is proposed. This method drives known malicious mining samples, extracts heap snapshots and stack code features of a dynamically running browser, and performs automated detection based on recurrent neural network. By modifying the kernel code of Chrome, a browser-based silent miner detection prototype system BMDetector was designed and implemented. With 1159 samples detected and analyzed, experimental results show that the recognition rate of the original mining sample is 98%, and 92% for the encrypted and confused, which is an effective and feasible method.
Bitcoin is a digital asset which is a crypto currency that can be buy, sell or transfer between two parties securely over the web. It can be proposed as the most secure digital currency in world and can be used as a medium to exchange values electronically without involvement of third parties like banks and other types of organizations or Institutions or any clearinghouse that act as a middleman in these transactions. It happens because it is a secure medium due to cryptographic hashing used in peer-to-peer connection which is possible within blockchain technology. Blockchain solves three issues of internet: value, trust and Reliability. In our research survey, we had analyse the working of blockchain and Cryptographic Hash technology. We also include the analysis of different secure options of transferring crypto currency. At the end, we have define relation between trust, security and reliability which helps in developing satisfaction in client in using these crypto currency.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Bitcoin is a cryptocurrency based on blockchain technology that enables peer-to-peer transactions without a central authority. Bitcoin is known for resolving double-spending problems. When two or more miners generate a block that includes transaction information at nearly the same time, an accidental fork occurs. In this case, the longest chain of blocks is selected to avoid the double-spending problem. However, if there is an attacker node whose hash power is greater than half of the total hash power, that node can perform a double-spending attack, i.e., a 51% or majority attack. We propose a random mining group selection technique to reduce the probability of successful double-spending attacks. The analysis results demonstrate that if the number of groups is greater than or equal to two, the probability that the attacker will find the next block is less than 50%.