ABSTRACT Darknet markets (DNM) and bitcoins are two emergent topics in the information field and have attracted much attention. However, few has explored them together. This study aims at understanding the relation between them. It is investigated that whether the bitcoin exchange value and the public interest in it are predictable of the daily sales in the darknet markets in the future. By applying the Granger‐causality analysis, we find that the daily bitcoin exchange value with one day lag are Granger causative of the sales, so does the daily searching frequency in Google with one, two, and three‐day(s) lags. From the linear regressions, we find that the increasing bitcoin price reduces the daily DNM sales, while the increasing public interest in bitcoins facilitate the sales. By understanding relation between the DNM sales and bitcoins, two emergent topics in information science, we can get some insights on how to monitor the activities in the DNM, especially those illegal transactions and can further extend to how to regulate the DNM.
The US Government has now officially blamed North Korea for the recent WannaCry ransomware campaign. The attribution was made with the agreement of the governments of the UK, Australia, Canada, New Zealand and Japan and based on an analysis presented to those countries but not publicly available.
Husam Basil Al Jawaheri, Mashael Al Sabah, Yazan Boshmaf
Recently, more than 100,000 cases for ransomware attacks were reported in the Middle East, Turkey and Africa region [2]. Ransomware is a malware category that limits the access of users to their files by encrypting them. This malware requires victims to pay in order to get access to the decryption keys. In order to remain anonymous, ransomware requires victims to pay through the Bitcoin network. However, due to an inherent weakness in Bitcoin's anonymity model, it is possible to link identities hidden behind Bitcoin addresses by analyzing the blockchain, Bitcoin's public ledger where all of the history of transactions is stored. In this work, we investigate the feasibility of linking users, as identities represented by Bitcoin's public addresses, to addresses owned by entities operating ransomware. To demonstrate how such linking is possible, we crawled BitcoinTalk, a famous forum for Bitcoin related discussions, and a subset of Twitter public datasets. Out of nearly 5B tweets and 1M forum pages, we found 4.2K and 41K unique online identities, respectively, along with their public personal information and Bitcoin addresses. Then we expanded these datasets of users by using closure analysis, where a Bitcoin address is used to identify a set of other addresses that are highly likely to be controlled by the same user. This allowed us to collect thousands more Bitcoin addresses for the users. By analyzing transactions in the blockchain, we were able to link 6 unique identities to different ransomware operators including CryptoWall [1] and WannaCry [3]. Moreover, in order to get insights into the economy and activity of these Ransomware addresses, we analyzed the money flow of these addresses along with the timestamps associated with transactions involving them. We observed that ransomware addresses were active from 2014 to 2017, with an average lifetime of nearly 62 days. While some addresses were only active during a certain year, others were operating for more than 3 years. We also observed that the revenue of these malware exceeds USD 6M for CryptoWall, and ranges from USD 3.8K to USD 700K for ransomware such as WannaCry and CryptoLocker, with an average number of transactions of nearly 52. One address associated with CryptoLocker ransomware also had a large amount of Bitcoins worth more than USD 34M at the time of writing. Finally, we believe that such type of analysis can potentially be used as a forensic tool to investigate ransomware attacks and possibly help authorities trace the roots of such malware. 1- «Ransom Cryptowall.» Symantec. June 14, 2014. Accessed November 01, 2017. https://www.symantec.com/security_response/writeup.jsp?docid = 2014-061923-2824-99.2 - Varghese, Joseph. «Ransomware could be deadly, cyber security expert warns.» Gulf Times. May 05, 2017. Accessed November 01, 2017. http://www.gulf times.com /story/546937/Ransomware-could-be-deadly-cyber-security-expert-w.3- Woollaston, Victoria. «WannaCry ransomware: what is it and how to protect yourself.» WIRED. June 28, 2017. Accessed November 01, 2017. http://www.wired.co.uk/article/wannacry-ransomware-virus-patch .
Bitcoin is the most popular cryptocurrency on the planet. It relies on strong cryptography and peer-to-peer network. Bitcoin is gaining more and more popularity in criminal society. That is why Bitcoin is often used as money laundering tool or payment method for illegal products and services. In this paper we explore various methods for Bitcoin users deanonimization, which is an important task in anti-money laundering process and cybercrime investigation.
Blockchain technologies have the potential to establish novel financial service infrastructures and reshape numerous fields. A blockchain is essentially a distributed ledger maintained by a set of peers (i.e., trading nodes) that do not fully trust each other. A key challenge that blockchain faces is to precisely classify the blockchain peers into categories with respect to their behavior patterns, which will not only enable deeper insights into the blockchain network but also facilitate more effective maintenance of the various peers (in private chains). In this paper, we introduce and formulate the problem of behavior pattern classification in blockchain networks and propose a novel deep-learning-based method, termedPeerClassifier, to address the problem. To the best of our knowledge, we are the first to formally define the problem of peer behavior classification in blockchain networks. Moreover, we conduct extensive experiments to evaluate our proposed approach. Experimental results demonstrate thatPeerClassifieris significantly more effective than the existing conventional methods.
Michał Pawlak, Aneta Poniszewska-Marańda, Natalia Kryvinska
There are many existing voting solutions which have different benefits and issues. The most significant ones are lack of transparency and auditability. Recently developed blockchain technology may be a solution to these issues. The paper describes the use of intelligent agents and multi-agent system concept for Auditable Blockchain Voting System (ABVS), which integrates e-voting process with blockchain technology into one supervised non-remote internet voting system which is end-to-end verifiable.
Savva Shanaev, Arina Shuraeva, Mikhail Vasenin, Maksim Kuznetsov
In this article, an event studies approach is utilized to assess the influence of 51% attacks on proof-of-work (PoW) cryptocurrency prices. The study uses an exhaustive sample of 14 individual attacks on 13 cryptocurrencies. Across multiple event studies techniques, majority attacks on blockchains are consistently shown to immediately decrease corresponding coin prices by 12% to 15%. Significantly negative price response is robust in various event windows. Coin prices do not recover to pre-attack levels one week after the event. There is evidence of pump-and-dump schemes prior to the 51% attack, however the market demonstrates high efficiency after the attacks. 51% attacks are suggested to be a fundamental risk factor for cryptocurrency investments, primarily characteristic of small PoW coins with low hash rates. <b>TOPICS:</b>Currency, risk management, financial crises and financial market history <b>Key Findings</b> • 51% attacks on Proof-of-Work cryptocurrencies decrease their market prices by 12.60% on average. • The effect is robust to different measurement techniques and in various event windows. • There is evidence of insider trading and “pump-and-dump” schemes prior to the attacks.
Jingjing Gu, Binglin Sun, Xiaojiang Du, Jun Wang · 6 authors
To address the problem of detecting malicious codes in malware and extracting the corresponding evidences in mobile devices, we construct a consortium blockchain framework, which is composed of a detecting consortium chain shared by test members and a public chain shared by users. Specifically, in view of different malware families in Android-based system, we perform feature modeling by utilizing statistical analysis method, so as to extract malware family features, including software package feature, permission and application feature, and function call feature. Moreover, for reducing false-positive rate and improving the detecting ability of malware variants, we design a multi-feature detection method of Android-based system for detecting and classifying malware. In addition, we establish a fact-base of distributed Android malicious codes by blockchain technology. The experimental results show that, compared with the previously published algorithms, the new proposed method can achieve higher detection accuracy in limited time with lower false-positive and false-negative rates.
Blockchain technology becomes increasingly popular. It also attracts scams, for example, Ponzi scheme, a classic fraud, has been found making a notable amount of money on Blockchain, which has a very negative impact. To help dealing with this issue, this paper proposes an approach to detect Ponzi schemes on blockchain by using data mining and machine learning methods. By verifying smart contracts on Ethereum, we first extract features from user accounts and operation codes of the smart contracts and then build a classification model to detect latent Ponzi schemes implemented as smart contracts. The experimental results show that the proposed approach can achieve high accuracy for practical use. More importantly, the approach can be used to detect Ponzi schemes even at the moment of its creation. By using the proposed approach, we estimate that there are more than 400 Ponzi schemes running on Ethereum. Based on these results, we propose to build a uniform platform to evaluate and monitor every created smart contract for early warning of scams.
Jan 1, 2018·Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences
Mikkel Alexander Harlev, Haohua Sun Yin, Klaus Christian Langenheldt, Raghava Rao Mukkamala · 5 authors
Bitcoin is a cryptocurrency whose transactions are recorded on a distributed, openly accessible ledger. On the Bitcoin Blockchain, an entity’s real-world identity is hidden behind a pseudonym, a so-called address. Therefore, Bitcoin is widely assumed to provide a high degree of anonymity, which is a driver for its frequent use for illicit activities. This paper presents a novel approach for reducing the anonymity of the Bitcoin Blockchain by using Supervised Machine Learning to predict the type of yet-unidentified entities. We utilised a sample of 434 entities (with ~ 200 million transactions), whose identity and type had been revealed, as training set data and built classifiers differentiating among 10 categories. Our main finding is that we can indeed predict the type of a yet-unidentified entity. Using the Gradient Boosting algorithm, we achieve an accuracy of 77% and F1-score of ~ 0.75. We discuss our novel approach of Supervised Machine Learning for uncovering Bitcoin Blockchain anonymity and its potential applications to forensics and financial compliance and its societal implications, outline study limitations and propose future research directions.
In blockchain networks adopting the proof-of-work schemes, the monetary incentive is introduced by the Nakamoto consensus protocol to guide the behaviors of the full nodes (i.e., block miners) in the process of maintaining the consensus about the blockchain state. The block miners have to devote their computation power measured in hash rate in a crypto-puzzle solving competition to win the reward of publishing (a.k.a., mining) new blocks. Due to the exponentially increasing difficulty of the crypto-puzzle, individual block miners tends to join mining pools, i.e., the coalitions of miners, in order to reduce the income variance and earn stable profits. In this paper, we study the dynamics of mining pool selection in a blockchain network, where mining pools may choose arbitrary block mining strategies. We identify the hash rate and the block propagation delay as two major factors determining the outcomes of mining competition, and then model the strategy evolution of the individual miners as an evolutionary game. We provide the theoretical analysis of the evolutionary stability for the pool selection dynamics in a case study of two mining pools. The numerical simulations provide the evidence to support our theoretical discoveries as well as demonstrating the stability in the evolution of miners' strategies in a general case.
Zcash is a fork of Bitcoin with optional anonymity features. While transparent transactions are fully linkable, shielded transactions use zero-knowledge proofs to obscure the parties and amounts of the transactions. First, we observe various metrics regarding the usage of shielded addresses. Moreover, we show that most coins sent to shielded addresses are later sent back to transparent addresses. We then search for round-trip transactions, where the same, or nearly the same number of coins are sent from a transparent address, to a shielded address, and back again to a transparent address. We argue that such behavior exhibits high linkability, especially when they occur nearby temporally. Using this heuristic our analysis matched 31.5% of all coins sent to shielded addresses.
Kentaroh Toyoda, Tomoaki Ohtsuki, P. Takis Mathiopoulos
Although Bitcoin is one of the most successful decentralized cryptocurrency, recent research has revealed that it can be used as fraudulent activities such as HYIP (High Yield Investment Program). To identify such undesired activities, it is important to obtain Bitcoin addresses related with fraud. So far, the identification of such activities is based upon relating Bitcoin addresses with graph mining procedures. In this paper, we follow a different approach for identifying Bitcoin addresses related with HYIP by analyzing transactions patterns. In particular, based on the individual inspection of HYIP activity in Bitcoin, we propose a number of features that can be extracted from transactions. In particular, a signed integer called pattern is assigned to each transaction and the frequency of each pattern is calculated as key features. By evaluating the classification performance with more than 1,500 labeled Bitcoin addresses, it is shown that about 83% of HYIP addresses are correctly classified while maintaining false positive rate less than 4.4%.
Bitcoin, a peer-to-peer payment system and digital currency, is often involved in illicit activities such as scamming, ransomware attacks, illegal goods trading, and thievery. At the time of writing, the Bitcoin ecosystem has not yet been mapped and as such there is no estimate of the share of illicit activities. This paper provides the first estimation of the portion of cyber-criminal entities in the Bitcoin ecosystem. Our dataset consists of 854 observations categorised into 12 classes (out of which 5 are cybercrime-related) and a total of 100,000 uncategorised observations. The dataset was obtained from the data provider who applied three types of clustering of Bitcoin transactions to categorise entities: co-spend, intelligence-based, and behaviour-based. Thirteen supervised learning classifiers were then tested, of which four prevailed with a cross-validation accuracy of 77.38%, 76.47%, 78.46%, 80.76% respectively. From the top four classifiers, Bagging and Gradient Boosting classifiers were selected based on their weighted average and per class precision on the cybercrime-related categories. Both models were used to classify 100,000 uncategorised entities, showing that the share of cybercrime-related is 29.81% according to Bagging, and 10.95% according to Gradient Boosting with number of entities as the metric. With regard to the number of addresses and current coins held by this type of entities, the results are: 5.79% and 10.02% according to Bagging; and 3.16% and 1.45% according to Gradient Boosting.
Since the global financial crisis in 2008 had caused the global economic depression, the public were commonly losing confidence in monetary system and international fund associations. Thus, the concept of untraditional currency exchange was developed. Nakamoto (2008) designed bitcoin, a decentralized digital currency which is launched and traded on the Internet. Bitcoin is being gradually accepted by the public, which is attributed to the feature of decentralization and anonymity. The exchange rate of bitcoin reached to the peak price at $4425.30 USD on August 16th, 2017. However, due to the concern of the security challenges such as being stolen, the public lost the confidence of bitcoin and had a conservative attitude toward bitcoin. It also shows that the relevant technical application and transaction model of bitcoin still need to be improved.
Haoyan Wu, Zhijie Li, Brian King, Zina Ben Miled · 6 authors
Supply chains (SC) span many geographies, modes and industries and involve several phases where data flows in both directions from suppliers, manufacturers, distributors, retailers, to customers. This data flow is necessary to support critical business decisions that may impact product cost and market share. Current SC information systems are unable to provide validated, pseudo real-time shipment tracking during the distribution phase. This information is available from a single source, often the carrier, and is shared with other stakeholders on an as-needed basis. This paper introduces an independent, crowd-validated, online shipment tracking framework that complements current enterprise-based SC management solutions. The proposed framework consists of a set of private distributed ledgers and a single blockchain public ledger. Each private ledger allows the private sharing of custody events among the trading partners in a given shipment. Privacy is necessary, for example, when trading high-end products or chemical and pharmaceutical products. The second type of ledger is a blockchain public ledger. It consists of the hash code of each private event in addition to monitoring events. The latter provide an independently validated immutable record of the pseudo real-time geolocation status of the shipment from a large number of sources using commuters-sourcing.
In recent years, with the development of the Internet, network currency has gradually emerged. Bitcoin which is produced on the basis of complex algorithms has developed rapidly and attracted wide attention in academia. This paper explores the influence factors of bitcoin market transaction by analyzing the interaction between agents in bitcoin market transaction. Applying complex adaptive system modeling method based on multi-agent, this paper establishes an agent-based bitcoin market transaction model, and designs behavioral rules as well as transaction mechanism in detail for each agent in the process of market transaction. Then, we carry out a simulation on the Starlogo simulation platform and analyze the impact of the change in trader’s number on market transaction.
The wisdom of the crowd is a valuable asset in today’s society. It is not only important in predicting elections but also plays an essential role in marketing and the financial industry. Having a trustworthy source of opinion can make forecasts more accurate and markets predictable. Until now, a fundamental problem of surveys is the lack of incentives for participants to provide accurate information. Classical solutions like small monetary rewards or the chance of winning a prize are often not very attractive for participants. More attractive solutions, such as prediction markets, face the issue of illegality and are often unavailable. In this work, we present a solution that unites the advantages from classical polling and prediction markets via a customizable incentivization framework. Apart from predicting events, this framework can also be used to govern decentralized autonomous organizations.
Blockchain systems are designed to produce blocks at a constant average rate. The most popular systems currently employ a Proof of Work (PoW) algorithm as a means of creating these blocks. Bitcoin produces, on average, one block every 10 minutes. An unfortunate limitation of all deployed PoW blockchain systems is that the time between blocks has high variance. For example, 5% of the time, Bitcoin's inter-block time is at least 40 minutes. This variance impedes the consistent flow of validated transactions through the system. We propose an alternative process for PoW-based block discovery that results in an inter-block time with significantly lower variance. Our algorithm, called Bobtail, generalizes the current algorithm by comparing the mean of the k lowest order statistics to a target. We show that the variance of inter-block times decreases as k increases. If our approach were applied to Bitcoin, about 80% of blocks would be found within 7 to 12 minutes, and nearly every block would be found within 5 to 18 minutes; the average inter-block time would remain at 10 minutes. Further, we show that low-variance mining significantly thwarts doublespend and selfish mining attacks. For Bitcoin and Ethereum currently (k=1), an attacker with 40% of the mining power will succeed with 30% probability when the merchant sets up an embargo of 8 blocks; however, when k>=20, the probability of success falls to less than 1%. Similarly, for Bitcoin and Ethereum currently, a selfish miner with 40% of the mining power will claim about 66% of blocks; however, when k>=5, the same miner will find that selfish mining is less successful than honest mining. The cost of our approach is a larger block header.