Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

2,015 papersLast indexed Aug 31, 2026
Search papers

Paper index

2,015 results · page 68 of 84

Clear filters
Dec 1, 2019·2019 International Conference on ReConFigurable Computing and FPGAs (ReConFig)
2 cites
Almost-Zero Logic Implementation of Troika Hash Function on Reconfigurable Devices

Tolga Yalçın, Elif Bilge Kavun

Blockchain technology has gained immense popularity in the recent years due to its decentralized computing architecture. While it originally emerged as a technology for (crypto)currencies, it has since found many different application areas including (but not limited to) payments, money transfers, smart contracts, supply-chain management, networking, IoT, etc. Initially, it was only Bitcoin, the de facto standard for cryptocurrencies, but then it was followed by several (in fact hundreds of) others. Each new cryptocurrency had or claimed to have certain advantages over Bitcoin, such as transaction speed and cost. However, they all relied on the original idea of distributed ledger where each block has maintained a complete history of each transaction in the network. Blockchain technology has more recently been challenged by two new technologies called Tangle and Hashgraph, which are “directed acyclic graphs”, i.e. in layman's terms blockchains without blocks and chains. IOTA network is the original Tangle technology, which relies on ternary arithmetic architecture and uses ternary hash function “Troika”. It works on GF(3) and its design follows the sponge construction. Two of the main claims of IOTA are scalability and micro-transitions, both of which are likely to utilize compact hardware platforms in practical implementations. In this paper, an almost-zero logic compact and yet adequately fast hardware architectures of Troika hash function targeting reconfigurable devices are presented. The proposed architectures mainly depend on the utilization of BRAMs on FPGAs. Three different RAM-based hardware implementations have been realized on Xilinx Artix-7xc7a12tcpg238-3 device; all using only a single BRAM tile with minimal number of LUTs and FFs. The proposed architectures can easily be implemented on different reconfigurable devices with similar efficiency. To the best of our knowledge, this is the first reported hardware implementation of Troika hash function on reconfigurable devices which is also compact and fast.

Physical Unclonable Functions (PUFs) and Hardware Security
Advanced Malware Detection Techniques
Quantum Computing Algorithms and Architecture
Original source
Dec 1, 2019·2019 IEEE Globecom Workshops (GC Wkshps)
15 cites
MAD-IoT: Memory Anomaly Detection for the Internet of Things

Jonathan Myers, Leonardo Babun, Edward Yao, Sarah C. Helble · 5 authors

In the Internet of Things (IoT), applications hosted on resource-limited devices interact with the user and the physical world to provide digital connectivity and automation to daily activities, and frequently provide a point of entry into networks. However, many IoT applications are vulnerable to cyber attacks that can put networks, data, and connected devices at risk. Integrity measurement is an active defense technique used to detect malicious modification of software at runtime. While its usefulness has been well-demonstrated, integrity measurement is application-dependent and requires domain knowledge of the targeted software. Currently, adding integrity measurement to a platform requires substantial human effort, and thus application has been limited to usage on widely-deployed software such as the Linux kernel. Due to the diversity of IoT, vendors are unlikely to devote a substantial amount of effort to add integrity measurement systems to their devices. In this paper we introduce MAD- IOT (Memory Anomaly Detection for the Internet of Things), an integrity measurement framework for IoT. In order to provide low-cost integrity measurement agents and software anomaly detection for IoT platforms, MAD-IOT uses a process called IMAGE: Integrity Measurement Agent GEneration. The IMAGE process uses machine learning to automatically generate integrity measurement agents for arbitrary IoT devices. We demonstrated MAD-IOT and IMAGE on a proof-of-concept testbed and evaluated its performance with supervised and unsupervised machine learning models. Our results indicate that IMAGE is highly effective in recognizing known forms of misbehavior on IoT app operations, and very promising in identifying zero-day attacks. Finally, MAD-IOT introduces minimal overhead, making it feasible to implement on systems with very limited resources.

Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Security and Verification in Computing
Original source
Dec 1, 2019·2019 26th Asia-Pacific Software Engineering Conference (APSEC)
28 cites
SIF: A Framework for Solidity Contract Instrumentation and Analysis

Chao Peng, Sefa Akca, Ajitha Rajan

Solidity is an object-oriented and high-level language for writing smart contracts that are used to execute, verify and enforce credible transactions on permissionless blockchains. In the last few years, analysis of smart contracts has raised considerable interest and numerous techniques have been proposed to check the presence of vulnerabilities in them. Current techniques lack traceability in source code and have widely differing work flows. There is no single unifying framework for analysis, instrumentation, optimisation and code generation of Solidity contracts at the source code level. In this paper, we present SIF, a comprehensive framework for Solidity contract analysis, query, instrumentation, and code generation. SIF provides support for Solidity contract developers and testers to build source level techniques for analysis, understanding, diagnostics, optimisations and code generation. We show feasibility and applicability of the framework by building practical tools on top of it and running them on 1838 real smart contracts deployed on the Ethereum network.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Adversarial Robustness in Machine Learning
Original source
Dec 1, 2019·2019 9th International Symposium on Embedded Computing and System Design (ISED)
6 cites
Energy and Performance Comparison of Cryptocurrency Mining for Embedded Devices

Sriram Sankaran, Nithuna Pramod, Krishnashree Achuthan

Blockchains are composed of a network of computing entities which maintain an immutable distributed ledger thus facilitating auditability and accountability of transactions. The process of Cryptocurrency mining involves miners verifying transactions and adding them to the ledger. While Cryp-tocurrency mining prevents random nodes from creating and appending blocks, it incurs a negative impact on the embedded devices due to their resource-constrained nature. Thus, a need for profiling the power consumption of cryptocurrency mining platforms for embedded devices becomes necessary. In this work, we comparatively study the performance and power consumption of a suite of commonly used cryptocurrency mining platforms and analyze energy-performance trade-offs. In particular, our analysis is based on the power consumption during mining, changes in the power behavior and their impact on the overall system. Experiments conducted using real devices indicate that mining incurs a 2-fold increase in power consumption compared to those without mining. Our insights can be used to further investigate the impact of cryptocurrency malware on power consumption as well as design algorithms for energy efficient mining.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Original source
Dec 1, 2019·2019 IEEE Global Communications Conference (GLOBECOM)
79 cites
Co-IoT: A Collaborative DDoS Mitigation Scheme in IoT Environment Based on Blockchain Using SDN

Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi

The recent proliferation of Internet of Things (IoT) is paving the way for the emergence of smart cities, where billions of IoT devices are interconnected to provide novel pervasive services and automate our daily lives tasks (e.g., smart healthcare, smart home). However, as the number of insecure IoT devices continues to grow at a rapid rate, the impact of Distributed Denial-of-Service (DDoS) attacks is growing rapidly. With the advent of IoT botnets such as Mirai, the view towards IoT has changed from enabler of smart cities into a powerful amplifying tool for cyberattacks. This motivates the development of new techniques to provide flexibility and efficiency of decision making on the attack collaboration in a software defined networks (SDN) context. The new emerging technologies, such as SDN and blockchain, introduce new opportunities for low-cost, efficient and flexible DDoS attacks collaboration for the IoT based environment. In this paper, we propose Co-IoT, a blockchain-based framework for collaborative DDoS mitigation; it uses the concept of smart contracts (i.e., Ethereum's smart contracts) to facilitate the collaboration among SDN-based domains and transfer attacks information in a decentralized manner. The implementation of Co-IoT is deployed on Ethereum official test network Ropsten [1]. The experimental results confirm that Co-IoT achieves flexibility, efficiency, security and cost effectiveness making it a promising approach to mitigate large scale DDoS attacks.

Network Security and Intrusion Detection
Software-Defined Networks and 5G
Advanced Malware Detection Techniques
Original source
Nov 28, 2019·Proceedings of the 41st ACM SIGPLAN Conference on Programming Language Design and Implementation
62 cites
Securing smart contract with runtime validation

Ao Li, Jemin Andrew Choi, Fan Long

We present Solythesis, a source to source Solidity compiler which takes a smart contract code and a user specified invariant as the input and produces an instrumented contract that rejects all transactions that violate the invariant. The design of Solythesis is driven by our observation that the consensus protocol and the storage layer are the primary and the secondary performance bottlenecks of Ethereum, respectively. Solythesis operates with our novel delta update and delta check techniques to minimize the overhead caused by the instrumented storage access statements. Our experimental results validate our hypothesis that the overhead of runtime validation, which is often too expensive for other domains, is in fact negligible for smart contracts. The CPU overhead of Solythesis is only 0.12% on average for our 23 benchmark contracts.

Open access
3 source records
Security and Verification in Computing
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Original source
Nov 18, 2019·Proceedings on Privacy Enhancing Technologies 2021
3 cites
ZKSENSE: A Friction-less Privacy-Preserving Human Attestation Mechanism for Mobile Devices

Iñigo Querejeta-Azurmendi, Panagiotis Papadopoulos, Matteo Varvello, Antonio Nappa · 6 authors

Abstract Recent studies show that 20.4% of the internet traffic originates from automated agents. To identify and block such ill-intentioned traffic, mechanisms that verify the humanness of the user are widely deployed, with CAPTCHAs being the most popular. Traditional CAPTCHAs require extra user effort (e.g., solving mathematical puzzles), which can severely downgrade the end-user’s experience, especially on mobile, and provide sporadic humanness verification of questionable accuracy. More recent solutions like Google’s reCAPTCHA v3, leverage user data, thus raising significant privacy concerns. To address these issues, we present zkSENSE: the first zero-knowledge proof-based humanness attestation system for mobile devices. zkSENSE moves the human attestation to the edge: onto the user’s very own device, where humanness of the user is assessed in a privacy-preserving and seamless manner. zkSENSE achieves this by classifying motion sensor outputs of the mobile device, based on a model trained by using both publicly available sensor data and data collected from a small group of volunteers. To ensure the integrity of the process, the classification result is enclosed in a zero-knowledge proof of humanness that can be safely shared with a remote server. We implement zkSENSE as an Android service to demonstrate its effectiveness and practicality. In our evaluation, we show that zkSENSE successfully verifies the humanness of a user across a variety of attacking scenarios and demonstrate 92% accuracy. On a two years old Samsung S9, zkSENSE’s attestation takes around 3 seconds (when visual CAPTCHAs need 9.8 seconds) and consumes a negligible amount of battery.

Open access
2 source records
cs.CR
User Authentication and Security Systems
Advanced Malware Detection Techniques
Original source
Nov 18, 2019·Lecture notes in computer science
5 cites
What are the Actual Flaws in Important Smart Contracts (And How Can We Find Them)?

Alex Groce, Josselin Feist, Gustavo Grieco, Michael Colburn

An important problem in smart contract security is understanding the likelihood and criticality of discovered, or potential, weaknesses in contracts. In this paper we provide a summary of Ethereum smart contract audits performed for 23 professional stakeholders, avoiding the common problem of reporting issues mostly prevalent in low-quality contracts. These audits were performed at a leading company in blockchain security, using both open-source and proprietary tools, as well as human code analysis performed by professional security engineers. We categorize 246 individual defects, making it possible to compare the severity and frequency of different vulnerability types, compare smart contract and non-smart contract flaws, and to estimate the efficacy of automated vulnerability detection approaches.

Open access
2 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Advanced Malware Detection Techniques
Original source
Nov 18, 2019·arXiv (Cornell University)
6 cites
ZKSENSE: a Privacy-Preserving Mechanism for Bot Detection in Mobile Devices

Panagiotis Papadopoulos, Iñigo Querejeta Azurmendi, Jiexin Zhang, Matteo Varvello · 6 authors

Recent studies show that 20.4% of the internet traffic originates from automated agents. To identify and block such ill-intentioned traffic, mechanisms that verify the humanness of the user are widely deployed across the internet. CAPTCHA is the most popular among such mechanisms. Original CAPTCHAs require extra user effort (e.g., solving mathematical or image-based puzzles), which severely harms user's experience, especially on mobile, and provide only sporadic verification of their humanness. More recent solutions like Google's reCAPTCHA v3 leverage attestation data (e.g., user behavioral data, device fingerprints) shared with a remote server, thus raising significant privacy concerns. To address all of the above, we present ZKSENSE: the first zero knowledge proof-based humanness attestation system designed for mobile devices. Contrary to state-of-the-art systems, ZKSENSE assesses humanness continuously on the background in a privacy preserving way. ZKSENSE achieves that by classifying the motion sensor outputs of the mobile device based on a model trained by using both publicly available sensor data and data collected from a small group of volunteers. The classification result is enclosed in a zero knowledge proof of humanness that can be safely shared with an attestation service such as Privacy Pass. We implement ZKSENSE as an Android service to demonstrate its effectiveness and practicability. In our evaluation, we show that ZKSENSE verifies the humanness of the users asynchronously, on the background, without degrading their experience or jeopardizing user privacy, while it achieves 91% accuracy across a variety of attack scenarios. On a two years old Samsung S9, each attestation takes around 3 seconds in total (when visual CAPTCHAs need 9.8 seconds) and consumes a negligible amount of battery.

Open access
User Authentication and Security Systems
Advanced Malware Detection Techniques
Privacy, Security, and Data Protection
Original source
Nov 15, 2019·Security and Privacy
102 cites
Utilization of blockchain for mitigating the distributed denial of service attacks

Rajeev Singh, Sudeep Tanwar, Teek Parval Sharma

Abstract Distributed Denial of Service (DDoS) attacks cause devastating effects on the web services and hence harm the digital availability. The DDoS attackers use vulnerabilities exposed through new networking technologies like wireless, mobile, IoT, and associated protocol weaknesses for bringing down the networks and servers. Owing to availability of easily available tools and botnet armies, the DDoS attack incidences in the internet world are increasing day by day. Several techniques have been proposed by the researchers against DDoS attacks. This paper concentrates on the utilization of one of the latest and most promising technologies, that is, blockchain technology against DDoS attacks. The blockchain technology is rapidly finding use in various applications ranging from financial to gaming; this is because of its stable, decentralized, and secure architecture. The DDoS solutions based on blockchain are still in infancy and some solutions provide only architectural details without bothering about the implementation details. This paper presents a study of the blockchain‐based DDoS solutions. It also compares the existing blockchain‐based techniques against DDoS attacks and analyses them. This paper facilitates the development of future research proposals in this emerging area of blockchain technology.

Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Nov 6, 2019·Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
273 cites
Learning to Fuzz from Symbolic Execution with Application to Smart Contracts

Jingxuan He, Mislav Balunović, Nodar Ambroladze, Petar Tsankov · 5 authors

Fuzzing and symbolic execution are two complementary techniques for discovering software vulnerabilities. Fuzzing is fast and scalable, but can be ineffective when it fails to randomly select the right inputs. Symbolic execution is thorough but slow and often does not scale to deep program paths with complex path conditions. In this work, we propose to learn an effective and fast fuzzer from symbolic execution, by phrasing the learning task in the framework of imitation learning. During learning, a symbolic execution expert generates a large number of quality inputs improving coverage on thousands of programs. Then, a fuzzing policy, represented with a suitable architecture of neural networks, is trained on the generated dataset. The learned policy can then be used to fuzz new programs. We instantiate our approach to the problem of fuzzing smart contracts, a domain where contracts often implement similar functionality (facilitating learning) and security is of utmost importance. We present an end-to-end system, ILF (for Imitation Learning based Fuzzer), and an extensive evaluation over >18K contracts. Our results show that ILF is effective: (i) it is fast, generating 148 transactions per second, (ii) it outperforms existing fuzzers (e.g., achieving 33% more coverage), and (iii) it detects more vulnerabilities than existing fuzzing and symbolic execution tools for Ethereum.

Advanced Malware Detection Techniques
Adversarial Robustness in Machine Learning
Software Testing and Debugging Techniques
Original source
Nov 1, 2019·2019 Sixth HCT Information Technology Trends (ITT)
12 cites
The Semantics of Anomalies in IoT Integrated BlockChain Network

Zakea Il-Agure, Belsam Attallah, Yun‐Ke Chang

The recent substantial increase of Internet connected devices can be attributed to the new paradigm known as Internet of Things (IoT). IoT refers to objects that are connected and able to smartly function together to achieve a goal without human intervention. IoT systems have many weaknesses concerning confidentiality, security, privacy, and data integrity. This is due to having a large number of devices on a network, leading to the creation of anomalous behavior and security problems. For this reason, researchers have recently integrated IoT with Blockchain. Blockchain technology, a security by design technology that aims to overcome IoT weaknesses. This is because Blockchain permits validation, non-repudiation, reliability, controls authorization and automation of networks. However, Blockchain-based systems/networks may still face malicious attacks that threaten their security. This paper proposes using a link-mining tool based on anomaly detection within Blockchain networks. Aiming at gathering Meta-data in the form of forks (i.e. divergent paths from the Blockchain protocol) in order to find the semantic interpretation of anomalous paths/activities, through mutual information based measure. This tool will aid in the prevention of malicious attacks and improve the security of the Blockchain network and IoT devices.

Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Nov 1, 2019·2019 IEEE 16th International Conference on Mobile Ad Hoc and Sensor Systems (MASS)
1 cites
Securing IoT Protocol Implementations Through Hardware Monitoring

Arman Pouraghily, Tilman Wolf

The Internet of Things (IoT) represents the technical foundation to solve some of the most important societal and environmental problems. One of the key challenges in IoT systems is providing security for distributed, networked IoT components that are implemented with potentially very low-end embedded processing systems. As the value of sensor data and actuator access increases in IoT deployments, attackers may increasingly target these vulnerable systems and protocol implementations running on them. For protocols that involve economic transactions on blockchains, as we show in our work, there is a direct monetary value associated with successful attacks. To address this problem, we present a hardware monitoring system that augments processors with logic that tracks the correct execution of software on the embedded systems. Attacks on the system, such as buffer overflow attacks, are recognized and stopped by the hardware monitor. Therefore, the system can avoid economic loss due to an attack and ensure that the protocol implementation is secured. We show the effectiveness of our system on a prototype that uses Linux running on a soft-core LEON3 processor on an Intel Stratix IV FPGA and interacts with the Ethereum blockchain.

Security and Verification in Computing
Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Original source
Nov 1, 2019·2019 1st International Informatics and Software Engineering Conference (UBMYK)
20 cites
Implementation of Blockchain Based Distributed Web Attack Detection Application

Mustafa TANRIVERDİ, Adem Tekerek

In last decades' web application security has become one of the most important case study of information security studies. Business processes are transferred to web platforms. So web application usage is increased very fast. Web-based attacks have also increased due to the increased use of web applications. In order to ensure the security of web applications, intrusion detection and prevention systems and web application firewalls are used against web based attacks. Blockchain technology, which has become popular in recent years, enables reliable and transparent sharing of data with all stakeholders. In this study, in order to detect web-based attacks, a blockchain based web attack detection model that uses the signature based detection method is proposed. The signature based detection refers to the detection of attacks by looking for specific patterns against known web based attack types, such as Structured Query Language (SQL) Injection, Cross Site Scripting (XSS), Command Injection. Three web servers were used for the experimental study. A blockchain node has been installed with the MultiChain application for each server. Attacks on web applications are detected using the signature list found in the web application as well as detected using the signature list updated on the blockchain. According to the experimental results, the attacks signature detected and defined by a web application are updated in the blockchain lists and used by all web applications.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Malware Detection Techniques
Original source
Nov 1, 2019·2019 APWG Symposium on Electronic Crime Research (eCrime)
20 cites
Assessing the Threat of Blockchain-based Botnets

Leon Böck, Νικόλαος Αλεξόπουλος, Emine Saracoglu, Max Mühlhäuser · 5 authors

Time and time again the security community has faced novel threats that were previously never analyzed, sometimes with catastrophic results. To avoid this, proactive analysis of envisioned threats is of great importance. One such threat is blockchain-based botnets. Bitcoin, and blockchain-based decentralized cryptocurrencies in general, promise a fair and more transparent financial system. They do so by implementing an open and censorship-resistant atomic broadcast protocol that enables the maintenance of a global transaction ledger, known as a blockchain. In this paper, we consider how this broadcast protocol may be used for malicious behavior as a botnet command and control (C2) channel. Botmasters have been known to misuse broadcasting platforms, like social media, as C2 channels. However, these platforms lack the integral censorship-resistant property of decentralized cryptocurrencies. In this paper, we provide a comprehensive systematization of knowledge study on using blockchains as botnet C2 channels, generating a number of important insights. We set off by providing a critical analysis of the state of the art of blockchain-based botnets, along with an abstract model of such a system. We then examine the inherent limitations of the design, in an attempt to challenge the feasibility of such a botnet. With such limitations in mind, we move forward with an experimental analysis of the detectability of such botnets and discuss potential countermeasures. Contrary to previous work that proposed such botnets, we provide a broad overview of the associated risk and view the problem in relation to other existing botnet C2 channels. We conclude that despite its limitations, the blockchain, as a backup mechanism, practically renders attempts to suppress the control channel of a botnet futile. Thus, more focus should be put on detecting and disinfecting machines at the network edge (router) or even per-bot level.

Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Nov 1, 2019·2019 34th IEEE/ACM International Conference on Automated Software Engineering Workshop (ASEW)
31 cites
Securing Smart Contracts in Blockchain

Jaturong Kongmanee, Phongphun Kijsanayothin, Rattikorn Hewett

Blockchain is an emerging technology that underlies creation and exchange of the digital assets, including cryptocurrency such as Bitcoin and Ether, without the need for a central authority. It provides a public ledger for recording sequence of transactions in blocks that are linked as a chain. Smart contracts are computer programs governing participant agreements that are automatically enforced by consensus protocols in the blockchain. Together, blockchain and smart contracts revolutionize efficient transaction stores, services and workflows that work even among distrusting participants and without a trusted authority. Unfortunately, like most software, smart contracts are vulnerable as evidenced by a recent Decentralized Autonomous Organization (DAO) attack that lost cryptocurrency then-valued about $60 million. Correctness of executions alone is not sufficient to guarantee security of smart contracts. This paper addresses how we can apply model checking, a well-established formal verification technique, to help alleviate security issues in smart contract development. Most existing studies have focused on verification of smart contracts on a specific language and specific platform. Smart contracts may have hidden operational side effects that impact software behaviors. Thus, applying model checking to smart contracts is not necessarily straightforward. This paper presents a general technique for building the core functional models applicable for model checking to identify all possible executions that lead to security breaches. It also shows how resulting executions can be systematically analyzed to help identify security issues. The models are language and system independent in that they can represent any smart contract in any language or any platform. We illustrate and evaluate the technique with a widely used example of a smart contract in a financial system along with experimental results using a well-known model checker, NuSMV in various scenarios.

Blockchain Technology Applications and Security
Security and Verification in Computing
Advanced Malware Detection Techniques
Original source
Nov 1, 2019·2019 International Conference on Innovative Computing (ICIC)
78 cites
Security Of Cryptocurrency Using Hardware Wallet And QR Code

Abdul Ghaffar Khan, Amjad Hussain Zahid, Muzammil Hussain, Usama Riaz

Today, the privacy and the security of any organization are the key requirement, the digital online transaction of money or coins also needed a certain level of security not only during the broadcasting of the transaction but before the sending of the transaction. In this research paper we proposed and implemented a cryptocurrency (Bitcoin) wallet for the android operating system, by using the QR code-based android application and a secure private key storage (Cold Wallet). Two android applications have been implemented one of them is called cold wallet and the other one is hot wallet. Cold wallet (offline) is to store and generate the private key addresses for secure transaction confirmation and the hot wallet is used to send bitcoin to the network. Hot wallet application gives facility to the user view history of performed transactions, to send and compose a new bitcoin transaction, receive bitcoin, sign it and send it to the network. By using the process of cross QR code scanning of the hot and cold wallet to the identification, validation and authentication of the user made it secure.

2 source records
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Malware Detection Techniques
Original source
Nov 1, 2019·2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE)
59 cites
MuSC: A Tool for Mutation Testing of Ethereum Smart Contract

Zixin Li, Haoran Wu, Jiehui Xu, Xingya Wang · 6 authors

The smart contract cannot be modified when it has been deployed on a blockchain. Therefore, it must be given thorough test before its being deployed. Mutation testing is considered as a practical test methodology to evaluate the adequacy of software testing. In this paper, we introduce MuSC, a mutation testing tool for Ethereum Smart Contract (ESC). It can generate numerous mutants at a fast speed and supports the automatic operations such as creating test nets, deploying and executing tests. Specially, MuSC implements a set of novel mutation operators w.r.t ESC programming language, Solidity. Therefore, it can expose the defects of smart contracts to a certain degree. The demonstration video of MuSC is available at https: //youtu.be/3KBKXJPVjbQ, and the source code can be downloaded at https://github.com/belikout/MuSC-Tool-Demo-repo.

Advanced Malware Detection Techniques
Software Testing and Debugging Techniques
Security and Verification in Computing
Original source
Oct 23, 2019·Proceedings of the Third Central European Cybersecurity Conference
5 cites
On the Feasibility of Secure Logging for Industrial Control Systems Using Blockchain

Stefan Schorradt, Edita Bajramović, Felix Freiling

With industrial control systems (ICSs) being increasingly networked, the need for sound forensic capabilities for such systems increases. One vital source of information in forensic investigation are log files. Techniques for secure logging aim to protect log files from manipulation. We investigate how a blockchain can enable secure logging for ICSs. We argue that a blockchain fits well both into general models of secure logging and into the Purdue model for ICSs. We report on experiences from connecting the syslog functionality of a Siemens SIMATIC S7-1500 programmable logic controller to the public Ethereum blockchain network. While the level of manipulation protection is comparably high, the transaction time for the public Ethereum blockchain severely limits the usefulness of this type of secure logging for ICSs.

Digital and Cyber Forensics
Advanced Malware Detection Techniques
Security and Verification in Computing
Original source
Oct 21, 2019·Computer Communications Volume 171, 1 April 2021, Pages 126-139
74 cites
Cryptomining Makes Noise: a Machine Learning Approach for Cryptojacking Detection

Maurantonio Caprolu, Simone Raponi, Gabriele Oligeri, Roberto Di Pietro

Cryptojacking occurs when an adversary illicitly runs crypto-mining software over the devices of unaware users. This novel cybersecurity attack, that is emerging in both the literature and in the wild, has proved to be very effective given the simplicity of running a crypto-client into a target device. Several countermeasures have recently been proposed, with different features and performance, but all characterized by a host-based architecture. The cited solutions, designed to protect the individual user, are not suitable for efficiently protecting a corporate network, especially against insiders. In this paper, we propose a network-based approach to detect and identify crypto-clients activities by solely relying on the network traffic, even when encrypted and mixed with non-malicious traces. First, we provide a detailed analysis of the real network traces generated by three major cryptocurrencies, Bitcoin, Monero, and Bytecoin, considering both the normal traffic and the one shaped by a VPN. Then, we propose Crypto-Aegis, a Machine Learning (ML) based framework built over the results of our investigation, aimed at detecting cryptocurrencies related activities, e.g., pool mining, solo mining, and active full nodes. Our solution achieves a striking 0.96 of F1-score and 0.99 of AUC for the ROC, while enjoying a few other properties, such as device and infrastructure independence. Given the extent and novelty of the addressed threat we believe that our approach, supported by its excellent results, pave the way for further research in this area.

Open access
2 source records
cs.CR
cs.NI
Internet Traffic Analysis and Secure E-voting
Original source
Oct 18, 2019·Proceedings of the Internet Measurement Conference
66 cites
A First Look at the Crypto-Mining Malware Ecosystem

Sergio Pastrana, Guillermo Suárez‐Tangil

Illicit crypto-mining leverages resources stolen from victims to mine cryptocurrencies on behalf of criminals. While recent works have analyzed one side of this threat, i.e.: web-browser cryptojacking, only commercial reports have partially covered binary-based crypto-mining malware.

Open access
Advanced Malware Detection Techniques
Digital and Cyber Forensics
Spam and Phishing Detection
Original source
Oct 15, 2019·IEEE Internet of Things Journal
75 cites
BoSMoS: A Blockchain-Based Status Monitoring System for Defending Against Unauthorized Software Updating in Industrial Internet of Things

Sen He, Wei Ren, Tianqing Zhu, Kim‐Kwang Raymond Choo

The role of the Industrial Internet of Things (IIoT) in critical infrastructure sectors, such as power, chemistry, and manufacturing, will be increasingly important as we move toward Industry 5.0. For example, IIoT devices are deployed in factories to help the manufacturing companies (e.g., automotive) gain in-depth insight into the various states of production, and thus improving production efficiency and achieving cost reductions. However, malicious code may compromise IIoT devices if either the devices are exposed to outside or unexposed inner devices are updated unauthentically. Due to their limited resources and features, it is challenging to implement strong security solutions for such embedded devices. In this article, we propose a blockchain-based software status monitoring system, called BoSMoS. The system is designed to monitor the software status of IIoT devices to detect and respond to identified malicious behaviors (e.g., intrusions). BoSMoS takes a snapshot of the statue of monitored software and monitors its file system calls. In order to ensure the software integrity information, we use blockchain as the distributed ledger to store a snapshot of software status. The blockchain network of BoSMoS can employ different consensus algorithms. We also evaluate the performance of BoSMoS, in terms of exception response delay, resistance performance to various intrusions, and scalability. The experimental results justify that BoSMoS is practical and sound. In addition, the evaluation of scalability and security demonstrates that the system can carry deployment of large-scale IIoT devices and can guarantee authenticated software updating, as well as detect unauthorized software status.

IoT and Edge/Fog Computing
Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Original source
Oct 14, 2019·IEEE/WIC/ACM International Conference on Web Intelligence - Companion Volume
7 cites
BARRETT BlockchAin Regulated REmote aTTestation

Michail Bampatsikos, Christoforos Ntantogian, Christos Xenakis, Stelios C. A. Thomopoulos

Today, an increasing number of Internet of Things (IoT) healthcare devices, crucial to a person's wellbeing and life, connects to the internet and consequently is exposed to a variety of threats. These devices possess low computational resources, and as a result they cannot use security tools such as antivirus or firewalls. Consequently, they become easy targets for cyber-attacks and malware infection, thus putting a person's life at risk. One way to protect these devices from malware infection is Remote Attestation (RA), a process by which a device with low computational power (prover) verifies its internal state to a party with higher computational resources (verifier) upon the latter's request. However, in case the verifier is malicious, it may constantly send numerous requests for RA to a prover to prevent it from performing the functions it was designed for. Thus, keeping it busy and rendering it unusable to its legit users as well as services. In short, the verifier performs a Computational Denial of Service (CDoS) attack against the prover. This paper proposes the BARRETT architecture which uses a Public Ethereum Network (PEN) in conjunction with an RA protocol to protect the prover from CDoS attacks. In particular, the PEN in BARRETT deters CDoS by forcing the verifier to pay a fee in Ether cryptocurrency every time they wish to send an Attestation Request (AR) to a prover. The verifier pays the fee since in BARRETT it can send the AR only via Ethereum transactions. Consequently, any attempt to perform a CDoS becomes prohibitively expensive.

Open access
Security and Verification in Computing
Advanced Malware Detection Techniques
IoT and Edge/Fog Computing
Original source