Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

2,015 papersLast indexed Aug 31, 2026
Search papers

Paper index

2,015 results ¡ page 69 of 84

Clear filters
Oct 7, 2019¡Journal of Money Laundering Control
30 cites
A target-centric intelligence approach to WannaCry 2.0

Adam Turner, Stephen McCombie, Allon J. Uhlmann

Purpose This paper aims to demonstrate the utility of a target-centric approach to intelligence collection and analysis in the prevention and investigation of ransomware attacks that involve cryptocurrencies. The paper uses the May 2017 WannaCry ransomware usage of the Bitcoin ecosystem as a case study. The approach proves particularly beneficial in facilitating information sharing and an integrated analysis across intelligence domains. Design/methodology/approach This study conducted data collection and analysis of the component Bitcoin elements of the WannaCry ransomware attack. A note of both technicalities of Bitcoin operations and current models for sharing cyber intelligence was made. Our analysis builds on and further develops current definitions and strategies for sharing cyber threat intelligence. It uses the problem definition model (PDM) and generic target network model (TNM) to create an analytic framework for the WannaCry ransomware attack scenario, allowing analysts the ability to test their hypotheses and integrate and share data for collaborative investigation. Findings Using a target-centric intelligence approach to WannaCry 2.0 shows that it is possible to model the intelligence problem of collecting and analysing data related to inflows and outflows of Bitcoin-related ransomware transactions. Bitcoin transactions form graph networks and allow to build a target network model for collecting, analysing and sharing intelligence with multiple stakeholders. Although attribution and anonymity prevail under cryptocurrency usage, there is a means for developing transaction walks using this method to target nefarious cryptocurrency exchanges where criminals are inclined to cash out their proceeds of crime. Originality/value The application of a target-centric intelligence approach to the cryptocurrency components of a ransomware attack provides a framework for intelligence units to break down the problem in the financial domain and model the network behaviour of illicit Bitcoin transactions relating to ransomware.

Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Network Security and Intrusion Detection
Original source
Oct 2, 2019¡IEEE Transactions on Information Forensics and Security
22 cites
Cryptomining Cannot Change Its Spots: Detecting Covert Cryptomining Using Magnetic Side-Channel

Ankit Gangwal, Mauro Conti

With new cryptocurrencies being frequently introduced to the market, the demand for cryptomining - a fundamental operation associated with most of the cryptocurrencies - has initiated a new stream of earning financial gains. The cost associated with the lucrative cryptomining has driven general masses to unethically mine cryptocurrencies using “plundered” resources in the public organizations (e.g., universities) as well as in the corporate sector that follows Bring Your Own Device (BYOD) culture. Such exploitation of the resources causes financial detriment to the affected organizations, which often discover the abuse when the damage has already been done. In this paper, we present a novel approach that leverages magnetic side-channel to detect covert cryptomining. Our proposed approach works even when the examiner does not have login-access or root-privileges on the suspect device. It merely requires the physical proximity of the examiner and a magnetic sensor, which is often available on smartphones. The fundamental idea of our approach is to profile the magnetic field emission of a processor for the set of available mining algorithms. We built a complete implementation of our system using advanced machine learning techniques. In our experiments, we included all the cryptocurrencies supported by the top-10 mining pools, which collectively comprise the largest share (84% during Q3 2018) of the cryptomining market. Moreover, we tested our methodology primarily on two different laptops. By using the data recorded from the magnetometer of an ordinary smartphone, our classifier achieved an average precision of over 88% and an average F1 score of 87%. Apart from our primary goal - which is to identify covert cryptomining - we also performed four additional experiments to further evaluate our approach. We found that due to its underlying design, our system is future-ready and can readily adapt even to zero-day cryptocurrencies.

Digital Media Forensic Detection
Advanced Malware Detection Techniques
Anomaly Detection Techniques and Applications
Original source
Oct 1, 2019¡2019 IEEE 10th Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON)
13 cites
Consortium Blockchain-Based Architecture for Cyber-attack Signatures and Features Distribution

Oluwaseyi Ajayi, Obinna Igbe, Tarek Saadawi

One of the effective ways of detecting malicious traffic in computer networks is intrusion detection systems (IDS). Though IDS identify malicious activities in a network, it might be difficult to detect distributed or coordinated attacks because they only have single vantage point. To combat this problem, cooperative intrusion detection system was proposed. In this detection system, nodes exchange attack features or signatures with a view of detecting an attack that has previously been detected by one of the other nodes in the system. Exchanging of attack features is necessary because a zero-day attacks (attacks without known signature) experienced in different locations are not the same. Although this solution enhanced the ability of a single IDS to respond to attacks that have been previously identified by cooperating nodes, malicious activities such as fake data injection, data manipulation or deletion and data consistency are problems threatening this approach. In this paper, we propose a solution that leverages blockchain's distributive technology, tamper-proof ability and data immutability to detect and prevent malicious activities and solve data consistency problems facing cooperative intrusion detection. Focusing on extraction, storage and distribution stages of cooperative intrusion detection, we develop a blockchain-based solution that securely extracts features or signatures, adds extra verification step, makes storage of these signatures and features distributive and data sharing secured. Performance evaluation of the system with respect to its response time and resistance to the features/signatures injection is presented. The result shows that the proposed solution prevents stored attack features or signature against malicious data injection, manipulation or deletion and has low latency.

Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Oct 1, 2019¡2019 International Conference on Speech Technology and Human-Computer Dialogue (SpeD)
13 cites
FPGA based architecture for securing IoT with blockchain

Florin Răstoceanu, Radoi Ionut

The Internet of Things (IoT) became widely utilized during last years, due to the large number of object that are connected to it - not only computers, but also humans, sensors and actuators. In the near future, a large number of objects will communicate to each other in a way never experienced before by the humankind. Connecting all these objects together will come with a wide area of challenges. One of the most important issues concerns trust. In majority of cases, centralized architectures are used to solve the problem, but the enormous number of object that can be connected in IoT will make almost impossible to manage and implement these solutions. Blockchain technology offers powerful solutions for decentralized architectures, which can be the future of IoT systems. A strong solution needs to be flexible to changes and must offer powerful resources to be successful. A hardware platform that uses FPGAs is suitable for those systems. In this paper we propose a solution for securing IoT systems using blockchain technology, implemented on a FPGA based architecture.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
IoT and Edge/Fog Computing
Original source
Oct 1, 2019¡2019 IEEE International Scientific-Practical Conference Problems of Infocommunications, Science and Technology (PIC S&T)
18 cites
Cybersecurity in the Blockchain Era : A Survey on Examining Critical Infrastructure Protection with Blockchain-Based Technology

Taylor Rodriguez Vance, Andrew Vance

Cybercriminals and nation-state hackers are investing heavily in strategies devised to disrupt critical infrastructure systems. Nearly one out of two Industrial Control System (ICS) computers in the energy sector had been impacted by malicious cyber activity in 2018. With threats increasing and attack vectors expanding, critical infrastructure sectors like energy need to implement innovative technology to ensure Critical Infrastructure Protection. This study reviewed blockchain research published between 2015 and 2019 in order to examine the development of blockchain, evaluate current applications of blockchain in the energy sector, and propose additional opportunities for the application of blockchain technology. Quantitative analysis revealed that blockchain-based cybersecurity research and application in the energy sector is increasing at an annual average growth rate of 169% since 2015 with intensified focus on Internet of Things (IoT) and Smart Grid infrastructures. Computed projections forecast a continued increase in the research and application of IoT and Smart Grids. Calculations indicate that nearly 50% of the new research will be in blockchain-based cybersecurity solutions such as cryptographic communications and secure email. Qualitative analysis indicates potential for blockchain- based cybersecurity solutions to provide enhanced Critical Infrastructure Protection in those sectors against pervasive phishing and social engineering threats.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Advanced Malware Detection Techniques
Original source
Oct 1, 2019¡2019 IEEE 8th Global Conference on Consumer Electronics (GCCE)
8 cites
Multiple Layered Security Analyses Method for Cryptocurrency Exchange Servicers

Hironao TAKAHASHI, Uzair Lakhani

Internet is a common method of trading business today. The usage of cryptocurrencies has increased these days and it has become a trend to utilize them. Cryptocurrency exchange servicers provide different smartphone apps that unfortunately may become the target of malicious attacks. This paper focuses on how it achieves highest security and proposes the multiple layered security analyses method for cryptocurrency exchange servicers.

Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Spam and Phishing Detection
Original source
Oct 1, 2019¡2019 IEEE 10th Annual Information Technology, Electronics and Mobile Communication Conference (IEMCON)
5 cites
A Smart Contract Grammar to Protect IoT Firmware Updates using Hyperledger Fabric

Xinchi He, Rose Gamble, Mauricio Papa

Securing firmware updates for IoT devices is a challenging undertaking because of their limited hardware resources. Most of the existing solutions are based on centralized architectures that may expose a single point of failure. Blockchain technology is largely accepted as a secure, robust and distributed platform for a number of different applications. This paper proposes the use of a blockchain platform to facilitate firmware updates for IoT devices. The distributed nature of the framework helps secure the firmware update process against single points of failure. In addition, the use of smart contracts can further strengthen the process by specifying firmware update conditions, verifying firmware update legitimacy, and protecting against potential cyber-attacks. Previous work in this area is extended by introducing a grammar and compiler to assist stakeholders in generating smart contracts. To validate the approach, a web- based prototype has been implemented to directly generate smart contracts in chaincode format that can be deployed in Hyperledger Fabric, an open source and permission-based blockchain framework. The grammar and compiler were evaluated for different use cases of the firmware update operations. Preliminary results with a prototype implementation show potential in simplifying the smart contract development process and reducing the amount of work needed to generate a working chaincode.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Security and Verification in Computing
Original source
Oct 1, 2019¡Journal of Communications and Networks
100 cites
An intelligent agriculture network security system based on private blockchains

Hsin‐Te Wu, Chun‐Wei Tsai

Countries around the world are nowadays actively promoting development in intelligent agriculture. Each of them must develop a specific plan tailored to environmental farming indices of each individual farm, and such information would be both important and sensitive. This is why information in intelligent agriculture requires protection from network security to ensure data privacy and integrity. This study proposes applying dark web technology to ensure the privacy of blockchains and servers. The study will monitor packet transmission frequency in intelligent agriculture to prevent distributed denial-of-service (DDOS) attacks. The main features of system include: (1) An identity authentication mechanism, (2) secure transmission of information, (3) establishment of private blockchains, (4) a faster, improved authentication system for blockchain information, and (5) resistance against DDOS attacks. The proposed scheme can safeguard network security for the IoT as well as the servers by way of applying dark web technology, which can avoid exposure of blockchains and server ID addresses and thus in turn lower the risks of DDOS attack damages. Experiment results indicate that the application of lightweight encryption of proposed scheme does indeed improve the authentication speed while also satisfying requirements of network security.

Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Advanced Malware Detection Techniques
Original source
Oct 1, 2019¡arXiv (Cornell University)
13 cites
Basis Path Coverage Criteria for Smart Contract Application Testing

Xinming Wang, Zhijian Xie, Jiahao He, Gansen Zhao ¡ 5 authors

The widespread recognition of the smart contracts has established their importance in the landscape of next generation blockchain technology. However, writing a correct smart contract is notoriously difficult. Moreover, once a state-changing transaction is confirmed by the network, the result is immutable. For this reason, it is crucial to perform a thorough testing of a smart contract application before its deployment. This paper's focus is on the test coverage criteria for smart contracts, which are objective rules that measure test quality. We analyze the unique characteristics of the Ethereum smart contract program model as compared to the conventional program model. To capture essential control flow behaviors of smart contracts, we propose the notions of whole transaction basis path set and bounded transaction interaction. The former is a limited set of linearly independent inter-procedural paths from which the potentially infinite paths of Ethereum transactions can be constructed by linear combination, while the latter is the permutations of transactions within a certain bound. Based on these two notions, we define a family of path-based test coverage criteria. Algorithms are given to the generation of coverage requirements. A case study is conducted to compare the effectiveness of the proposed test coverage criteria with random testing and statement coverage testing.

Open access
3 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cryptography and Data Security
Original source
Oct 1, 2019¡arXiv
37 cites
MPro: Combining Static and Symbolic Analysis for Scalable Testing of Smart Contract

William Zhang, Sebastian Banescu, Leonardo Pasos, Steven Stewart ¡ 5 authors

Smart contracts are executable programs that enable the building of a programmable trust mechanism between multiple entities without the need of a trusted third-party. At the time of this writing, there were over 10 million smart contracts deployed on the Ethereum networks and this number continues to grow at a rapid pace. Smart contracts are often written in a Turing-complete programming language called Solidity, which is not easy to audit for subtle errors. Further, since smart contracts are immutable, errors have led to attacks resulting in losses of cryptocurrency worth 100s of millions of USD and reputational damage. Unfortunately, manual security analyses do not scale with size and number of smart contracts. Automated and scalable mechanisms are essential if smart contracts are to gain mainstream acceptance. Researchers have developed several security scanners in the past couple of years. However, many of these analyzer either do not scale well, or if they do, produce many false positives. This issue is exacerbated when bugs are triggered only after a series of interactions with the functions of the contract-under-test. A depth-n vulnerability, refers to a vulnerability that requires invoking a specific sequence of n functions to trigger. Depth-n vulnerabilities are time-consuming to detect by existing automated analyzers, because of the combinatorial explosion of sequences of functions that could be executed on smart contracts. In this paper, we present a technique to analyze depth-n vulnerabilities in an efficient and scalable way by combining symbolic execution and data dependency analysis. A significant advantage of combining symbolic with static analysis is that it scales much better than symbolic alone and does not have the problem of false positive that static analysis tools typically have. We have implemented our technique in a tool called MPro, a scalable and automated smart contract analyzer based on the existing symbolic analysis tool Mythril-Classic and the static analysis tool Slither. We analyzed 100 randomly chosen smart contracts on MPro and our evaluation shows that MPro is about n-times faster than Mythril-Classic for detecting depth-n vulnerabilities, while preserving all the detection capabilities of Mythril-Classic.

Open access
2 source records
Security and Verification in Computing
Advanced Malware Detection Techniques
Adversarial Robustness in Machine Learning
Original source
Oct 1, 2019¡2019 Sixth International Conference on Internet of Things: Systems, Management and Security (IOTSMS)
153 cites
SoliAudit: Smart Contract Vulnerability Assessment Based on Machine Learning and Fuzz Testing

Jianwei Liao, Tsung-Ta Tsai, Chia-Kang He, Chin‐Wei Tien

Blockchain has flourished in recent years. As a decentralized system architecture, smart contracts give the blockchain a user-defined logical concept. The smart contract is an executable program that can be used for automatic transactions on the Ethereum blockchain. In 2016, the DAO attack resulted in the theft of 60M USD due to unsafe smart contracts. Smart contracts are vulnerable to hacking because they are difficult to patch and there is a lack of assessment standards for ensuring their quality. Hackers can exploit the vulnerabilities in smart contracts when they have been published on Ethereum. Thus, this study presents SoliAudit (Solidity Audit), which uses machine learning and fuzz testing for smart contract vulnerability assessment. SoliAudit employs machine learning technology using Solidity machine code as learning features to verify 13 kinds of vulnerabilities, which have been listed as Top 10 threats by an open security organization. We also created a gray-box fuzz testing mechanism, which consists of a fuzzer contract and a simulated blockchain environment for on-line transaction verification. Different from previous research systems, SoliAudit can detect vulnerabilities without expert knowledge or predefined patterns. We subjected SoliAudit to real-world evaluation by using near 18k smart contracts from the Ethereum blockchain and Capture-the-Flag samples. The results show that the accuracy of SoliAudit can reach to 90% and the fuzzing can help identify potential weaknesses, including reentrancy and arithmetic overflow problems.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Sep 30, 2019¡International Journal of Recent Technology and Engineering (IJRTE)
3 cites
Cryptojacking Malware Detection using the Bayesian Consensus Clustering with Large Iterative Multi-Tier Ensemble in the Cryptocurrency in the Cloud

S. Balamurugan, M. Thangaraj

Virtual Currencies and cryptocurrency are a trending digital currency method which uses the Blockchain technology. Cryptocurrency is a digital method designed to exchange the asset between the users based on a powerful cryptography which ensures the transaction are safe and controllable. We have various legal areas identified while using the cryptocurrency, as being the virtual currency, the amount of assets used by the users increases rapidly. With the increase in the asset the security breaches are one of the key vulnerable areas to focus. Cryptocurrency mining malware or Cryptojacking remains a trending terminology which identifies the malicious software or malware developed to use the data from the smart phones and computers. The major threat of the Cryptojacking is cryptocurrency mining without user’s approval. This article implemented based on our CCEC Framework method published for Malware detection in SMS’s for the Smartphone users. The article explains about how the Malware detected using the CCEC Framework. Malwares created in various format so identifying the Malware takes time before which user assets remains vulnerable. So, the proposed method ensures we have a reduction in time by using various online data sources to identify the Cryptojacking malware.

Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Original source
Sep 27, 2019¡arXiv (Cornell University)
1 cites
Gas limit aware mutation testing of smart contracts at scale.

Pieter Hartel, Richard Schumi

The blockchain is a key technology that has been adopted in many application areas to increase security and reliability and to avoid the need for a central trusted authority. One of its essential underlying foundations are smart contracts, which are executable programs for managing data or assets on the blockchain. It is crucial that smart contracts are tested thoroughly due to their immutable nature and since even small bugs can lead to huge monetary losses. However, it is not enough to just test smart contracts, it is also important to ensure the quality and completeness of the tests. Hence, we introduce new smart contract specific mutation operators as well as a novel killing condition that is able to detect a deviation in the gas consumptions, i.e., in the monetary value that is required to perform transactions. Moreover, we establish a baseline for mutation testing of smart contracts by applying our method to a replay test suite and by testing about a thousand contracts.

Open access
Software Testing and Debugging Techniques
Advanced Malware Detection Techniques
Software System Performance and Reliability
Original source
Sep 27, 2019¡Lecture notes in computer science
27 cites
Mutation Testing of Smart Contracts at Scale

Pieter Hartel, Richard Schumi

It is crucial that smart contracts are tested thoroughly due to their immutable nature. Even small bugs in smart contracts can lead to huge monetary losses. However, testing is not enough; it is also important to ensure the quality and completeness of the tests. There are already several approaches that tackle this challenge with mutation testing, but their effectiveness is questionable since they only considered small contract samples. Hence, we evaluate the quality of smart contract mutation testing at scale. We choose the most promising of the existing (smart contract specific) mutation operators, analyse their effectiveness in terms of killability and highlight severe vulnerabilities that can be injected with the mutations. Moreover, we improve the existing mutation methods by introducing a novel killing condition that is able to detect a deviation in the gas consumption, i.e., in the monetary value that is required to perform transactions. This paper has a replication package at https://github.com/pieterhartel/Mutation-at-scale

Open access
4 source records
Software Testing and Debugging Techniques
Advanced Malware Detection Techniques
Adversarial Robustness in Machine Learning
Original source
Sep 26, 2019¡Botnets
7 cites
Use of Botnets for Mining Cryptocurrencies

Renita Murimi

This chapter explores the threats that malware, specifically, botnets pose to the mining of cryptocurrencies. The reader will be introduced to the history of botnet-inspired threats, operational mechanisms of botnets, and an in-depth look at significant botnets that have attacked cryptocurrencies. The chapter looks at countermeasures in terms of detection, prevention, and thwarting. It presents implications for growing cryptocurrency usage and therefore, increasing exposure to various security threats, both organized and unintentional, on botnet black markets, Internet-of-thing devices and from unsuspecting users. The chapter describes a general overview of the consensus operation in cryptomining and shows how threats to the consensus mechanisms could affect the cryptocurrency mining process. It provides an overview of the consensus mechanism in cryptomining and significant threats posed by botnets to the consensus mechanism.

Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Sep 16, 2019¡arXiv
9 cites
Broken Metre: Attacking Resource Metering in EVM

Daniel PĂŠrez, Benjamin Livshits

Blockchain systems, such as Ethereum, use an approach called "metering" to assign a cost to smart contract execution, an approach which is designed to incentivise miners to operate the network and protect it against DoS attacks. In the past, the imperfections of Ethereum metering allowed several DoS attacks which were countered through modification of the metering mechanism. This paper presents a new DoS attack on Ethereum which systematically exploits its metering mechanism. We first replay and analyse several months of transactions, during which we discover a number of discrepancies in the metering model, such as significant inconsistencies in the pricing of the instructions. We further demonstrate that there is very little correlation between the execution cost and the utilised resources, such as CPU and memory. Based on these observations, we present a new type of DoS attack we call Resource Exhaustion Attack, which uses these imperfections to generate low-throughput contracts. To do this, we design a genetic algorithm that generates contracts with a throughput on average 200 times slower than typical contracts. We then show that all major Ethereum client implementations are vulnerable and, if running on commodity hardware, would be unable to stay in sync with the network when under attack. We argue that such an attack could be financially attractive not only for Ethereum competitors and speculators, but also for Ethereum miners. Finally, we discuss short-term and potential long-term fixes against such attacks. Our attack has been responsibly disclosed to the Ethereum Foundation and awarded a bug bounty reward of 5,000 USD.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Security and Verification in Computing
Original source
Sep 14, 2019¡IEEE Transactions on Dependable and Secure Computing
71 cites
Oracle-Supported Dynamic Exploit Generation for Smart Contracts

Haijun Wang, Ye Liu, Yi Li, Shang‐Wei Lin · 7 authors

Despite the high stakes involved in smart contracts, they are often developed in an undisciplined manner, leaving the security and reliability of blockchain transactions at risk. In this article, we introduce ContraMaster—an oracle-supported dynamic exploit generation framework for smart contracts. Existing approaches mutate only single transactions; ContraMaster exceeds these by mutating the transaction sequences. ContraMaster uses data-flow, control-flow, and the dynamic contract state to guide its mutations. It then monitors the executions of target contract programs, and validates the results against a general-purpose semantic test oracle to discover vulnerabilities. Being a dynamic technique, it guarantees that each discovered vulnerability is a violation of the test oracle and is able to generate the attack script to exploit this vulnerability. In contrast to rule-based approaches, ContraMaster has not shown any false positives, and it easily generalizes to unknown types of vulnerabilities (e.g., logic errors). We evaluate ContraMaster on 218 vulnerable smart contracts. The experimental results confirm its practical applicability and advantages over the state-of-the-art techniques, and also reveal three new types of attacks.

Open access
3 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Security and Verification in Computing
Original source
Sep 1, 2019¡2019 IEEE 24th International Workshop on Computer Aided Modeling and Design of Communication Links and Networks (CAMAD)
52 cites
Protecting IoTs from Mirai Botnet Attacks Using Blockchains

Zohaib Ahmed, Syed Muhammad Danish, Hassaan Khaliq Qureshi, Marios Lestas

The exponential growth of Internet of Things (IoT) devices with limited computing resources and poor security configurations make them vulnerable to different cyber-attacks. Mirai Botnet malware exploits vulnerabilities of IoT devices resulting in massive Distributed Denial of Service (DDoS) attacks. Various techniques have been proposed to mitigate Mirai botnet attacks, but most of them are centralized or just provide precautionary steps to secure the IoT devices. This paper addresses IoT security against Mirai Botnet attacks using a novel blockchain based architecture. In our proposed approach, the network is divided into different Autonomous Systems (AS), through which host connectivity is established. Blockchains are used to store and share a list of Internet Protocol (IP) addresses of different hosts connected to an AS, indicating which of these have been identified as malicious. Every AS monitors the communication activity inside the network using the proposed approach and determines whether a host is infected with malware or not by comparing the total number of packets sent by the host with a specified threshold value. The proposed approach is simulated on a custom developed simulator which is used to determine a suitable value for the malicious threshold. The results indicate that the proposed solution works effectively in blocking malicious packets from the infected host so that they do not affect the response time of the victim. Furthermore, a scalability analysis is conducted and the block propagation delay is evaluated for different AS sizes and consensus algorithms.

Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Sep 1, 2019¡2019 24th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA)
13 cites
On-Off Attack on a Blockchain-based IoT System

Fereidoun Moradi, Ali Sedaghatbaf, Sara Abbaspour Asadollah, Aida Čaušević · 5 authors

There is a growing interest in using the Blockchain for resolving IoT security and trustworthiness issues existing in today's complex systems. Blockchain concerns trust in peer to peer networks by providing a distributed tamper-resistant ledger. However, the combination of these two emerging technologies might create new problems and vulnerabilities that attackers might abuse. In this paper, we aim to investigate the trust mechanism of Lightweight Scalable BlockChain (LSB), that is a Blockchain specifically designed for Internet of Things networks, to show that a malicious participant in a Blockchain architecture have possibility to pursue an On-Off attack and downgrade the integrity of the distributed ledger. We choose a remote software update process as an instance to represent this violation. Finally, using the actor-based language Rebeca, we provide a model of a system under attack and verify the described attack scenario.

Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Advanced Malware Detection Techniques
Original source
Sep 1, 2019¡2019 IEEE 18th International Symposium on Network Computing and Applications (NCA)
9 cites
Efficient License Management Based on Smart Contracts Between Software Vendors and Service Providers

Federico Magnanini, Luca Ferretti, Michele Colajanni

In a fully interconnected world where even network-related services are becoming more dependent on software, the management of license agreements is critical for the business of any software vendor and communication provider. Building, managing and protecting the infrastructure to handle software license validation and scalability for the provider and, on the other hand, assessing the correct use of the software licenses for the vendor can become an expensive part of the relationship costs. We propose a novel approach for decentralized software licensing that leverages blockchain and smart contracts as fundamental enabling technologies. Our proposal guarantees a secure and inexpensive system with no central point of failure that can regulate the relations among untrusted parties. We describe the main design choices and present a prototype experimentation that demonstrates the benefits of the proposal in the context of virtualized network infrastructures.

Open access
Blockchain Technology Applications and Security
Software-Defined Networks and 5G
Advanced Malware Detection Techniques
Original source
Sep 1, 2019¡IEEE Consumer Electronics Magazine
18 cites
Rise of Anonymous Cryptocurrencies: Brief Introduction

Jong‐Hyouk Lee

Bitcoin cannot provide enough anonymity for its users and, thus, people started to worry about a possible traceability in their cryptocurrency transactions. More and more people get into the crypto-ecosphere while privacy concerns are paramount. In this paper, five well-known cryptocurrencies that claim they provide anonymity are analyzed to see how, if at all, they achieve anonymity. We then examine the considered cryptocurrencies: Dash, Monero, Verge, PIVX, and Zcash.

Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Malware Detection Techniques
Original source