Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

266 papersLast indexed Aug 31, 2026
Search papers

Paper index

266 results · page 9 of 12

Clear filters
Jan 1, 2023·SSRN Electronic Journal
2 cites
DeFi Security: Turning The Weakest Link Into The Strongest Attraction

Ravi Kashyap

The primary innovation we pioneer -- focused on blockchain information security -- is called the Safe-House. The Safe-House is badly needed since there are many ongoing hacks and security concerns in the DeFi space right now. The Safe-House is a piece of engineering sophistication that utilizes existing blockchain principles to bring about greater security when customer assets are moved around. The Safe-House logic is easily implemented as smart contracts on any decentralized system. The amount of funds at risk from both internal and external parties -- and hence the maximum one time loss -- is guaranteed to stay within the specified limits based on cryptographic fundamentals. To improve the safety of the Safe-House even further, we adapt the one time password (OPT) concept to operate using blockchain technology. Well suited to blockchain cryptographic nuances, our secondary advancement can be termed the one time next time password (OTNTP) mechanism. The OTNTP is designed to complement the Safe-House making it even more safe. We provide a detailed threat assessment model -- discussing the risks faced by DeFi protocols and the specific risks that apply to blockchain fund management -- and give technical arguments regarding how these threats can be overcome in a robust manner. We discuss how the Safe-House can participate with other external yield generation protocols in a secure way. We provide reasons for why the Safe-House increases safety without sacrificing the efficiency of operation. We start with a high level intuitive description of the landscape, the corresponding problems and our solutions. We then supplement this overview with detailed discussions including the corresponding mathematical formulations and pointers for technological implementation. This approach ensures that the article is accessible to a broad audience.

Open access
2 source records
cs.CR
cs.CE
cs.CY
Original source
Dec 23, 2022·Computer Science and Information Systems
10 cites
Blockchain-based model for tracking compliance with security requirements

Jelena Marjanović, Nikola Dalčeković, Goran Sladić

The increasing threat landscape in Industrial Control Systems (ICS) brings different risk profiles with comprehensive impacts on society and safety. The complexity of cybersecurity risk assessment increases with a variety of third-party software components that comprise a modern ICS supply chain. A central issue in software supply chain security is the evaluation whether the secure development lifecycle process (SDL) is being methodologically and continuously practiced by all vendors. In this paper, we investigate the possibility of using a decentralized, tamper-proof system that will provide trustworthy visibility of the SDL metrics over a certain period, to any authorized auditing party. Results of the research provide a model for creating a blockchain-based approach that allows inclusion of auditors through a consortium decision while responding to SDL use cases defined by this paper. The resulting blockchain architecture successfully responded to requirements mandated by the security management practice as defined by IEC 62443-4-1 standard.

Open access
Economic and Technological Systems Analysis
Information and Cyber Security
Smart Grid Security and Resilience
Original source
Dec 21, 2022·Law and Safety
1 cites
Development of multi-agent information security management system

Іnnа Khavina, Yu. V. Hnusov, Oleksandr Mozhaiev

The issue of creating an information security system is very relevant in the world today. One of the urgent tasks is to solve the issues of effective protection of information from both external and internal threats through the creation and implementation of information security management systems in automated systems of enterprises, which, among other things, requires the formalization of the task of protecting information for its subsequent implementation by software and other means. Now there are security analysis systems, for example, that examine the security elements settings of workstations and servers operating systems, analyze the network topology, look for unprotected network connections, examine the settings of firewalls. The disadvantage of these systems is that they are not suitable for monitoring large volumes of network traffic. The solution to this problem is the use of monitoring tools capable of analyzing large amounts of data in real time. Therefore, a significant place in the article is given to the review of developments based on artificial intelligence technologies, namely multi-agent systems, review of information security models, threat risk assessment in automated systems.
 The functional architecture of the information security management system based on a multi-agent system has been proposed to search in real time for information security optimal solutions through the selection of such coalitions of protection mechanisms agents that will allow to build the optimal protection of the automated system according to the selected criteria. The model with complete overlapping of threats has been substantiated and adopted as a basis, which allows to analyze the overall situation and choose strategically important decisions directly during the organization of information security. The essence of of multi-agent systems functioning that implement a decentralized control system based on the work of autonomous agents that can be implemented programmatically has been revealed. The role of threat agents, resource agents, agents of protection mechanisms and their functional purpose have been defined. The problem of searching a set of protection mechanisms agents coalition for the current state of the automated system as a problem of optimal search by the criterion of protection cost, taking into account the value of information, has been generalized. Due to the modularity of the multi-agent system, the further work will be aimed at detailing its components and perfection.

Open access
Network Security and Intrusion Detection
Smart Grid Security and Resilience
Information and Cyber Security
Original source
Dec 19, 2022·Applied Sciences
10 cites
An Effective Blockchain-Based Defense Model for Organizations against Vishing Attacks

Ahlam Fakieh, Aymen Akremi

Social engineering (SE) attacks (also called social hacking) refer to various methods used by cybercriminals to exploit the weak nature of human beings rather than the logical and physical security measures used by organizations. This research paper studies the various methods of SE used by criminals to exploit the psychological vulnerabilities of human beings. On this basis, the paper proposes a new defense categorization of SE attacks based on two security principles: dual control (i.e., more than one entity to complete the task) and split knowledge (i.e., dual controlling of the knowledge to complete the task). We describe how those measures could stop SE attacks and avoid human weaknesses. Then, we propose an original new SE defense model that implements the security principles using blockchain technology to both dual control the transactions and record them safely for organizations. The proposed model’s first aim is to avoid the dependence on the cognitive or psychological status of the victim and enable more verification steps to be taken in a fast and flexible manner. The paper demonstrates the quick and easy adoption of the existing private blockchain platform to implement the proposed SE defense model.

Open access
Information and Cyber Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
Oct 3, 2022·Multidisciplinary Research in Computing Information Systems
1 cites
DIGITAL IDENTITY MANAGEMENT SYSTEMS: A CROSSSECTORAL SECURITY AND PRIVACY PERSPECTIVE

Dr. Muhammad Zain Abbas

As the digital ecosystem evolves, secure and efficient Digital IdentityManagement Systems (DIMS) have become pivotal in managing identities acrossgovernmental, financial, healthcare, and commercial sectors. This paper offers across-sectoral examination of DIMS, emphasizing security and privacy concerns andtheir mitigation strategies. Drawing on current technologies such as blockchain,biometrics, and zero-knowledge proofs, the study explores how these systems canprotect sensitive information while ensuring interoperability and compliance withregulatory frameworks. Through comparative analysis, graphical insights, and realworld case studies, the paper underscores the need for standardized and resilientidentity infrastructures that balance user privacy and system functionality

Open access
Information and Cyber Security
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Original source
Jul 19, 2022·arXiv (Cornell University)
6 cites
A Survey on EOSIO Systems Security: Vulnerability, Attack, and Mitigation

Ningyu He, Haoyu Wang, Lei Wu, Xiapu Luo · 6 authors

EOSIO, as one of the most representative blockchain 3.0 platforms, involves lots of new features, e.g., delegated proof of stake consensus algorithm and updatable smart contracts, enabling a much higher transaction per second and the prosperous decentralized applications (DApps) ecosystem. According to the statistics, it has reached nearly 18 billion USD, taking the third place of the whole cryptocurrency market, following Bitcoin and Ethereum. Loopholes, however, are hiding in the shadows. EOSBet, a famous gambling DApp, was attacked twice within a month and lost more than 1 million USD. No existing work has surveyed the EOSIO from a security researcher perspective. To fill this gap, in this paper, we collected all occurred attack events against EOSIO, and systematically studied their root causes, i.e., vulnerabilities lurked in all relying components for EOSIO, as well as the corresponding attacks and mitigations. We also summarized some best practices for DApp developers, EOSIO official team, and security researchers for future directions.

Open access
3 source records
Blockchain Technology Applications and Security
Information and Cyber Security
Cybercrime and Law Enforcement Studies
Original source
Jun 23, 2022·Security Engineering for Embedded and Cyber-Physical Systems
60 cites
Blockchain and Cyber-Physical System for Security Engineering in the Smart Industry

Javaid Ahmad Malik, Muhammad Saleem

Smart manufacturing systems grow based on multiple demands to predict equipment reliability and quality. To this end, many machine learning techniques are examined. Data security and management are other issues that are important for the industry. The integrated blockchain and cyber-physical systems have been used to protect system transactions from hacking the data during transmission to overcome the above problems. In the private blockchain platform, the blockchain system was implemented. The quality control system was evaluated based on non-linear techniques that are complex and demonstrate the truly positive quality control rate of this system. Similarly, the prediction aspect of fault diagnosis was assessed based on hybrid prediction techniques.

Information and Cyber Security
Smart Grid Security and Resilience
Advanced Malware Detection Techniques
Original source
May 27, 2022·International Journal of Network Security & Its Applications
1 cites
An Evaluation of Security in Blockchain-based Sharing of Student Records in Higher Education

Timothy Arndt, Angela Guercio, Young-Hun Chae

Blockchain has recently taken off as a disruptive technology, from its initial use in cryptocurrencies to wider applications in areas such as property registration and insurance due to its characteristic as a distributed ledger which can remove the need for a trusted third party to facilitate transactions. This spread of the technology to new application areas has been driven by the development of smart contracts – blockchain-based protocols which can automatically enforce a contract by executing code based on the logic expressed in the contract. One exciting area for blockchain is higher education. Students in higher education are ever more mobile, and in an ever more agile world, the friction and delays caused by multiple levels of administration in higher education can cause many anxieties and hardships for students as well as potential employers who need to examine and evaluate student credentials. Distance learning as a primary platform for higher education promises to open up higher education to a wider range of learners than ever before. Blockchain-based storage of academic credentials is being widely studied due to the advantages it can bring. As with any network-based system, blockchain comes with a number of security and privacy concerns. Blockchain needs to meet several security-related requirements to be widely accepted: decentralization; confidentiality; integrity; transparency; and immutability. Researchers have been busy devising schemes to ensure that such requirements can be met in blockchain-based systems. Several types of blockchain-specific attacks have been identified: 51% attacks; malicious contracts; spam attacks; mining pools; targeted DDoS attacks; and others. Real-world attacks on blockchain-based systems have been seen on cryptocurrency sites. In this paper, we will evaluate the specific privacy and security concerns for blockchain-based systems used for academic credentials as well as suggested solutions. We also examine the issues for academic credentials which are stored “off-chain” in such systems (as is often the case). In this case, a Distributed File System (DFS) implemented with a peer-to-peer (P2P) architecture is often the choice for the storage of the academic credentials since it matches the decentralized nature of blockchain. Blockchain then contributes much to the usefulness of such a DFS, making it in turn a good match for a P2P DFS such as IPFS.

Open access
2 source records
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Cryptography and Data Security
Original source
May 2, 2022·IEEE Security & Privacy
7 cites
Ransomware-Bitcoin Threat Intelligence Sharing Using Structured Threat Information Expression

Adam Turner, Stephen McCombie, Allon J. Uhlmann

To address the challenge of representing ransomware-cryptocurrency payments, this article outlines a novel approach to the extraction and sharing of threat intelligence data from the Bitcoin blockchain. This work results in the creation of two new cyber-observable objects, x-cryptocurrency-address, and x-cryptocurrency-transaction.

Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Original source
Jan 1, 2022·International Journal of Security and Networks
9 cites
Using blockchains to protect critical infrastructures: a comparison between Ethereum and Hyperledger Fabric

Wilson S. Melo, Lucas S. Dos Santos, Lucila M. S. Bento, Paulo R. Nascimento · 6 authors

The monitoring and protection of critical infrastructures, especially the ones involving physical assets (e.g., dams, nuclear energy facilities, governmental buildings), constitute a challenging problem. The failure and collapse of these infrastructures can cause untold consequences. Recent works have proposed blockchains as a tool to improve monitoring systems in different critical infrastructures. However, most previous works lack on presenting a more in-depth discussion about how to implement these solutions. In this paper, we develop a practical approach. We propose a comprehensive framework that describes how to implement a blockchain-based system to monitor and protect critical infrastructures. We implement our framework in two distinct blockchain platforms: Ethereum and Hyperledger Fabric. We compare both implementations and discuss their differences in terms of performance, easiness of development, security, privacy, complexity, and costs. We believe that our results can be valuable for professionals interested in applying blockchain-based solutions to protect critical infrastructures.

2 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Original source
Dec 17, 2021·2021 4th International Conference on Blockchain Technology and Applications
17 cites
Under Pressure. A User-Centered Threat Model for Cryptocurrency Owners

Michael Froehlich, Philipp Hulm, Florian Alt

Cryptocurrencies have gained popularity in recent years. However, for many users, keeping ownership of their cryptocurrency is a complex task. News reports frequently bear witness to scams, hacked exchanges, and fortunes beyond retrieval. However, we lack a systematic understanding of user-centered cryptocurrency threats, as causes leading to loss are scattered across publications. To address this gap, we conducted a focus group (n=6) and an expert elicitation study (n=25) following a three-round Delphi process with a heterogeneous group of blockchain and security experts from academia and industry. We contribute the first systematic overview of threats cryptocurrency users are exposed to and propose six overarching categories. Our work is complemented by a discussion on how the human-computer-interaction community can address these threats and how practitioners can use the model to understand situations in which users might find themselves under the pressure of an attack to ultimately engineer more secure systems.

Information and Cyber Security
User Authentication and Security Systems
Privacy, Security, and Data Protection
Original source
Dec 7, 2021·Digital War
11 cites
Developing a Trusted Human-AI Network for Humanitarian Benefit

S. Kate Devitt, Jason Scholz, Timo Schless, L Lewis

Abstract Artificial intelligences (AI) will increasingly participate digitally and physically in conflicts yet there is a lack of trusted communications with humans for humanitarian purposes. For example, in disasters and conflicts messaging and social media are used to share information, however, international humanitarian relief organisations treat this information as unverifiable and untrustworthy. Furthermore, current AI implementations can be brittle, with a narrow scope of application and wide scope of ethical risks. Meanwhile, human error can cause significant civilian harms even by combatants committed to compliance with international humanitarian law. AI offers an opportunity to help reduce the tragedy of war and better deliver humanitarian aid to those who need it. However, to be successful, these systems must be trusted by humans and their information systems, overcoming flawed information flows in conflict and disaster zones that continue to be marked by intermittent communications, poor situation awareness, mistrust and human errors. In this paper, we consider the integration of a communications protocol (the ‘Whiteflag protocol’), distributed ledger ‘blockchain’ technology, and information fusion with artificial intelligence (AI), to improve conflict communications called “Protected Assurance Understanding Situation & Entities” (PAUSE). Such a trusted human-AI communication network could provide accountable information exchange regarding protected entities, critical infrastructure, humanitarian signals and status updates for humans and machines in conflicts. Trust-based information fusion provides resource-efficient use of diverse data sources to increase the reliability of reports. AI can catch human mistakes and complement human decision making, while human judgment can direct and override AI recommendations. We examine several realistic potential case studies for the integration of these technologies into a trusted human-AI network for humanitarian benefit including mapping a conflict zone with civilians and combatants in real time, preparation to avoid incidents and using the network to manage misinformation. We finish with a real-world example of a PAUSE-like network, the Human Security Information System (HSIS), being developed by USAID, that uses blockchain technology to provide a secure means to better understand the civilian environment.

Open access
3 source records
cs.CY
cs.AI
cs.HC
Original source
Nov 1, 2021·DOAJ (DOAJ: Directory of Open Access Journals)
0 cites
Key Update Mechanism in Bitcoin Based on Improved P2PKHCA Script Scheme

GAO Hong-feng XIANG A-xin

Bitcoin is one of the most mature public chain application systems,the user key is the critical factor to the process of determining the ownership of Bitcoin,the security of Bitcoin is guaranteed by the safe management of the user key,and the loss of the key will lead to the loss of a large number of user assets.So it is an urgent problem to recover the lost assets.This paper proposes a key update mechanism in Bitcoin based on the improved P2PKHCA (pay-to-public-key-hash-with-conditional-anonymity) script scheme to solve above problems.Firstly,the key generation algorithm in the P2PKHCA scheme is improved by introducing the key life cycle and random number to solve its key leakage problem.Secondly,the two new opcodes,OP_KEYUPDATE and OP_TSELECTION,are proposed to design the new key update script to realize the user key update of the Bitcoin system.Finally,two types of key update schemes based on the key update script are constructed to make the script suitable for the requirements of different key update applications.The security analysis and performance analysis of the key update mechanism show that the proposed mechanism realizes the recovery of lost Bitcoins in the Bitcoin system on the premise of the effective completion of update of user's key.

Open access
Information and Cyber Security
Original source
Aug 26, 2021·Applied Sciences
31 cites
Avoidance of Cybersecurity Threats with the Deployment of a Web-Based Blockchain-Enabled Cybersecurity Awareness System

Abdul Razaque, Abrar Al Ajlan, Noussaiba Melaoune, Munif Alotaibi · 9 authors

Modern information technology (IT) is well developed, and almost everyone uses the features of IT and services within the Internet. However, people are being affected due to cybersecurity threats. People can adhere to the recommended cybersecurity guidelines, rules, adopted standards, and cybercrime preventive measures to largely mitigate these threats. The ignorance of or lack of cybersecurity knowledge also causes a critical problem regarding confidentiality and privacy. It is not possible to fully avoid cybercrimes that often lead to sufficient business losses and spread forbidden themes (disgust, extremism, child porn, etc.). Therefore, to reduce the risk of cybercrimes, a web-based Blockchain-enabled cybersecurity awareness program (WBCA) process is introduced in this paper. The proposed WBCA trains users to improve their security skills. The proposed program helps with understanding the common behaviors of cybercriminals and improves user knowledge of cybersecurity hygiene, best cybersecurity practices, modern cybersecurity vulnerabilities, and trends. Furthermore, the proposed WBCA uses Blockchain technology to protect the program from potential threats. The proposed program is validated and tested using real-world cybersecurity topics with real users and cybersecurity experts. We anticipate that the proposed program can be extended to other domains, such as national or corporate courses, to increase the cybersecurity awareness level of users. A CentOS-based virtual private server is deployed for testing the proposed WBCA to determine its effectiveness. Finally, WBCA is also compared with other state-of-the-art web-based programs designed for cybersecurity awareness.

Open access
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Advanced Malware Detection Techniques
Original source
Apr 30, 2021·2021 Systems and Information Engineering Design Symposium (SIEDS)
11 cites
Trust and Security of Embedded Smart Devices in Advanced Logistics Systems

Christopher M. VanYe, Beatrice Li, Andrew Koch, Mai N. Luu · 12 authors

This paper addresses security and risk management of hardware and embedded systems across several applications. There are three companies involved in the research. First is an energy technology company that aims to leverage electric- vehicle batteries through vehicle to grid (V2G) services in order to provide energy storage for electric grids. Second is a defense contracting company that provides acquisition support for the DOD's conventional prompt global strike program (CPGS). These systems need protections in their production and supply chains, as well as throughout their system life cycles. Third is a company that deals with trust and security in advanced logistics systems generally. The rise of interconnected devices has led to growth in systems security issues such as privacy, authentication, and secure storage of data. A risk analysis via scenario-based preferences is aided by a literature review and industry experts. The analysis is divided into various sections of Criteria, Initiatives, C-I Assessment, Emergent Conditions (EC), Criteria-Scenario (C-S) relevance and EC Grouping. System success criteria, research initiatives, and risks to the system are compiled. In the C-I Assessment, a rating is assigned to signify the degree to which criteria are addressed by initiatives, including research and development, government programs, industry resources, security countermeasures, education and training, etc. To understand risks of emergent conditions, a list of Potential Scenarios is developed across innovations, environments, missions, populations and workforce behaviors, obsolescence, adversaries, etc. The C-S Relevance rates how the scenarios affect the relevance of the success criteria, including cost, schedule, security, return on investment, and cascading effects. The Emergent Condition Grouping (ECG) collates the emergent conditions with the scenarios. The generated results focus on ranking Initiatives based on their ability to negate the effects of Emergent Conditions, as well as producing a disruption score to compare a Potential Scenario's impacts to the ranking of Initiatives. The results presented in this paper are applicable to the testing and evaluation of security and risk for a variety of embedded smart devices and should be of interest to developers, owners, and operators of critical infrastructure systems.

Physical Unclonable Functions (PUFs) and Hardware Security
Information and Cyber Security
Security and Verification in Computing
Original source
Apr 1, 2021·Security and Privacy. 2021;e191
79 cites
Augmenting Zero Trust Architecture to Endpoints Using Blockchain: A State-of-The-Art Review

Lampis Alevizos, Vinh‐Thong Ta, Mahmoud Hashem Eiza

Abstract With the purpose of defending against lateral movement in today's borderless networks, zero trust architecture (ZTA) adoption is gaining momentum. With a full‐scale ZTA implementation, it is unlikely that adversaries will be able to spread through the network starting from a compromised endpoint. However, the already authenticated and authorized session of a compromised endpoint can be leveraged to carry out limited, though malicious, activities ultimately rendering the endpoints the Achilles heel of ZTA. To effectively detect such attacks, distributed collaborative intrusion detection systems with an attack scenario‐based approach have been developed. Nonetheless, advanced persistent threats have demonstrated their ability to bypass this approach with a high success ratio. As a result, adversaries can pass undetected or potentially alter the detection logging mechanisms to achieve a stealthy presence. Recently, blockchain technology has demonstrated solid use cases in the cyber security domain. In this paper, motivated by the convergence of ZTA and blockchain‐based intrusion detection and prevention, we examine how ZTA can be augmented onto endpoints. Namely, we perform a state‐of‐the‐art review of ZTA models, real‐world architectures with a focus on endpoints, and blockchain‐based intrusion detection systems. We discuss the potential of blockchain's immutability fortifying the detection process and identify open challenges as well as potential solutions and future directions.

Open access
3 source records
cs.CR
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Jan 1, 2021·International Journal of Multidisciplinary Research and Growth Evaluation
2 cites
Evaluating the Efficacy of DID Chain-Enabled Blockchain Frameworks for Real-Time Provenance Verification and Anti-Counterfeit Control in Global Pharmaceutical Supply Chains

Ifeoluwa Oreofe Oluwafemi, T. Prabhakar Clement, Oluwasanmi Segun Adanigbo, Toluwase Peter Gbenle · 5 authors

The global pharmaceutical industry faces growing threats from counterfeit and substandard drugs, undermining public health, regulatory compliance, and supply chain trust. To address these challenges, this paper evaluates the efficacy of DIDChain-enabled blockchain frameworks, which integrate Decentralized Identifiers (DIDs) with distributed ledger technology to establish real-time provenance verification and anti-counterfeit control. Drawing on a comprehensive body of literature, including conceptual frameworks in digital transformation, cybersecurity, business intelligence, and cloud-based analytics, the study explores how DIDChain infrastructure can enhance transparency, immutability, and interoperability in pharmaceutical logistics. The analysis incorporates findings from prior research on AI-driven fraud detection, supply chain resilience, and data governance models, particularly those applied in the financial, energy, and SME sectors. The evaluation highlights the role of DIDChain in supporting secure product authentication, automated compliance auditing, and cross-border regulatory coordination. This research contributes to emerging discourse on digital trust technologies, offering a scalable and interoperable solution for ensuring drug integrity in complex and globalized pharmaceutical ecosystems.

Open access
Big Data and Business Intelligence
Information and Cyber Security
Cloud Data Security Solutions
Original source
Jan 1, 2021·IEEE Transactions on Knowledge and Data Engineering
237 cites
Combining Graph Neural Networks with Expert Knowledge for Smart Contract Vulnerability Detection

Zhenguang Liu, Peng Qian, Xiaoyang Wang, Yuan Zhuang · 6 authors

Smart contract vulnerability detection draws extensive attention in recent years due to the substantial losses caused by hacker attacks. Existing efforts for contract security analysis heavily rely on rigid rules defined by experts, which are labor-intensive and non-scalable. More importantly, expert-defined rules tend to be error-prone and suffer the inherent risk of being cheated by crafty attackers. Recent researches focus on the symbolic execution and formal analysis of smart contracts for vulnerability detection, yet to achieve a precise and scalable solution. Although several methods have been proposed to detect vulnerabilities in smart contracts, there is still a lack of effort that considers combining expert-defined security patterns with deep neural networks. In this paper, we explore using graph neural networks and expert knowledge for smart contract vulnerability detection. Specifically, we cast the rich control- and data- flow semantics of the source code into a contract graph. To highlight the critical nodes in the graph, we further design a node elimination phase to normalize the graph. Then, we propose a novel temporal message propagation network to extract the graph feature from the normalized graph, and combine the graph feature with designed expert patterns to yield a final detection system. Extensive experiments are conducted on all the smart contracts that have source code in Ethereum and VNT Chain platforms. Empirical results show significant accuracy improvements over the state-of-the-art methods on three types of vulnerabilities, where the detection accuracy of our method reaches 89.15%, 89.02%, and 83.21% for reentrancy, timestamp dependence, and infinite loop vulnerabilities, respectively.

Open access
2 source records
Blockchain Technology Applications and Security
Web Application Security Vulnerabilities
Information and Cyber Security
Original source
Dec 29, 2020·Journal of Sensor and Actuator Networks
16 cites
Blockchain and IoMT against Physical Abuse: Bullying in Schools as a Case Study

Nikolaos Ersotelos, Mirko Bottarelli, Haider Al‐Khateeb, Gregory Epiphaniou · 7 authors

By law, schools are required to protect the well-being of students against problems such as on-campus bullying and physical abuse. In the UK, a report by the Office for Education (OfE) showed 17% of young people had been bullied during 2017–2018. This problem continues to prevail with consequences including depression, anxiety, suicidal thoughts, and eating disorders. Additionally, recent evidence suggests this type of victimisation could intensify existing health complications. This study investigates the opportunities provided by Internet of Medical Things (IoMT) data towards next-generation safeguarding. A new model is developed based on blockchain technology to enable real-time intervention triggered by IoMT data that can be used to detect stressful events, e.g., when bullying takes place. The model utilises private permissioned blockchain to manage IoMT data to achieve quicker and better decision-making while revolutionising aspects related to compliance, double-entry, confidentiality, and privacy. The feasibility of the model and the interaction between the sensors and the blockchain was simulated. To facilitate a close approximation of an actual IoMT environment, we clustered and decomposed existing medical sensors to their attributes, including their function, for a variety of scenarios. Then, we demonstrated the performance and capabilities of the emulator under different loads of sensor-generated data. We argue to the suitability of this emulator for schools and medical centres to conduct feasibility studies to address sensor data with disruptive data processing and management technologies.

Open access
Bullying, Victimization, and Aggression
COVID-19 and Mental Health
Information and Cyber Security
Original source
Dec 7, 2020·III Workshop em Blockchain: Teoria, Tecnologias e Aplicações (WBlockchain 2020)
0 cites
Simulação do Penny Attack no Ethereum e sua Identificação usando Classificadores

José Eduardo de Azevedo Sousa, Vinícius Cunha Oliveira, Júlia Almeida Valadares, Alex Borges Vieira · 7 authors

O crescimento do interesse em Ethereum leva a preocupações relacionadas à sua segurança, dado que já houveram ataques que exploraram o seu mecanismo de tarifação ou Penny Attack. Esses ataques afetaram a rede ocasionando lentidão nas transações e há indícios que Ethereum continua susceptível a esse tipo de ataque. Analisamos o comportamento da rede Ethereum durante um Penny Attack, buscando técnicas de aprendizado de máquina para detectá-lo previamente, utilizando atributos das transações. Nossas técnicas tiveram AUC, Fb e recall superior a 94%, 82% e 98% respectivamente.

Open access
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Information and Cyber Security
Original source
Oct 28, 2020·2020 11th IEEE Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON)
26 cites
Cyber Fraud: Detection and Analysis of the Crypto-Ransomware

İlker Kara, Murat Aydos

Currently as the widespread use of virtual monetary units (like Bitcoin, Ethereum, Ripple, Litecoin) has begun, people with bad intentions have been attracted to this area and have produced and marketed ransomware in order to obtain virtual currency easily. This ransomware infiltrates the victim's system with smartly-designed methods and encrypts the files found in the system. After the encryption process, the attacker leaves a message demanding a ransom in virtual currency to open access to the encrypted files and warns that otherwise the files will not be accessible. This type of ransomware is becoming more popular over time, so currently it is the largest information technology security threat. In the literature, there are many studies about detection and analysis of this cyber-bullying. In this study, we focused on crypto-ransomware and investigated a forensic analysis of a current attack example in detail. In this example, the attack method and behavior of the crypto-ransomware were analyzed and it was identified that information belonging to the attacker was accessible. With this dimension, we think our study will significantly contribute to the struggle against this threat.

Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Information and Cyber Security
Original source