1,720,990 research outputs found

    On the economic significance of ransomware campaigns: A Bitcoin transactions perspective

    No full text
    Bitcoin cryptocurrency system enables users to transact securely and pseudo-anonymously by using an arbitrary number of aliases (Bitcoin addresses). Cybercriminals exploit these characteristics to commit immutable and presumably untraceable monetary fraud, especially via ransomware; a type of malware that encrypts files of the infected system and demands ransom for decryption. In this paper, we present our comprehensive study on all recent ransomware and report the economic impact of such ransomware from the Bitcoin payment perspective. We also present a lightweight framework to identify, collect, and analyze Bitcoin addresses managed by the same user or group of users (cybercriminals, in this case), which includes a novel approach for classifying a payment as ransom. To verify the correctness of our framework, we compared our findings on CryptoLocker ransomware with the results presented in the literature. Our results align with the results found in the previous works except for the final valuation in USD. The reason for this discrepancy is that we used the average Bitcoin price on the day of each ransom payment whereas the authors of the previous studies used the Bitcoin price on the day of their evaluation. Furthermore, for each investigated ransomware, we provide a holistic view of its genesis, development, the process of infection and execution, and characteristic of ransom demands. Finally, we also release our dataset that contains a detailed transaction history of all the Bitcoin addresses we identified for each ransomware

    A survey on security and privacy issues of bitcoin

    No full text
    Bitcoin is a popular cryptocurrency that records all transactions in a distributed append-only public ledger called blockchain. The security of Bitcoin heavily relies on the incentive-compatible proof-of-work (PoW) based distributed consensus protocol, which is run by the network nodes called miners. In exchange for the incentive, the miners are expected to maintain the blockchain honestly. Since its launch in 2009, Bitcoin economy has grown at an enormous rate, and it is now worth about 150 billions of dollars. This exponential growth in the market value of bitcoins motivate adversaries to exploit weaknesses for profit, and researchers to discover new vulnerabilities in the system, propose countermeasures, and predict upcoming trends. In this paper, we present a systematic survey that covers the security and privacy aspects of Bitcoin. We start by giving an overview of the Bitcoin system and its major components along with their functionality and interactions within the system. We review the existing vulnerabilities in Bitcoin and its major underlying technologies such as blockchain and PoW-based consensus protocol. These vulnerabilities lead to the execution of various security threats to the standard functionality of Bitcoin. We then investigate the feasibility and robustness of the state-of-the-art security solutions. Additionally, we discuss the current anonymity considerations in Bitcoin and the privacy-related threats to Bitcoin users along with the analysis of the existing privacy-preserving solutions. Finally, we summarize the critical open challenges, and we suggest directions for future research towards provisioning stringent security and privacy solutions for Bitcoin

    When Blockchain Meets Smart Cities:Opportunities, Security and Future Research

    No full text
    Smart cities use information and communication technologies to offer efficient management of services, resources and infrastructure to improve the quality of life for their citizens while addressing environmental and urban challenges and promoting economic growth. The smart city concept relies on digital connectivity and a growing number of networked smart devices and sensors deployed in cities and urban environments enabling real-time data collection and analytics for data-driven decision-making in various smart city applications. In this chapter, we explore how blockchain technology can address some of the application-specific challenges in smart cities and identify open issues and future research directions for the adoption of blockchain in smart city applications. The chapter further focuses on the potential of blockchain technology in enhancing the security of smart city applications.</p

    Efficient Hardware Implementations of Grain-128AEAD

    No full text
    We implement the Grain-128AEAD stream cipher in hardware, using a 65 nm library. By exploring different optimization techniques, both at RTL level but also during synthesis, we first target high throughput, then low power. We reach over 33 GB/s targeting a high-speed design, at expense of power and area. We also show that, when targeting low power, the design only requires 0.23 {\upmu }W running at 100 kHz. By unrolling the design, the energy consumed when encrypting a fixed length message decreases, making the 64 parallelized version the most energy efficient implementation, requiring only 11.2 nJ when encrypting a 64 kbit message. At the same time, the best throughput/power ratio is achieved at a parallelization of 4

    Going Beyond Counting First Authors in Author Co-citation Analysis

    Get PDF
    The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed

    Security Services Using Crowdsourcing

    No full text
    AbstractSecurity-as-a-service is an emerging area in cloud computing. Traditionally, security approaches are service provider-centric and provider-driven. In this paper, we propose a model for security-as-a-service using “crowdsourcing”. Though crowdsourcing has been used to provide specific security services like browser security, detecting phishing attacks, detecting cybersecurity threats, there has been no work which provides a unified framework to provide different types of security verification. Dispersed computing power of devices is used to perform security verifications. This is done by subscribers in a collaborative way, using their idle resources, in exchange of certain incentives. Our architecture guarantees anonymity of users who request service and the crowd who contribute in verification by using virtualization concepts and virtual machines. Moreover, we propose an approach for managing these security verification jobs, subscribers in a fault tolerant manner. To the best of our knowledge, we are the first to propose a unified security-as-a-service framework using crowdsourcing, thus introducing a new research problem. We discuss a number of applications, challenges and problems of crowdsourcing in security verification

    Securing cloud data

    No full text
    Clouds are increasingly being used to store personal and sensitive information such as health records and important documents. We address the problem of storing sensitive information in the cloud so that the cloud service provider cannot tamper with the stored data. We present three problems: computing on encrypted data, access control of stored data, and auditing techniques for integrity verification. The first problem uses a cryptographic primitive called homomorphic encryption; the second problem uses attribute-based encryption (ABE), and the third uses provable data possession (PDP) and proof of retrievability (PoR). We survey recent results and discuss some open problems in this domain

    From Centralized to Decentralized Remote Electronic Voting

    No full text
    Elections generally involve the simple tasks of counting votes and publishing the final tally to voters. Depending on the election’s scope, these processes require sophisticated methods embedded in the electorate’s various technological and societal factors (e.g., the voting culture). An election’s integrity is the pinnacle of the trust placed in the voting process and its final results. Previous research on cryptographic voting schemes continuously refined voting protocols to achieve private and verifiable elections. These cryptographic schemes enable novel ways to allow remote voting systems to (i) provide a remote voting alternative to on-site voting with a ballot box and (ii) offer a technical path to building an end-to-end verifiable Electronic Voting system by applying cryptographic primitives. This chapter explicitly addresses Remote Electronic Voting (REV), which enables vote casting in an uncontrolled environment and vote transmission over communication channels (e.g., over the Internet). Further, this chapter clarifies how the Distributed Ledger (DL) technology can enhance the decentralization of the electoral process, ensuring transparency and the ability to verify results while guaranteeing the confidentiality of voters. Thus, necessary cryptographic fundamentals and examples of voting schemes, their properties, and trade-offs will be investigated. The different approaches toward REV systems are detailed, followed by an overview of related work. Further, a centralized REV voting system architecture, all stakeholders involved, and critical trust assumptions are outlined. This leads to the proposal of a fully decentralized architecture, which is being evaluated in qualified discussions with respect to long-term privacy, verifiability, and voter authentication. Finally, open research aspects are complemented by overall considerations on decentralized REV

    Variations on the Author

    Get PDF
    “Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship
    corecore