Score
Empirical and simulation-based analysis of on-chain data to measure behaviors and system risks, identify account exposures and attack surfaces, and validate theoretical predictions (e.g., mining gaps) to inform mitigations and policy decisions.
Traditional attack graphs struggle to dynamically assess the likelihood of known vulnerabilities being exploited and the risk of compromise at critical nodes. This work proposes a novel approach that integrates Bayesian attack graphs with process mining to enable real-time monitoring of network behavior for malicious traffic detection and dynamic updating of conditional probabilities associated with vulnerability exploitation. By incorporating process mining into the Bayesian attack graph framework for the first time, the method overcomes the limitations of static analysis. Evaluated in a test environment containing multiple CVE-listed vulnerabilities, the approach effectively identifies exploitation activities and significantly improves both the accuracy and timeliness of estimating the probability of system compromise.
The rapidly growing demand for blockchain data analytics lacks a systematic, holistic characterization in existing surveys. To address this gap, we conduct a rigorous scoping review of 466 studies following the PRISMA-ScR guidelines, establishing— for the first time—a structured, end-to-end thematic framework covering the entire blockchain data analytics pipeline. Our analysis identifies six core themes, with illicit activity detection (38%) and financial analytics (29%) dominating the literature, while cross-domain applications such as business intelligence remain markedly underexplored. We uncover critical methodological gaps, including fragmented analytical approaches and insufficient contextual adaptation to real-world blockchain use cases. Based on these findings, we propose three key future directions: enhancing model interpretability, enabling interoperable multi-chain analytics, and closing the business-value loop through actionable insights. This work provides both a theoretical roadmap and practical guidance for unlocking the full analytical potential of blockchain data.
To address the challenge of detecting Advanced Persistent Threats (APTs) that evade traditional rule-based engines, this paper proposes a lightweight, interpretable predictive analytics framework integrating logistic regression and K-means clustering. Designed for low-resource settings with small-scale security event data (Kaggle dataset, *n* = 2,000), it enables real-time threat detection and response. Methodologically, it is the first to synergistically combine these two models in resource-constrained environments and employs SPSS-based statistical tests to validate feature significance. Compared to baseline rule engines, the framework achieves significantly improved threat alert sensitivity (+23.6%) and reduces average response time by 41%, while preserving high model interpretability. It thus delivers actionable, proactive defense decision support for Security Operations Centers (SOCs).
This study addresses the growing prevalence of Web3 security incidents, many of which stem from off-chain systems, organizational processes, and human error—risks inadequately covered by existing security frameworks. The work presents the first systematic qualitative analysis of high-impact Web3 security breaches, structurally mapping case studies onto a Web2 reference framework by integrating OWASP vulnerability categories with organizational security control domains to identify critical failure modes. Building on these insights, the paper proposes a novel security control taxonomy that synthesizes Information Security Management System (ISMS) principles with blockchain-specific characteristics. This framework explicitly delineates high-risk areas such as key management and transaction approval governance, offering Web3 organizations a practical and actionable set of security controls.
This study addresses a novel Lazarus Group campaign targeting cryptocurrency wallets and financial data, focusing on its persistence mechanisms, C2 communication patterns, and data exfiltration tactics. Method: We systematically map the underlying infrastructure and innovatively integrate Tactics, Techniques, and Procedures (TTPs) with multi-source threat intelligence to construct a threat-hunting hypothesis model aligned with the MITRE ATT&CK framework. The methodology combines static and dynamic reverse engineering, IoC correlation mining, and real-time behavioral anomaly detection. Contribution/Results: We derive actionable detection rules and alert-optimization strategies that bridge tactical analysis with strategic risk forecasting. Experimental evaluation demonstrates over a threefold improvement in threat detection speed, significantly enhancing predictive capability against APT behaviors and strengthening defensive resilience.
This study addresses a critical gap in blockchain research, which has predominantly focused on on-chain transactions while neglecting the comprehensive lifecycle management of cryptographic assets. For the first time, the paper introduces the ISO 15489-1:2016 records management standard into the blockchain domain, leveraging records lifecycle theory to propose a seven-stage data lifecycle framework spanning from creation to disposition. The applicability of this model is demonstrated through case studies involving Bitcoin, fungible tokens, and non-fungible tokens. By elucidating the inherent characteristics of blockchain as a records management system, the framework clarifies the boundaries between on-chain and off-chain data and examines how privacy-enhancing technologies affect lifecycle visibility. This structured perspective offers valuable insights for the governance of crypto-assets, regulatory compliance, and forensic investigations.
This study addresses a critical disconnect between blockchain security audits and real-world attack incidents, which has led to significant defensive blind spots. By systematically analyzing 23,818 audit reports and 218 on-chain attacks from 2022 to 2026, the work reveals a severe misalignment between audit focus and high-impact attack vectors—nearly 50% of financial losses stemmed from social engineering attacks (e.g., private key compromises and phishing), which are rarely covered in audits. Moreover, 71.4% of total losses were concentrated in just the top 20 incidents. Leveraging multi-source data fusion and distribution modeling, this research challenges conventional risk assessment assumptions and exposes systemic biases in current auditing paradigms, particularly in coverage breadth and risk-weighting prioritization.
This work addresses the challenge of securing open-source software supply chains, where source code unavailability or obfuscation often hinders effective threat detection, and runtime behavior analysis struggles with scalability and efficiency. To overcome these limitations, we propose HeteroGAT-Rank, a novel system that introduces an “analyst-in-the-loop” paradigm for runtime behavior mining. It models component behaviors as lightweight heterogeneous graphs and employs an attention-based graph neural network to produce interpretable rankings of security-relevant behavioral patterns. By decoupling offline mining from online analysis, the system enables efficient cross-ecosystem discovery of threat indicators. Experiments on large-scale real-world execution traces demonstrate that our approach effectively highlights key behavioral signals aligned with known vulnerabilities and emerging attack trends, thereby supporting human-driven threat investigation workflows.
This study addresses the limitations of traditional industrial control system (ICS) intrusion detection methods that rely on binary labels, which fail to capture the rich diversity of attack behaviors. The authors propose a physics-informed behavioral representation framework that maps multivariate process trajectories into five interpretable behavioral patterns: drift, spike, oscillation, repetition, and switching, thereby transcending the binary evaluation paradigm. For the first time, cross-dataset hierarchical behavioral evaluation is conducted across multiple ICS benchmarks—including SWaT, WADI, and HAI—exposing significant dataset biases and model blind spots. Experimental results reveal a substantial performance degradation under behavioral stratification (e.g., macro F1 on SWaT drops from 85.44% to 37.84%), highlighting the inadequacy of conventional evaluation metrics in reflecting real-world detection capabilities.
Existing Bitcoin mining evaluations predominantly rely on ex-post proxy metrics, failing to adequately capture uncertainty and dynamic adjustments. This paper introduces the first ex-ante statistical model grounded in the fundamental premise that hash computations constitute Bernoulli trials. It establishes a closed-form analytical framework incorporating Bitcoin’s difficulty adjustment mechanism to jointly quantify—per unit of computational power—the expected revenue, downside risk (Value-at-Risk and Expected Shortfall), and upside profit probability. Methodologically, the approach integrates Bayesian modeling, stochastic process analysis, empirical calibration, and sensitivity analysis, enabling comparable assessments across hardware types, mining pools, and operational conditions. The model accurately reproduces historical mining performance and provides an analytically tractable risk–return trade-off tool. It delivers a robust quantitative foundation for grid load forecasting and miner behavioral modeling.