Follow the money: Revealing risky nodes in a Ransomware-Bitcoin network

dc.contributor.authorTurner, Adam
dc.contributor.authorMccombie, Stephen
dc.contributor.authorUhlmann, Allon
dc.date.accessioned2020-12-24T19:18:03Z
dc.date.available2020-12-24T19:18:03Z
dc.date.issued2021-01-05
dc.description.abstractThis paper demonstrates the use of network analysis to identify core nodes associated with ransomware attacks in cryptocurrency transaction networks. The method helps trace the cyber entities involved in cryptocurrency attacks and supports intelligence efforts to identify and disrupt cryptocurrency networks. A data corpus is built by the unsupervised machine learning graph algorithm ‘DeepWalk’ [1]. DeepWalk evaluates the position of nodes within networks. It compares the relative position of different nodes (similarity) and identifies those whose removal would most affect the network (riskiness). This method helps identify on the blockchain the key nodes that are involved in the execution of a ransomware attack. When applied to the ransomware “cash out” graph, the method derived “riskiness” scores for specific nodes. Analysing the derived “riskiness” at a community level (groups of nodes in the network) provides an enhanced granularity for identifying and targeting influential nodes. Such insight could potentially support both intelligence and forensics investigations.
dc.format.extent13 pages
dc.identifier.doi10.24251/HICSS.2021.189
dc.identifier.isbn978-0-9981331-4-0
dc.identifier.urihttp://hdl.handle.net/10125/70801
dc.language.isoEnglish
dc.relation.ispartofProceedings of the 54th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectMachine Learning and Predictive Analytics in Accounting, Finance, and Management
dc.subjectbitcoin
dc.subjectcryptocurrency
dc.subjectgraph analytics
dc.subjectmachine learning
dc.subjectransomware
dc.subjectrisk
dc.titleFollow the money: Revealing risky nodes in a Ransomware-Bitcoin network
prism.startingpage1560

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0154.pdf
Size:
1.05 MB
Format:
Adobe Portable Document Format