Researchers reveal Bitcoin blockchain security flaw caused by excessive node concentration

Researchers reveal Bitcoin blockchain security flaw caused by excessive node concentration

At the 38th IEEE Security and Privacy Symposium, Aviv Zohar of the Hebrew University will present a report (download the full text of the Coin Library) that details how to attack the Bitcoin blockchain through the Internet's routing architecture. In the report, Zohar and his research partners Maria Apostolaki and Laurent Vanbever demonstrated two ways that the Border Gateway Protocol (BGP) can attack Bitcoin - partition attack attack and delayed attack attack.

In a partition attack scenario, if an Internet Service Provider (ISP) is the only path to a significant portion of the Bitcoin network, a black hole (network Trojan) could block both parties (blockchain and network routing) from communicating. While these two "islands" process transactions and mine Bitcoins on their own, once an intruder connects both parties again, there is no choice but to lose the mined Bitcoins, transactions, and mining revenue.

Researchers say that in some ways, delay attacks are considered the worst-case scenario because, unlike partition attacks, they are undetectable. Merchants can easily double-spend after being attacked; miners' transaction processing capacity will also be wasted, and ordinary nodes will not be able to propagate normally in the blockchain.

Such problems are daunting for bitcoin developers, who have no control over attack vectors or the BGP protocol that determines the path that packets take in the network.

BGP is a simplified product of this era, used to trust the information received. An intentional or unintentional error in a carrier or ISP network will have a negative impact on BGP routing information and endanger most network traffic.

Both types of attacks require an insider to provide ISP information in order to succeed. Despite this, they still have the potential to cause significant attacks on the Bitcoin network and can be easily overlooked. Bitcoin nodes tend to cluster in a small number of ISPs. It is estimated that 30% of the Bitcoin network exists in 13 hosts and 60% of Bitcoin traffic is visible in 3 ISPs.

The researchers mentioned that in November 2015 alone, BGP attacks affected hundreds of Bitcoin nodes, accounting for 8% of the total network nodes (447 nodes) at the time. However, the report also proposed some countermeasures, most of which can be deployed immediately, such as ensuring the diversity of node connections, considering routing conditions when selecting nodes, and "encrypting Bitcoin connections or using message authentication codes (MACs) to verify the authenticity of each message content, which makes delay attacks more difficult."

Michael Perklin, chief information security officer of cryptocurrency asset exchange Shapeshift, said that Bitcoin was designed to resist attacks, just like the Internet, whose reason for existence is to withstand nuclear attacks on cities; through the decentralization of nodes, unilateral failure is ensured to be non-existent. Perklin said that the Bitcoin blockchain record contains the details of each transaction. Therefore, once the blockchain and ISP attacks are blocked, two different records will be generated. The reversal of payments and the destruction of new coins will cause consensus failure, which will have a catastrophic impact on the economy.

Perklin concluded:

Fortunately, ISPs are aware of the importance of BGP in node connectivity and they regularly take steps to prevent related attacks. While such attacks are theoretically possible (like brute-forcing private keys), we can rest assured that they are difficult to carry out in practice because the attackers have to have privileged access to highly protected devices.

The details of the security issues mentioned in this report will be announced at the IEEE conference in May this year. The researchers said they will release code in GitHub to simulate the attack prototype.

<<:  Nchain reportedly created the largest acquisition in Bitcoin history with $300 million, with Australian “Satoshi Nakamoto” serving as chief scientist

>>:  Coin Zone Trends: Bitcoin Price Trends Based on Big Data This Week (2017-04-17)

Recommend

What kind of women are more likely to get divorced?

As the divorce rate in society gets higher and hi...

Is it good for a woman to have a mole on the back of her right hand?

Moles are closely related to us and have a certai...

What are the people who are born with good fortune?

In life, we find that many elderly people will lo...

Coinbase will pay 4% annual yield to users holding USDC

Major cryptocurrency exchange Coinbase has announ...

See your future fortune from your facial features

From the perspective of physiognomy, a person'...

Five facial features of women who are prone to cheating

As one of the traditional physiognomy techniques, ...

Bitcoin Energy Consumption Index-2018-03-13

Bitcoin Energy Consumption Index-2018-03-13 Bitco...

What does a mole in the ear hole mean and how does it affect your destiny?

Moles are very familiar to people, and different ...

Palmistry wisdom line to see the career suitable for you

Some people have been determined to work in a cer...