论文标题
使用智能合约和IPFS勒索软件作为服务
Ransomware as a Service using Smart Contracts and IPFS
论文作者
论文摘要
分散的系统,例如分布式分类帐和行星际文件系统(IPFS),旨在提供更多开放和强大的服务。但是,它们也为非法活动创造了机会。我们演示了这些技术如何用于推出勒索软件作为服务活动。我们表明,罪犯可以与分支机构和受害者进行交易,而不必透露其身份。此外,通过利用对IPF搅拌的鲁棒性和弹性,以及以太坊的分散计算能力,在大多数程序中,犯罪分子都可以保持离线,并提供许多隐私保证。
Decentralized systems, such as distributed ledgers and the InterPlanetary File System (IPFS), are designed to offer more open and robust services. However, they also create opportunities for illegal activities. We demonstrate how these technologies can be used to launch a ransomware as a service campaign. We show that criminals can transact with affiliates and victims without having to reveal their identity. Furthermore, by exploiting the robustness and resilience to churn of IPFS, as well as the decentralized computing capabilities of Ethereum, criminals can remain offline during most procedures, with many privacy guarantees.