Little or no research has been directed to analysis and researching forensic analysis of the Bitcoin mixing or 'tumbling' service themselves. This work is intended to examine effective tooling and methodology for recovering forensic artifacts from two privacy focused mixing services namely Obscuro which uses the secure enclave on intel chips to provide enhanced confidentiality and Wasabi wallet which uses CoinJoin to mix and obfuscate crypto currencies. These wallets were set up on VMs and then several forensic tools used to examine these VM images for relevant forensic artifacts. These forensic tools were able to recover a broad range of forensic artifacts and found both network forensics and logging files to be a useful source of artifacts to deanonymize these mixing services.
翻译:这项工作旨在审查从两个以隐私为重点的混合服务机构,即Obscuro(利用英特尔芯片上的安全飞地来提供强化的保密性)和Wasabi钱包(利用Coinjoin来混合和混淆密码货币)中回收法医文物的有效工具和方法。这些钱包是在VMs上设置的,然后是用来检查这些VM图像的法医文物。这些法医工具能够回收广泛的法医文物,发现网络法医和伐木档案是这些混合服务的有用手工艺来源。