Cybercriminals often leverage Bitcoin for their illicit activities. In this work, we propose back-and-forth exploration, a novel automated Bitcoin transaction tracing technique to identify cybercrime financial relationships. Given seed addresses belonging to a cybercrime campaign, it outputs a transaction graph, and identifies paths corresponding to relationships between the campaign under study and external services and other cybercrime campaigns. Back-and-forth exploration provides two key contributions. First, it explores both forward and backwards, instead of only forward as done by prior work, enabling the discovery of relationships that cannot be found by only exploring forward (e.g., deposits from clients of a mixer). Second, it prevents graph explosion by combining a tagging database with a machine learning classifier for identifying addresses belonging to exchanges. We evaluate back-and-forth exploration on 30 malware families. We build oracles for 4 families using Bitcoin for C&C and use them to demonstrate that back-and-forth exploration identifies 13 C&C signaling addresses missed by prior work, 8 of which are fundamentally missed by forward-only explorations. Our approach uncovers a wealth of services used by the malware including 44 exchanges, 11 gambling sites, 5 payment service providers, 4 underground markets, 4 mining pools, and 2 mixers. In 4 families, the relations include new attribution points missed by forward-only explorations. It also identifies relationships between the malware families and other cybercrime campaigns, highlighting how some malware operators participate in a variety of cybercriminal activities.
翻译:网络犯罪分子往往利用Bitcoin进行非法活动。 在这项工作中,我们提议进行回向和后向的探索,即创新的自动化Bitcoin交易追踪技术,以识别网络犯罪的金融关系。根据属于网络犯罪运动的种子地址,它产出了一个交易图,并确定了与研究运动与外部服务和其他网络犯罪运动之间关系的路径。后向和后向的探索提供了两个主要贡献。首先,它探索前向和后向,而不是仅像以往工作那样向前推进,从而得以发现无法仅通过探索而找到的多种关系(例如,来自混合商客户的存款)。第二,它通过将标签数据库与机器学习分类师相结合,确定属于交易所的地址,防止图形爆炸。我们评估了30个恶意家庭之间的回向和前向探索。我们为4个家庭使用Bitcoin进行回向回向和前向和向后向的勘探提供了两个关键贡献。它不仅确定了13 C&C发出先前工作错失的地址,其中8个是前向式探索从根本上错失的。我们的方法还揭示了在4号客户之间使用的服务的财富,包括4号交易公司、11号赌场的前向前向交易、4号交易公司、前向交易、4号交易公司、前向前向交易、4号交易公司、4号交易公司、前向交易公司、前向交易交易、前向前向前向交易、前向交易公司、前向交易、前向交易、第11号交易、前向交易、第11号交易、前交易公司、第11号交易、第4号交易、第11号交易、第11号交易、第11号交易、第11号交易、第1号交易、第1号交易、第1号交易、第4号交易、第1号交易、第1号交易、第1号交易、第4号、第4号交易、第4号、第8号、第4号、第4号、第8号、第8号交易、第8号交易、第8号、第8号、第8号、第8号、第8号、第8号、第8号、第8号、第8号、第8号、第8号、第8号、第8号、第8号、第8号、第8号、第4号、第8号、第8号