{"id":"https://openalex.org/W4311755273","doi":"https://doi.org/10.1016/j.fsidi.2022.301486","title":"A framework for live host-based Bitcoin wallet forensics and triage","display_name":"A framework for live host-based Bitcoin wallet forensics and triage","publication_year":2022,"publication_date":"2022-12-09","ids":{"openalex":"https://openalex.org/W4311755273","doi":"https://doi.org/10.1016/j.fsidi.2022.301486"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.fsidi.2022.301486","pdf_url":null,"source":{"id":"https://openalex.org/S4210178067","display_name":"Forensic Science International Digital Investigation","issn_l":"2666-2817","issn":["2666-2817","2666-2825"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"journal-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://doi.org/10.1016/j.fsidi.2022.301486","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5077832182","display_name":"A. Holmes","orcid":null},"institutions":[{"id":"https://openalex.org/I251738","display_name":"Edinburgh Napier University","ror":"https://ror.org/03zjvnn91","country_code":"GB","type":"education","lineage":["https://openalex.org/I251738"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Arran Holmes","raw_affiliation_strings":["Blockpass ID Lab, Edinburgh Napier University, Edinburgh, UK"],"affiliations":[{"raw_affiliation_string":"Blockpass ID Lab, Edinburgh Napier University, Edinburgh, UK","institution_ids":["https://openalex.org/I251738"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5068020099","display_name":"William J. Buchanan","orcid":"https://orcid.org/0000-0003-0809-3523"},"institutions":[{"id":"https://openalex.org/I251738","display_name":"Edinburgh Napier University","ror":"https://ror.org/03zjvnn91","country_code":"GB","type":"education","lineage":["https://openalex.org/I251738"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"William J. Buchanan","raw_affiliation_strings":["Blockpass ID Lab, Edinburgh Napier University, Edinburgh, UK"],"affiliations":[{"raw_affiliation_string":"Blockpass ID Lab, Edinburgh Napier University, Edinburgh, UK","institution_ids":["https://openalex.org/I251738"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":["https://openalex.org/A5068020099"],"corresponding_institution_ids":["https://openalex.org/I251738"],"apc_list":{"value":2950,"currency":"USD","value_usd":2950,"provenance":"doaj"},"apc_paid":{"value":2950,"currency":"USD","value_usd":2950,"provenance":"doaj"},"fwci":0.844,"has_fulltext":true,"fulltext_origin":"pdf","cited_by_count":4,"citation_normalized_percentile":{"value":0.374362,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":80,"max":83},"biblio":{"volume":"44","issue":null,"first_page":"301486","last_page":"301486"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9987,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9987,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9984,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9978,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/money-laundering","display_name":"Money Laundering","score":0.50149345},{"id":"https://openalex.org/keywords/hacker","display_name":"Hacker","score":0.41239128}],"concepts":[{"id":"https://openalex.org/C180706569","wikidata":"https://www.wikidata.org/wiki/Q13479982","display_name":"Cryptocurrency","level":2,"score":0.89492774},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6901746},{"id":"https://openalex.org/C2780262971","wikidata":"https://www.wikidata.org/wiki/Q44554","display_name":"Law enforcement","level":2,"score":0.6649339},{"id":"https://openalex.org/C2780005421","wikidata":"https://www.wikidata.org/wiki/Q151900","display_name":"Money laundering","level":2,"score":0.50149345},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.47144473},{"id":"https://openalex.org/C2779777834","wikidata":"https://www.wikidata.org/wiki/Q4202277","display_name":"Enforcement","level":2,"score":0.44516724},{"id":"https://openalex.org/C76178495","wikidata":"https://www.wikidata.org/wiki/Q4808784","display_name":"Asset (computer security)","level":2,"score":0.4378491},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.42558542},{"id":"https://openalex.org/C84418412","wikidata":"https://www.wikidata.org/wiki/Q3246940","display_name":"Digital forensics","level":2,"score":0.42348713},{"id":"https://openalex.org/C86844869","wikidata":"https://www.wikidata.org/wiki/Q2798820","display_name":"Hacker","level":2,"score":0.41239128},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.38991106},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.32086393},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.14653274},{"id":"https://openalex.org/C10138342","wikidata":"https://www.wikidata.org/wiki/Q43015","display_name":"Finance","level":1,"score":0.13840654}],"mesh":[],"locations_count":3,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.fsidi.2022.301486","pdf_url":null,"source":{"id":"https://openalex.org/S4210178067","display_name":"Forensic Science International Digital Investigation","issn_l":"2666-2817","issn":["2666-2817","2666-2825"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true},{"is_oa":true,"landing_page_url":"http://researchrepository.napier.ac.uk/Output/2975129","pdf_url":"https://www.napier.ac.uk/-/media/worktribe/output-2975129/a-framework-for-live-host-based-bitcoin-wallet-forensics-and-triage.ashx","source":{"id":"https://openalex.org/S4306402591","display_name":"Edinburgh Napier Research Repository (Edinburgh Napier University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I251738","host_organization_name":"Edinburgh Napier University","host_organization_lineage":["https://openalex.org/I251738"],"host_organization_lineage_names":["Edinburgh Napier University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true},{"is_oa":true,"landing_page_url":"https://napier-repository.worktribe.com/file/2975129/1/A%20Framework%20For%20Live%20Host-based%20Bitcoin%20Wallet%20Forensics%20And%20Triage","pdf_url":"https://napier-repository.worktribe.com/file/2975129/1/A%20Framework%20For%20Live%20Host-based%20Bitcoin%20Wallet%20Forensics%20And%20Triage","source":{"id":"https://openalex.org/S4306402591","display_name":"Edinburgh Napier Research Repository (Edinburgh Napier University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I251738","host_organization_name":"Edinburgh Napier University","host_organization_lineage":["https://openalex.org/I251738"],"host_organization_lineage_names":["Edinburgh Napier University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.fsidi.2022.301486","pdf_url":null,"source":{"id":"https://openalex.org/S4210178067","display_name":"Forensic Science International Digital Investigation","issn_l":"2666-2817","issn":["2666-2817","2666-2825"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[{"score":0.81,"display_name":"Peace, justice, and strong institutions","id":"https://metadata.un.org/sdg/16"}],"grants":[{"funder":"https://openalex.org/F4320320619","funder_display_name":"Edinburgh Napier University","award_id":null}],"datasets":[],"versions":[],"referenced_works_count":32,"referenced_works":["https://openalex.org/W1578425966","https://openalex.org/W1986896180","https://openalex.org/W1995875735","https://openalex.org/W2064794020","https://openalex.org/W2102573472","https://openalex.org/W2251438464","https://openalex.org/W2337532746","https://openalex.org/W2573410114","https://openalex.org/W2579276500","https://openalex.org/W2614042168","https://openalex.org/W2628759714","https://openalex.org/W2763255326","https://openalex.org/W2789491237","https://openalex.org/W2887243807","https://openalex.org/W2889271520","https://openalex.org/W2935359245","https://openalex.org/W2941654642","https://openalex.org/W2972259821","https://openalex.org/W2982130953","https://openalex.org/W2999834558","https://openalex.org/W3035749538","https://openalex.org/W3123868249","https://openalex.org/W3171252221","https://openalex.org/W4242289848","https://openalex.org/W4244111462","https://openalex.org/W4245505814","https://openalex.org/W4246863002","https://openalex.org/W4248175462","https://openalex.org/W4254920161","https://openalex.org/W4289038676","https://openalex.org/W4289765558","https://openalex.org/W4315746341"],"related_works":["https://openalex.org/W54587564","https://openalex.org/W4389915954","https://openalex.org/W4366411693","https://openalex.org/W3211641817","https://openalex.org/W3164717803","https://openalex.org/W2620272321","https://openalex.org/W2552093437","https://openalex.org/W2185441218","https://openalex.org/W2159614226","https://openalex.org/W1531316950"],"abstract_inverted_index":{"Organised":[0],"crime":[1,31],"and":[2,12,21,48,124,140,156,175,200,242,244,254],"cybercriminals":[3],"use":[4],"Bitcoin,":[5],"a":[6,59,98,116,125,130,148,158,167,228,235,269,285,317],"popular":[7],"cryptocurrency,":[8],"to":[9,26,65,89,95,207,214,238,261,299],"launder":[10],"money":[11],"move":[13],"it":[14,85,93],"across":[15],"borders":[16],"with":[17,173],"impunity.":[18],"The":[19],"UK":[20,35],"other":[22,90],"countries":[23],"have":[24],"legislation":[25],"recover":[27,239],"the":[28,51,66,134,162,196,201,217,222],"proceeds":[29],"of":[30,53,161,170,219,247,272,290],"from":[32,108,166,221],"criminals.":[33],"Recent":[34],"case":[36],"law":[37,117,176],"has":[38,82],"recognised":[39],"cryptocurrency":[40,60,74],"assets":[41],"as":[42],"property":[43],"that":[44,72,145,157,309],"can":[45,211,311],"be":[46,87,106,212],"seized":[47,77,107],"realised":[49],"under":[50],"Proceeds":[52],"Crime":[54],"Act":[55],"(POCA).":[56],"To":[57],"seize":[58,96],"asset":[61],"generally":[62],"requires":[63],"access":[64],"private":[67,292],"key.":[68],"Anecdotal":[69],"evidence":[70],"suggests":[71],"if":[73,263],"is":[75,147,227,266],"not":[76],"quickly":[78],"after":[79],"enforcement":[80,118,177],"action":[81],"taken":[83],"place,":[84],"will":[86],"transferred":[88],"wallets":[91],"making":[92],"difficult":[94],"at":[97],"future":[99],"time.":[100],"We":[101,128,192,256,296,306],"investigate":[102],"how":[103],"Bitcoin":[104,137,141,153,220,232,240],"could":[105],"an":[109,264],"Electrum":[110,197],"or":[111],"Ledger":[112,202,320],"hardware":[113,205],"wallet,":[114,206],"during":[115],"search,":[119],"using":[120,268],"live":[121],"forensic":[122,233],"techniques":[123],"dictionary":[126],"attack.":[127],"conduct":[129,312],"literature":[131,164],"review":[132],"examining":[133],"state-of-the-art":[135],"in":[136,150,216,252,287,294],"application":[138],"forensics":[139],"wallet":[142,154,199],"attacks.":[143],"Concluding,":[144],"there":[146],"gap":[149],"research":[151],"on":[152],"security":[155],"significant":[159],"proportion":[160],"available":[163],"comes":[165],"small":[168],"group":[169],"academics":[171],"working":[172],"industry":[174],"(Volety":[178],"et":[179,185,189],"al.":[180],"2019;":[181],"Van":[182],"Der":[183],"Horst":[184],"al.,":[186,190],"2017;":[187],"Zollner":[188],"2019).":[191],"then":[193,257],"forensically":[194],"examine":[195],"software":[198],"Nano":[203],"S":[204],"establish":[208,262],"what":[209],"artefacts":[210,241],"recovered":[213],"assist":[215],"recovery":[218],"wallets.":[223],"Our":[224],"main":[225],"contribution":[226],"proposed":[229],"framework":[230],"for":[231],"triage,":[234],"collection":[236],"tool":[237],"identifiers,":[243],"two":[245],"proof":[246],"concept":[248],"dictionary-attack":[249],"tools":[250,260],"written":[251],"Python":[253],"OpenCL.":[255],"evaluate":[258],"these":[259],"attack":[265],"practicable":[267],"low-cost":[270],"cluster":[271],"public":[273],"cloud-based":[274],"Graphics":[275],"Processing":[276],"Unit":[277],"(GPU)":[278],"instances.":[279],"During":[280],"our":[281],"investigation,":[282],"we":[283,310],"find":[284],"weakness":[286],"Electrum's":[288],"storage":[289],"encrypted":[291],"keys":[293],"RAM.":[295],"leverage":[297],"this":[298],"make":[300],"around":[301],"2.4":[302],"trillion":[303],"password":[304,318],"guesses.":[305],"also":[307],"demonstrate":[308],"16.6":[313],"billion":[314],"guesses":[315],"against":[316],"protected":[319],"seed":[321],"phrase.":[322]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4311755273","counts_by_year":[{"year":2023,"cited_by_count":4}],"updated_date":"2025-01-02T05:54:26.270629","created_date":"2022-12-28"}