This book discusses understand cybersecurity management in decentralized finance (DeFi). It commences with introducing fundamentals of DeFi and cybersecurity to readers. It emphasizes on the importance of cybersecurity for decentralized finance by illustrating recent cyber breaches, attacks, and financial losses. The book delves into understanding cyber threats and adversaries who can exploit those threats. It advances with cybersecurity threat, vulnerability, and risk management in DeFi. The book helps readers understand cyber threat landscape comprising different threat categories for that can exploit different types of vulnerabilities identified in DeFi. It puts forward prominent threat modelling strategies by focusing on attackers, assets, and software.
The book includes the popular blockchains that support DeFi include Ethereum, Binance Smart Chain, Solana, Cardano, Avalanche, Polygon, among others. With so much monetary value associated with all these technologies, the perpetrators are always lured to breach security by exploiting the vulnerabilities that exist in these technologies. For simplicity and clarity, all vulnerabilities are classified into different categories: arithmetic bugs, re-Entrancy attack, race conditions, exception handling, using a weak random generator, timestamp dependency, transaction-ordering dependence and front running, vulnerable libraries, wrong initial assumptions, denial of service, flash loan attacks, and vampire
Since decentralized finance infrastructures are the worst affected by cyber-attacks, it is imperative to understand various security issues in different components of DeFi infrastructures and proposes measures to secure all components of DeFi infrastructures. It brings the detailed cybersecurity policies and strategies that can be used to secure financial institutions. Finally, the book provides recommendations to secure DeFi infrastructures from cyber-attacks.
About the Author: Dr. Gurdip Kaur is a CISSP, and CompTIA certified Cybersecurity Analyst (CySA+) experienced in detecting and analyzing malicious network traffic, FinTech risk management, and network attack traffic classification. She led multiple cybersecurity teams to generate three publicly available cybersecurity datasets for Android malware analysis, DNS over HTTPS (DoH) attack mitigation, and darknet traffic detection. She is an active contributor to cybersecurity blogs and articles as part of the cybersecurity awareness program. Dr. Gurdip is the first author of the book titled "Understanding Cybersecurity Management in FinTech" published by Springer in 2021. She has published several book chapters and research papers in reputed journals. She was awarded two gold medals in Bachelor of Technology and a silver medal for the research project on high interaction honeypots by NDRF, India. Her research project on malware reverse engineering was selected among the top 10 projects in the National Student Project Contest in 2015. She is strongly inclined towards cybersecurity, malware analysis, vulnerability management, incident reporting, SIEM solutions, and SOC design.
Dr. Arash Habibi Lashkari is a Canada Research Chair (CRC) in Cybersecurity. He is senior member of the IEEE and an Associate Professor in Cybersecurity at York University (Canada). Prior to this, he was an Associate Professor at the Faculty of Computer Science, University of New Brunswick (Canada), and the Research Coordinator of the Canadian Institute for Cybersecurity (CIC). His research focuses on cyber threat modeling and detection, malware analysis, big data security, internet traffic analysis, and cybersecurity dataset generation.
Arash Lashkari has over 22 years of teaching experience, spanning several international universities, and was responsible for designing the first cybersecurity Capture the Flag (CTF) competition for post-secondary students in Canada. He has been the recipient of 15 awards at international computer security competitions - including three gold awards - and was recognized as one of Canada's Top 150 Researchers for 2017. In 2020, Dr. Lashkari was recognized with the University of New Brunswick's prestigious Teaching Innovation Award for his personally-created teaching methodology, the Think-Que-Cussion Method.
He is the author of ten published books and more than 110 academic articles on a variety of cybersecurity-related topics and the co-author of the national award-winning article series, "Understanding Canadian Cybersecurity Laws", which was recently recognized with a Gold Medal at the 2020 Canadian Online Publishing Awards.
Iman Sharafaldin is Application & Cloud Security Lead at Forward Securiy Inc in Vancouver, Canada. Passionate about all things code, Iman has more than 8 years of cybersecurity and software related experience. He is also a PhD candidate in computer science at the University of New Brunswick, Canada, with more than 1000 citations on his cybersecurity related publications.
Ziba Habibi Lashkari is an Assistant Professor of Finance in the Department of Organization Engineering, Business Administration, and Statistics, the Technical University of Madrid, Spain. She had been participating in the project of "Análisis de Modelos en Dinámica de poblaciones Estructuradas en Valoración de Derivados Financieros" financed by the Spanish Ministry of Economy. She has more than 15 years of academic and industry experience in financial management. Her research focuses on asset pricing, risk Management, cybersecurity risk in digital financial and data science in fintech.