Peeling Chain 연속성 기반 잔돈 주소 식별을 통한 비트코인 주소 클러스터링
Bitcoin Address Clustering via Peeling Chain Continuity-Based Change Address Identification
- 주제(키워드) 비트코인 , 잔돈 주소 , 주소 클러스터링 , 필링 체인 , 휴리스틱
- 주제(DDC) 355
- 발행기관 아주대학교 일반대학원
- 지도교수 김기형
- 발행년도 2026
- 학위수여년월 2026. 8
- 학위명 석사
- 학과 및 전공 일반대학원 국방디지털융합학과
- 실제URI http://www.dcollection.net/handler/ajou/000000036458
- 본문언어 한국어
- 저작권 아주대학교 논문은 저작권에 의해 보호받습니다.
초록/요약
비트코인과 같은 가상자산은 모든 거래 내역이 공개 블록체인에 기록된다는 점에서 높은 투명성을 제공하지만, 거래에 사용되는 주소와 실제 사용자 신원이 직접 연결되지 않는 의사익명성을 가진다. 이러한 특성은 이용자의 금융 프라이버시를 보호하는 데 기여하는 동시에 랜섬웨어, 다크웹 거래, 해킹 피해금 이동, 자금세탁 등 불법 자금 흐름을 추적하는 데 어려움을 발생시킨다. 이에 따라 공개 온체인 데이터를 기반으로 거래 흐름을 분석하고, 동일 주체가 통제할 가능성이 있는 주소 집합을 식별하는 주소 클러스터링 기법은 가상자산 포렌식 분야에서 중요한 분석 방법으로 활용되고 있다.[1][2][3] 비트코인 주소 클러스터링에서 대표적으로 활용되는 방법은 다중 입력 휴리스틱과 잔돈 주소 휴리스틱이다. 다중 입력 휴리스틱은 하나의 거래에 포함된 입력 주소들이 동일 개체에 의해 통제될 가능성이 높다는 가정에 기반한다. 그러나 이 방법은 입력 주소 집합을 병합하는 데 효과적인 반면, 거래 출력으로 새롭게 생성되는 잔돈 주소를 식별하는 데에는 한계가 있다. 이를 보완하기 위해 기존 연구에서는 신규 주소 여부, 주소 재사용 여부, script type, 금액 패턴, 입력 UTXO 대비 출력 금액 조건 등을 이용한 잔돈 주소 식별 휴리스틱이 제안되었다. 특히 H7 휴리스틱은 여러 조건이 하나의 후보를 일관되게 지목하는 경우에만 잔돈 주소를 선택하는 보수적인 접근법이다.[4] 그러나 H7을 포함한 기존 잔돈 주소 식별 휴리스틱은 주로 단일 거래 시점에서 관찰 가능한 입출력 구조에 의존하므로, 후보 출력이 이후 거래에서 어떻게 소비되는지와 같은 거래 간 연속성을 충분히 반영하기 어렵다. 본 논문에서는 이러한 한계를 보완하기 위해 Peeling Chain Continuity Heuristic(PCCH)을 제안한다. PCCH는 H7 휴리스틱이 식별한 잔돈 주소 후보 출력을 초기 시작점으로 사용하고, 해당 후보 출력이 후속 거래에서 소비되는 경우 소비 거래의 출력 구조, 금액 조건, script type 호환성, 수수료 유효성, 단일 입력 후속 소비 여부 등을 종합적으로 검토하여 다음 잔돈 주소 후보를 판별한다. 이를 통해 기존 단일 거래 기반 잔돈 주소 식별 방식을 필링 체인(peeling chain)의 후속 소비 연속성 관점으로 확장한다. 실험은 비트코인 블록 60,001번부터 70,000번까지 총 10,000개 블록을 대상으로 수행하였다. 실험 결과 H1+PCCH는 기존 H1+H7보다 더 많은 잔돈 주소 후보를 식별하였고, 클러스터링 결과에서도 더 낮은 클러스터 수와 더 높은 주소 감소율을 보였다. 또한 PCCH 기반 분석을 통해 총 88개의 필링 체인 후보 구조를 식별하였으며, 이를 통해 제안 기법이 단일 거래 단위에서는 확인하기 어려운 연속적인 잔돈 후보 흐름을 chain 단위로 추적할 수 있음을 확인하였다. 본 연구의 결과는 PCCH가 기존 잔돈 주소 식별 휴리스틱을 대체하기보다, H7이 제공하는 보수적인 초기 후보를 기반으로 후속 소비 연속성을 추가 반영하는 보완적 접근임을 보여준다. 또한, 제안 기법은 주소 클러스터링의 구조적 확장뿐만 아니라, 필링 체인 후보 구조를 별도로 구성하여 연속적인 자금 흐름을 분석할 수 있는 기반을 제공한다. 다만 실제 온체인 데이터에서는 동일 소유자 정보를 확인할 수 있는 Ground Truth가 제공되지 않으므로, 클러스터 수 감소를 동일 소유자 식별 정확도의 직접적인 향상으로 단정하기는 어렵다. 따라서 본 연구는 PCCH를 통해 후속 소비 연속성을 만족하는 잔돈 주소 후보를 추적하고, 이를 가상자산 포렌식 분석에서 활용 가능한 주소 클러스터링 확장 단서로 제시한다는 점에서 의의를 가진다. 주제어: 비트코인, 잔돈 주소, 주소 클러스터링, 필링 체인, 휴리스틱
more초록/요약
Virtual assets such as Bitcoin provide transparency because all transactions are recorded on a public blockchain. At the same time, Bitcoin offers pseudo-anonymity because blockchain addresses are not directly linked to real-world identities. This characteristic protects user privacy, but it also makes it difficult to trace illicit fund flows related to ransomware, darknet markets, hacked assets, and money laundering. Accordingly, address clustering has become an important technique in cryptocurrency forensics, as it aims to identify groups of addresses that are likely controlled by the same entity using public on-chain data. In Bitcoin address clustering, the multi-input heuristic and change address heuristics are widely used. The multi-input heuristic assumes that all input addresses in a single transaction are likely controlled by the same entity. However, it is limited in identifying newly generated change addresses in transaction outputs. To address this limitation, previous studies have proposed various change address heuristics based on new address detection, address reuse, script type, amount patterns, and output amount conditions. Among them, the H7 heuristic takes a conservative approach by selecting a change address only when multiple conditions consistently indicate a unique candidate. However, existing change address heuristics, including H7, mainly rely on the input-output structure observed within a single transaction and do not sufficiently consider how a candidate output is spent in subsequent transactions. This thesis proposes the Peeling Chain Continuity Heuristic (PCCH) to incorporate subsequent spending continuity into change address identification. PCCH uses the change address candidate identified by H7 as an initial starting point. When the candidate output is spent in a subsequent transaction within the analysis range, PCCH examines the output structure, amount condition, script type compatibility, fee validity, and single-input subsequent spending condition to identify the next change address candidate. In this way, PCCH extends single-transaction-based change address identification by reflecting the continuity of peeling-chain-like transaction flows. Experiments were conducted on 10,000 Bitcoin blocks from block 60,001 to block 70,000. The results show that H1+PCCH identified more change address candidates than H1+H7 and produced fewer clusters with a higher address reduction rate. PCCH also identified 88 peeling-chain candidate structures, demonstrating that the proposed heuristic can trace continuous change-candidate flows that are difficult to capture using only single-transaction-based heuristics. The results indicate that PCCH is not intended to replace H7, but rather to complement it by extending H7-based candidates through subsequent spending continuity. The proposed method contributes to address clustering by providing structural clues for clustering expansion and by organizing peeling-chain candidate flows for further forensic analysis. Since ground-truth ownership labels are not available in the on-chain dataset, the reduction in the number of clusters should not be interpreted as direct evidence of improved ownership identification accuracy. Nevertheless, this study shows that PCCH can serve as a useful auxiliary heuristic for tracing change address candidates and analyzing continuous fund flows in Bitcoin forensic investigations.
more목차
제 1 장 서론 1
제 1 절 연구 배경 및 필요성 1
제 2 절 연구 목적 및 범위 5
제 3 절 논문의 구성 7
제 2 장 이론적 배경 및 관련 연구 9
제 1 절 비트코인 거래 구조와 UTXO 모델 9
제 2 절 비트코인 주소와 의사익명성 10
제 3 절 주소 클러스터링과 잔돈 주소 12
제 4 절 기존 잔돈 주소 식별 휴리스틱 14
제 5 절 필링 체인과 기존 연구의 한계 16
제 3 장 Peeling Chain Continuity Heuristic(PCCH) 19
제 1 절 제안 기법의 개요 19
제 2 절 H7 기반 초기 잔돈 주소 후보 식별 20
제 3 절 후속 소비 연속성 기반 후보 확장 21
제 4 절 PCCH 후보 판정 조건 22
제 5 절 PCCH chain 구성 및 주소 클러스터링 적용 24
제 4 장 실험 설계 및 구현 26
제 1 절 실험 데이터셋 26
제 2 절 데이터 수집 및 전처리 27
제 3 절 거래 입력출력 연결 및 이전 출력 참조 정보 구성 28
제 4 절 비교 대상 휴리스틱 29
제 5 절 클러스터링 구현 방법 및 평가지표 31
제 5 장 실험 결과 및 분석 34
제 1 절 휴리스틱별 잔돈 주소 후보 식별 결과 34
제 2 절 클러스터링 결과 비교 35
제 3 절 클러스터 크기 및 상위 클러스터 분석 37
제 4 절 PCCH chain 분석 40
제 5 절 결과 해석 및 검증 한계 43
제 6 장 결론 45
제 1 절 연구 결과 요약 45
제 2 절 연구 의의 46
제 3 절 연구 한계 및 향후 연구 방향 46
참고문헌 48
Abstract 51

