首次系统分析智能合约全生命周期安全漏洞特征。
Mining Characteristics of Vulnerable Smart Contracts Across Lifecycle Stages
- 从部署、执行、升级到销毁各阶段分析漏洞特征。
- 发现不同阶段漏洞具有独特交易与网络属性。
- 用五种机器学习模型实现阶段级漏洞识别。
智能合约是去中心化应用和金融协议的核心,扩展了数字货币交易的应用。然而,这些应用引入了显著的安全挑战,导致重大经济损失。现有解决方案主要关注智能合约代码漏洞,但仅涵盖50%的安全事件。因此,对智能合约安全问题进行更全面的研究至关重要。现有实证研究虽从生命周期视角进行静态分析并提出各阶段对策,但缺乏对各阶段漏洞特征的深入分析及差异区分。本文首次开展智能合约全生命周期安全性的实证研究,涵盖部署与执行、升级、销毁等阶段,深入探讨各阶段的安全问题,并提供至少七项特征描述。基于这七项特征,采用五种机器学习分类模型识别不同阶段的漏洞。分类结果表明,存在漏洞的合约在各阶段表现出不同的交易特征与自我网络属性。
原文摘要 · Abstract (English)
Smart contracts are the cornerstone of decentralized applications and financial protocols, which extend the application of digital currency transactions. The applications and financial protocols introduce significant security challenges, resulting in substantial economic losses. Existing solutions predominantly focus on code vulnerabilities within smart contracts, accounting for only 50% of security incidents. Therefore, a more comprehensive study of security issues related to smart contracts is imperative. The existing empirical research realizes the static analysis of smart contracts from the perspective of the lifecycle and gives the corresponding measures for each stage. However, they lack the characteristic analysis of vulnerabilities in each stage and the distinction between the vulnerabilities. In this paper, we present the first empirical study on the security of smart contracts throughout their lifecycle, including deployment and execution, upgrade, and destruction stages. It delves into the security issues at each stage and provides at least seven feature descriptions. Finally, utilizing these seven features, five machine-learning classification models are used to identify vulnerabilities at different stages. The classification results reveal that vulnerable contracts exhibit distinct transaction features and ego network properties at various stages.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。