Smart Contract Risk Assessment How Secure is the Contract You Are Calling

被引:0
|
作者
Li, Zexin [1 ]
Wang, Chao [1 ]
Zhang, Xucan [1 ]
Yu, Xiang [2 ]
Cui, Ting [3 ]
Yu, Yifan [4 ]
机构
[1] Guangzhou Univ, Guangdong Key Lab Blockchain Secur, Guangzhou 510006, Peoples R China
[2] Taizhou Univ, Sch Elect & Informat Engn, Taizhou 318000, Peoples R China
[3] Guangdong Univ Finance & Econ, Sch Econ, Guangzhou 510320, Peoples R China
[4] Jinan Univ, Sch Art, Guangzhou 510632, Peoples R China
关键词
Blockchain; smart contract security; dynamic analysis; risk assessment; vulnerability detection;
D O I
10.1007/978-3-031-77489-8_40
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Smart contracts, due to their decentralized nature and immutability, have demonstrated significant potential in various sectors such as finance and supply chains. However, as their applications have expanded, their security vulnerabilities have increasingly come to light. In response to the frequent occurrences of smart contract attacks, researchers have undertaken a series of studies, including the development of automated vulnerability detection tools, dynamic monitoring techniques, and vulnerability remediation strategies. However, these detection tools often rely on static analysis and fail to capture dynamic vulnerabilities that occur during runtime. Additionally, dynamic monitoring is limited by the ability to acquire and process real-time data, and it lacks the capability to globally analyze security risks during phased attacks. Similarly, mechanisms for updating vulnerabilities might inadvertently introduce new risks by leaving backdoors in smart contracts. To address these issues, this paper proposes a new method for assessing the reputation and evaluating the risks of smart contracts, aimed at enhancing the security of the blockchain ecosystem through the analysis of smart contract invocation trajectories. The effectiveness and practicality of this method have been validated by evaluating real attack cases that have occurred on-chain. Finally, the paper summarizes the research findings and explores potential future research directions, aiming to provide new insights and solutions for the field of smart contract security.
引用
收藏
页码:526 / 534
页数:9
相关论文
共 50 条
  • [31] A secure vehicle theft detection framework using Blockchain and smart contract
    Debashis Das
    Sourav Banerjee
    Utpal Biswas
    Peer-to-Peer Networking and Applications, 2021, 14 : 672 - 686
  • [32] A Secure and Traceable Vehicles and Parts System Based on Blockchain and Smart Contract
    Chen, Chin-Ling
    Zhu, Zhi-Peng
    Zhou, Ming
    Tsaur, Woei-Jiunn
    Wu, Chih-Ming
    Sun, Hongyu
    SENSORS, 2022, 22 (18)
  • [33] A Multidimensional Contract Design for Smart Contract-as-a-Service
    Sun, Jinghan
    Long, Hou-Wan
    Kang, Hong
    Fang, Zhixuan
    El Saddik, Abdulmotaleb
    Cai, Wei
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2025,
  • [34] A Blacklisting Smart Contract
    Kruger, Byron
    Leung, Wai Sze
    BUSINESS INFORMATION SYSTEMS WORKSHOPS (BIS 2020), 2020, 394 : 120 - 131
  • [35] Smart Contract Engineering
    Hu, Kai
    Zhu, Jian
    Ding, Yi
    Bai, Xiaomin
    Huang, Jiehua
    ELECTRONICS, 2020, 9 (12) : 1 - 26
  • [36] Delegate contract signing mechanism based on smart contract
    Xiong, Wei
    Hu, Yangcheng
    PLOS ONE, 2022, 17 (08):
  • [37] Smart Contract Repair
    Yu, Xiao Liang
    Al-Bataineh, Omar
    Lo, David
    Roychoudhury, Abhik
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2020, 29 (04)
  • [38] Smart Contract Microservitization
    Wang, Siyuan
    Zhang, Xuehan
    Yu, Wei
    Hu, Kai
    Zhu, Jian
    2020 IEEE 44TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2020), 2020, : 1569 - 1574
  • [39] Smart contract tontines
    Abou Daya, Mohamad Hassan
    Bernard, Carole
    APPLIED ECONOMICS, 2024,
  • [40] Honeypot Contract Risk Warning on Ethereum Smart Contracts
    Chen, Weili
    Guo, Xiongfeng
    Chen, Zhiguang
    Zheng, Zibin
    Lu, Yutong
    Li, Yin
    2020 IEEE INTERNATIONAL CONFERENCE ON JOINT CLOUD COMPUTING (JCC 2020), 2020, : 1 - 8