Penetration testing framework for smart contract Blockchain

被引:58
|
作者
Bhardwaj, Akashdeep [1 ]
Shah, Syed Bilal Hussian [2 ]
Shankar, Achyut [3 ]
Alazab, Mamoun [4 ]
Kumar, Manoj [1 ]
Gadekallu, Thippa Reddy [5 ]
机构
[1] Univ Petr & Energy Studies, Sch Comp Sci, Dehra Dun, Uttarakhand, India
[2] Dalian Univ Technol China, Sch Software, Dalian, Peoples R China
[3] Amity Univ, Dept Comp Sci, Noida, Uttar Pradesh, India
[4] Charles Darwin Univ, Coll Engn IT & Environm, Brinkin, NT 0909, Australia
[5] Vellore Inst Technol, Sch Informat Technol & Engn, Vellore, Tamil Nadu, India
关键词
Attack vectors; Blockchain; Cyber threats; Cybersecurity; OWASP; Smart contracts; SOCIAL-SYSTEMS; IOT; SECURITY; PRIVACY;
D O I
10.1007/s12083-020-00991-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart contracts powered by blockchain ensure transaction processes are effective, secure and efficient as compared to conventional contacts. Smart contracts facilitate trustless process, time efficiency, cost effectiveness and transparency without any intervention by third party intermediaries like lawyers. While blockchain can counter traditional cybersecurity attacks on smart contract applications, cyberattacks keep evolving in the form of new threats and attack vectors that influence blockchain similar to other web and application based systems. Effective blockchain testing help organizations to build and utilize the technology securely withe connected infrastructure. However, during the course of our research, the authors detected that Blockchain technology comes with security considerations like irreversible transactions, insufficient access, and non-competent strategies. Attack vectors, like these are not found on web portals and other applications. This research presents a new Penetration Testing framework for smart contracts and decentralized apps. The authors compared results from the proposed penetration-testing framework with automated penetration test Scanners. The results detected missing vulnerability that were not reported during regular pen test process.
引用
收藏
页码:2635 / 2650
页数:16
相关论文
共 50 条
  • [1] Penetration testing framework for smart contract Blockchain
    Akashdeep Bhardwaj
    Syed Bilal Hussian Shah
    Achyut Shankar
    Mamoun Alazab
    Manoj Kumar
    Thippa Reddy Gadekallu
    Peer-to-Peer Networking and Applications, 2021, 14 : 2635 - 2650
  • [2] Secured Insurance Framework Using Blockchain and Smart Contract
    Hassan, Abid
    Ali, Md. Iftekhar
    Ahammed, Rifat
    Khan, Mohammad Monirujjaman
    Alsufyani, Nawal
    Alsufyani, Abdulmajeed
    SCIENTIFIC PROGRAMMING, 2021, 2021
  • [3] Smart Contract in Blockchain: An Exploration of Legal Framework in Malaysia
    Zain, Nor Razinah Binti Mohd
    Ali, Engku Rabiah Adawiah Engku
    Abideen, Adewale
    Rahman, Hamizah Abdul
    INTELLECTUAL DISCOURSE, 2019, 27 (02) : 595 - 617
  • [4] Blockchain-based smart contract for international business - a framework
    Sinha, Deepankar
    Roy Chowdhury, Shuvo
    JOURNAL OF GLOBAL OPERATIONS AND STRATEGIC SOURCING, 2021, 14 (01) : 224 - 260
  • [5] A secure vehicle theft detection framework using Blockchain and smart contract
    Das, Debashis
    Banerjee, Sourav
    Biswas, Utpal
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2021, 14 (02) : 672 - 686
  • [6] The application framework of blockchain technology in higher education based on the smart contract
    Wu, Tao
    Chang, Maiga
    2021 INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE BIG DATA AND INTELLIGENT SYSTEMS (HPBD&IS), 2021, : 140 - 144
  • [7] Blockchain and Smart Contract Engineering
    Carver, Jeffrey C.
    Staron, Miroslaw
    IEEE SOFTWARE, 2020, 37 (05) : 94 - 96
  • [8] A secure vehicle theft detection framework using Blockchain and smart contract
    Debashis Das
    Sourav Banerjee
    Utpal Biswas
    Peer-to-Peer Networking and Applications, 2021, 14 : 672 - 686
  • [9] Blockchain and Smart Contract for IoT
    Shurman, Mohammad
    Obeidat, Abed Al-Rahman
    Al-Shurman, Saif Al-Deen
    2020 11TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS (ICICS), 2020, : 361 - 366
  • [10] Smart Contract Broker: Improving Smart Contract Reusability in a Blockchain Environment
    Park, Joonseok
    Jeong, Sumin
    Yeom, Keunhyuk
    SENSORS, 2023, 23 (13)