Penetration testing framework for smart contract Blockchain

被引:58
|
作者
Bhardwaj, Akashdeep [1 ]
Shah, Syed Bilal Hussian [2 ]
Shankar, Achyut [3 ]
Alazab, Mamoun [4 ]
Kumar, Manoj [1 ]
Gadekallu, Thippa Reddy [5 ]
机构
[1] Univ Petr & Energy Studies, Sch Comp Sci, Dehra Dun, Uttarakhand, India
[2] Dalian Univ Technol China, Sch Software, Dalian, Peoples R China
[3] Amity Univ, Dept Comp Sci, Noida, Uttar Pradesh, India
[4] Charles Darwin Univ, Coll Engn IT & Environm, Brinkin, NT 0909, Australia
[5] Vellore Inst Technol, Sch Informat Technol & Engn, Vellore, Tamil Nadu, India
关键词
Attack vectors; Blockchain; Cyber threats; Cybersecurity; OWASP; Smart contracts; SOCIAL-SYSTEMS; IOT; SECURITY; PRIVACY;
D O I
10.1007/s12083-020-00991-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart contracts powered by blockchain ensure transaction processes are effective, secure and efficient as compared to conventional contacts. Smart contracts facilitate trustless process, time efficiency, cost effectiveness and transparency without any intervention by third party intermediaries like lawyers. While blockchain can counter traditional cybersecurity attacks on smart contract applications, cyberattacks keep evolving in the form of new threats and attack vectors that influence blockchain similar to other web and application based systems. Effective blockchain testing help organizations to build and utilize the technology securely withe connected infrastructure. However, during the course of our research, the authors detected that Blockchain technology comes with security considerations like irreversible transactions, insufficient access, and non-competent strategies. Attack vectors, like these are not found on web portals and other applications. This research presents a new Penetration Testing framework for smart contracts and decentralized apps. The authors compared results from the proposed penetration-testing framework with automated penetration test Scanners. The results detected missing vulnerability that were not reported during regular pen test process.
引用
收藏
页码:2635 / 2650
页数:16
相关论文
共 50 条
  • [21] Blockchain and Smart Contract for Digital Certificate
    Cheng, Jiin-Chiou
    Lee, Narn-Yih
    Chi, Chien
    Chen, Yi-Hua
    PROCEEDINGS OF 4TH IEEE INTERNATIONAL CONFERENCE ON APPLIED SYSTEM INNOVATION 2018 ( IEEE ICASI 2018 ), 2018, : 1046 - 1051
  • [22] Smart Contract Designs on Blockchain Applications
    Abuhashim, Alkhansaa
    Tan, Chiu C.
    2020 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2020, : 1020 - 1023
  • [23] Smart grid security based on blockchain and smart contract
    Zhang, Ming
    Liu, Yutong
    Cheng, Qian
    Li, Hui
    Liao, Dan
    Li, Huiyong
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2024, 17 (04) : 2167 - 2184
  • [24] Blockchain and smart contract for IoT enabled smart agriculture
    Pranto, Tahmid Hasan
    Noman, Abdulla All
    Mahmud, Atik
    Haque, A. K. M. Bahalul
    PEERJ COMPUTER SCIENCE, 2021,
  • [25] Blockchain and smart contract for IoT enabled smart agriculture
    Pranto T.H.
    Noman A.A.
    Mahmud A.
    Haque A.B.
    PeerJ Computer Science, 2021, 7 : 1 - 29
  • [26] Smart Contract Data Feed Framework for Privacy-Preserving Oracle System on Blockchain
    Park, Junhoo
    Kim, Hyekjin
    Kim, Geunyoung
    Ryou, Jaecheol
    COMPUTERS, 2021, 10 (01) : 1 - 12
  • [27] Blockchain Eco-System for Thai Insect Industry: A Smart Contract Conceptual Framework
    Jintapitak, Manissaward
    Ansari, Muhammad Ahsan
    Kamyod, Chayapol
    Singkhamfu, Walaiporn
    Kamthe, Neelam Sanjay
    Temdee, Punnarumol
    2019 22ND INTERNATIONAL SYMPOSIUM ON WIRELESS PERSONAL MULTIMEDIA COMMUNICATIONS (WPMC), 2019,
  • [28] Blockchain smart contract reference framework and program logic architecture for transactive energy systems
    Gourisetti, Sri Nikhil Gupta
    Sebastian-Cardenas, D. Jonathan
    Bhattarai, Bishnu
    Wang, Peng
    Widergren, Steve
    Borkum, Mark
    Randall, Alysha
    APPLIED ENERGY, 2021, 304
  • [29] A Smart Contract Architecture Framework for Successful Industrial Symbiosis Applications Using Blockchain Technology
    Bruel, Aurelien
    Godina, Radu
    SUSTAINABILITY, 2023, 15 (07)
  • [30] Smart Supply Chain Management Using the Blockchain and Smart Contract
    Turjo M.D.
    Khan M.M.
    Kaur M.
    Zaguia A.
    Khan, Mohammad Monirujjaman (monirujjaman.khan@northsouth.edu), 1600, Hindawi Limited (2021):