Penetration testing framework for smart contract Blockchain

被引:58
|
作者
Bhardwaj, Akashdeep [1 ]
Shah, Syed Bilal Hussian [2 ]
Shankar, Achyut [3 ]
Alazab, Mamoun [4 ]
Kumar, Manoj [1 ]
Gadekallu, Thippa Reddy [5 ]
机构
[1] Univ Petr & Energy Studies, Sch Comp Sci, Dehra Dun, Uttarakhand, India
[2] Dalian Univ Technol China, Sch Software, Dalian, Peoples R China
[3] Amity Univ, Dept Comp Sci, Noida, Uttar Pradesh, India
[4] Charles Darwin Univ, Coll Engn IT & Environm, Brinkin, NT 0909, Australia
[5] Vellore Inst Technol, Sch Informat Technol & Engn, Vellore, Tamil Nadu, India
关键词
Attack vectors; Blockchain; Cyber threats; Cybersecurity; OWASP; Smart contracts; SOCIAL-SYSTEMS; IOT; SECURITY; PRIVACY;
D O I
10.1007/s12083-020-00991-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart contracts powered by blockchain ensure transaction processes are effective, secure and efficient as compared to conventional contacts. Smart contracts facilitate trustless process, time efficiency, cost effectiveness and transparency without any intervention by third party intermediaries like lawyers. While blockchain can counter traditional cybersecurity attacks on smart contract applications, cyberattacks keep evolving in the form of new threats and attack vectors that influence blockchain similar to other web and application based systems. Effective blockchain testing help organizations to build and utilize the technology securely withe connected infrastructure. However, during the course of our research, the authors detected that Blockchain technology comes with security considerations like irreversible transactions, insufficient access, and non-competent strategies. Attack vectors, like these are not found on web portals and other applications. This research presents a new Penetration Testing framework for smart contracts and decentralized apps. The authors compared results from the proposed penetration-testing framework with automated penetration test Scanners. The results detected missing vulnerability that were not reported during regular pen test process.
引用
收藏
页码:2635 / 2650
页数:16
相关论文
共 50 条
  • [41] Governance in the Blockchain Era: The Smart Social Contract
    Carata, Cristina
    Knottenbelt, William J.
    Malinoiu, Vali-Marius
    PROCEEDINGS OF THE 25TH ANNUAL INTERNATIONAL CONFERENCE ON DIGITAL GOVERNMENT RESEARCH, DGO 2024, 2024, : 104 - 115
  • [42] Blockchain 2.O: A Smart Contract
    Saini, Kavita
    Roy, Abhishek
    Chelliah, Pethuru Raj
    Patel, Tanisha
    2021 INTERNATIONAL CONFERENCE ON COMPUTATIONAL PERFORMANCE EVALUATION (COMPE-2021), 2021, : 524 - 528
  • [43] A blockchain framework for smart mobility
    Lopez, David
    Farooq, Bilal
    2018 IEEE INTERNATIONAL SMART CITIES CONFERENCE (ISC2), 2018,
  • [44] A Blockchain Smart ContractApplication Framework
    Mendi, Arif Furkan
    Erol, Tolga
    Safak, Emre
    Kayin, Tolga
    2019 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC 2019), 2019,
  • [45] Framework Architecture for Securing IoT Using Blockchain, Smart Contract and Software Defined Network Technologies
    Al-Sakran, Hasan
    Alharbi, Yaser
    Serguievskaia, Irina
    2019 2ND INTERNATIONAL CONFERENCE ON NEW TRENDS IN COMPUTING SCIENCES (ICTCS), 2019, : 189 - 194
  • [46] Smart Contract Framework for Secure and Efficient P2P Energy Trading with Blockchain
    Gurjar, Garima
    Nikose, Mangesh D.
    JOURNAL OF ELECTRICAL ENGINEERING & TECHNOLOGY, 2025, 20 (01) : 255 - 269
  • [47] An Approach Towards Implementing Online Voting System Framework Using Blockchain Technology and Smart Contract
    Haldar, Paranjay
    Roy, Rajdeep
    Biswas, Utpal
    WIRELESS PERSONAL COMMUNICATIONS, 2024, 138 (04) : 2699 - 2732
  • [48] Decision Framework and Detailed Analysis on Privacy Preserving Smart Contract Frameworks for Enterprise Blockchain Applications
    Abraham, Misha
    Mohan, Krishnan
    2020 INTERNATIONAL CONFERENCE ON OMNI-LAYER INTELLIGENT SYSTEMS (IEEE COINS 2020), 2020, : 240 - 245
  • [49] A Smart Contract Architecture Framework for Insurance Industry Using Blockchain and Business Process Management Technology
    Rachad A.
    Gaiz L.
    Bouragba K.
    Ouzzif M.
    IEEE Engineering Management Review, 2024, 52 (02): : 55 - 68
  • [50] Smart-Graph: Graphical Representations for Smart Contract on the Ethereum Blockchain
    Pierro, Giuseppe Antonio
    2021 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ANALYSIS, EVOLUTION AND REENGINEERING (SANER 2021), 2021, : 708 - 714