A Survey on Ethereum Systems Security: Vulnerabilities, Attacks, and Defenses

被引:140
|
作者
Chen, Huashan [1 ]
Pendleton, Marcus [2 ,3 ,4 ]
Njilla, Laurent [2 ,5 ]
Xu, Shouhuai [1 ]
机构
[1] Univ Texas San Antonio, One UTSA Circle, San Antonio, TX 78249 USA
[2] US Air Force Res Lab, Wright Patterson AFB, OH USA
[3] 90 COS CYD, Wright Patterson AFB, OH USA
[4] 250 Ball Blvd,Suite 359, San Antonio, TX 78243 USA
[5] 26 Elect Pkwy, Rome, NY 13441 USA
基金
美国国家科学基金会;
关键词
Blockchain; Ethereum; smart contract; security; BLOCKCHAIN; CONSENSUS; METRICS; BITCOIN;
D O I
10.1145/3391195
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Blockchain technology is believed by many to be a game changer in many application domains. While the first generation of blockchain technology (i.e., Blockchain 1.0) is almost exclusively used for cryptocurrency, the second generation (i.e., Blockchain 2.0), as represented by Ethereum, is an open and decentrafind platform enabling a new paradigm of computing-Decentralized Applications (DApps) running on top of blockchains. The rich applications and semantics of DApps inevitably introduce many security vulnerabilities, which have no counterparts in pure cryptocurrency systems like Bitcoin. Since Ethereum is a new, yet complex, system, it is imperative to have a systematic and comprehensive understanding on its security from a holistic perspective, which was previously unavailable in the literature. To the best of our knowledge, the present survey, which can also be used as a tutorial, fills this void. We systematize three aspects of Ethereum systems security: vulnerabilities, attacks, and defenses. We draw insights into vulnerability root causes, attack consequences, and defense capabilities, which shed light on future research directions.
引用
收藏
页数:43
相关论文
共 50 条
  • [1] Vehicle Security: A Survey of Security Issues and Vulnerabilities, Malware Attacks and Defenses
    Abu Elkhail, Abdulrahman
    Refat, Rafi Ud Daula
    Habre, Ricardo
    Hafeez, Azeem
    Bacha, Anys
    Malik, Hafiz
    [J]. IEEE ACCESS, 2021, 9 : 162401 - 162437
  • [2] A Systematic Survey on Security in Anonymity Networks: Vulnerabilities, Attacks, Defenses, and Formalization
    Chao, Daichong
    Xu, Dawei
    Gao, Feng
    Zhang, Chuan
    Zhang, Weiting
    Zhu, Liehuang
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2024, 26 (03): : 1775 - 1829
  • [3] A SURVEY OF SECURITY IN ROBOTIC SYSTEMS: VULNERABILITIES, ATTACKS, AND SOLUTIONS
    Archibald, Christopher
    Schwalm, Luke
    Ball, John E.
    [J]. INTERNATIONAL JOURNAL OF ROBOTICS & AUTOMATION, 2017, 32 (02): : 151 - 157
  • [4] A Survey of Microarchitectural Side-channel Vulnerabilities, Attacks, and Defenses in Cryptography
    Lou, Xiaoxuan
    Zhang, Tianwei
    Jiang, Jun
    Zhang, Yinqian
    [J]. ACM COMPUTING SURVEYS, 2021, 54 (06)
  • [5] Security Vulnerabilities in Ethereum Smart Contracts
    Dika, Ardit
    Nowostawski, Mariusz
    [J]. IEEE 2018 INTERNATIONAL CONGRESS ON CYBERMATICS / 2018 IEEE CONFERENCES ON INTERNET OF THINGS, GREEN COMPUTING AND COMMUNICATIONS, CYBER, PHYSICAL AND SOCIAL COMPUTING, SMART DATA, BLOCKCHAIN, COMPUTER AND INFORMATION TECHNOLOGY, 2018, : 955 - 962
  • [6] Security Vulnerabilities in Ethereum Smart Contracts
    Mense, Alexander
    Flatscher, Markus
    [J]. IIWAS2018: THE 20TH INTERNATIONAL CONFERENCE ON INFORMATION INTEGRATION AND WEB-BASED APPLICATIONS & SERVICES, 2014, : 375 - 380
  • [7] The state of affairs in BGP security: A survey of attacks and defenses
    Mitseva, Asya
    Panchenko, Andriy
    Engel, Thomas
    [J]. COMPUTER COMMUNICATIONS, 2018, 124 : 45 - 60
  • [8] Attacks and defenses in user authentication systems: A survey
    Wang, Xuerui
    Yan, Zheng
    Zhang, Rui
    Zhang, Peng
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 188
  • [9] Security of Online Reputation Systems The evolution of attacks and defenses
    Sun, Yan
    Liu, Yuhong
    [J]. IEEE SIGNAL PROCESSING MAGAZINE, 2012, 29 (02) : 87 - 97
  • [10] Security of Cyber Physical Systems: Vulnerabilities, Attacks and Countermeasure
    Alrefaei, Faisal
    Alzahrani, Abdullah
    Song, Houbing
    Zohdy, Mohamed
    [J]. 2020 IEEE INTERNATIONAL IOT, ELECTRONICS AND MECHATRONICS CONFERENCE (IEMTRONICS 2020), 2020, : 551 - 556