Technical Usability Assessment of Security Analysis Tools for Ethereum Based Smart Contracts

被引:0
|
作者
Zeeshan, Rana [1 ]
Tal, Irina [2 ]
机构
[1] Dublin City Univ, Sch Comp, Dublin, Ireland
[2] Dublin City Univ, Sch Comp, Lero, Dublin, Ireland
关键词
Smart contracts; Solidity; Blockchain; Ethere-um; Security Analysis Tools; Vulnerability analysis; Usability study;
D O I
10.1109/QRS-C57518.2022.00021
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Over the past few years, Ethereum has surfaced as a widely adopted standard Blockchain platform that is increasingly being utilized to develop Decentralized Applications (DApps). By introducing Smart Contracts to software developers and programmers, Ethereum has triggered the development of countless Blockchain solutions. Among its main applications, many involve the exchange of valuable financial assets. Simply put, we cannot afford to base our Blockchain solutions or applications on potentially vulnerable smart contracts. This is where the Security Analysis Tools come into picture, for the timely detection of vulnerabilities in the Smart Contracts. Since this is a recent phenomenon, it offers a lot of research opportunities for us to contribute towards improving the existing state of security analysis tools and resolving their shortcomings. Although most of these tools have been evaluated in terms of effectiveness, installation and reliability; the literature largely lacks the technical usability perspective i.e. execution and evaluation. Therefore, based on a selection criteria, we committed our time to 4 such tools for an extensive usability assessment. We designed our usability study in a manner that combined the advantages of multiple evaluation methods. The results were useful not only in terms of comparative analysis, but also as a validation of the need of identified usability improvements.
引用
收藏
页码:87 / 95
页数:9
相关论文
共 50 条
  • [41] EOSAFE: Security Analysis of EOSIO Smart Contracts
    He, Ningyu
    Zhang, Ruiyi
    Wang, Haoyu
    Wu, Lei
    Luo, Xiapu
    Guo, Yao
    Yu, Ting
    Jiang, Xuxian
    PROCEEDINGS OF THE 30TH USENIX SECURITY SYMPOSIUM, 2021, : 1271 - 1288
  • [42] A Survey on Security Analysis Methods of Smart Contracts
    Zhu, Huijuan
    Yang, Lei
    Wang, Liangmin
    Sheng, Victor S.
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2024, 17 (06) : 4522 - 4539
  • [43] Panda: Security Analysis of Algorand Smart Contracts
    Sun, Zhiyuan
    Luo, Xiapu
    Zhang, Yinqian
    PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM, 2023, : 1811 - 1828
  • [44] SECURIFY: Practical Security Analysis of Smart Contracts
    Tsankov, Petar
    Dan, Andrei
    Drachsler-Cohen, Dana
    Gervais, Arthur
    Bunzli, Florian
    Vechev, Martin
    PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, : 67 - 82
  • [45] Test Case Generation for Ethereum Smart Contracts Based on Cross-Contract Data Flow Analysis
    Wang, Xingya
    Yang, Yumao
    Liu, Linwei
    Chen, Zhenyu
    Huang, Song
    IEEE TRANSACTIONS ON RELIABILITY, 2024,
  • [46] HORSTIFY: Sound Security Analysis of Smart Contracts
    Holler, Sebastian
    Biewer, Sebastian
    Schneidewind, Clara
    2023 IEEE 36TH COMPUTER SECURITY FOUNDATIONS SYMPOSIUM, CSF, 2023, : 245 - 260
  • [47] The Structural Role of Smart Contracts and Exchanges in the Centralisation of Ethereum-Based Cryptoassets
    De Collibus, Francesco Maria
    Piskorec, Matija
    Partida, Alberto
    Tessone, Claudio J.
    ENTROPY, 2022, 24 (08)
  • [48] SKLEE: A Dynamic Symbolic Analysis Tool for Ethereum Smart Contracts (Tool Paper)
    Jain, Namrata
    Kaneko, Kosuke
    Sharma, Subodh
    SOFTWARE ENGINEERING AND FORMAL METHODS, SEFM 2022, 2022, 13550 : 244 - 250
  • [49] Vulnerabilities and Excess Gas Consumption Analysis Within Ethereum-Based Smart Contracts for Electricity Market
    Danielius, Paulius
    Stolarski, Piotr
    Masteika, Saulius
    BUSINESS INFORMATION SYSTEMS WORKSHOPS (BIS 2020), 2020, 394 : 99 - 110
  • [50] Designing Secure Ethereum Smart Contracts: A Finite State Machine Based Approach
    Mavridou, Anastasia
    Laszka, Aron
    FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2018, 2018, 10957 : 523 - 540