• 中国精品科技期刊
  • CCF推荐A类中文期刊
  • 计算领域高质量科技期刊T1类
高级检索

一种基于运行时信息的以太坊智能合约防御技术

向杰, 杨哲慜, 周顺帆, 杨珉

向杰, 杨哲慜, 周顺帆, 杨珉. 一种基于运行时信息的以太坊智能合约防御技术[J]. 计算机研究与发展, 2021, 58(4): 834-848. DOI: 10.7544/issn1000-1239.2021.20200135
引用本文: 向杰, 杨哲慜, 周顺帆, 杨珉. 一种基于运行时信息的以太坊智能合约防御技术[J]. 计算机研究与发展, 2021, 58(4): 834-848. DOI: 10.7544/issn1000-1239.2021.20200135
Xiang Jie, Yang Zhemin, Zhou Shunfan, Yang Min. A Runtime Information Based Defense Technique for Ethereum Smart Contract[J]. Journal of Computer Research and Development, 2021, 58(4): 834-848. DOI: 10.7544/issn1000-1239.2021.20200135
Citation: Xiang Jie, Yang Zhemin, Zhou Shunfan, Yang Min. A Runtime Information Based Defense Technique for Ethereum Smart Contract[J]. Journal of Computer Research and Development, 2021, 58(4): 834-848. DOI: 10.7544/issn1000-1239.2021.20200135
向杰, 杨哲慜, 周顺帆, 杨珉. 一种基于运行时信息的以太坊智能合约防御技术[J]. 计算机研究与发展, 2021, 58(4): 834-848. CSTR: 32373.14.issn1000-1239.2021.20200135
引用本文: 向杰, 杨哲慜, 周顺帆, 杨珉. 一种基于运行时信息的以太坊智能合约防御技术[J]. 计算机研究与发展, 2021, 58(4): 834-848. CSTR: 32373.14.issn1000-1239.2021.20200135
Xiang Jie, Yang Zhemin, Zhou Shunfan, Yang Min. A Runtime Information Based Defense Technique for Ethereum Smart Contract[J]. Journal of Computer Research and Development, 2021, 58(4): 834-848. CSTR: 32373.14.issn1000-1239.2021.20200135
Citation: Xiang Jie, Yang Zhemin, Zhou Shunfan, Yang Min. A Runtime Information Based Defense Technique for Ethereum Smart Contract[J]. Journal of Computer Research and Development, 2021, 58(4): 834-848. CSTR: 32373.14.issn1000-1239.2021.20200135

一种基于运行时信息的以太坊智能合约防御技术

详细信息
  • 中图分类号: TP309.2

A Runtime Information Based Defense Technique for Ethereum Smart Contract

  • 摘要: 智能合约是区块链技术最成功的应用之一,已经被广泛集成到应用程序中,成为应用去中心化的常见实现方案.然而,智能合约由于其独有的金融特性,一直以来饱受安全攻击,各种新的恶意攻击类型层出不穷.现有的研究工作提出了多种有效检测合约漏洞的方法,但在实际应用中都存在着各种局限:仅针对已知的漏洞类型,需要修改合约代码来消除漏洞,链上开销过大.由于智能合约部署到链上后的不可修改性,这些针对特定漏洞类型的检测防御手段无法对原有的合约进行修复,因此很难及时地应对新型的漏洞和攻击.为此,提出了一种基于运行时信息的智能合约可升级防御技术,通过引入运行时的各种信息,为链下对攻击和漏洞的检测提供实时的数据.同时,设计了一套部署在合约上的访问控制机制,基于动态检测的结果,对合约的访问进行限制,从而在不需要修改合约代码的情况下实现动态的防御.由于以太坊本身的机制无法对实时攻击进行识别和拦截,为了减小这一影响,利用竞争(race condition)的机制来增强防御的效果.实验结果分析表明:该防御技术可以有效地检测并防御攻击,对于后续的攻击交易,可以实现100%的拦截成功率,对于首次检测到的实时攻击,利用竞争可以达到97.5%的成功率.
    Abstract: As one of the most successful applications of blockchain technology, Ethereum smart contract has been widely integrated into programs and become a common implementation scheme for decentralized applications. However, smart contract suffers from security attacks since born because of its unique financial characteristics, and fresh attack forms continue to dribble out. State-of-art research works have proposed many effective mechanisms to detect vulnerabilities in smart contract, but they all have limitations in practical, such as design only for known vulnerabilities, need to modify the contract code, and the cost on-chain is too high. Because of the immutability of smart contract, these defense techniques which aim at specific vulnerabilities cannot fix the original contract, and as a result, they can hardly work on the new attack forms. To this end, we present a runtime information based upgradable defense system for Ethereum smart contract, which provides real-time data for the off-chain attack detection by collecting kinds of runtime information. At the same time, we design an access control mechanism deployed on smart contract, which restricts the access to the contract based on the dynamic detection result, so that we can secure the contract without modifying the code. Ethereum does not provide a mechanism to recognize and intercept real-time attack transactions, So we make use of race condition to enhance the defense on the real-time attack. The evaluation results show that out defense technology is extremely effective to prevent attacks, which can achieve 100% success rate for the follow-up attacks and achieve 97.5% success rate for the first attack detected by the use of race condition.
  • 期刊类型引用(4)

    1. 林炼升,郑焕钦,苏申,雷凯,陈晓丰,田志宏. 一种DeFi价格操纵攻击在线防御机制. 计算机研究与发展. 2025(02): 443-457 . 本站查看
    2. 郭春霞. 基于权限验证图的Web访问控制漏洞检测方法. 自动化与仪器仪表. 2024(06): 252-256+260 . 百度学术
    3. 安洋,李坤,李军怀,王怀军,臧东玲. 基于智能合约和企业信用的访问控制模型. 计算机系统应用. 2022(03): 197-202 . 百度学术
    4. 孙彬文,陈竟飞,柳絮. 基于UML的智能合约生命周期动态模型. 工业技术创新. 2021(04): 79-88+108 . 百度学术

    其他类型引用(7)

计量
  • 文章访问数:  767
  • HTML全文浏览量:  4
  • PDF下载量:  462
  • 被引次数: 11
出版历程
  • 发布日期:  2021-03-31

目录

    /

    返回文章
    返回