GasFuzzer: Fuzzing Ethereum Smart Contract Binaries to Expose Gas-Oriented Exception Security Vulnerabilities
GasFuzzer: Fuzzing Ethereum Smart Contract Binaries to Expose Gas-Oriented Exception Security Vulnerabilities
复制标题
GasFuzzer:模糊以太坊智能合约二进制文件以暴露面向 Gas 的异常安全漏洞
DOI:
10.1109/access.2020.2995183
复制
发表时间:
2020-05
期刊:
影响因子:
3.9
通讯作者:
W. K. Chan
中科院分区:
文献类型:
--
作者:
Imran Ashraf;Xiaoxue Ma;Bo Jiang;W. K. Chan
Ethereum is a kind of blockchain platform where developers may develop and run programs called smart contracts. It inherently relies on gas consumption within a specified allowance to constrain code execution, making every instruction along an execution path to be a location for raising an exception. In this paper, we present GasFuzzer, the first work in exploring the effects of gas allowance manipulation to expose gas-oriented exception security vulnerabilities. GasFuzzer consists of two phases. The first phase introduces a gas-greedy strategy to favor transactions having higher gas consumption for mutation to obtain test transactions with different gas consumptions. The second phase introduces a novel notion of fractional gas consumption coverage and a novel gas-leveling strategy. It applies them to mutate the gas allowances of some of these transactions resulting in the highest gas consumptions produced in the first phase followed by applying these allowance-mutated transactions together with those which remained non-mutated to fuzz test the smart contract. We report an evaluation of GasFuzzer via an experiment on 3170 real-world smart contracts deployed on the public Ethereum Blockchain between October 2017 and July 2019. The findings show that GasFuzzer with gas-greedy strategy can detect more Exceptions Disorder kind of security vulnerabilities (7 more cases) than the previous state-of-the-art black-box fuzzer, and GasFuzzer with gas-leveling strategy and gas coverage criterion can detect 6 additional cases of Exceptions Disorder security vulnerabilities, which is significant.
登录
查看更多内容
DOI:
10.1145/3368089.3417064
发表时间:
2019-05
期刊:
Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering
影响因子:
--
作者:
Valentin Wüstholz;M. Christakis
通讯作者:
Valentin Wüstholz;M. Christakis
DOI:
10.1109/dsa51864.2020.00031
发表时间:
2020-11
期刊:
2020 7th International Conference on Dependable Systems and Their Applications (DSA)
影响因子:
--
作者:
Anqi Wang;Hongya Wang;Bo Jiang;W. Chan
通讯作者:
Anqi Wang;Hongya Wang;Bo Jiang;W. Chan
DOI:
--
发表时间:
2018-09
期刊:
ArXiv
影响因子:
--
作者:
Lexi Brent;Anton Jurisevic;Michael Kong;Eric Liu;François Gauthier;Vincent Gramoli;Ralph Holz
通讯作者:
Lexi Brent;Anton Jurisevic;Michael Kong;Eric Liu;François Gauthier;Vincent Gramoli;Ralph Holz
DOI:
10.1002/9781119711063.ch4
发表时间:
2021-01
期刊:
Blockchain for Business
影响因子:
--
作者:
Shaveta Bhatia;S. Tyagi
通讯作者:
Shaveta Bhatia;S. Tyagi
DOI:
10.1145/3338906.3341175
发表时间:
2019-08
期刊:
Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering
影响因子:
--
作者:
Ying Fu;Meng Ren;Fuchen Ma;Heyuan Shi;Xin Yang;Yu Jiang;Huizhong Li;Xiang Shi
通讯作者:
Ying Fu;Meng Ren;Fuchen Ma;Heyuan Shi;Xin Yang;Yu Jiang;Huizhong Li;Xiang Shi