EVMFuzzer: detect EVM vulnerabilities via fuzz testing

EVMFuzzer: detect EVM vulnerabilities via fuzz testing
复制标题

DOI:
10.1145/3338906.3341175
复制
发表时间:
2019-08
期刊:
Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering
影响因子:
--
通讯作者:
Ying Fu;Meng Ren;Fuchen Ma;Heyuan Shi;Xin Yang;Yu Jiang;Huizhong Li;Xiang Shi
Ying Fu;Meng Ren;Fuchen Ma;Heyuan Shi;Xin Yang;Yu Jiang;Huizhong Li;Xiang Shi
中科院分区:
其他
文献类型:
--
作者:
Ying Fu;Meng Ren;Fuchen Ma;Heyuan Shi;Xin Yang;Yu Jiang;Huizhong Li;Xiang Shi

文献摘要

被引文献

相似文献

以太坊虚拟机(EVM)是智能合约的运行环境,其漏洞可能会给以太坊生态带来严重问题。随着许多用于验证智能合约的技术不断开发,由于特殊的测试输入格式和预言机的缺乏,EVM 的测试仍然具有挑战性。在本文中,我们提出了 EVMFuzzer,这是第一个使用差分模糊技术来检测 EVM 漏洞的工具。其核心思想是不断生成种子合约并将其反馈给目标EVM和基准EVM,从而尽可能多地发现执行结果之间的不一致,最终通过输出交叉引用发现漏洞。给定目标 EVM 及其 API,EVMFuzzer 通过一组预定义的变异器生成种子合约,然后采用动态优先级调度算法来指导种子合约选择并最大化不一致性。最后,EVMFuzzer 利用基准 EVM 作为交叉引用预言机,以避免手动检查。通过 EVMFuzzer,我们在 4 个广泛使用的 EVM 中发现了几个以前未知的安全漏洞,其中 5 个已包含在美国国家漏洞数据库的通用漏洞和暴露 (CVE) ID 中。该视频发布于 https://youtu.be/9Lejgf2GSOk。
Ethereum Virtual Machine (EVM) is the run-time environment for smart contracts and its vulnerabilities may lead to serious problems to the Ethereum ecology. With lots of techniques being continuously developed for the validation of smart contracts, the testing of EVM remains challenging because of the special test input format and the absence of oracles. In this paper, we propose EVMFuzzer, the first tool that uses differential fuzzing technique to detect vulnerabilities of EVM. The core idea is to continuously generate seed contracts and feed them to the target EVM and the benchmark EVMs, so as to find as many inconsistencies among execution results as possible, eventually discover vulnerabilities with output cross-referencing. Given a target EVM and its APIs, EVMFuzzer generates seed contracts via a set of predefined mutators, and then employs dynamic priority scheduling algorithm to guide seed contracts selection and maximize the inconsistency. Finally, EVMFuzzer leverages benchmark EVMs as cross-referencing oracles to avoid manual checking. With EVMFuzzer, we have found several previously unknown security bugs in four widely used EVMs, and 5 of which had been included in Common Vulnerabilities and Exposures (CVE) IDs in U.S. National Vulnerability Database. The video is presented at https://youtu.be/9Lejgf2GSOk.