Vandal: A Scalable Security Analysis Framework for Smart Contracts

Vandal: A Scalable Security Analysis Framework for Smart Contracts
复制标题

DOI:
--
复制
发表时间:
2018-09
期刊:
ArXiv
影响因子:
--
通讯作者:
Lexi Brent;Anton Jurisevic;Michael Kong;Eric Liu;François Gauthier;Vincent Gramoli;Ralph Holz
Lexi Brent;Anton Jurisevic;Michael Kong;Eric Liu;François Gauthier;Vincent Gramoli;Ralph Holz
中科院分区:
其他
文献类型:
--
作者:
Lexi Brent;Anton Jurisevic;Michael Kong;Eric Liu;François Gauthier;Vincent Gramoli;Ralph Holz

文献摘要

被引文献

相似文献

现代区块链的兴起促进了智能合约的出现:在区块链上运行和运行的自治程序。智能合约已迅速崛起,预计将在法律、商业、商业和治理领域得到应用。智能合约通常用高级语言(例如以太坊的 Solidity)编写,并转换为紧凑的低级字节码以部署在区块链上。部署后,字节码通常由图灵完备的虚拟机自动执行。与所有程序一样,由于编程方法、语言和工具链(包括有缺陷的编译器)的缺陷,智能合约很容易受到恶意攻击。同时,智能合约也是高价值目标,往往掌握着大量的加密货币。因此,开发人员和审计人员需要能够分析低级字节码以检测潜在安全漏洞的安全框架。在本文中,我们提出了 Vandal:以太坊智能合约的安全分析框架。 Vandal 包含一个分析管道,可将低级以太坊虚拟机 (EVM) 字节码转换为语义逻辑关系。该框架的用户可以以声明方式表达安全分析:安全分析以 \souffle 语言编写的逻辑规范来表达。我们对一组常见的智能合约安全漏洞进行了大规模的实证研究,并展示了破坏的有效性和效率。 Vandal 既快速又强大,成功分析了所有 141k 个独特合约中的 95% 以上,平均运行时间为 4.15 秒;在同等条件下,其性能优于当前最先进的工具——Oyente、EthIR、Mythril 和 Rattle。
The rise of modern blockchains has facilitated the emergence of smart contracts: autonomous programs that live and run on the blockchain. Smart contracts have seen a rapid climb to prominence, with applications predicted in law, business, commerce, and governance. Smart contracts are commonly written in a high-level language such as Ethereum's Solidity, and translated to compact low-level bytecode for deployment on the blockchain. Once deployed, the bytecode is autonomously executed, usually by a %Turing-complete virtual machine. As with all programs, smart contracts can be highly vulnerable to malicious attacks due to deficient programming methodologies, languages, and toolchains, including buggy compilers. At the same time, smart contracts are also high-value targets, often commanding large amounts of cryptocurrency. Hence, developers and auditors need security frameworks capable of analysing low-level bytecode to detect potential security vulnerabilities. In this paper, we present Vandal: a security analysis framework for Ethereum smart contracts. Vandal consists of an analysis pipeline that converts low-level Ethereum Virtual Machine (EVM) bytecode to semantic logic relations. Users of the framework can express security analyses in a declarative fashion: a security analysis is expressed in a logic specification written in the \souffle language. We conduct a large-scale empirical study for a set of common smart contract security vulnerabilities, and show the effectiveness and efficiency of Vandal. Vandal is both fast and robust, successfully analysing over 95\% of all 141k unique contracts with an average runtime of 4.15 seconds; outperforming the current state of the art tools---Oyente, EthIR, Mythril, and Rattle---under equivalent conditions.