Code cloning in smart contracts: a case study on verified contracts from the Ethereum blockchain platform

Code cloning in smart contracts: a case study on verified contracts from the Ethereum blockchain platform
复制标题

DOI:
10.1007/s10664-020-09852-5
复制
发表时间:
2020-09-09
影响因子:
4.1
通讯作者:
Mizuno, Osamu
Mizuno, Osamu
中科院分区:
计算机科学2区
文献类型:
--
作者:
Kondo, Masanari;Oliva, Gustavo A.;Mizuno, Osamu

文献摘要

被引文献

相似文献

以太坊是一个区块链平台,可托管和执行智能合约。智能合约已用于实施加密货币和众筹计划(ICO)。以太坊的主要问题是智能合约的安全。与传统软件开发不同,一旦部署了智能合约。因此,智能合约中的漏洞和错误可能导致灾难性的金融失败。为了避免冒险撰写越野车代码的风险,鼓励智能合约开发人员从信誉良好的来源(例如Openzeppelin)重复使用代码。在本文中,我们研究以太坊中的代码克隆。我们的目标是量化以太坊(RQ1)中克隆的数量,了解克隆群的关键特征(RQ2),并确定智能合约是否包含与OpenZeppelin(RQ3)发布的代码相同的代码。我们将基于树的克隆检测器Deckard应用于所有可用源代码的以太坊合同。我们观察到开发人员经常克隆合同。特别是,研究合同中有79.2%是克隆,我们注意到每季度克隆合同数量的上升趋势。关于克隆簇的特性,我们观察到:(i)在前十名最大的克隆群中有9个是代币经理,(ii)集群的大部分活动往往集中在一些合同上,并且(iii)在一个集群中签订合同,由几位作者创建。最后,我们注意到,所研究的合同具有不同的代码块比例,这些块与Openzeppelin项目提供的合同相同。由于智能合约的不变性以及一旦被视为最终交易的不可能恢复交易的可能性,我们得出的结论是,上述发现对智能合约的安全性,开发和使用产生了影响。
Ethereum is a blockchain platform that hosts and executes smart contracts. Smart contracts have been used to implement cryptocurrencies and crowdfunding initiatives (ICOs). A major concern in Ethereum is the security of smart contracts. Different from traditional software development, smart contracts are immutable once deployed. Hence, vulnerabilities and bugs in smart contracts can lead to catastrophic financial loses. In order to avoid taking the risk of writing buggy code, smart contract developers are encouraged to reuse pieces of code from reputable sources (e.g., OpenZeppelin). In this paper, we study code cloning in Ethereum. Our goal is to quantify the amount of clones in Ethereum (RQ1), understand key characteristics of clone clusters (RQ2), and determine whether smart contracts contain pieces of code that are identical to those published by OpenZeppelin (RQ3). We applied Deckard, a tree-based clone detector, to all Ethereum contracts for which the source code was available. We observe that developers frequently clone contracts. In particular, 79.2% of the studied contracts are clones and we note an upward trend in the number of cloned contracts per quarter. With regards to the characteristics of clone clusters, we observe that: (i) 9 out of the top-10 largest clone clusters are token managers, (ii) most of the activity of a cluster tends to be concentrated on a few contracts, and (iii) contracts in a cluster to be created by several authors. Finally, we note that the studied contracts have different ratios of code blocks that are identical to those provided by the OpenZeppelin project. Due to the immutability of smart contracts, as well as the impossibility of reverting transactions once they are deemed final, we conclude that the aforementioned findings yield implications to the security, development, and usage of smart contracts.