跳到主要导航 跳到搜索 跳到主要内容

ContractFuzzer: Fuzzing smart contracts for vulnerability detection

  • Bo Jiang*
  • , Ye Liu
  • , W. K. Chan
  • *此作品的通讯作者
  • Beihang University
  • City University of Hong Kong

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Decentralized cryptocurrencies feature the use of blockchain to transfer values among peers on networks without central agency. Smart contracts are programs running on top of the blockchain consensus protocol to enable people make agreements while minimizing trusts. Millions of smart contracts have been deployed in various decentralized applications. The security vulnerabilities within those smart contracts pose significant threats to their applications. Indeed, many critical security vulnerabilities within smart contracts on Ethereum platform have caused huge financial losses to their users. In this work, we present ContractFuzzer, a novel fuzzer to test Ethereum smart contracts for security vulnerabilities. ContractFuzzer generates fuzzing inputs based on the ABI specifications of smart contracts, defines test oracles to detect security vulnerabilities, instruments the EVM to log smart contracts runtime behaviors, and analyzes these logs to report security vulnerabilities. Our fuzzing of 6991 smart contracts has flagged more than 459 vulnerabilities with high precision. In particular, our fuzzing tool successfully detects the vulnerability of the DAO contract that leads to $60 million loss and the vulnerabilities of Parity Wallet that have led to the loss of $30 million and the freezing of $150 million worth of Ether.

源语言英语
主期刊名ASE 2018 - Proceedings of the 33rd ACM/IEEE International Conference on Automated Software Engineering
编辑Christian Kastner, Marianne Huchard, Gordon Fraser
出版商Association for Computing Machinery, Inc
259-269
页数11
ISBN(电子版)9781450359375
DOI
出版状态已出版 - 3 9月 2018
活动33rd IEEE/ACM International Conference on Automated Software Engineering, ASE 2018 - Montpellier, 法国
期限: 3 9月 20187 9月 2018

出版系列

姓名ASE 2018 - Proceedings of the 33rd ACM/IEEE International Conference on Automated Software Engineering

会议

会议33rd IEEE/ACM International Conference on Automated Software Engineering, ASE 2018
国家/地区法国
Montpellier
时期3/09/187/09/18

学术指纹

探究 'ContractFuzzer: Fuzzing smart contracts for vulnerability detection' 的科研主题。它们共同构成独一无二的学术指纹。

引用此