arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

智能合约不变量可抵御网络犯罪分子

Smart Contract Invariants Protect Against Cybercriminals

Sofia Bobadilla, Humaira Afrin, Angela Novelli, Martin Monperrus

arXiv 2608.13191首次发表:更新:

AI 中文总结

该研究提出用智能合约不变量抵御区块链网络犯罪,基于含28个以太坊漏洞的INVARIANTEVAL基准,经PONDEREPLAY重放108637笔交易验证,可阻止所有相关攻击。

AI 中文摘要

区块链是计算领域中对抗性最强的环境之一,网络犯罪分子利用漏洞窃取了数十亿美元,这是一个开放性问题,尚无任何概念或技术被证明能真正产生效果。本文提出,经典的程序不变量概念或许是解决该问题最强大的方案。我们设计了一套原创实验协议,用于研究不变量如何抵御过去的真实攻击,以及最先进的自动化工具能否找到这些不变量。该实验工具链基于INVARIANTEVAL,这是一个包含28个真实以太坊漏洞利用的基准,每个漏洞都配有人类编写的可阻止攻击的不变量。我们使用PONDEREPLAY(一种重放框架)对每个不变量进行验证,该框架通过重放交易来证明智能合约不变量的正确性与可靠性。我们证明,智能合约不变量可阻止INVARIANTEVAL中的所有网络犯罪攻击,且通过重放108637笔历史交易完成了全面验证。我们的大规模实验清晰表明,智能合约不变量可抵御网络犯罪分子。

英文摘要

Blockchains are among the most adversarial environments in computing. Billions are stolen by cybercriminals who exploit vulnerabilities. This is an open problem and no concept or technique has proven to really make a difference. In this paper, we claim that the classical notion of program invariant is perhaps the most powerful solution to the problem. We devise anoriginal experimental protocol to 1) study how invariants would have protected against past real-world attacks and 2) whether state-of-the-art automated tools can find them. The experimental toolchain is sophisticated. It is based on INVARIANTEVAL, a benchmark of 28 real Ethereum exploits, each paired with a human-authored invariant that blocks the attack. We validate every invariant with PONDEREPLAY, a replay framework that re-executes transactions in order to prove the correctness and soundness of smart contract invariants. We demonstrate that smart contract invariants block all the cybercriminal attacks in INVARIANTEVAL, fully validated by replaying 108,637 historical transactions. Our large-scale experiments clearly demonstrate that smart contract invariants protect against cybercriminals.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑