函数名即所需:检测区块链应用攻击
Function Name Is All You Need to Detect Blockchain Application Attacks
浏览论文内容
中文总结 AI 辅助
本文提出TxLucent框架,利用函数名序列和Transformer学习交易语义,无需源代码或手工规则即可检测区块链应用攻击,在424起事件中漏报率仅1.56%,误报率极低,且支持实时检测。
中文摘要 AI 辅助
区块链应用攻击针对去中心化应用(dApps)中的业务逻辑漏洞,已日益引起开发者与用户的担忧,并造成重大经济损失。现有攻击检测器要么依赖手工规则进行检测,要么需要难以获取的智能合约源代码来分析攻击交易,这使得它们在实践中脆弱且不适用。本文中,我们认为函数名序列足以捕获交易的高级语义,因此可用于检测区块链应用攻击。我们对来自424起真实世界攻击事件的交易进行的实证研究表明,98.46%的调用轨迹可解析为函数名,而仅有74.78%的调用轨迹所调用的合约具有可用源代码。基于此观察,我们提出TxLucent(发音为“translucent”),一个通过从交易调用轨迹中提取应用语义来自动检测区块链应用攻击的框架。TxLucent将调用轨迹映射为函数名序列,并使用Transformer从这些序列中学习语义。因此,TxLucent无需依赖手工编码模式或源代码即可检测攻击。我们的结果显示,在包含14,611笔攻击交易的424起已知事件中,TxLucent实现了1.56%的漏报率,并在以太坊区块链超过5亿笔交易中,对良性交易的估计误报率为0.0017%。最后,TxLucent平均仅需24.90毫秒即可分析一笔交易,从而支持在主流区块链上进行实时攻击检测。
英文摘要
Blockchain application attacks, targeting business logic bugs in decentralized applications (dApps), have been an increasing concern to their developers and users, causing significant financial loss. Existing attack detectors either rely on handcrafted rules for detection, or need difficult-to-obtain smart contract source code to analyze attack transactions. This makes them brittle and inapplicable in practice. In this paper, we argue that function name sequences suffice to capture the high-level semantics of a transaction, and hence can be used to detect blockchain application attacks. Our empirical study on transactions from 424 real-world attack incidents shows that 98.46% of call traces can be resolved to function names, whereas only 74.78% invoke contracts with available source code. Based on this observation, we propose TxLucent (pronounced "translucent"), an automated framework to detect blockchain application attacks by extracting application semantics from transaction call traces. TxLucent maps call traces to function name sequences and uses a transformer to learn semantics from such sequences. Consequently, TxLucent can detect attacks without relying on hand-coded patterns or source code. Our results show that TxLucent achieves a 1.56% false negative rate on 424 known incidents with 14,611 attack transactions, and an estimated 0.0017% false positive rate for benign transactions from over 500 million transactions on the Ethereum blockchain. Finally, TxLucent takes an average of 24.90 milliseconds to analyze a transaction, thus supporting real-time attack detection on popular blockchains.
发表机构
- University of British Columbia(不列颠哥伦比亚大学)
机构由 AI 辅助整理,请以论文原文为准。