HCC: A Language-Independent Hardening Contract Compiler for Smart Contracts

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Giesen, Jens-Rene, Andreina, Sebastien, Rodler, Michael, Karame, Ghassan O., Davi, Lucas
Format: Preprint
Publié: 2022
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866912145971609600
author Giesen, Jens-Rene
Andreina, Sebastien
Rodler, Michael
Karame, Ghassan O.
Davi, Lucas
author_facet Giesen, Jens-Rene
Andreina, Sebastien
Rodler, Michael
Karame, Ghassan O.
Davi, Lucas
contents Developing secure smart contracts remains a challenging task. Existing approaches are either impractical or leave the burden to developers for fixing bugs. In this paper, we propose the first practical smart contract compiler, called HCC, which automatically inserts security hardening checks at the source-code level based on a novel and language-independent code property graph (CPG) notation. The high expressiveness of our developed CPG allows us to mitigate all of the most common smart contract vulnerabilities, namely reentrancy, integer bugs, suicidal smart contracts, improper use of tx.origin, untrusted delegate-calls, and unchecked low-level call bugs. Our large-scale evaluation on 10k real-world contracts and several sets of vulnerable contracts from related work demonstrates that HCC is highly practical, outperforms state-of-the-art contract hardening techniques, and effectively prevents all verified attack transactions without hampering functional correctness.
format Preprint
id arxiv_https___arxiv_org_abs_2203_00364
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle HCC: A Language-Independent Hardening Contract Compiler for Smart Contracts
Giesen, Jens-Rene
Andreina, Sebastien
Rodler, Michael
Karame, Ghassan O.
Davi, Lucas
Cryptography and Security
Developing secure smart contracts remains a challenging task. Existing approaches are either impractical or leave the burden to developers for fixing bugs. In this paper, we propose the first practical smart contract compiler, called HCC, which automatically inserts security hardening checks at the source-code level based on a novel and language-independent code property graph (CPG) notation. The high expressiveness of our developed CPG allows us to mitigate all of the most common smart contract vulnerabilities, namely reentrancy, integer bugs, suicidal smart contracts, improper use of tx.origin, untrusted delegate-calls, and unchecked low-level call bugs. Our large-scale evaluation on 10k real-world contracts and several sets of vulnerable contracts from related work demonstrates that HCC is highly practical, outperforms state-of-the-art contract hardening techniques, and effectively prevents all verified attack transactions without hampering functional correctness.
title HCC: A Language-Independent Hardening Contract Compiler for Smart Contracts
topic Cryptography and Security
url https://arxiv.org/abs/2203.00364