Enhancing Smart Contract Security Analysis with Execution Property Graphs

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Qin, Kaihua, Ye, Zhe, Wang, Zhun, Li, Weilin, Zhou, Liyi, Zhang, Chao, Song, Dawn, Gervais, Arthur
Format: Preprint
Publié: 2023
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866913790000365568
author Qin, Kaihua
Ye, Zhe
Wang, Zhun
Li, Weilin
Zhou, Liyi
Zhang, Chao
Song, Dawn
Gervais, Arthur
author_facet Qin, Kaihua
Ye, Zhe
Wang, Zhun
Li, Weilin
Zhou, Liyi
Zhang, Chao
Song, Dawn
Gervais, Arthur
contents Smart contract vulnerabilities have led to significant financial losses, with their increasing complexity rendering outright prevention of hacks increasingly challenging. This trend highlights the crucial need for advanced forensic analysis and real-time intrusion detection, where dynamic analysis plays a key role in dissecting smart contract executions. Therefore, there is a pressing need for a unified and generic representation of smart contract executions, complemented by an efficient methodology that enables the modeling and identification of a broad spectrum of emerging attacks. We introduce Clue, a dynamic analysis framework specifically designed for the Ethereum virtual machine. Central to Clue is its ability to capture critical runtime information during contract executions, employing a novel graph-based representation, the Execution Property Graph. A key feature of Clue is its innovative graph traversal technique, which is adept at detecting complex attacks, including (read-only) reentrancy and price manipulation. Evaluation results reveal Clue's superior performance with high true positive rates and low false positive rates, outperforming state-of-the-art tools. Furthermore, Clue's efficiency positions it as a valuable tool for both forensic analysis and real-time intrusion detection.
format Preprint
id arxiv_https___arxiv_org_abs_2305_14046
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Enhancing Smart Contract Security Analysis with Execution Property Graphs
Qin, Kaihua
Ye, Zhe
Wang, Zhun
Li, Weilin
Zhou, Liyi
Zhang, Chao
Song, Dawn
Gervais, Arthur
Cryptography and Security
Smart contract vulnerabilities have led to significant financial losses, with their increasing complexity rendering outright prevention of hacks increasingly challenging. This trend highlights the crucial need for advanced forensic analysis and real-time intrusion detection, where dynamic analysis plays a key role in dissecting smart contract executions. Therefore, there is a pressing need for a unified and generic representation of smart contract executions, complemented by an efficient methodology that enables the modeling and identification of a broad spectrum of emerging attacks. We introduce Clue, a dynamic analysis framework specifically designed for the Ethereum virtual machine. Central to Clue is its ability to capture critical runtime information during contract executions, employing a novel graph-based representation, the Execution Property Graph. A key feature of Clue is its innovative graph traversal technique, which is adept at detecting complex attacks, including (read-only) reentrancy and price manipulation. Evaluation results reveal Clue's superior performance with high true positive rates and low false positive rates, outperforming state-of-the-art tools. Furthermore, Clue's efficiency positions it as a valuable tool for both forensic analysis and real-time intrusion detection.
title Enhancing Smart Contract Security Analysis with Execution Property Graphs
topic Cryptography and Security
url https://arxiv.org/abs/2305.14046