Are We There Yet? Unraveling the State-of-the-Art Smart Contract Fuzzers

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Wu, Shuohan, Li, Zihao, Yan, Luyi, Chen, Weimin, Jiang, Muhui, Wang, Chenxu, Luo, Xiapu, Zhou, Hao
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866913223176880128
author Wu, Shuohan
Li, Zihao
Yan, Luyi
Chen, Weimin
Jiang, Muhui
Wang, Chenxu
Luo, Xiapu
Zhou, Hao
author_facet Wu, Shuohan
Li, Zihao
Yan, Luyi
Chen, Weimin
Jiang, Muhui
Wang, Chenxu
Luo, Xiapu
Zhou, Hao
contents Given the growing importance of smart contracts in various applications, ensuring their security and reliability is critical. Fuzzing, an effective vulnerability detection technique, has recently been widely applied to smart contracts. Despite numerous studies, a systematic investigation of smart contract fuzzing techniques remains lacking. In this paper, we fill this gap by: 1) providing a comprehensive review of current research in contract fuzzing, and 2) conducting an in-depth empirical study to evaluate state-of-the-art contract fuzzers' usability. To guarantee a fair evaluation, we employ a carefully-labeled benchmark and introduce a set of pragmatic performance metrics, evaluating fuzzers from five complementary perspectives. Based on our findings, we provide direction for the future research and development of contract fuzzers.
format Preprint
id arxiv_https___arxiv_org_abs_2402_02973
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Are We There Yet? Unraveling the State-of-the-Art Smart Contract Fuzzers
Wu, Shuohan
Li, Zihao
Yan, Luyi
Chen, Weimin
Jiang, Muhui
Wang, Chenxu
Luo, Xiapu
Zhou, Hao
Software Engineering
Given the growing importance of smart contracts in various applications, ensuring their security and reliability is critical. Fuzzing, an effective vulnerability detection technique, has recently been widely applied to smart contracts. Despite numerous studies, a systematic investigation of smart contract fuzzing techniques remains lacking. In this paper, we fill this gap by: 1) providing a comprehensive review of current research in contract fuzzing, and 2) conducting an in-depth empirical study to evaluate state-of-the-art contract fuzzers' usability. To guarantee a fair evaluation, we employ a carefully-labeled benchmark and introduce a set of pragmatic performance metrics, evaluating fuzzers from five complementary perspectives. Based on our findings, we provide direction for the future research and development of contract fuzzers.
title Are We There Yet? Unraveling the State-of-the-Art Smart Contract Fuzzers
topic Software Engineering
url https://arxiv.org/abs/2402.02973