Are We There Yet? Unraveling the State-of-the-Art Smart Contract Fuzzers
Fuente:
arXiv
Guardado en:
| Autores principales: | , , , , , , , |
|---|---|
| Formato: | Preprint |
| Publicado: |
2024
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
| _version_ | 1866913223176880128 |
|---|---|
| author | Wu, Shuohan Li, Zihao Yan, Luyi Chen, Weimin Jiang, Muhui Wang, Chenxu Luo, Xiapu Zhou, Hao |
| author_facet | Wu, Shuohan Li, Zihao Yan, Luyi Chen, Weimin Jiang, Muhui Wang, Chenxu Luo, Xiapu Zhou, Hao |
| contents | Given the growing importance of smart contracts in various applications, ensuring their security and reliability is critical. Fuzzing, an effective vulnerability detection technique, has recently been widely applied to smart contracts. Despite numerous studies, a systematic investigation of smart contract fuzzing techniques remains lacking. In this paper, we fill this gap by: 1) providing a comprehensive review of current research in contract fuzzing, and 2) conducting an in-depth empirical study to evaluate state-of-the-art contract fuzzers' usability. To guarantee a fair evaluation, we employ a carefully-labeled benchmark and introduce a set of pragmatic performance metrics, evaluating fuzzers from five complementary perspectives. Based on our findings, we provide direction for the future research and development of contract fuzzers. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2402_02973 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Are We There Yet? Unraveling the State-of-the-Art Smart Contract Fuzzers Wu, Shuohan Li, Zihao Yan, Luyi Chen, Weimin Jiang, Muhui Wang, Chenxu Luo, Xiapu Zhou, Hao Software Engineering Given the growing importance of smart contracts in various applications, ensuring their security and reliability is critical. Fuzzing, an effective vulnerability detection technique, has recently been widely applied to smart contracts. Despite numerous studies, a systematic investigation of smart contract fuzzing techniques remains lacking. In this paper, we fill this gap by: 1) providing a comprehensive review of current research in contract fuzzing, and 2) conducting an in-depth empirical study to evaluate state-of-the-art contract fuzzers' usability. To guarantee a fair evaluation, we employ a carefully-labeled benchmark and introduce a set of pragmatic performance metrics, evaluating fuzzers from five complementary perspectives. Based on our findings, we provide direction for the future research and development of contract fuzzers. |
| title | Are We There Yet? Unraveling the State-of-the-Art Smart Contract Fuzzers |
| topic | Software Engineering |
| url | https://arxiv.org/abs/2402.02973 |