Instrumenting Transaction Trace Properties in Smart Contracts: Extending the EVM for Real-Time Security

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Zhiyang, Gorzny, Jan, Derka, Martin
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912002588278784
author Chen, Zhiyang
Gorzny, Jan
Derka, Martin
author_facet Chen, Zhiyang
Gorzny, Jan
Derka, Martin
contents In the realm of smart contract security, transaction malice detection has been able to leverage properties of transaction traces to identify hacks with high accuracy. However, these methods cannot be applied in real-time to revert malicious transactions. Instead, smart contracts are often instrumented with some safety properties to enhance their security. However, these instrumentable safety properties are limited and fail to block certain types of hacks such as those which exploit read-only re-entrancy. This limitation primarily stems from the Ethereum Virtual Machine's (EVM) inability to allow a smart contract to read transaction traces in real-time. Additionally, these instrumentable safety properties can be gas-intensive, rendering them impractical for on-the-fly validation. To address these challenges, we propose modifications to both the EVM and Ethereum clients, enabling smart contracts to validate these transaction trace properties in real-time without affecting traditional EVM execution. We also use past-time linear temporal logic (PLTL) to formalize transaction trace properties, showcasing that most existing detection metrics can be expressed using PLTL. We also discuss the potential implications of our proposed modifications, emphasizing their capacity to significantly enhance smart contract security.
format Preprint
id arxiv_https___arxiv_org_abs_2408_14621
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Instrumenting Transaction Trace Properties in Smart Contracts: Extending the EVM for Real-Time Security
Chen, Zhiyang
Gorzny, Jan
Derka, Martin
Logic in Computer Science
Cryptography and Security
In the realm of smart contract security, transaction malice detection has been able to leverage properties of transaction traces to identify hacks with high accuracy. However, these methods cannot be applied in real-time to revert malicious transactions. Instead, smart contracts are often instrumented with some safety properties to enhance their security. However, these instrumentable safety properties are limited and fail to block certain types of hacks such as those which exploit read-only re-entrancy. This limitation primarily stems from the Ethereum Virtual Machine's (EVM) inability to allow a smart contract to read transaction traces in real-time. Additionally, these instrumentable safety properties can be gas-intensive, rendering them impractical for on-the-fly validation. To address these challenges, we propose modifications to both the EVM and Ethereum clients, enabling smart contracts to validate these transaction trace properties in real-time without affecting traditional EVM execution. We also use past-time linear temporal logic (PLTL) to formalize transaction trace properties, showcasing that most existing detection metrics can be expressed using PLTL. We also discuss the potential implications of our proposed modifications, emphasizing their capacity to significantly enhance smart contract security.
title Instrumenting Transaction Trace Properties in Smart Contracts: Extending the EVM for Real-Time Security
topic Logic in Computer Science
Cryptography and Security
url https://arxiv.org/abs/2408.14621