科研成果详情

题名Demystifying and Detecting Cryptographic Defects in Ethereum Smart Contracts
作者
发表日期2025
会议名称47th IEEE/ACM International Conference on Software Engineering, ICSE 2025
会议录名称Proceedings - International Conference on Software Engineering
ISSN0270-5257
页码3009-3021
会议日期2025-04-27——2025-04-27
会议地点can,Ottawa
摘要Ethereum has officially provided a set of system-level cryptographic APIs to enhance smart contracts with cryptographic capabilities. These APIs have been utilized in over 10% of Ethereum transactions, motivating developers to implement various on-chain cryptographic tasks, such as digital signatures. However, since developers may not always be cryptographic experts, their ad-hoc and potentially defective implementations could compromise the theoretical guarantees of cryptography, leading to real-world security issues. To mitigate this threat, we conducted the first study aimed at demystifying and detecting cryptographic defects in smart contracts. Through the analysis of 2,406 real-world security reports, we defined nine types of cryptographic defects in smart contracts with detailed descriptions and practical detection patterns. Based on this categorization, we proposed Crysol, a fuzzing-based tool to automate the detection of cryptographic defects in smart contracts. It combines transaction replaying and dynamic taint analysis to extract fine-grained crypto-related semantics and employs crypto-specific strategies to guide the test case generation process. Furthermore, we collected a large-scale dataset containing 25,745 real-world crypto-related smart contracts and evaluated CRYSOL's effectiveness on it. The result demonstrated that CRySOL achieves an overall precision of 95.4% and a recall of 91.2%. Notably, CRySOL revealed that 5,847 (22.7%) out of 25,745 smart contracts contain at least one crvptographic defect' hiahlighting the prevalence of these defects.
关键词cryptography defects detection Ethereum smart contracts
DOI10.1109/ICSE55347.2025.00010
URL查看来源
语种英语English
Scopus入藏号2-s2.0-105010334937
引用统计
文献类型会议论文
条目标识符https://repository.uic.edu.cn/handle/39GCC9TT/13437
专题个人在本单位外知识产出
通讯作者Chen,Jiachi; Chen,Zhong
作者单位
1.Peking University,School of Computer Science,Beijing,China
2.Sun Yat-sen University,Zhuhai,China
3.University of Electronic Science and Technology of China,Chengdu,China
4.Beijing Jiaotong University,Beijing Key Laboratory of Security and Privacy in Intelligent Transportation,Beijing,China
推荐引用方式
GB/T 7714
Zhang,Jiashuo,Shen,Yiming,Chen,Jiachiet al. Demystifying and Detecting Cryptographic Defects in Ethereum Smart Contracts[C], 2025: 3009-3021.
条目包含的文件
条目无相关文件。
个性服务
查看访问统计
谷歌学术
谷歌学术中相似的文章
[Zhang,Jiashuo]的文章
[Shen,Yiming]的文章
[Chen,Jiachi]的文章
百度学术
百度学术中相似的文章
[Zhang,Jiashuo]的文章
[Shen,Yiming]的文章
[Chen,Jiachi]的文章
必应学术
必应学术中相似的文章
[Zhang,Jiashuo]的文章
[Shen,Yiming]的文章
[Chen,Jiachi]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。