题名 | EASYFLOW: Keep ethereum away from overflow |
作者 | |
发表日期 | 2019-05-01 |
会议名称 | 41st IEEE/ACM International Conference on Software Engineering: Companion, ICSE-Companion 2019 |
会议录名称 | 2019 IEEE/ACM 41st International Conference on Software Engineering: Companion Proceedings, ICSE-Companion 2019
![]() |
ISBN | 9781728117645 |
页码 | 23-26 |
会议日期 | 25-31 May 2019 |
会议地点 | Montreal, Canada |
摘要 | While Ethereum smart contracts enabled a wide range of blockchain applications, they are extremely vulnerable to different forms of security attacks. Due to the fact that transactions to smart contracts commonly involve cryptocurrency transfer, any successful attacks can lead to money loss or even financial disorder. In this paper, we focus on the overflow attacks in Ethereum, mainly because they widely rooted in many smart contracts and comparatively easy to exploit. We have developed EASYFLOW, an overflow detector at Ethereum Virtual Machine level. The key insight behind EASYFLOW is a taint analysis based tracking technique to analyze the propagation of involved taints. Specifically, EASYFLOW can not only divide smart contracts into safe contracts, manifested overflows, well-protected overflows and potential overflows, but also automatically generate transactions to trigger potential overflows. In our preliminary evaluation, EASYFLOW managed to find potentially vulnerable Ethereum contracts with little runtime overhead. A demo video of EASYFLOW is at https://youtu.be/QbUJkQI0L6o. |
关键词 | Ethereum Overflow Vulnerability Smart Contract Taint Analysis |
DOI | 10.1109/ICSE-Companion.2019.00029 |
URL | 查看来源 |
收录类别 | CPCI-S |
语种 | 英语English |
WOS研究方向 | Computer Science |
WOS类目 | Computer Science, Software Engineering |
WOS记录号 | WOS:000503272600010 |
Scopus入藏号 | 2-s2.0-85071837509 |
引用统计 | |
文献类型 | 会议论文 |
条目标识符 | https://repository.uic.edu.cn/handle/39GCC9TT/13494 |
专题 | 个人在本单位外知识产出 |
作者单位 | 1.School of EECS,Peking University,Beijing,China 2.School of Software,Tsinghua University,Beijing,China 3.National Engineering Research Center for Software Engineering,Peking University,Beijing,China |
推荐引用方式 GB/T 7714 | Gao, Jianbo,Liu, Han,Liu, Chaoet al. EASYFLOW: Keep ethereum away from overflow[C], 2019: 23-26. |
条目包含的文件 | 条目无相关文件。 |
个性服务 |
查看访问统计 |
谷歌学术 |
谷歌学术中相似的文章 |
[Gao, Jianbo]的文章 |
[Liu, Han]的文章 |
[Liu, Chao]的文章 |
百度学术 |
百度学术中相似的文章 |
[Gao, Jianbo]的文章 |
[Liu, Han]的文章 |
[Liu, Chao]的文章 |
必应学术 |
必应学术中相似的文章 |
[Gao, Jianbo]的文章 |
[Liu, Han]的文章 |
[Liu, Chao]的文章 |
相关权益政策 |
暂无数据 |
收藏/分享 |
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论