节点文献

以太坊智能合约安全漏洞分析及对策

Ethereum Smart Contract Security Vulnerability Scenario Analysis

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 邱欣欣; 马兆丰; 徐明昆;

【Author】 QIU Xinxin;Ma Zhaofeng;Xu Mingkun;Institute of network technology, Beijing University of Posts and Telecommunications;School of Cyberspace Security, Beijing University of Posts and Telecommunications;

【机构】 北京邮电大学网络技术研究院; 北京邮电大学网络空间安全学院;

【摘要】 智能合约是一种旨在以信息化方式传播、验证和执行合同的计算机协议。由于智能合约自带金融属性,执行过程中若出现漏洞会给用户及投资者带来较大困扰,因此如何编写安全可靠的智能合约至关重要。针对以太坊环境,对智能合约的漏洞进行了相关的研究和分析,提出了几种可能导致漏洞的常见编程陷阱,包括重入漏洞、整数溢出漏洞、拒绝服务漏洞、未检查call返回值以及短地址/参数攻击漏洞等。并有针对性地对这几种陷阱进行详细的原理分析和场景复现,并给出了相应的规避和解决的方法,提出了在安全模式下智能合约安全问题的解决方案。

【Abstract】 Intelligent contract is a computer protocol that aims to propagate, verify and execute contracts through information technology. Since intelligent contracts have their own financial attributes, if there are loopholes in the execution process, users and investors will be greatly troubled, so how to write safe and reliable intelligent contracts is very important.Aiming at the environment of ETF, the vulnerabilities of intelligent contract are studied and analyzed. Several common programming traps which may lead to vulnerabilities are proposed, including re-entry vul-nerabilities, integer overflow vulnerabilities, denial of service vulnerabilities, unchecked call return values and short address/parameter attack vulnerabilities.In addition, the detailed principle analysis and scene reproduction of these traps are carried out, and the corresponding methods of avoiding and resolving them are given. A solution to the security problem of intelligent contract under the security mode is put forward.

  • 【文献出处】 信息安全与通信保密 ,Information Security and Communications Privacy , 编辑部邮箱 ,2019年02期
  • 【分类号】TP311.13;TP309
  • 【被引频次】29
  • 【下载频次】878
节点文献中: