节点文献

目标驱动的智能合约漏洞检测机制

Target-driven Smart Contract Vulnerability Detection Mechanism

【作者】 李铭;

【导师】 代炜琦;

【作者基本信息】 华中科技大学 , 网络空间安全, 2023, 硕士

【摘要】 智能合约作为运行在区块链上的代码随着Web 3.0的到来在各大关键领域有着广泛应用,但频发的安全事故和多样的安全威胁使得智能合约安全性问题研究尤为关键。现有的合约安全审计工作主要集中在完整合约代码的漏洞检测,然而在合约定向检测和漏洞验证场景中,缺少对合约代码特定位置反复验证的审计工具。同时,现有安全审计工具在检测效率和准确率方面还有一定的提升空间。针对上述问题,提出了目标驱动的智能合约模糊测试机制(Target Guided Fuzzy Testing Mechanism for Smart Contracts,TGfuzz),实现利用合约代码和目标行信息就可以对合约目标位置进行定向安全验证。首先在代码静态分析模块,利用抽象语法树和代码逆向控制流分析技术对待测合约代码实现了函数信息和目标行约束路径提取,并针对漏洞合约代码特征建模生成具体的漏洞特征标识。其次基于静态分析报告信息,在智能合约模糊器中实现待测合约的函数变量匹配和约束条件下的目标行变量定向求解和生成,同时根据合约运行环境特征调整状态函数和全局变量执行顺序实现可以到达目标点位的交易序列。最后在漏洞合约代码特征反馈和约束信息分解的基础上,设计了种子文件反馈和变量值距离计算方案,实现了基于代码漏洞特征的种子变异策略和基于距离的种子变异策略,提升目标行变量生成效率和漏洞触发几率。TGfuzz在传统合约模糊器的基础上实现,模糊器提供了合约部署的私有链和9种漏洞类型的验证模型。在此基础上配置相应实验环境,并从真实世界的三个数据集中获取真实合约进行功能和性能测试。分别对TGfuzz在不同数据集中进行了功能对比测试、代码覆盖率与交易效率的性能测试以及种子变异策略的模块化测试。测试结果表明TGfuzz具有更优秀的检测性能,在原有基础上提升了7.8%的准确率,并能够在37.8%的低覆盖率和489.6tx/s的交易效率的低成本条件下出色完成安全审计工作。

【Abstract】 Smart contracts,as code running on blockchain,have been widely used in various key fields with the arrival of Web 3.0.However,the frequent security incidents and diverse security threats make the research on the security issues of smart contracts particularly crucial.The existing contract security audit work mainly focuses on vulnerability detection of complete contract code.However,in contract directed detection and vulnerability verification scenarios,there is a lack of audit tools that repeatedly verify specific locations of contract code.At the same time,there is still room for improvement in the detection efficiency and accuracy of existing security audit tools.To address the above issues,a Target Guided Fuzz Testing Mechanism for Smart Contracts(TGfuzz)is proposed,which enables targeted security verification of contract target locations using contract code and target line information.First,in the code static analysis module,the abstract syntax tree and code reverse Control flow analysis technology are used to extract the function information and target line constraint path of the contract code to be tested,and specific vulnerability feature identification is generated for the vulnerability contract code feature modeling.Secondly,based on static analysis report information,the function variable matching of the tested contract and the targeted solution and generation of target row variables under constraint conditions are achieved in the smart contract fuzzier.At the same time,the execution order of the state function and global variables is adjusted according to the characteristics of the contract operating environment to achieve a transaction sequence that can reach the target point.Finally,based on the feedback of vulnerability contract code features and the decomposition of constraint information,a seed file feedback and variable value distance calculation scheme were designed.The seed mutation strategy based on code vulnerability features and the seed mutation strategy based on distance were implemented,improving the efficiency of target line variable generation and vulnerability triggering probability.TGfuzz is implemented on the basis of traditional contract fuzziers,which provide private chains for contract deployment and validation models for 9 types of vulnerabilities.On this basis,configure the corresponding experimental environment and obtain real contracts from three datasets in the real world for functional and performance testing.The function comparison test,the performance test of code coverage and transaction efficiency,and the modularization test of seed mutation strategy of TGfuzz in different data sets are conducted respectively.The test results show that TGfuzz has better detection performance,improving the accuracy by 7.8% on the original basis,and can excellently complete security audit work under low-cost conditions of low coverage of 37.8% and transaction efficiency of 489.6tx/s.

  • 【分类号】TP311.13;TP309
节点文献中: