节点文献

区块链智能合约威胁检测与防护方法研究

Research on Threat Detection and Protection Methods of Blockchain Smart Contracts

【作者】 杨柳;

【导师】 段莉;

【作者基本信息】 北京交通大学 , 网络与信息安全(专业学位), 2024, 硕士

【摘要】 以太坊是支持智能合约的主流区块链平台,为开发者提供了构建去中心化应用和创新解决方案的开放环境。智能合约作为运行在以太坊上的程序,在去中心化网络中执行的同时可操纵数字资产。伴随着智能合约数量的增加,频繁出现的安全漏洞问题导致区块链社区遭受重大损失,给用户带来了信任危机。因此,如何高效保障以太坊智能合约安全成为亟待解决的问题。为了提高区块链系统安全性,本文针对智能合约的已知漏洞检测、未知威胁探索以及跨链风险防护展开研究,系统化地为智能合约提供安全防护措施,具体来说包括以下三个方面。针对智能合约中安全漏洞频发的问题,提出了一种融合操作码和源码特征的智能合约漏洞检测方法,规避了合约漏洞带来的潜在风险,可以实现对重入、时间戳、交易顺序依赖漏洞的高效检测,降低智能合约的链上风险。该方法分别从智能合约操作码和源码中提取2-gram特征以及token特征,进行不同层面的智能合约特征表示。实验表明,与单级特征相比,融合特征可以显著提高智能合约漏洞检测能力,对三种漏洞的检测准确率分别高达98%、98%和94%。每个合约的平均检测时间为0.99秒,表明该方法适用于智能合约漏洞的自动批量检测。针对智能合约检测模型对于未知漏洞泛化能力差的问题,提出了一种基于领域自适应的智能合约未知威胁检测方法,实现了目标分类器对未知漏洞的检测,降低未知威胁带来的潜在风险。该方法主要包括变分自编码器进行数据生成以及分域网络模型的特征训练和迁移过程。通过领域分类训练、共享特征的目标分类器训练以及特征重构任务,实现分类器在目标数据集上的迁移。在对智能合约进行特征迁移之后,模型对目标域漏洞的检测能力明显提升,不同数据集下准确率提高的范围为8.7%-24.9%,通过正向迁移的结果验证了对未知威胁检测的有效性。针对跨链系统中的智能合约风险扩散问题,提出了以太坊-联盟链异构跨链系统的攻击检测与防护方法,从合约检测和代码执行两方面进行防护分析,降低以太坊端智能合约威胁给跨链系统带来的辐射影响。该方法从跨链攻击产生原理、临界条件以及应用场景进行分析,并在跨链系统上实现了漏洞的攻击及其对应的防护算法。通过对研究点一应用拓展实现了对四种跨链攻击的检测,从检测角度进行防护以降低合约的链上风险,提高整个跨链系统的安全性和可靠性。

【Abstract】 Ethereum is a mainstream blockchain platform that supports smart contracts,providing developers with an open environment to build decentralized applications and innovative solutions.Smart contracts,as programs running on Ethereum,are executed in a decentralized network and can manipulate digital assets.With the increase in the number of smart contracts,frequent security vulnerabilities have caused heavy losses to the blockchain community and brought a crisis of trust to users.Therefore,how to effectively protect the security of Ethereum smart contracts has become an urgent problem.In order to ensure the security of the blockchain system,we conduct research on the known vulnerability detection,unknown threat exploration and cross-chain risk protection of smart contracts,and systematically provide security protection measures for smart contracts.It specifically includes the following three aspects.Aiming at the problem of frequent security vulnerabilities in smart contracts,a new smart contract anomaly detection method by fusing opcode and source code features is proposed.It avoids potential risks caused by contract vulnerabilities,and can realize efficient detection of reentrancy,timestamp,and transaction order dependence vulnerabilities,reducing on-chain risks of smart contracts.In this method,2-gram features and token features are extracted from the opcode and source code of smart contracts respectively,which represents the features of the smart contract at different levels.Experiments show that compared with single-level features,fused features can significantly improve smart contract vulnerability detection capabilities.The detection accuracy is as high as 98%,98% and 94% for the three vulnerabilities,respectively.The average detection time is 0.99 second per contract,indicating the proposed method is suitable for automatic batch detection of vulnerabilities in smart contracts.Aiming at the problem of poor generalization ability of smart contract detection models to unknown vulnerabilities,a domain-adaptive smart contract unknown threat detection method is proposed.It realizes the detection of unknown vulnerabilities by the target classifier and reduces the potential risks caused by unknown threats.This method mainly includes data generation by Variational Auto-Encoder and feature training and migration process of Domain Separation Networks model.Through domain classification training,target classifier training with shared features and feature reconstruction tasks,the migration of the classifier on the target dataset is realized.After the feature transfer of smart contracts,the model’s ability to detect vulnerabilities in the target domain has been significantly improved,and the accuracy of the improvement ranges from 8.7% to 24.9% under different datasets.The results of forward migration demonstrate the effectiveness of unknown threat detection.Aiming at the risk diffusion problem of smart contracts in cross-chain systems,the attack detection and protection methods of the Ethereum-Fabric heterogeneous cross-chain system is proposed.Protection analysis is carried out from both contract detection and code execution to reduce the radiation impact of the Ethereum smart contract threat on the cross-chain system.This method analyzes the principles,critical conditions and application scenarios of cross-chain attacks,and implements vulnerability attacks and corresponding protection algorithms on the cross-chain system.By expanding the application of research point one,the detection of four cross-chain attacks is realized.It protects the contract from the perspective of detection to reduce the on-chain risk and improve the security and reliability of the entire cross-chain system.

  • 【分类号】TP311.13;TP309
节点文献中: