TARU PUBLICATIONS
Journal of Discrete Mathematical Sciences and Cryptography cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0065·ISSN (Print): 0972-0529

Monthly Journal: Publishes theoretical and applied research in all areas of Discrete Mathematical Sciences, Cryptography, Combinatorics, Elliptic Curves and Information Security.

Issues up to 2022 co-published with and available at:Taylor & Francis Online
submissions@tarupublications.com
Open Access Research Article

An efficient approach to secure smart contract of Ethereum blockchain using hybrid security analysis approach

, * ,

* Corresponding author · click or hover a name for details

pp. 1499–1517Vol. 26Issue 5August 2023DOI: 10.47974/JDMSC-1815 Crossmark XML
Published Online:
09 Sep 2023
Article type:
Research Article
Language:
EN
Article no.:
JDMSC-1815
Pages:
1499–1517

Abstract

The technology behind blockchain is quickly becoming one of the most crucial innovations in recent years. The Smart contracts are digital agreements, made in between two untrusted parties. Smart contracts are self-executable small piece of code that gets executed due to some predefined triggering conditions. Smart contracts store cryptocurrencies as their balances and deal in cryptocurrencies on network transactions. Because of this, smart contracts are constantly open to the possibility of being attacked. A single security vulnerability can make the smart contract very much insecure. The immutability property of the blockchain ensures that, once a smart contract has been placed on the blockchain, cannot be modified in any way. So, the smart contract must be analyzed for any kind of security vulnerability before its deployment on the blockchain. Existing analysis approaches detect vulnerabilities with high false positive rates. Our proposed approach analyses the smart contracts using a hybrid combination of pattern matching and symbolic execution, which produces results with a low false positive rate. We have performed a comparative analysis of our proposed approach to prove its efficiency with the existing research approaches on a data set of 453 smart contracts with tagged vulnerabilities.

Keywords

Subject Classifications

68M25 Computer security

References

[1] Sefa Akca, Ajitha Rajan, and Chao Peng. SolAnalyser: A Framework for Analysing and Testing Smart Contracts. In 2019 26th Asia-Pacific Software Engineering Conference (APSEC), IEEE, 482-489 (2019). DOI:https://doi.org/10.1109/APSEC48747.2019.00071.
[2] A. Averin and O. Averina. Review of Blockchain Technology Vulnerabilities and Blockchain-System Attacks. In 2019 International Multi-Conference on Industrial Engineering and Modern Technologies (FarEastCon), IEEE, 1-6 (2019). DOI:https://doi.org/10.1109/FarEastCon.2019.8934243.
[3] Jialiang Chang, Bo Gao, Hao Xiao, Jun Sun, Yan Cai, and Zijiang Yang. sCompile: Critical Path Identification and Analysis for Smart Contracts. 286-304 (2019). DOI:https://doi.org/10.1007/978-3-030-32409-4_18.
[4] Ting Chen, Youzheng Feng, Zihao Li, Hao Zhou, Xiaopu Luo, Xiaoqi Li, Xiuzhuo Xiao, Jiachi Chen, and Xiaosong Zhang. GasChecker: Scalable Analysis for Discovering Gas-Inefficient Smart Contracts. IEEE Trans Emerg Top Comput 9, 3 (July 2021), 1433-1448 (2021). DOI:https://doi.org/10.1109/TETC.2020.2979019.
[5] Josselin Feist, Gustavo Grieco, and Alex Groce. Slither: A Static Analysis Framework for Smart Contracts. In 2019 IEEE/ACM 2nd International Workshop on Emerging Trends in Software Engineering for Blockchain (WETSEB), IEEE, 8-15 (2019). DOI:https://doi.org/10.1109/WETSEB.2019.00008.
[6] Baraq Ghaleb, Ahmed Al-Dubai, Elias Ekonomou, Mamoun Qasem, Imed Romdhani, and Lewis Mackenzie. Addressing the DAO Insider Attack in RPL’s Internet of Things Networks. IEEE Communications Letters 23, 1 (January 2019), 68-71 (2019). DOI:https://doi.org/10.1109/LCOMM.2018.2878151.
[7] Neville Grech, Michael Kong, Anton Jurisevic, Lexi Brent, Bernhard Scholz, and Yannis Smaragdakis. MadMax: surviving out-of-gas conditions in Ethereum smart contracts. Proceedings of the ACM on Programming Languages 2, OOPSLA (October 2018), 1-27 (2018). DOI:https://doi.org/10.1145/3276486.
[8] Sukrit Kalra, Seep Goel, Mohan Dhawan, and Subodh Sharma. ZEUS: Analyzing Safety of Smart Contracts. In Proceedings 2018 Network and Distributed System Security Symposium, Internet Society, Reston, VA. (2018). DOI:https://doi.org/10.14722/ndss.2018.23082.
[9] Gupta S, Bairwa AK, Kushwaha SS, Joshi S. Decentralized Identity Management System using the amalgamation of Blockchain Technology. In2023 3rd International Conference on Intelligent Communication and Computational Techniques (ICCT), pp. 1-6 (2023 Jan 19). IEEE.
[10] Loi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena, and Aquinas Hobor. Making Smart Contracts Smarter. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, ACM, New York, NY, USA, 254-269 (2016). DOI:https://doi.org/10.1145/2976749.2978309.
[11] Robert Norvill, Beltran Borja Fiz Pontiveros, Radu State, and Andrea Cullen. Visual emulation for Ethereum’s virtual machine. In NOMS 2018 - 2018 IEEE/IFIP Network Operations and Management Symposium, IEEE, 1-4 (2018). DOI:https://doi.org/10.1109/NOMS.2018.8406332.
[12] Sergei Tikhomirov, Ekaterina Voskresenskaya, Ivan Ivanitskiy, Ramil Takhaviev, Evgeny Marchenko, and Yaroslav Alexandrov. 2018. SmartCheck. In Proceedings of the 1st International Workshop on Emerging Trends in Software Engineering for Blockchain, ACM, New York, NY, USA, 9-16. DOI:https://doi.org/10.1145/3194113.3194115.
[13] Petar Tsankov, Andrei Dan, Dana Drachsler-Cohen, Arthur Gervais, Florian Bünzli, and Martin Vechev. Securify. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, ACM, New York, NY, USA, 67-82 (2018). DOI:https://doi.org/10.1145/3243734.3243780.
[14] Ence Zhou, Song Hua, Bingfeng Pi, Jun Sun, Yoshihide Nomura, Kazuhiro Yamashita, and Hidetoshi Kurihara. Security Assurance for Smart Contract. In 2018 9th IFIP International Conference on New Technologies, Mobility and Security (NTMS), IEEE, 1-5 (2018). DOI:https://doi.org/10.1109/NTMS.2018.8328743.
[15] Regex Generator. Retrieved September 5, 2022, from https://regex-generator.olafneumann.org/.
[16] Pythex. Retrieved November 5, 2022, from https://pythex.org/.
[17] SWC Registry: Smart Contract Weakness Classification and Test Cases. Retrieved October 5, 2022, from https://swcregistry.io/.
[18] SolidiFI-Benchmark. Retrieved October 5, 2022, from https://github.com/smartbugs/SolidiFI-benchmark.
[19] SB Curated: A Curated Dataset of Vulnerable Solidity Smart Contracts n.d. Retrieved September 5, 2022, from https://github.com/smartbugs/smartbugs/blob/master/dataset.
[20] SmartBugs Wild Dataset n.d. Retrieved October 5, 2022, from https://github.com/smartbugs/smartbugs-wild. 
[21] Etherscan: The Ethereum Blockchain Explorer n.d. Retrieved November 5, 2022, from https://etherscan.io.
[22] Mythril. Retrieved September 5, 2022, from https://github.com/ConsenSys/mythril.
[23] Amit Kumar Gupta, Pushpa Gothwal, Dinesh Goyal & Carlos M. Travieso-Gonzalez. IoT-Galvanized pandemic special E-Toilet for generation of sanitized environment, Journal of Discrete Mathematical Sciences and Cryptography (2022), DOI: 10.1080/09720529.2022.2068607.
[24] Amit Kumar Gupta, Vijander Singh, Priya Mathur & Carlos M. Travieso-Gonzalez. Prediction of COVID-19 pandemic measuring criteria using support vector machine, prophet and linear regression models in Indian scenario, Journal of Interdisciplinary Mathematics (2020), DOI:https://doi.org/10.1080/09720502.2020.1833458.
[25] Anil Kumar, Ravinder Kumar, Sartaj Singh Sodhi. A novel privacy preserving blockchain based secure storage framework for electronic health records. Journal of Information and Optimization Sciences 43:3, pages 549-570 (2022).

Views: 274Downloads: 9Citations: 3