A comprehensive security framework for Ethereum smart contracts : Integrating static analysis and dynamic testing
Satpal Singh Kushwahasatpal.singh@jaipur.manipal.eduDepartment of Computer Science and EngineeringManipal University JaipurJaipur, Rajasthan, 303007, IndiaView full profile → , *Anubhav SaxenaCorresponding authoranubhav1cse@gmail.comDepartment of IoT and Intelligent SystemsManipal University JaipurJaipur, Rajasthan, 303007, IndiaView full profile →
* Corresponding author · click or hover a name for details
- Received:
- 01 Dec 2025
- Published Online:
- 31 Aug 2026
- Article type:
- Research Article
- Language:
- EN
- Article no.:
- JIOS-2207
- Pages:
- 1–9
Abstract
Ethereum smart contracts, pivotal components of decentralized applications, are increasingly susceptible to various security vulnerabilities. To address these challenges, this paper presents a unified security approach that combines static analysis and dynamic testing techniques. Static analysis, with its capability to scrutinize code without execution, offers a comprehensive detection of vulnerabilities by analyzing the smart contract’s source code. Dynamic testing, on the other hand, involves executing the code in a controlled environment to uncover runtime issues that static analysis might overlook. Our approach leverages the strengths of both techniques to enhance the overall security assessment of Ethereum smart contracts. Static analysis is employed to identify potential security flaws in the codebase, such as reentrancy, integer overflow, and access control issues. Subsequently, dynamic testing, through fuzzing and symbolic execution, validates these findings and detects additional vulnerabilities by observing the contract’s behavior during execution. The integration of these methodologies provides a more robust and comprehensive security analysis framework. We demonstrate the effectiveness of our hybrid approach through highlighting its superiority in identifying and mitigating security threats compared to traditional single-method analyses. This unified security approach not only enhances the detection of vulnerabilities but also contributes to the development of more secure and reliable smart contracts in the Ethereum ecosystem.
Keywords
Subject Classifications
References
[1] N. Grech, M. Kong, A. Jurisevic, L. Brent, B. Scholz, and Y. Smaragdakis, “MadMax: Surviving out-of-gas conditions in Ethereum smart contracts,” Proc. ACM Program. Lang., vol. 2, no. OOPSLA, Art. no. 116, pp. 1–27 (2018), doi: 10.1145/3276486.
[2] S. Akca, A. Rajan, and C. Peng, “Solanalyser: A framework for analysing and testing smart contracts,” in Proc. 26th Asia-Pacific Softw. Eng. Conf. (APSEC), Auckland, New Zealand, pp. 482–489 (Dec. 2019).
[3] T. Chen, Y. Feng, Z. Li, H. Zhou, X. Luo, X. Li, and X. Zhang, “GasChecker: Scalable analysis for discovering gas-inefficient smart contracts,” IEEE Trans. Emerg. Topics Comput., vol. 9, no. 3, pp. 1433–1448 (Jul.–Sep. 2021).
[4] J. Feist, G. Grieco, and A. Groce, “Slither: A static analysis framework for smart contracts,” in Proc. IEEE/ACM 2nd Int. Workshop Emerg. Trends Softw. Eng. Blockchain (WETSEB), Montreal, QC, Canada, pp. 8–15 (May 2019).
[5] S. Kalra, S. Goel, M. Dhawan, and S. Sharma, “ZEUS: Analyzing safety of smart contracts,” in Proc. Netw. Distrib. Syst. Secur. Symp. (NDSS), San Diego, CA, USA, pp. 1–12 (Feb. 2018).
[6] L. Luu, D. H. Chu, H. Olickel, P. Saxena, and A. Hobor, “Making smart contracts smarter,” in Proc. ACM SIGSAC Conf. Comput. Commun. Secur. (CCS), Vienna, Austria, pp. 254–269 (Oct. 2016).
[7] J. Chang, B. Gao, H. Xiao, J. Sun, Y. Cai, and Z. Yang, “sCompile: Critical path identification and analysis for smart contracts,” in Proc. Int. Conf. Formal Eng. Methods (ICFEM), Cham, Switzerland: Springer, pp. 286–304 (Oct. 2019).
[8] R. Norvill, B. B. F. Pontiveros, R. State, and A. Cullen, “Visual emulation for Ethereum’s virtual machine,” in Proc. IEEE/IFIP Netw. Oper. Manage. Symp. (NOMS), Taipei, Taiwan, pp. 1–4 (Apr. 2018).
[9] S. Tikhomirov, E. Voskresenskaya, I. Ivanitskiy, R. Takhaviev, E. Marchenko, and Y. Alexandrov, “SmartCheck: Static analysis of Ethereum smart contracts,” in Proc. 1st Int. Workshop Emerg. Trends Softw. Eng. Blockchain (WETSEB), Gothenburg, Sweden, pp. 9–16 (May 2018).
[10] E. Zhou, S. Hua, B. Pi, J. Sun, Y. Nomura, K. Yamashita, and H. Kurihara, “Security assurance for smart contract,” in Proc. 9th IFIP Int. Conf. New Technol., Mobility Secur. (NTMS), Paris, France, pp. 1–5 (Feb. 2018).
[11] Etherscan, “Etherscan: The Ethereum Blockchain Explorer.” [Online]. Available: https://etherscan.io. [Accessed: Nov. 5, 2022].
[12] P. Tsankov, A. Dan, D. Drachsler-Cohen, A. Gervais, F. Buenzli, and M. Vechev, “Securify: Practical security analysis of smart contracts,” in Proc. ACM SIGSAC Conf. Comput. Commun. Secur. (CCS), Toronto, ON, Canada, pp. 67–82 (Oct. 2018).
[13] Mythril, “Mythril: Security analysis tool for EVM bytecode,” GitHub repository. [Online]. Available: https://github.com/ConsenSysDiligence/mythril. [Accessed: Jun. 12, 2024].
[14] V. P. Singh, S. S. Biswas, B. Alankar, and S. Tanweer, “Cryptographic modeling and discrete structures for intrusion detection in Ethereum smart contracts,” J. Discrete Math. Sci. Cryptogr., vol. 28, no. 8, pp. 3039–3048 (2025).
[15] A. Dadhich, B. Keswani, and D. Goyal, “Comparative analysis of a novel smart contract-based hybrid access control model for blockchain-enabled secure IoT home automation systems,” J. Discrete Math. Sci. Cryptogr., vol. 28, no. 7, pp. 2875–2888 (2025).
[16] V. Ramachandran, H. M. A. Ghanimi, B. Marapelli, N. Kaur, M. R. Laxmi, R. K. Bommisetti, S. Sengan, and P. Dadheech, “An enterprise blockchain model: A reliable cryptography-based cyber-physical systems for securing user data,” J. Discrete Math. Sci. Cryptogr., vol. 28, no. 5-B, pp. 2103–2114 (2025).




