Papers1 provider Ā· 1 record
January 4, 2022Ā· 2022 14th International Conference on COMmunication Systems & NETworkS (COMSNETS)
conference-paper

Smart Contract Fuzzing for Enterprises: The Language Agnostic Way

Authors:Siddhasagar PaniHarshita Vani NallagondaSaumya PrakashR. VigneswaranRaveendra Kumar MedicherlaM A Rajan

Abstract

Blockchain based applications backed by smart contracts are becoming increasingly popular in various domains. Smart contracts are vulnerable to attacks due to bugs in them and such attacks resulted in huge monetary losses, disruption in operation and so on in the past. Fuzz testing is one of the prominent methods used for identifying bugs in blockchain smart contracts. Multiple fuzzers are used for fuzzing smart contracts written in different programming languages. However, maintenance of multiple fuzzers become prohibitively difficult in an enterprise DevOps setup, in terms of skills, time, and efforts required in patching and keeping them up to date. Hence, we propose a novel vulnerability detection framework which uses a single fuzzer to fuzz smart contracts written in different programming languages, using LLVM IR. In this paper, we validated the proposed framework by testing Hyperledger Fabric smart contracts using fuzzing tools AFL++ and Honggfuzz and presented the results.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.