Papers1 provider Ā· 1 record
September 14, 2024Ā· Proceedings of the 2024 8th International Conference on Big Data and Internet of Things
conference-paper

An Empirical Study of Integer Overflow Detection and False Positive Analysis in Smart Contracts

Abstract

Smart contracts are programs running on the blockchain, and once deployed, they cannot be modified. Integer overflow and underflow, have always been one of the most common vulnerabilities in Ethereum, and to this day, integer overflow and underflow incidents still occur, resulting in financial losses or functional failures. Currently, many vulnerability detection tools can detect Integer overflow/underflow. However, these tools often produce false positives. In order to better understand why existing vulnerability detection tools generate false positive reports and to guide us in improving the accuracy of vulnerability detection tools, it is necessary to conduct empirical research on the causes of false positives in arithmetic bugs in smart contracts. This work empirically studies the detection results of well-known vulnerability detection tools such as Mythril and Osiris, and analyzes the causes for false positive reports. We randomly selected 1000 smart contracts with arithmetic bugs from the SmartBugs Wild Dataset, along with 2343 corresponding vulnerability detection reports, as the subjects of this study. After manual screening, we obtained 449 false positive reports. After further manual analysis, we identified 8 types of false positive causes, covering the majority of false positive reports, and provided statistics on the distribution of causes. We believe that our findings play a positive role in reducing the false positive rate and improving the accuracy of future vulnerability detection tools.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.