SmartScan: An approach to detect Denial of Service Vulnerability in\n Ethereum Smart Contracts
Abstract
Blockchain technology (BT) Ethereum Smart Contracts allows programmable\ntransactions that involve the transfer of monetary assets among peers on a BT\nnetwork independent of a central authorizing agency. Ethereum Smart Contracts\nare programs that are deployed as decentralized applications, having the\nbuilding blocks of the blockchain consensus protocol. This technology enables\nconsumers to make agreements in a transparent and conflict-free environment.\nHowever, the security vulnerabilities within these smart contracts are a\npotential threat to the applications and their consumers and have shown in the\npast to cause huge financial losses. In this paper, we propose a framework that\ncombines static and dynamic analysis to detect Denial of Service (DoS)\nvulnerability due to an unexpected revert in Ethereum Smart Contracts. Our\nframework, SmartScan, statically scans smart contracts under test (SCUTs) to\nidentify patterns that are potentially vulnerable in these SCUTs and then uses\ndynamic analysis to precisely confirm their exploitability of the\nDoS-Unexpected Revert vulnerability, thus achieving increased performance and\nmore precise results. We evaluated SmartScan on a set of 500 smart contracts\ncollected from the Etherscan. Our approach shows an improvement in precision\nand recall when compared to available state-of-the-art techniques.\n
Community
0 commentsNo discussion yet
Be the first to share a question or observation.