Synergy Model of Threats in Defi Smart Contracts
Abstract
Smart contracts are key elements of decentralized financial protocols, but security incidents are usually caused not by single vulnerabilities, but by combined scenarios in which several threats interact and reinforce each other. The article proposes a synergistic graph model of threats in DeFi smart contracts, which formalizes the set of threats, their impact on information security properties (confidentiality, integrity, availability, authenticity, accountability, and auditability), and reflects the projection of compromised properties onto security domains (CS/IS/SI). The proposed approach differs in that it introduces synergistic links between threats as a separate type of edges in the graph, which allows reproducing characteristic trajectories of combined attacks and explaining the mechanisms of their implementation. In particular, a typical chain of economic attacks is shown, in which an attacker uses an instant unsecured loan to manipulate the market price, which leads to a distortion of the oracle's price data and, as a result, creates conditions for exploiting logical defects in the smart contract or abusing liquidation mechanisms. The proposed model can be used as a methodological basis for risk analysis, prioritization of smart contract audits, and planning of protective measures in DeFi ecosystems.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.