Computer networks and internet services are increasingly threatened by attacks like Distributed Denial-of-Service (DDoS). DDoS attack mitigation techniques now in use are ineffective due to a lack of resources and a lack of adaptability. Using blockchains like Ethereum, DDoS attacks can be thwarted in innovative ways. With smart contracts, it is possible to track down the IP addresses of attackers without additional hardware. This study examines blockchain-based solutions to combat DDoS attacks for feasibility, effectiveness, as well as cost and performance. The cost model delves into economic aspects like gas, gas price, and Ether value. In it, the evaluation of various smart contracts for the signalization of DDoS attacks is documented and compared to assess three system variants, analyzing gas costs, deployment, speed, and accuracy. It also details Ethereum's ecosystem and how that affects smart contract design and it also acknowledges scalability challenges and suggests outsourcing data for a more scalable solution, advocating for specialized blockchains for DDoS signaling applications. The analysis provides insights into the gas costs associated with different variants, considering various scenarios and highlighting the trade-offs and efficiencies of each approach.
Blockchain is an innovative technology that gives built-in security to any software or application. There is a wide range of applications for blockchain, from risk management to financial services, crypto-currencies and the Internet of Things (IoT). This innovation is based on transparency, immutability, security, efficiency and decentralization. It is a trending topic since cryptocurrencies are a hot topic in the market. Blockchain is a combination of mathematics, cryptography, algorithms and models. In this paper, we present a general overview of the security aspects of blockchain technology.
The ability of blockchain technology to improve security and transparency across a range of industries has receivedA great deal of attention has been garnered lately in correcting the sentence.. In the domain of intrusion detection, where the identification and mitigation of cyber threats are paramount, blockchain has emerged as a promising solution. This abstract examines how blockchain is used in intrusion detection systems and emphasizes its advantages. Blockchain technology improves the security and integrity of intrusion detection systems by using a decentralized and immutable ledger. It provides an immutable audit trail, distributed consensus, and increased resilience to attacks. Moreover, blockchain fosters trust, transparency, and collaboration among stakeholders, enabling faster threat detection and response. This research can explore novel approaches to integrating blockchain into intrusion detection systems, providing stronger protection against cyber threats.Immutable Audit Trail: In the context of intrusion detection, the capacity of blockchain to produce an unalterable and transparent audit trail is of enormous value. Research in this area can focus on developing techniques to leverage the blockchain's audit trail for effective incident response, forensic investigations, and attribution of cyberattacks. We will use theweighted product model in this study, which is a research approach that gives weights to various factors and combines them to make conclusions based on their relative relevance in a weighted way. Taken as alternative is“IDS1, IDS2, IDS3, IDS4, IDS5, IDS6, IDS7, and IDS8”.Detection Quality, Performance, Stability, User Interface, Profile update, ConvenienceThe By this we can see that IDS4 has 1 RANK and IDS5 has the 8th RANK.In conclusion, blockchain technology holds great potential in the intrusion detection domain. Its decentralized and immutable nature can enhance the security and reliability of intrusion detection systems by providing transparent and tamper-proof logs of network activity. Blockchain-based solutions can improve threat detection, facilitate secure information sharing among entities, and enhance the overall resilience of intrusion detection systems. As the technology continues to evolve, further research and development in integrating blockchain with intrusion detection will unlock new possibilities for combating cyber threats.
Decentralized Finance (DeFi) is a prominent application of smart contracts, representing a novel financial paradigm in contrast to centralized finance. While DeFi applications are rapidly emerging on mainstream blockchain platforms, their quality varies greatly, presenting numerous challenges, particularly in terms of their governance mechanisms. In this paper, we present a comprehensive study of governance issues in DeFi applications. Initially, we collected 3,165 academic papers and numerous industry reports. After thorough screening, we selected 44 academic papers and 11 industry reports for detailed analysis. Drawing upon insights from industry reports and academic research articles, we develop a taxonomy to categorize these governance issues. We collect and build a dataset of 4,446 audit reports from seventeen Web3 security companies, categorizing their governance issues according to our constructed taxonomy. We conducted a thorough analysis of governance issues and identified vulnerabilities in the governance design and implementation, e.g., voting sybil attack and proposal front-running. Our statistical analysis indicates that a significant portion (35.48%) of governance-related issues is classified as severe. Within these, ownership-related problems constitute the largest share (65.38%). Despite DeFi governance being essential for the long-term success of DeFi projects, our data shows that both auditors and development teams have not fully grasped its significance. Based on audit reports, we also analyzed common vulnerabilities and issues in the governance domain. Our research identifies two primary categories of DeFi governance issues: technology-centric and human-centric. Technology-centric issues can be addressed through technology updates and iterations, whereas human-centric issues are influenced not only by the development team's technical skills but also by their understanding of DeFi governance. Data analysis reveals that design and implementation issues are frequently overlooked; although not directly associated with vulnerabilities, these issues can impact the equitable distribution of project benefits. Furthermore, our analysis of 104 projects’ tokenomics configurations, including 15 collected from DeFi platforms, uncovered 27 inconsistent configurations, with only two projects exhibiting no issues. This suggests that such issues are relatively common. We therefore advise project teams to ensure consistency between their tokenomics design and the actual code. Our study culminates in providing several key practical implications for various DeFi stakeholders, including developers, users, researchers, and regulators, aiming to deepen the understanding of DeFi governance issues and contribute to the robust growth of DeFi systems.
Smart contract vulnerability detection is an important security practice aimed at identifying and fixing potential vulnerabilities. This detection technique involves using static and dynamic analysis methods to inspect and test contract code, in order to identify code patterns and logical errors that may lead to security vulnerabilities. However, summarizing previous research reveals limitations in terms of scalability and generalizability, which can result in higher rates of false positives and false negatives in detection results. Therefore, we propose a novel smart contract detection framework called TSCSG: Two-Stage Smart Contract Vulnerability Detection Combining Semantic Features and Graph Features. In the graph extraction stage, TSCSG utilizes the data flow graph and control flow graph of smart contracts to extract the required contract graph. After processing the graph data, TSCSG employs our proposed RTMP network to extract smart contract graph features. In the semantic extraction stage of contract vulnerabilities, TSCSG utilizes smart contract data propagation chains to extract semantic features of smart contract vulnerabilities, which are then combined with the graph features to obtain the final detection results. Our large-scale empirical study on the EtherScan dataset demonstrates that TSCSG achieves satisfactory results in detecting reentrancy and timestamp vulnerabilities, outperforming 9 state-of-the-art vulnerability detection methods.
The main goal of this research is to examine how well blockchain technology functions to prevent financial fraud. The purpose of this study is to determine whether blockchain technology can effectively combat financial fraud, a type of white-collar crime that is dramatically increasing throughout the world. With this concern, this project aimed to identify the effectiveness of blockchain technology in preventing financial fraud among public listed companies in Malaysia. Since there are only a few studies have analysed various factors that influence financial fraud, this study intends to achieve the aim of the study which is to figure out the level of influence that the factors identified as independent variables on the dependent variable, financial fraud. The primary method is used by the researcher to acquire the data. The three factors examined in this study—immutability, consensus method, and distributed ledger technology—all have a major impact on financial fraud. The data was acquired from staff of public listed companies in Malaysia. Statistical Package of the Social Sciences (SPSS) is used to analyze the correlations between the three factors and all of the factors were shown to have a substantial link with financial fraud in Malaysian public listed companies. This study's findings suggest that individuals and businesses should be aware of the threats of financial theft that exist all around them and the value of having key tools that are resistant to phishing scams. The investigation raises awareness of the application of blockchain technology among customers as well as companies to prevent financial fraud.
Raghu Raman, Vinith Kumar Nair, Prema Nedungadi, Indrakshi Ray · 5 authors
The Darkweb, part of the deep web, can be accessed only through specialized computer software and used for illegal activities such as cybercrime, drug trafficking, and exploitation. Technological advancements like Tor, bitcoin, and cryptocurrencies allow criminals to carry out these activities anonymously, leading to increased use of the Darkweb. At the same time, computers have become an integral part of our daily lives, shaping our behavior, and influencing how we interact with each other and the world. This work carries out the bibliometric study on the research conducted on Darkweb over the last decade. The findings illustrate that most research on Darkweb can be clustered into four areas based on keyword co-occurrence analysis: (i) network security, malware, and cyber-attacks, (ii) cybercrime, data privacy, and cryptography, (iii) machine learning, social media, and artificial intelligence, and (iv) drug trafficking, cryptomarket. National Science Foundation from the United States is the top funder. Darkweb activities interfere with the Sustainable Development Goals (SDG) laid forth by the United Nations to promote peace and sustainability for current and future generations. SDG 16 (Peace, Justice, and Strong Institutions) has the highest number of publications and citations but has an inverse relationship with Darkweb, as the latter undermines the former. This study highlights the need for further research in bitcoin, blockchain, IoT, NLP, cryptocurrencies, phishing and cybercrime, botnets and malware, digital forensics, and electronic crime countermeasures about the Darkweb. The study further elucidates the multi-dimensional nature of the Darkweb, emphasizing the intricate relationship between technology, psychology, and geopolitics. This comprehensive understanding serves as a cornerstone for evolving effective countermeasures and calls for an interdisciplinary research approach. The study also delves into the psychological motivations driving individuals towards illegal activities on the Darkweb, highlighting the urgency for targeted interventions to promote pro-social online behavior.
Nov 1, 2023·2023 International Conference on Research Methodologies in Knowledge Management, Artificial Intelligence and Telecommunication Engineering (RMKMATE)
Numerous cutting-edge commercial possibilities have emerged as a result of the widespread use of cryptocurrencies, but it has also drawn a growing number of fraudulent individuals looking to commit fraud. This paper proposes an extensive strategy that makes use of machine learning(ML) techniques to meet the urgent demand for effective fraud detection tools inside the cryptocurrency industry. This paper presents a comprehensive investigation of several fraudulent practices that are common in the virtual currencies ecosystem. The next step has been to investigate several of ML approaches, including Adaptive Boosting(AdaBoost), Random Forest(RF) and Extreme Gradient Boosting(XGBoost), that are designed to spot unusual patterns suggestive of fraudulent behaviour. A crypto fraud detection dataset of fraud instances and real-world cryptocurrency transactions has been utilised in trials to gauge the effectiveness of the suggested approach. To gauge the accuracy and resilience of the models, performance metrics including precision, recall, and F1-score are used. In order to establish which algorithms are most suited for real-time fraud detection, multiple approaches have also been examined for efficiency and scalability. The results show how ML techniques can be used to improve the security of cryptocurrency networks. The XGBoost approach has the best accuracy, at 98%, followed by AdaBoost and RF, at 67% and 90% respectively. The suggested models show encouraging results in spotting fraudulent behaviour, with substantial successes in spotting previously unidentified attack patterns.
Helen Milner, Redowan Mahmud, Mahbuba Afrin, Sashowta G. Siddhartha · 6 authors
The popularity of Ethereum as a platform for Stablecoin transactions (for example, AUDN) continues to rise. It is therefore paramount that the integrity and security of transactions within these decentralized systems are guaranteed. The intricate network of interactions occurring during the exchange of cryptocurrencies made the task of identifying specific transactions as fraudulent difficult because fraudulent behaviour can be concealed within legitimate smart contract operations. Leveraging the inherent structure and interconnectedness of Ethereum transactions, this paper proposes a comprehensive framework to address issues such as Frontrunning within the cryptocurrency ecosystem. Constructing a knowledge graph representation of fraudulent Ethereum blockchain transactions, the proposed solution captures the relationships between addresses, transactions, and smart contracts and generates BotVictim recommendations based on Victim Receiver similarity scores exceeding 85%. These results are generated by excluding temporal transactions, a unique approach when examining the Ethereum network. Thus, our approach enables early detection and prevention of fraudulent activities, potentially safeguarding the interests of cryptocurrency users and mitigating potential financial losses. To evaluate the effectiveness of the proposed framework, its performance is compared against traditional fraud detection methods. The proposed solution demonstrates superiority in terms of accuracy and efficiency.
As blockchain technology continues to advance, the secure deployment of smart contracts has become increasingly prevalent, underscoring the critical need for robust security measures. This surge in usage has led to a rise in security breaches, often resulting in substantial financial losses for users. This article presents a comprehensive survey of smart contract quality assurance, from understanding vulnerabilities to evaluating the effectiveness of detection tools. Our work is notable for its innovative classification of 40 smart contract vulnerabilities, mapping them to established attack patterns. We further examine nine defense mechanisms, assessing their efficacy in mitigating smart contract attacks. Furthermore, we develop a labeled dataset as a benchmark encompassing 10 common vulnerability types, which serves as a critical resource for future research. We also conduct comprehensive experiments to evaluate 14 vulnerability detection tools, providing a comparative analysis that highlights their strengths and limitations. In summary, this survey synthesizes state-of-the-art knowledge in smart contract security, offering practical recommendations to guide future research and foster the development of robust security practices in the field.
In the face of increasingly sophisticated cybercrime threats, large companies now need innovative solutions to protect their data and interests. Blockchain technology, which is based on the principles of decentralization and strong encryption, offers great potential in improving corporate cybersecurity. This research investigates the implementation of blockchain technology in the context of enterprise security by developing a blockchain-based dynamic system model. These findings make an important contribution in changing the way audits and general accounting operations are carried out, presenting fundamental changes in the profession. This new approach integrates blockchain technology into various aspects of cybersecurity, embracing innovation and creativity in the face of current challenges. By creating accurate computer models, this research brings a breakthrough in understanding system responses to employee fraud in corporate environments that adopt blockchain technology. This research aims to explore the potential of blockchain technology in improving corporate cybersecurity by identifying security gaps and designing effective updates, creating a safe and trustworthy digital environment for companies in this digital era. The findings of this research highlight the importance of integrating blockchain technology in auditing and general accounting operations, creating a foundation for the development of robust cybersecurity systems. In the context of companies using blockchain technology, this research reveals improved system responsiveness to employee fraud, indicating positive potential in mitigating security risks. This research provides a solid foundation for further development in the field of enterprise cybersecurity, inspiring innovation in protecting businesses and digital assets in a rapidly evolving cyberspace.
Abstract Security threats posed by Ponzi schemes present a considerably higher risk compared to many other online crimes. These fraudulent online businesses, including Ponzi schemes, have witnessed rapid growth and emerged as major threats in societies like Nigeria, particularly due to the high poverty rate. Many individuals have fallen victim to these scams, resulting in significant financial losses. Despite efforts to detect Ponzi schemes using various methods, including machine learning (ML), current techniques still face challenges, such as deficient datasets, reliance on transaction records, and limited accuracy. To address the negative impact of Ponzi schemes, this paper proposes a novel approach focusing on detecting Ponzi schemes on Ethereum using ML algorithms like random forest (RF), neural network (NN), and K-nearest neighbor (KNN). Over 20,000 datasets related to Ethereum transaction networks were gathered from Kaggle and preprocessed for training the ML models. After evaluating and comparing the three models, RF demonstrated the best performance with an accuracy of 0.94, a class-score of 0.8833, and an overall-score of 0.96667. Comparative evaluations with previous models indicate that our model achieves high accuracy. Moreover, this innovative work successfully detects key fraud features within the Ponzi scheme dataset, reducing the number of features from 70 to only 10 while maintaining a high level of accuracy. The main strength of this proposed method lies in its ability to detect clever Ponzi schemes from their inception, offering valuable insights to combat these financial threats effectively.
The chapter addresses how the VASPs’ nature could lend itself to illicit uses, due to the technological progress that has allowed to protect the authors’ names of transactions with virtual currency. Background aspects such as the pandemic and the conflict between Russia and Ukraine may have accelerated the use of VASPs also in illicit terms. Therefore, regulation is necessary for the uncontrolled development of the illicit exploitation of a distributed ledger technology (DLT) as an upstream subject of VASPs. The role of the FAFT is essential to understand what the international orientation and commitment are in contrasting the cyberlaundering phenomenon, in which the VASPs represent one of the main players and a particularly attentive element to all international jurisdictions.
Tanuja Kayarga, C Kavitha, P. Lokamathe, M. Yamuna · 5 authors
Electronic First Information Report (e-FIR) is a basic document filed to the police stations by a victim or someone on his/her behalf when a cognizable offense such as murder, kidnapping, rape, theft, etc. is committed. In the e-FIR database, the offense&s;s record can be compromised due to its centralized nature, and further the intentional registration of false e-FIR can occur. Thus, data integrity and transparency are key concerns in e-FIR database. In this paper, e-FIR data integrity and false registration appended with police stations in a centralized database are addressed via a consensus-based distributed blockchain solution, as an integral part of a smart city environment. Specifically, a smart contract based intelligent framework has been utilized to explore the potential of Ethereum blockchain in providing integrity to e-FIR data stored in a police station&s;s database. Local database is interfaced with Ethereum blockchain using Web3 Remote Procedure Call (RPC) protocol. Multiple simulations have been performed to evaluate the performance of the proposed framework. Our results show a trade-off between different hashing algorithm security level for the offenses data and number of transactions stored in a single block on blockchain ledger.
This study proposes a smart contract risk management model built on the NIST Risk Management Framework (RMF) to help identify, assess, and manage the risks of smart contracts. While smart contracts are beloved as a means to automate and disintermediate business processes, their security vulnerabilities can be critical. The main issue discussed in this paper is the lack of a holistic approach to risk management smart contracts. The resulting framework consists of six steps: Risk identification, assessment, prioritization, mitigation, testing, and continuous monitoring (and was developed through reviewing existing literature on smart contract security and the NIST RMF). It is recommended that a case study be performed to prove the proposed model's effectiveness in managing the risks of smart contracts and minimizing financial losses and reputational harm. The paper presents a risk management framework for smart contracts to increase trust and adoption to enhance security while reducing financial losses and reputation damage. This has wider implications for the security of smart contracts and can be used as a starting point for future work. This study is expected to significantly contribute to smart contract security by introducing an organized way to address these contracts' risks using the NIST RMF.
Given the substantial economic repercussions resulting from smart contract security vulnerabilities, the detection and prevention of such vulnerabilities have emerged as critical issues warranting robust solutions. Recently, many researchers try to apply deep learning methods to the vulnerability detection task of smart contracts. However, deep learning-based approaches often focus on a singular feature of the smart contract source code, inhibiting a more comprehensive extraction of semantic and structural information embedded within the smart contract. The datasets employed for smart contract vulnerability detection are limited in size, which also restricts the learning capacity of the model, leading to suboptimal performance in identifying vulnerabilities related to smart contracts. To overcome these challenges, this paper introduces a novel vulnerability detection model centered on the fusion of semantic and structural features. These features, extracted from abstract syntax trees and contract graphs by Text Convolutional Neural Networks (TextCNN) and Temporal Message Propagation Network (TMP) respectively, are integrated to construct a classification prediction model. In addition, we added the pre-trained vector of SmartEmbed (smart contract similarity measurement model) to the training, and used the rich knowledge captured by the smart contract pre-trained word vector as the prior knowledge of our model, which can enhance the characterization of security features, and improve the performance of the vulnerability detection model, especially identifying hidden vulnerability rules when using limited labeled datasets. We conduct extensive experiments on approximately 5,000 smart contracts deployed on real-world Ethereum. Experiments prove that our method improves the detection accuracy and recall rate on the detection tasks of reentrancy vulnerability and timestamp dependence vulnerability, the accuracy rate reaches 78% and 89%, and the recall rate reaches 77% and 91% respectively, which is better than state-of-the-art methods.
With the rapid development of prepaid consumption, the problem of prepaid funds being occupied by individual merchants is increasingly prominent. In order to effectively solve this risk, this paper explores the innovative combination of digital RMB and smart contract technology. The article first elaborates the theoretical basis of smart contracts and digital currencies, and then proposes smart contract design schemes for prepaid consumption scenarios such as supply chain settlement and distribution refund, including using Solidity language to write code, setting payment trigger conditions, etc. In the deployment execution process, the article clarifies specific steps such as compilation, release, and user access to achieve automatic supervision and payment of funds. Although smart contracts still face privacy and security issues, the combination of digital RMB and smart contracts provides an innovative solution for the prepaid consumption field through continuous optimization of technical solutions and improvement of regulations, which is of great practical significance.
Distributed ledger technology (DLT), decentralized finance (DeFi), blockchain – these are terms that have been trending especially in technology circles. Today, blockchain has gained more acceptance, but sceptics continue to raise concerns about the technology's scalability, security, and long-term viability. There are also concerns regarding its being associated with crime and the dark web, which might imply it will have negative consequences if adopted. It has its own peculiar cyber security loopholes, but these can be addressed. That notwithstanding, organizations stand to gain from the blockchain in terms of cyber security; especially its qualities of decentralization and immutability. It has been successfully implemented in some sectors with positive results. This chapter seeks to illustrate how the blockchain can be used to boost and optimize cyber security for organizations.
Constantinos Patsakis, Eugenia Politou, Efthimios Alepis, Julio Hernández-Castro
Abstract The fast pace of blockchain technology and cryptocurrencies’ evolution makes people vulnerable to financial fraud and provides a relatively straightforward monetisation mechanism for cybercriminals, in particular ransomware groups which exploit crypto’s pseudo-anonymity properties. At the same time, regulatory efforts for addressing crimes related to crypto assets are emerging worldwide. In this work, we shed light on the current state of practice of ransomware monetisation to provide evidence of their payment traceability, explore future trends, and—above all—showcase that over-regulating cryptocurrencies is not the best way to mitigate their risks. For that purpose, first, we provide an overview of the legislative initiatives currently taken by the USA, the EU, and the OECD to regulate cryptocurrencies, showing that strict laws and the divergences between the regulatory regimes can hardly efficiently regulate the global phenomenon of cryptocurrency, which transcends borders and states. Next, we focus on illicit payments in bitcoin to ransomware groups, illustrating how these payments are siphoned off and how criminals cash out the ransom, often leaving traceable evidence behind. To this end, we leverage a publicly available dataset and a set of state-of-the-art blockchain analysis tools to identify payment patterns, trends, and transaction trails, which are provided in an anonymised form. Our work reveals that a significant amount of illicit bitcoin transactions can be easily traced, and consequently, many cyber crimes like ransomware can actually be tracked down and investigated with existing tools and laws, thus providing fertile ground for better and fairer legislation on crypto.
Firas Zawaideh, Waheeb Abu-Ulbeh, Salameh A. Mjlae, Yousef A. Baker El–Ebiary · 6 authors
The rapid growth of electronic commerce (e-commerce) has revolutionized the way Small and Medium-sized Enterprises (SMEs) conduct business, enabling them to reach global markets and unlock new growth opportunities. However, this digital transformation has also exposed SMEs to an escalating array of cybersecurity threats that could compromise their data, financial integrity, and reputation. Blockchain technology, known for its decentralized and immutable nature, has emerged as a potential solution to enhance the security and resilience of e-commerce operations for SMEs. This research paper aims to investigate the current state of cybersecurity preparedness among SMEs engaged in e-commerce and identify the prevalent threats they face in the digital landscape. To achieve this goal, the study incorporates systematic literature review (SLR) method to examine the best technological solution to address the cybersecurity issues faced by e-commerce organizations in this paper of SMEs operating in e-commerce to gather data on their security practices, incident history, and perceptions of cybersecurity risks. In the context of this research, blockchain technology will be explored as a potential mechanism to enhance the security of e-commerce operations for SMEs. The inherent features of blockchain, such as decentralization, transparency, and immutability, could help protect sensitive data and thwart cyberattacks. By exploring the integration of blockchain into e-commerce systems, the research aims to shed light on the potential benefits and challenges associated with its adoption by SMEs. The research findings will not only shed light on the prevailing cybersecurity practices within SMEs and highlight their vulnerabilities but will also explore how blockchain technology can be leveraged to address these challenges. By understanding these patterns and exploring the feasibility of blockchain integration, the research aims to provide comprehensive recommendations for enhancing cybersecurity resilience among SMEs in e-commerce. This could include proposing tailored cybersecurity training programs, suggesting cost-effective security solutions leveraging blockchain technology, and advocating for regulatory support to safeguard SMEs from cyberattacks. The significance of this study lies in its potential to contribute to the existing body of knowledge on SMEs' cybersecurity landscape in the e-commerce domain, addressing a critical research gap in understanding and addressing the unique challenges faced by these businesses. As SMEs continue to drive economic growth and job creation in many economies, safeguarding their digital assets and ensuring the integrity of e-commerce transactions become imperative for sustainable economic development in the digital era. The exploration of blockchain technology in this context could pave the way for more secure and resilient e-commerce ecosystems, benefiting SMEs and the broader digital economy alike.
The security of smart contracts has garnered considerable attention given the potential for substantial financial losses and erosion of trust in blockchain platforms. Numerous methods have been proposed to detect vulnerabilities in smart contracts. Notably, as the number of smart contracts continues to proliferate, automated techniques based on deep learning (DL) are making remarkable progress. However, a significant challenge persists in acquiring an efficient embedding representation that is compatible with DL models with input length restrictions. In this paper, we propose a novel detection method named GraBit for identifying reentrancy vulnerability-one of the most critical vulnerabilities in smart contracts. GraBit leverages the pre-trained model GraphCodeBERT to embed both the source code and concise key data flow graphs extracted from the code. Additionally, we customize a sequential model based on Bi-directional Long Short-Term Memory and attention mechanism to effectively capture contextual semantic information. To evaluate the performance of GraBit, we conduct extensive experiments on a public large-scale dataset. Our experimental results reveal that GraBit achieves a remarkable F1-score of 94.44% in detecting reentrancy vulnerability, outperforming state-of-the-art methods.
Lei Yu, Junyi Lu, Xianglong Liu, Yang Li · 6 authors
With the increasing security issues in the blockchain, smart contract vulnerability detection has gradually become the focus of research. Recently, many approaches have been proposed to detect smart contract vulnerabilities. Despite promising results, these approaches still have three drawbacks: 1) Symbolic execution and static analysis methods are constrained by predefined rules, which limits their adaptability to different vulnerabilities. 2) Most smart contract code contains abundant irrelevant information which is useless for vulnerability detection. 3) Pre-trained models fail to bridge the gap between pre-training and detecting smart contract vulnerabilities.To solve these problems, we propose an approach named PSCVFinder for detecting reentrancy vulnerability and times-tamp dependency vulnerability, which are two severe vulnerabilities in smart contract. To better detect these vulnerabilities, we propose CSCV which is a smart contract slicing method to reduce the irrelevant code. Unlike existing approaches, our model first learns the representation of programming language through the pre-training model, then fully exploits the capacity of large language model with prompt-tuning to precisely detect smart contract vulnerability. We conduct experiments on real-world dataset and the results reflect that PSCVFinder scores 93.83% and 93.49% on two kinds of vulnerabilities in F1-score, surpassing the state-of-the-art baseline by 1.14% and 4.02%, respectively.