THREAT PREVENTION & VULNERABILITY ANALYSIS OF SMART CONTRACTS IN BLOCKCHAIN NETWORKS
DOI:
https://doi.org/10.55766/sujst-2023-05-e01234Keywords:
Smart contract auditing, Delegate call, Self destruct, Denial of Service, Time-stamp Manipulation, ReentrancyAbstract
Blockchain technology now relies heavily on smart contracts, which offer self-executing code for the exchange of goods and data. Smart contracts enable financial activities like payments and auctions on blockchain systems. Even if bugs are found, they cannot be changed. They are frequently used to automate the implementation of agreements so that all parties may be confident in the conclusion without the need for an intermediary. But because of their openness and how they interact with one another in the blockchain ecosystem, these contracts are vulnerable to security risks. Smart contract security research has advanced significantly in recent years. The research community of smart contract security has made a significant improvement recently. Researchers have identified several security flaws in smart contracts and have created frameworks for verification and static analysis to find them. This study attempts to identify the most critical software security issues that affect smart contracts. These are then handled utilizing a variety of methods and equipment common to the sector
References
Ali M.H. and Ahmed M.S. (2022). A survey of smart contract: Architecture, applications, and future directions. Journal of Network and Computer Applications, 172:1-23
Antonopoulos, A.M., and Wood, G. (2018). Mastering ethereum: building smart contracts and dapps. O’reilly Media.
Atzei, N., Bartoletti, M., and Cimoli, T. (2017). A survey of attacks on ethereum smart contracts (sok). In Principles of Security and Trust: 6th International Conference, POST 2017, Held as Part of the European Joint Conferences on Theory and Practice of Software, ETAPS 2017, Uppsala, Sweden, p. 164-186.
Bitcoin (2022). Hacker Siphons $80 Million from Qubit Cross-Chain Bridge, Largest DeFi Exploit of 2022 to Date. Retrieved Mar 10, 2023.
Brent, L., Grech, N., Lagouvardos, S., Scholz, B., and Smaragdakis, Y. (2020). Ethainter: a smart contract security analyzer for composite vulnerabilities. In Proceedings of the 41st ACM SIGPLAN Conference on Programming Language Design and Implementation, 454-469.
Buterin, V. (2014). A next-generation smart contract and decentralized application platform. white paper, 3(37):2-1.
Chainlink. (2021). Introduction to Chainlink VRF. Chainlink Documentation. Mar 16, 2023.
Chen, H., Pendleton, M., Njilla, L., and Xu, S. (2020b). A survey on ethereum systems security: Vulnerabilities, attacks, and defenses. ACM Computing Surveys (CSUR), 53(3):1-43.
Chen, J. (2020a, December). Finding ethereum smart contracts security issues by comparing history versions. In Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering, 1,382-1,384.
Cointelegraph (2023). Nomad Token Bridge Drained $190M in Funds in Security Exploit. Retrieved Mar 10, 2023.
Crypto Times (2022). Hackers Compromised Wormhole Bridge with Largest Hacks of 2022, Run Away with $321M Worth WETH. Retrieved Mar 10, 2023.
Delmolino K., Arnett M., Kosba A, Miller A. and Shi E. (2016). Step by step towards creating a safe smart contract: Lessons and insights from a cryptocurrency lab, in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 98-113.
Drake, J., Ryan, D., and Buterin, V. (2021). Ethereum 2.0: A Complete Guide to Eth2 and the Ethereum Merge. Ethereum Foundation. [Online]. Available: https://ethereum.org/en/eth2/.
Goyal A. and Gupta N. (2020). Phishing with tx.origin: A New Vulnerability in Ethereum Smart Contracts. 11th International Conference on Computing, Communication and Networking Technologies (ICCCNT), 1-6.
Habashneh M.A.Al, Qutayri A.Al, Ghaleb A. and Alkhaldi I.A. (2020). Towards Understanding and Mitigating Block Timestamp Manipulation Attacks in Blockchain-based Smart Contracts. 11th International Conference on Information and Communication Systems (ICICS), 22-27.
Hwang, S., and Ryu, S. (2020). Gap between theory and practice: An empirical study of security patches in solidity. In Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering, 542-553.
Islam M.R, Hossain M.A, Alam M, Islam M.S. and Ahmed S.U. (2020). Arithmetic Overflow and Underflow Vulnerabilities in Solidity Smart Contracts. 6th International Conference on Advances in Electrical Engineering (ICAEE), 157-162,
Li, H. Zhang, Y. Xie, and X. Chen (2019). DOS attacks on Ethereum smart contracts: Analyzing the causes and defenses. in IEEE 39th International Conference on Distributed Computing Systems (ICDCS), 1,274-1,279.
Jain, S., Shah, N.K., Kurariya, P., Vohra, N., Nandukar, S., Harne, N., and Indraveni, C. (2022). Smart contract-security assessment integrated framework (SC-SIF) for hyperledger fabric. In 2022 IEEE 7th International conference for Convergence in Technology (I2CT), 1-11.
Yamashita K., Nomura Y., Zhou E., Pi B.and Jun S. (2019). Potential Risks of Hyperledger Fabric Smart Contracts. 2019 IEEE International Workshop on Blockchain Oriented Software Engineering (IWBOSE), 2019, 1-10 Doi: https://doi.org/10.1109/IWBOSE.2019.8666486.
Kamble S., Patil A., and Kadam S. (2021). Honeypot Based Security Mechanisms for Smart Contracts on Blockchain. International Conference on Intelligent Sustainable Systems (ICISS), 832-836.
Kumar A., Kumar K. and Singh S. (2018). Understanding and Mitigating Self-Destruct Vulnerability in Ethereum Smart Contracts, 3rd International Conference on Computational Systems and Information Technology for Sustainable Solutions (CSITSS), 73-78.
Kushwaha, S.S., Joshi, S., Singh, D., Kaur, M., and Lee, H.N. (2022). Systematic review of security vulnerabilities in ethereum blockchain smart contract.nIEEE Access, 10:6,605-6,621.
Li J., Yu J. and Zhang Z (2020). Understanding and Mitigating Delegate Call Attacks in Solidity Smart Contracts. 2nd International Conference on Computer Science and Software Engineering (CSSE), 61-65.
Liu, J., and Liu, Z. (2019). A survey on security verification of blockchain smart contracts. IEEE Access, 7:77894-77904.
Lu, N., Wang, B., Zhang, Y., Shi, W., and Esposito, C. (2021). NeuCheck: A more practical Ethereum smart contract security analysis tool. Software: Practice and Experience, 51(10):2,065-2,084.
Lubin, J., and Wood, G. (2014). Ethereum: Platform Review and Perspectives. ETHDEV. Retrieved from https://ethereum.org/pdfs/EthereumPlatformReview.pdf
Luu, L., Chu, D.H., Olickel, H., Saxena, P., and Hobor, A. (2016). Making smart contracts smarter. In Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, 254-269.
Mossberg, M., Manzano, F., Hennenfent, E., Groce, A., Grieco, G., Feist, J., and Dinaburg, A. (2019). Manticore: A user-friendly symbolic execution framework for binaries and smart contracts. In 2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE), 1,186-1,189.
Narayanan, A., Bonneau, J., Felten, E., Miller, A., and Goldfeder, S. (2016). Bitcoin and crypto Currency technologies: a comprehensive introduction. Princeton University Press.
Nikolic, I., Kolluri, A., Sergey, I., Saxena, P., Hobor, A. (2018). Finding the greedy, prodigal, and suicidal contracts at scale. In Proceedings of the 34th annual computer security applications conference, 653-663.
Open Zeppelin. (2019). Math library. Open Zeppelin Contracts 2.x Documentation. https://docs.openzeppelin. com/contracts/2.x/api/math
Perez, D., and Livshits, B. (2021). Smart contract vulnerabilities: Vulnerable does not imply exploited. In 30th USENIX Security Symposium (USENIX Security 21), 1,325-1,341.
Poleshchuk, E.M., Shcherbinina, I.A., and Putilova, S.E. (2012). Security Analysis of Smart Contracts in Blockchain Networks. In 2022 Ural-Siberian Conference on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT), 252-254.
Popov, S. (2016). The Tangle: A Directed Acyclic Graph (DAG) for Distributed Ledger Technologies. IOTA Foundation. Doi: https://iota.org/IOTA_Whitepaper.pdf
Sriram K and Sridharan S. (2019). Insecure Source of Randomness in Solidity Smart Contracts. 3rd International Conference on Inventive Systems and Control (ICISC), 1,359-1,362.
Swan, M. (2015). Blockchain: Blueprint for a new economy. O'Reilly Media, Inc.
Tikhomirov, S., Voskresenskaya, E., Ivanitskiy, I., Takhaviev, R., Marchenko, E., and Alexandrov, Y. (2018). Smartcheck: Static analysis of ethereum smart contracts. In Proceedings of the 1st international workshop on emerging trends in software engineering for blockchain, 9-16.
Torres, C.F., Schütte, J., and State, R. (2018). Osiris: Hunting for integer bugs in ethereum smart contracts. In Proceedings of the 34th annual computer security applications conference, 664-676.
Tsankov, P., Dan, A., Drachsler-Cohen, D., Gervais, A., Buenzli, F., and Vechev, M. (2018). Securify: Practical security analysis of smart contracts. In Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, 67-82.
Wan, Z., Xia, X., Lo, D., Chen, J., Luo, X., and Yang, X. (2021). Smart contract security: A practitioners perspective. In 2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE), 1,410-1,422.
Wang, Q., Chen, Z., Liang, X., and Ma, J. (2019). Contract lab: A comprehensive testing suite for smart contracts. Proceedings of the 2019 IEEE/ACM 41st International Conference on Software Engineering: Companion Proceedings (ICSE-Companion), 370-373.
Wang, X., Li, J., and Zhang, X. (2022). A semantic-based smart contract defect detection general platform. In 2022 IEEE International Conference on Advances in Electrical Engineering and Computer Applications (AEECA), 34-37.
Wood, G. (2014). Ethereum: A secure decentralised generalised transaction ledger. Ethereum project yellow paper, 151(2014):1-32.
Yao, Y., Li, H., Yang, X., and Le, Y. (2022). An Improved Vulnerability Detection System of Smart Contracts Based on Symbolic Execution. In 2022 IEEE International Conference on Big Data (Big Data), 3,225-3,234.
Ye, J., Ma, M., Lin, Y., Sui, Y., and Xue, Y. (2020). Clairvoyance: Cross-contract static analysis for detecting practical reentrancy vulnerabilities in smart contracts. In Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering: Companion Proceedings, 274-275.
Zhou, E., Hua, S., Pi, B., Sun, J., Nomura, Y., Yamashita, K., and Kurihara, H. (2018). Security assurance for smart contract. In 2018 9th IFIP International Conference on New Technologies. Mobility and Security (NTMS), 1-5.








