Periodical
MadMax: Analyzing the Out-of-Gas World of Smart Contracts.
| Τίτλος: | MadMax: Analyzing the Out-of-Gas World of Smart Contracts. |
|---|---|
| Συγγραφείς: | Grech, Neville, Kong, Michael, Jurisevic, Anton, Brent, Lexi, Scholz, Bernhard, Smaragdakis, Yannis |
| Πηγή: | Communications of the ACM; Oct2020, Vol. 63 Issue 10, p87-95, 9p, 7 Diagrams |
| Θεματικοί όροι: | Electronic contracts, Computer security vulnerabilities, Computer crime prevention, Blockchains, Decompilers (Computer programs) |
| Περίληψη: | Ethereum is a distributed blockchain platform, serving as an ecosystem for smart contracts: full-fledged intercommunicating programs that capture the transaction logic of an account. A gas limit caps the execution of an Ethereum smart contract: instructions, when executed, consume gas, and the execution proceeds as long as gas is available. Gas-focused vulnerabilities permit an attacker to force key contract functionality to run out of gas-effectively performing a permanent denial-of-service attack on the contract. Such vulnerabilities are among the hardest for programmers to protect against, as out-of-gas behavior may be uncommon in nonattack scenarios and reasoning about these vulnerabilities is nontrivial. In this paper, we identify gas-focused vulnerabilities and present MadMax: a static program analysis technique that automatically detects gas-focused vulnerabilities with very high confidence. MadMax combines a smart contract decompiler and semantic queries in Datalog. Our approach captures high-level program modeling concepts (such as "dynamic data structure storage" and "safely resumable loops") and delivers high precision and scalability. MadMax analyzes the entirety of smart contracts in the Ethereum blockchain in just 10 hours and flags vulnerabilities in contracts with a monetary value in billions of dollars. Manual inspection of a sample of flagged contracts shows that 81% of the sampled warnings do indeed lead to vulnerabilities. [ABSTRACT FROM AUTHOR] |
| Copyright of Communications of the ACM is the property of Association for Computing Machinery and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Βάση Δεδομένων: | Complementary Index |
| FullText | Links: – Type: other Text: Availability: 0 |
|---|---|
| Header | DbId: edb DbLabel: Complementary Index An: 146056008 RelevancyScore: 885 AccessLevel: 6 PubType: Periodical PubTypeId: serialPeriodical PreciseRelevancyScore: 884.619140625 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: MadMax: Analyzing the Out-of-Gas World of Smart Contracts. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Grech%2C+Neville%22">Grech, Neville</searchLink><br /><searchLink fieldCode="AR" term="%22Kong%2C+Michael%22">Kong, Michael</searchLink><br /><searchLink fieldCode="AR" term="%22Jurisevic%2C+Anton%22">Jurisevic, Anton</searchLink><br /><searchLink fieldCode="AR" term="%22Brent%2C+Lexi%22">Brent, Lexi</searchLink><br /><searchLink fieldCode="AR" term="%22Scholz%2C+Bernhard%22">Scholz, Bernhard</searchLink><br /><searchLink fieldCode="AR" term="%22Smaragdakis%2C+Yannis%22">Smaragdakis, Yannis</searchLink> – Name: TitleSource Label: Source Group: Src Data: Communications of the ACM; Oct2020, Vol. 63 Issue 10, p87-95, 9p, 7 Diagrams – Name: Subject Label: Subject Terms Group: Su Data: <searchLink fieldCode="DE" term="%22Electronic+contracts%22">Electronic contracts</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+vulnerabilities%22">Computer security vulnerabilities</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+crime+prevention%22">Computer crime prevention</searchLink><br /><searchLink fieldCode="DE" term="%22Blockchains%22">Blockchains</searchLink><br /><searchLink fieldCode="DE" term="%22Decompilers+%28Computer+programs%29%22">Decompilers (Computer programs)</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: Ethereum is a distributed blockchain platform, serving as an ecosystem for smart contracts: full-fledged intercommunicating programs that capture the transaction logic of an account. A gas limit caps the execution of an Ethereum smart contract: instructions, when executed, consume gas, and the execution proceeds as long as gas is available. Gas-focused vulnerabilities permit an attacker to force key contract functionality to run out of gas-effectively performing a permanent denial-of-service attack on the contract. Such vulnerabilities are among the hardest for programmers to protect against, as out-of-gas behavior may be uncommon in nonattack scenarios and reasoning about these vulnerabilities is nontrivial. In this paper, we identify gas-focused vulnerabilities and present MadMax: a static program analysis technique that automatically detects gas-focused vulnerabilities with very high confidence. MadMax combines a smart contract decompiler and semantic queries in Datalog. Our approach captures high-level program modeling concepts (such as "dynamic data structure storage" and "safely resumable loops") and delivers high precision and scalability. MadMax analyzes the entirety of smart contracts in the Ethereum blockchain in just 10 hours and flags vulnerabilities in contracts with a monetary value in billions of dollars. Manual inspection of a sample of flagged contracts shows that 81% of the sampled warnings do indeed lead to vulnerabilities. [ABSTRACT FROM AUTHOR] – Name: Abstract Label: Group: Ab Data: <i>Copyright of Communications of the ACM is the property of Association for Computing Machinery and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edb&AN=146056008 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1145/3416262 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 9 StartPage: 87 Subjects: – SubjectFull: Electronic contracts Type: general – SubjectFull: Computer security vulnerabilities Type: general – SubjectFull: Computer crime prevention Type: general – SubjectFull: Blockchains Type: general – SubjectFull: Decompilers (Computer programs) Type: general Titles: – TitleFull: MadMax: Analyzing the Out-of-Gas World of Smart Contracts. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Grech, Neville – PersonEntity: Name: NameFull: Kong, Michael – PersonEntity: Name: NameFull: Jurisevic, Anton – PersonEntity: Name: NameFull: Brent, Lexi – PersonEntity: Name: NameFull: Scholz, Bernhard – PersonEntity: Name: NameFull: Smaragdakis, Yannis IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 10 Text: Oct2020 Type: published Y: 2020 Identifiers: – Type: issn-print Value: 00010782 Numbering: – Type: volume Value: 63 – Type: issue Value: 10 Titles: – TitleFull: Communications of the ACM Type: main |
| ResultId | 1 |