首页> 外文会议>International Conference on Financial Cryptography and Data Security >What are the Actual Flaws in Important Smart Contracts (And How Can We Find Them)?
【24h】

What are the Actual Flaws in Important Smart Contracts (And How Can We Find Them)?

机译:重要智能合约的实际缺陷是什么(以及如何找到它们)?

获取原文

摘要

An important problem in smart contract security is understanding the likelihood and criticality of discovered, or potential, weaknesses in contracts. In this paper we provide a summary of Ethereum smart contract audits performed for 23 professional stakeholders, avoiding the common problem of reporting issues mostly prevalent in low-quality contracts. These audits were performed at a leading company in blockchain security, using both open-source and proprietary tools, as well as human code analysis performed by professional security engineers. We categorize 246 individual defects, making it possible to compare the severity and frequency of different vulnerability types, compare smart contract and non-smart contract flaws, and to estimate the efficacy of automated vulnerability detection approaches.
机译:智能合约安全性中的一个重要问题是了解已发现或潜在的合约弱点的可能性和严重性。在本文中,我们提供了针对23个专业利益攸关方进行的以太坊智能合约审计的摘要,避免了报告问题的常见问题,这些问题大多发生在低质量的合约中。这些审计是在区块链安全领域的领先公司中进行的,使用开源和专有工具,以及由专业安全工程师执行的人工代码分析。我们对246个单独的缺陷进行了分类,从而可以比较不同漏洞类型的严重性和频率,比较智能合约和非智能合约缺陷,并估计自动化漏洞检测方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号