首页> 外文会议>International Conference on Technical Debt >Assessing Smart Contracts Security Technical Debts
【24h】

Assessing Smart Contracts Security Technical Debts

机译:评估智能合同安全技术债务

获取原文

摘要

Smart contracts are self-enforcing agreements that are employed to exchange assets without the approval of trusted third parties. This feature has encouraged various sectors to make use of smart contracts when transacting. Experience shows that many deployed contracts are vulnerable to exploitation due to their poor design, which allows attackers to steal valuable assets from the involved parties. Therefore, an assessment approach that allows developers to recognise the consequences of deploying vulnerable contracts is needed. In this paper, we propose a debt-aware approach for assessing security design vulnerabilities in smart contracts. Our assessment approach involves two main steps: (i) identification of design vulnerabilities using security analysis techniques and (ii) an estimation of the ramifications of the identified vulnerabilities leveraging the technical debt metaphor, its principal and interest. We use examples of vulnerable contracts to demonstrate the applicability of our approach. The results show that our assessment approach increases the visibility of security design issues. It also allows developers to concentrate on resolving smart contract vulnerabilities through technical debt impact analysis and prioritisation. Developers can use our approach to inform the design of more secure contracts and for reducing unintentional debts caused by a lack of awareness of security issues.
机译:智能合同是自行执行协议,该协议在未经可信第三方批准的情况下雇用资产。此功能鼓励各个部门在交易时使用智能合同。经验表明,由于其设计不佳,许多部署的合同易受剥削,这使得攻击者可以窃取所涉及的各方的宝贵资产。因此,需要开发人员识别部署弱势合同的后果的评估方法。在本文中,我们提出了一种债务意识到,用于评估智能合同中的安全设计漏洞。我们的评估方法涉及两个主要步骤:(i)使用安全分析技术和(ii)估算所识别的漏洞的后果的估算,利用技术债务隐喻,其本金和利息。我们使用弱势合同的示例来证明我们的方法的适用性。结果表明,我们的评估方法增加了安全设计问题的可见性。它还允许开发人员专注于通过技术债务影响分析和优先级解决解决智能合同脆弱性。开发人员可以使用我们的方法来告知设计更安全的合同,并减少因缺乏对安全问题而引起的无意债务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号