Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Finding permission bugs in smart contracts with role mining
KTH, Skolan för elektroteknik och datavetenskap (EECS), Datavetenskap, Teoretisk datalogi, TCS.ORCID-id: 0000-0002-3656-1614
2022 (engelsk)Inngår i: ISSTA 2022 - Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis, Association for Computing Machinery, Inc , 2022, s. 716-727Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Smart contracts deployed on permissionless blockchains, such as Ethereum, are accessible to any user in a trustless environment. Therefore, most smart contract applications implement access control policies to protect their valuable assets from unauthorized accesses. A difficulty in validating the conformance to such policies, i.e., whether the contract implementation adheres to the expected behaviors, is the lack of policy specifications. In this paper, we mine past transactions of a contract to recover a likely access control model, which can then be checked against various information flow policies and identify potential bugs related to user permissions. We implement our role mining and security policy validation in tool SPCon. The experimental evaluation on labeled smart contract role mining benchmark demonstrates that SPCon effectively mines more accurate user roles compared to the state-of-the-art role mining tools. Moreover, the experimental evaluation on real-world smart contract benchmark and access control CVEs indicates SPCon effectively detects potential permission bugs while having better scalability and lower false-positive rate compared to the state-of-the-art security tools, finding 11 previously unknown bugs and detecting six CVEs that no other tool can find.

sted, utgiver, år, opplag, sider
Association for Computing Machinery, Inc , 2022. s. 716-727
Emneord [en]
access control, information flow policy, role mining, Smart contract
HSV kategori
Identifikatorer
URN: urn:nbn:se:kth:diva-317527DOI: 10.1145/3533767.3534372ISI: 001122755200058Scopus ID: 2-s2.0-85136789338OAI: oai:DiVA.org:kth-317527DiVA, id: diva2:1695328
Konferanse
31st ACM SIGSOFT International Symposium on Software Testing and Analysis, ISSTA 2022, 18 July 2022 through 22 July 2022, Virtual, Online
Merknad

QC 20220913

Part of proceedings: ISBN 978-145039379-9

Tilgjengelig fra: 2022-09-13 Laget: 2022-09-13 Sist oppdatert: 2025-12-05bibliografisk kontrollert

Open Access i DiVA

Fulltekst mangler i DiVA

Andre lenker

Forlagets fulltekstScopus

Person

Artho, Cyrille

Søk i DiVA

Av forfatter/redaktør
Artho, Cyrille
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric

doi
urn-nbn
Totalt: 156 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf