基于静态与动态分析的智能合约漏洞检测实证研究
CSTR:
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP311

基金项目:

国家自然科学基金(U2336203)


Empirical Study on Smart Contract Vulnerability Detection Based on Static and Dynamic Analysis
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    近年来, 智能合约因其不可篡改性和可执行性在金融领域得到了广泛的应用. 与此同时, 智能合约引发的安全事件不断增多, 往往造成大规模的经济损失. 因此, 大多数研究人员致力于开发智能合约漏洞检测工具来检测智能合约的安全性. 然而, 不同的合约漏洞检测工具可能因为数据集的不一致使得研究人员无法客观评估其性能. 构建一个新的数据集, 并在统一的标准下系统地测试9个候选工具. 该数据集不仅包含真实世界的智能合约, 且涵盖了5类常见的智能合约漏洞. 从5个方面对工具进行细致的评估, 并提出一种新的智能合约分类方法来验证工具的鲁棒性. 实验结果表明: 1)多数现有工具易于安装, 但同时存在停止维护等问题. 2)静态检测工具在实际检测过程中仍然面临漏报率和误报率高的问题, 且依赖于智能合约不同版本的分析. 3)静态检测工具的时间开销较小, 而基于符号执行的工具容易因状态爆炸而导致时间开销较大. 4)部分静态检测工具不支持具有复杂继承关系的合约. 5)采用多种漏洞检测技术融合的方式, 可以有效提高检测的精确率和召回率.

    Abstract:

    In recent years, smart contracts have been widely used in the financial field due to their immutability and enforceability. At the same time, the number of security incidents caused by smart contracts has continued to increase, often causing large-scale economic losses. Therefore, most researchers focus on developing vulnerability detection tools to assess the security of smart contracts. However, the performance of different vulnerability detection tools cannot be objectively evaluated due to the use of inconsistent datasets. This study constructs a new dataset and systematically tests nine candidate tools under a unified benchmark. The dataset includes real-world smart contracts and covers five common types of vulnerabilities. This study evaluates the tools from five aspects and proposes a new smart contract classification method to verify the robustness of the tools. The experimental results are as follows. 1) Most existing tools are easy to install, but there are also problems such as discontinued maintenance. 2) Static detection tools still face the problem of high false positive and false negative rates in the actual detection process, and rely on the analysis of different versions of smart contracts. 3) Static detection tools have a small time overhead, while tools based on symbolic execution are prone to large time overhead due to state explosion. 4) Some static detection tools do not support contracts with complex inheritance relationships. 5) The integration of multiple vulnerability detection technologies can effectively improve the detection precision and recall.

    参考文献
    相似文献
    引证文献
引用本文

祝语,李珍,张笑睿,吴月明,邹德清.基于静态与动态分析的智能合约漏洞检测实证研究.软件学报,,():1-21

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-05-07
  • 最后修改日期:2025-09-23
  • 录用日期:
  • 在线发布日期: 2026-05-20
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号