OpenSCV: an open hierarchical taxonomy for smart contract vulnerabilities

被引:2
作者
Vidal, Fernando Richter [1 ]
Ivaki, Naghmeh [1 ]
Laranjeiro, Nuno [1 ]
机构
[1] Univ Coimbra, Ctr Informat & Syst, Dept Informat Engn, Coimbra, Portugal
基金
瑞典研究理事会;
关键词
Blockchain; Smart contracts; Vulnerabilities; Classification; Taxonomy; NETWORKS;
D O I
10.1007/s10664-024-10446-8
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Smart contracts are nowadays at the core of most blockchain systems. Like all computer programs, smart contracts are subject to the presence of residual faults, including severe security vulnerabilities. However, the key distinction lies in how these vulnerabilities are addressed. In smart contracts, when a vulnerability is identified, the affected contract must be terminated within the blockchain, as due to the immutable nature of blockchains, it is impossible to patch a contract once deployed. In this context, research efforts have been focused on proactively preventing the deployment of smart contracts containing vulnerabilities, mainly through the development of vulnerability detection tools. Along with these efforts, several heterogeneous vulnerability classification schemes appeared (e.g., most notably DASP and SWC). At the time of writing, these are mostly outdated initiatives, even though new smart contract vulnerabilities are consistently uncovered. In this paper, we propose OpenSCV, a new and Open hierarchical taxonomy for Smart Contract vulnerabilities, which is open to community contributions and matches the current state of the practice while being prepared to handle future modifications and evolution. The taxonomy was built based on the analysis of the existing research on vulnerability classification, community-maintained classification schemes, and research on smart contract vulnerability detection. We show how OpenSCV covers the announced detection ability of the current vulnerability detection tools and highlight its usefulness in smart contract vulnerability research. To validate OpenSCV, we performed an expert-based analysis wherein we invited multiple experts engaged in smart contract security research to participate in a questionnaire. The feedback from these experts indicated that the categories in OpenSCV are representative, clear, easily understandable, comprehensive, and highly useful. Regarding the vulnerabilities, the experts confirmed that they are easily understandable.
引用
收藏
页数:67
相关论文
共 146 条
  • [1] Blockchain Technology in Healthcare: A Systematic Review
    Agbo, Cornelius C.
    Mahmoud, Qusay H.
    Eklund, J. Mikael
    [J]. HEALTHCARE, 2019, 7 (02)
  • [2] SolAnalyser: A Framework for Analysing and Testing Smart Contracts
    Akca, Sefa
    Rajan, Ajitha
    Peng, Chao
    [J]. 2019 26TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC), 2019, : 482 - 489
  • [3] Blockchain Vulnerabilities in Practice
    Amiet, Nils
    [J]. DIGITAL THREATS: RESEARCH AND PRACTICE, 2021, 2 (02):
  • [4] [Anonymous], 2001, A taxonomy of computer attacks with applications to wireless networks
  • [5] [Anonymous], 2016, Understanding The DAO Attack
  • [6] [Anonymous], 2020, Overview smart contract weakness classification and test cases
  • [7] [Anonymous], 1994, Fundamentals of Computer Security Technology
  • [8] [Anonymous], 2013, Orthogonal Defect Classification v5.2 for Software Design and Code
  • [9] Antonopoulos A.M., 2019, Mastering Ethereum. Building Smart Contracts and DApps, V1st ed., P297
  • [10] Arganaraz MC, 2020, OpenAccess Series in Informatics (OASIcs), pp16, DOI [10.4230/OASIcs.SLATE.2020, DOI 10.4230/OASICS.SLATE.2020]