ASE 2024
Sun 27 October - Fri 1 November 2024 Sacramento, California, United States
Tue 29 Oct 2024 16:30 - 16:45 at Gardenia - Smart contract and block chain 1 Chair(s): Nafiz Imtiaz Khan

Smart contracts are susceptible to various vulnerabilities that can be exploited by hackers via developing adversarial contracts. Existing vulnerability detection techniques often concentrate solely on vulnerable contracts, neglecting adversarial contracts, which may weaken the effectiveness of vulnerability detection and fail to meet practical needs.

In this paper, we propose Skyeye, a novel technique that integrates adversarial and vulnerable contracts together to detect vulnerabilities and resulting imminent attacks. Skyeye works during the stage after adversarial contracts have been deployed but before attack transactions are initiated, providing a critical time window for emergency response to mitigate potential losses. Upon deployment of a smart contract, Skyeye detects whether it is adversarial, and then utilizes the probabilistic matching technique to localize victim contracts. By pairing adversarial and victim contracts, Skyeye comprehensively extracts complete attack behaviors. Furthermore, Skyeye leverages Large Language Model (LLM) to decide the types of vulnerabilities exploited by adversarial contracts. Our evaluation, conducted on 174 real-world adversarial contracts from 159 incidents resulting in financial losses totaling approximately $1.36 billion, demonstrates Skyeye’s effectiveness in detecting vulnerabilities and imminent attacks. Compared to state-of-the-art techniques, e.g., BlockWatchdog and Slither, Skyeye also reveals the superior performance.

Tue 29 Oct

Displayed time zone: Pacific Time (US & Canada) change

16:30 - 17:30
Smart contract and block chain 1Journal-first Papers / Research Papers / Tool Demonstrations at Gardenia
Chair(s): Nafiz Imtiaz Khan Department of Computer Science, University of California, Davis
16:30
15m
Talk
Skyeye: Detecting Imminent Attacks via Analyzing Adversarial Smart Contracts
Research Papers
Haijun Wang Xi’an Jiaotong University, Yurui Hu Xi'an Jiaotong University, Hao Wu Xi'an JiaoTong University, Dijun Liu Ant Group, Chenyang Peng Xi'an Jiaotong University, Yin Wu Xi'an Jiaotong University, Ming Fan Xi'an Jiaotong University, Ting Liu Xi'an Jiaotong University
16:45
15m
Talk
DL4SC: a novel deep learning-based vulnerability detection framework for smart contracts
Journal-first Papers
Yang Liu Shanghai Maritime University/National University of Singapore, Chao Wang University of Southern California, Yan Ma Nanjing University of Finance and Economics / National University of Singapore
17:00
10m
Talk
OpenTracer: A Dynamic Transaction Trace Analyzer for Smart Contract Invariant Generation and Beyond
Tool Demonstrations
Zhiyang Chen University of Toronto, Ye Liu Singapore Management University, Sidi Mohamed Beillahi University of Toronto, Yi Li Nanyang Technological University, Fan Long University of Toronto
DOI Pre-print Media Attached