arrow
返回

Mutation Testing for Integer Overflow in Ethereum Smart Contracts

delete2022-02-01
delete26
delete
OA
AI
J
Jinlei Sun
黄松 封面图
黄松 (Song Huang)
C
Changyou Zheng *
T
Tingyong Wang
C
Cheng Zong
Z
Zhanwei Hui
DOI:10.26599/TST.2020.9010036delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Integer overflow is a common vulnerability in Ethereum Smart Contracts (ESCs) and often causes huge economic losses. Smart contracts cannot be changed once it is deployed on the blockchain and thus demand further testing. Mutation testing is a fault-based testing method that can effectively improve the sufficiency of a test for smart contracts. However, existing methods cannot efficiently perform mutation testing specifically for integer overflow in ESCs. Therefore, by analyzing integer overflow in ESCs, we propose five special mutation operators to address such vulnerability in terms of detecting sufficiency in ESC testing. An empirical study on 40 open-source ESCs is conducted to evaluate the effectiveness of the proposed mutation operators. Results show that (1) our proposed mutation operators can reproduce all 179 integer overflow vulnerabilities in 40 smart contracts, and the generated mutants have high compilation pass rate and integer overflow vulnerability generation rate; moreover, (2) the generated mutants can find the shortcomings of existing testing methods for integer overflow vulnerability, thereby providing effective support to improve the sufficiency of the test.
Keyword:
blockchain
Ethereum Smart Contracts (ESCs)
integer overflow
mutation testing

期刊

T
Tsinghua Science and Technology
IF:
3.5
论文数:
987
被引数:
2.5K

机构

A
Army Engineering University of PLA
学者数:
5.0K
论文数: 3.7K
被引数: 5
引用论文

引用论文

暂无论文信息