arrow
Return

Bi-thresholds-based unknown vulnerability detection in smart contracts multi-classification model

delete2024-12-01
delete0
PRE
AI
P
Peiqiang Li
G
Guojun Wang *
G
Guangxin Zhai
W
Wanyi Gu
X
Xubin Li
X
Xiangyong Liu
Y
Yuheng Zhang
DOI:10.1016/j.compeleceng.2024.109682delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Ethereum's development has established a trusted environment for executing smart contracts. However, smart contracts often involve significant financial transfers and become immutable once deployed on the blockchain. If a security vulnerability occurs, developers will not be able to respond quickly, resulting in significant financial losses. Current solutions for detecting smart contracts focus mainly on known vulnerabilities, ignoring unknown ones. To address this issue, we propose a bi-thresholds-based scheme to identify unknown vulnerabilities. First, we collect the opcode sequences of transactions involving smart contracts by replaying the Ethereum transactions. Second, we use N-gram and TF-IDF techniques to extract features from the opcode sequences as inputs to a multi-classification model. Again, we set a double threshold to eliminate known vulnerabilities and normal sequences and to identify unknown vulnerability sequences, based on the principle that unknown and known vulnerabilities behave similarly. Finally, The experimental results show that our scheme has an accuracy of 90.9% and an F1-score of 91.5% in detecting unknown vulnerabilities in smart contracts.
Keywords:
Smart contracts
Opcode sequences
Unknown vulnerabilities
Multi-classification model
Bi-thresholds

Journal

C
Computers and Electrical Engineering
IF:
4.9
Papers:
6.7K
Citations:
1.3W

Organization

G
Guangzhou University
Scholars:
1.7W
Papers: 1.3W
Citations: 1.8W