Verifying Smart Contract Security against Re-entrancy Attacks through Relational Value Analysis
Divya Rathore, Kartik Nagar
Abstract
Reentrancy vulnerabilities are a critical security risk in smart contracts, posing a significant threat to the entire blockchain ecosystem. These vulnerabilities arise when a malicious attacker exploits the design of a smart contract to re-enter a function within the execution of another function, thus breaking atomicity and manipulating the smart contract state in unintended ways. While multiple countermeasures have been proposed to fortify smart contracts against re-entrancy based attacks, automatically verifying their effectiveness remains a difficult problem due to the inherent complexity of smart contracts and evolving attack techniques. In this work, we propose RAVEN, a sound and precise approach to verify smart contract safety against re-entrancy attacks automatically. At its core, RAVEN performs a content-sensitive semantic relational value analysis using the polyhedral abstract domain to establish hyper-properties such as absorption and commutativity of different program segments, which are sufficient to ensure safety against re-entrancy. Notably, unlike many prior approaches, we also prove the soundness of RAVEN, thus guaranteeing that contracts deemed as safe by RAVEN would not suffer from classical re-entrancy attacks. We have implemented our approach and evaluated RAVEN against nine state-of-the-art tools using four comprehensive test suites of Solidity smart contracts labeled for re-entrancy. The results demonstrate that RAVEN attains higher precision than existing approaches in detecting both re-entrancy-safe and vulnerable contracts. In particular, RAVEN produced 0/781 false positives on two test suites and 444/21,355 false positives on the remaining two, representing an approximate 77.3% reduction in false positives over prior tools. Moreover, this improvement was achieved with a comparable average analysis time of 141.9 seconds, versus 128.8 seconds for prior tools.
• Software and its engineering → Automated static analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d40cd4f3-8e60-4a63-b42d-35e9909abae2Builds on19
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
- Sereum: Protecting Existing Smart Contracts Against Re-Entrancy AttacksMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviNDSS 2019 · 298 citations
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin et al.ICSE 2020 · 260 citations
Related papers
- AdvSCanner: Generating Adversarial Smart Contracts to Exploit Reentrancy Vulnerabilities Using LLM and Static AnalysisYin Wu, Xiaofei Xie, Chenyang Peng, Dijun Liu et al.ASE 2024 · 9 citations
- Cross-Contract Static Analysis for Detecting Practical Reentrancy Vulnerabilities in Smart ContractsYinxing Xue, Mingliang Ma, Yun Lin, Yulei Sui et al.ASE 2020 · 77 citations
- Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker ContractsShuo Yang, Jiachi Chen, Mingyuan Huang, Zibin Zheng et al.ICSE 2024 · 24 citations
- Turn the Rudder: A Beacon of Reentrancy Detection for Smart Contracts on EthereumZibin Zheng, Neng Zhang, Jianzhong Su, Zhijie Zhong et al.ICSE 2023 · 52 citations
- Efficiently Detecting Reentrancy Vulnerabilities in Complex Smart ContractsZexu Wang, Jiachi Chen, Yanlin Wang, Yu Zhang et al.FSE 2024 · 27 citations
