As Strong As Its Weakest Link: How to Break Blockchain DApps at RPC Service
Kai Li, Jiaqi Chen, Xianghong Liu, Yuzhe Richard Tang, XiaoFeng Wang, Xiapu Luo
摘要
Modern blockchains have evolved from cryptocurrency substrates to trust-decentralization platforms, supporting a wider variety of decentralized applications known as DApps. Blockchain remote procedure call (RPC) services emerge as an intermediary connecting the DApps to a blockchain network. In this work, we identify the free contract-execution capabilities that widely exist in blockchain RPCs as a vulnerability of denial of service (DoS) and present the DoERS attack, a Denial of Ethereum RPC service that incurs zero Ether cost to the attacker.
To understand the DoERS exploitability in the wild, we conduct a systematic measurement study on nine real-world RPC services which control most DApp clients' connection to the Ethereum mainnet. In particular, we propose a novel measurement technique based on orphan transactions to discover the previously unknown behaviors inside the blackbox RPC services, including load balancing and gas limiting. Further DoERS strategies are proposed to evade the protection intended by these behaviors.
We evaluate the effectiveness of DoERS attacks on deployed RPC services with minimal service interruption. The result shows that all the nine services tested (as of Apr. 2020) are vulnerable to DoERS attacks that can result in the service latency increased by . Some of these attacks require only a single request. In addition, on a local Ethereum node protected by a very restrictive limit of block gas, sending 150 DoERS requests per second can slow down the block synchronization of the victim node by .
We propose mitigation techniques against DoERS without dropping service usability, via unpredictable load balancing, performance anomaly detection, and others. These techniques can be integrated into a RPC service transparently to its clients.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- Understanding Security Issues in the NFT EcosystemDipanjan Das, Priyanka Bose, Nicola Ruaro, Christopher Kruegel 等CCS 2022 · 被引用 173 次
- DETER: Denial of Ethereum Txpool sERvicesKai Li, Yibo Wang, Yuzhe TangCCS 2021 · 被引用 26 次
- Nurgle: Exacerbating Resource Consumption in Blockchain State Storage via MPT ManipulationZheyuan He, Zihao Li, Ao Qiao, Xiapu Luo 等S&P 2024 · 被引用 21 次
- Bad Apples: Understanding the Centralized Security Risks in Decentralized EcosystemsKailun Yan, Jilian Zhang, Xiangyu Liu, Wenrui Diao 等WWW 2023 · 被引用 12 次
- Understanding Ethereum Mempool Security under Asymmetric DoS by Symbolized Stateful FuzzingYibo Wang, Yuzhe Tang, Kai Li, Wanning Ding 等USENIX Security 2024 · 被引用 9 次
它引用的顶会 Paper3
- Hijacking Bitcoin: Routing Attacks on CryptocurrenciesMaria Apostolaki, Aviv Zohar, Laurent VanbeverS&P 2017 · 被引用 473 次
- A Stealthier Partitioning Attack against Bitcoin Peer-to-Peer NetworkMuoi Tran, Inho Choi, Gi Jun Moon, Anh V. Vu 等S&P 2020 · 被引用 126 次
- Broken Metre: Attacking Resource Metering in EVMDaniel Perez, Benjamin LivshitsNDSS 2020
相关 Paper
- Deanonymizing Ethereum Users behind Third-Party RPC ServicesShan Wang, Ming Yang, Wenxuan Dai, Yu Liu 等INFOCOM 2024 · 被引用 4 次
- Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction FeeShan Wang, Ming Yang, Yu Liu, Yue Zhang 等CCS 2025
- Is My RPC Response Reliable? Detecting RPC Bugs in Blockchain Client under ContextZhijie Zhong, Yuhong Nan, Mingxi Ye, Qing Xue 等ICSE 2026
- An Ever-evolving Game: Evaluation of Real-world Attacks and Defenses in Ethereum EcosystemShunfan Zhou, Zhemin Yang, Jie Xiang, Yinzhi Cao 等USENIX Security 2020
- Towards Automatic Discovery of Denial of Service Weaknesses in Blockchain Resource ModelsFeng Luo, Huangkun Lin, Zihao Li, Xiapu Luo 等CCS 2024 · 被引用 4 次
