Park: accelerating smart contract vulnerability detection via parallel-fork symbolic execution
Peilin Zheng, Zibin Zheng, Xiapu Luo
摘要
Symbolic detection has been widely used to detect vulnerabilities in smart contracts. Unfortunately, as reported, existing symbolic tools cost too much time, since they need to execute all paths to detect vulnerabilities. Thus, their accuracy is limited by time. To tackle this problem, in this paper, we propose Park, the first general framework of parallel-fork symbolic execution for smart contracts. The main idea is to use multiple processes during symbolic execution, leveraging multiple CPU cores to enhance efficiency. Firstly, we propose a fork-operation based dynamic forking algorithm to achieve parallel symbolic contract execution. Secondly, to address the SMT performance loss problem in parallelization, we propose an adaptive processes restriction and adjustment algorithm. Thirdly, we design a shared-memory based global variable reconstruction method to collect and rebuild the global variables from different processes. We implement Park as a plug-in and apply it to two popular symbolic execution tools for smart contracts: Oyente and Mythril. The experimental results with third-party datasets show that Park-Oyente and Park-Mythril can provide up to 6.84x and 7.06x speedup compared to original tools, respectively. CCS CONCEPTS • Software and its engineering → Development frameworks and environments; Software reliability; Software safety.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Efficiently Detecting Reentrancy Vulnerabilities in Complex Smart ContractsZexu Wang, Jiachi Chen, Yanlin Wang, Yu Zhang 等FSE 2024 · 被引用 27 次
- DeepInfer: Deep Type Inference from Smart Contract BytecodeKunsong Zhao, Zihao Li, Jianfeng Li, He Ye 等FSE 2023 · 被引用 24 次
- FlashSyn: Flash Loan Attack Synthesis via Counter Example Driven ApproximationZhiyang Chen, Sidi Mohamed Beillahi, Fan LongICSE 2024 · 被引用 21 次
- Safeguarding DeFi Smart Contracts against Oracle DeviationsXun Deng, Sidi Mohamed Beillahi, Cyrus Minwalla, Han Du 等ICSE 2024 · 被引用 12 次
- Enhancing Smart Contract Security Analysis with Execution Property GraphsKaihua Qin, Zhe Ye, Zhun Wang, Weilin Li 等ISSTA 2025 · 被引用 1 次
它引用的顶会 Paper9
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 被引用 373 次
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 被引用 345 次
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin 等ICSE 2020 · 被引用 260 次
相关 Paper
- SmarTrim: Symbolic Execution for Smart Contracts Powered by Redundant Transaction-Sequence PruningHyegeun Song, Jiseong Han, Sunbeom SoFSE 2026 · 被引用 1 次
- SmartDagger: a bytecode-based static analysis approach for detecting cross-contract vulnerabilityZeqin Liao, Zibin Zheng, Xiao Chen, Yuhong NanISSTA 2022 · 被引用 64 次
- FORAY: Towards Effective Attack Synthesis against Deep Logical Vulnerabilities in DeFi ProtocolsHongbo Wen, Hanzhi Liu, Jiaxin Song, Yanju Chen 等CCS 2024 · 被引用 6 次
- LENT-SSE: Leveraging Executed and Near Transactions for Speculative Symbolic Execution of Smart ContractsPeilin Zheng, Bowei Su, Xiapu Luo, Ting Chen 等ISSTA 2024 · 被引用 1 次
- Towards Smart Contract Fuzzing on GPUsWeimin Chen, Xiapu Luo, Haipeng Cai, Haoyu WangS&P 2024 · 被引用 8 次
