Precise static modeling of Ethereum "memory"
Sifis Lagouvardos, Neville Grech, Ilias Tsatiris, Yannis Smaragdakis
摘要
Static analysis of smart contracts as-deployed on the Ethereum blockchain has received much recent attention. However, high-precision analyses currently face significant challenges when dealing with the Ethereum VM (EVM) execution model. A major such challenge is the modeling of low-level, transient “memory” (as opposed to persistent, on-blockchain “storage”) that smart contracts employ. Statically understanding the usage patterns of memory is non-trivial, due to the dynamic allocation nature of in-memory buffers. We offer an analysis that models EVM memory, recovering high-level concepts (e.g., arrays, buffers, call arguments) via deep modeling of the flow of values. Our analysis opens the door to Ethereum static analyses with drastically increased precision. One such analysis detects the extraction of ERC20 tokens by unauthorized users. For another practical vulnerability (redundant calls, possibly used as an attack vector), our memory modeling yields analysis precision of 89%, compared to 16% for a state-of-the-art tool without precise memory modeling. Additionally, precise memory modeling enables the static computation of a contract’s gas cost. This gas-cost analysis has recently been instrumental in the evaluation of the impact of the EIP-1884 repricing (in terms of gas costs) of EVM operations, leading to a reward and significant publicity from the Ethereum Foundation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- eTainter: detecting gas-related vulnerabilities in smart contractsAsem Ghaleb, Julia Rubin, Karthik PattabiramanISSTA 2022 · 被引用 57 次
- WASAI: uncovering vulnerabilities in Wasm smart contractsWeimin Chen, Zihan Sun, Haoyu Wang, Xiapu Luo 等ISSTA 2022 · 被引用 43 次
- Elipmoc: advanced decompilation of Ethereum smart contractsNeville Grech, Sifis Lagouvardos, Ilias Tsatiris, Yannis SmaragdakisOOPSLA 2022 · 被引用 40 次
- Symbolic value-flow static analysis: deep, precise, complete modeling of Ethereum smart contractsYannis Smaragdakis, Neville Grech, Sifis Lagouvardos, Konstantinos Triantafyllou 等OOPSLA 2021 · 被引用 18 次
- Practical Verification of Smart Contracts using Memory SplittingShelly Grossman, John Toman, Alexander Bakst, Sameer Arora 等OOPSLA 2024 · 被引用 7 次
它引用的顶会 Paper6
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 被引用 345 次
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov 等CCS 2019 · 被引用 288 次
- VerX: Safety Verification of Smart ContractsAnton Permenev, Dimitar Dimitrov, Petar Tsankov, Dana Drachsler-Cohen 等S&P 2020 · 被引用 251 次
相关 Paper
- Synthesis of Sound and Precise Storage Cost Bounds via Unsound Resource Analysis and Max-SMTElvira Albert, Jesús Correas, Pablo Gordillo, Guillermo Román-Díez 等ISSTA 2024 · 被引用 1 次
- ETHBMC: A Bounded Model Checker for Smart ContractsJoel Frank, Cornelius Aschermann, Thorsten HolzUSENIX Security 2020
- PrettySmart: Detecting Permission Re-delegation Vulnerability for Token Behaviors in Smart ContractsZhijie Zhong, Zibin Zheng, Hong-Ning Dai, Qing Xue 等ICSE 2024 · 被引用 12 次
- eThor: Practical and Provably Sound Static Analysis of Ethereum Smart ContractsClara Schneidewind, Ilya Grishchenko, Markus Scherer, Matteo MaffeiCCS 2020 · 被引用 9 次
- Enhancing Smart Contract Security Analysis with Execution Property GraphsKaihua Qin, Zhe Ye, Zhun Wang, Weilin Li 等ISSTA 2025 · 被引用 1 次
