Fuzzing Enterprise-Grade Blockchain Systems: Industrial Practice and Solutions
Fuchen Ma, Yuanliang Chen, Zhen Yan, Yuanhang Zhou, Yu Jiang, Mingchao Wan
摘要
Blockchain has been widely adopted across diverse sectors. Yet, enterprise-grade systems remain vulnerable to critical flaws that undermine stability and security. Although academic fuzzing tools such as LOKI and Tyr have shown effectiveness in detecting such issues, their integration into industrial practice remains challenging.
In this paper, we present the industry practice of implementing system-level fuzzing techniques on enterprise-level blockchains. We summarize three main obstacles in industry deployment, namely the hard-to-build state models for fuzzing, the slow convergence of fuzz testing within CI/CD pipelines, and the difficulty of adapting logical bug oracles across diverse blockchain implementations. To address these obstacles, we design Thor, a practical fuzzing framework for industry blockchain systems. Thor uses active and passive packet generation for early stage state-aware testing. To perform efficient fuzzing under strict CI/CD time budgets, Thor adopts a two-tier parallel fuzzing method. And Thor also uses LLM-based oracles to extract logic properties from node logs. Over these years, Thor has discovered 87 bugs in 9 commercial blockchain systems, such as Chainmaker, Go-Ethereum, and WeBank FISCO BCOS.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov 等CCS 2019 · 被引用 288 次
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin 等ICSE 2020 · 被引用 260 次
- Regression Greybox FuzzingXiaogang Zhu, Marcel BöhmeCCS 2021 · 被引用 84 次
- ItyFuzz: Snapshot-Based Fuzzer for Smart ContractChaofan Shou, Shangyin Tan, Koushik SenISSTA 2023 · 被引用 76 次
相关 Paper
- LOKI: State-Aware Fuzzing Framework for the Implementation of Blockchain Consensus ProtocolsFuchen Ma, Yuanliang Chen, Meng Ren, Yuanhang Zhou 等NDSS 2023
- Fork State-Aware Differential Fuzzing for Blockchain Consensus ImplementationsWonhoi Kim, Hocheol Nam, Muoi Tran, Amin Jalilov 等ICSE 2025 · 被引用 1 次
- Tyr: Finding Consensus Failure Bugs in Blockchain System with Behaviour Divergent ModelYuanliang Chen, Fuchen Ma, Yuanhang Zhou, Yu Jiang 等S&P 2023
- RPCSpecter: Detecting Blockchain RPC Bugs through a Specification-Driven, Constraint-Aware Fuzzing ApproachYuming Xiao, Yuhong Nan, Zhijie Zhong, Mingxi Ye 等ISSTA 2026
- Finding Consensus Bugs in Ethereum via Multi-transaction Differential FuzzingYoungseok Yang, Taesoo Kim, Byung-Gon ChunOSDI 2021 · 被引用 57 次
