Your Exploit is Mine: Instantly Synthesizing Counterattack Smart Contract
Zhuo Zhang, Zhiqiang Lin, Marcelo Morales, Xiangyu Zhang, Kaiyuan Zhang
摘要
Smart contracts are susceptible to exploitation due to their unique nature. Despite efforts to identify vulnerabilities using fuzzing, symbolic execution, formal verification, and manual auditing, exploitable vulnerabilities still exist and have led to billions of dollars in monetary losses. To address this issue, it is critical that runtime defenses are in place to minimize exploitation risk. In this paper, we present STING, a novel runtime defense mechanism against smart contract exploits. The key idea is to instantly synthesize counterattack smart contracts from attacking transactions and leverage the power of Maximal Extractable Value (MEV) to front run attackers. Our evaluation with 62 real-world recent exploits demonstrates its effectiveness, successfully countering 54 of the exploits (i.e., intercepting all the funds stolen by the attacker). In comparison, a general front-runner defense could only handle 12 exploits. Our results provide a clear proof-of-concept that STING is a viable defense mechanism against smart contract exploits and has the potential to significantly reduce the risk of exploitation in the smart contract ecosystem.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Nyx: Detecting Exploitable Front-Running Vulnerabilities in Smart ContractsWuqi Zhang, Zhuo Zhang, Qingkai Shi, Lu Liu 等S&P 2024 · 被引用 23 次
- Demystifying Invariant Effectiveness for Securing Smart ContractsZhiyang Chen, Ye Liu, Sidi Mohamed Beillahi, Yi Li 等FSE 2024 · 被引用 15 次
- Rolling in the Shadows: Analyzing the Extraction of MEV Across Layer-2 RollupsChristof Ferreira Torres, Albin Mamuti, Ben Weintraub, Cristina Nita-Rotaru 等CCS 2024 · 被引用 12 次
- SlimArchive: A Lightweight Architecture for Ethereum Archive NodesHang Feng, Yufeng Hu, Yinghan Kou, Runhuai Li 等USENIX ATC 2024 · 被引用 11 次
- Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source ContractsSen Yang, Kaihua Qin, Aviv Yaish, Fan ZhangCCS 2026 · 被引用 3 次
它引用的顶会 Paper19
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 被引用 345 次
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 被引用 336 次
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin 等ICSE 2020 · 被引用 260 次
相关 Paper
- An Ever-evolving Game: Evaluation of Real-world Attacks and Defenses in Ethereum EcosystemShunfan Zhou, Zhemin Yang, Jie Xiang, Yinzhi Cao 等USENIX Security 2020
- On Identifying Sound Conditions for Frontrunning ResistanceSebastian Holler, Anna Piscitelli, Jannik Albrecht, Stephan Dübler 等CCS 2026
- SmarTest: Effectively Hunting Vulnerable Transaction Sequences in Smart Contracts through Language Model-Guided Symbolic ExecutionSunbeom So, Seongjoon Hong, Hakjoo OhUSENIX Security 2021 · 被引用 118 次
- Summary-Based Symbolic Evaluation for Smart ContractsYu Feng, Emina Torlak, Rastislav BodíkASE 2020 · 被引用 15 次
- Demystifying Exploitable Bugs in Smart ContractsZhuo Zhang, Brian Zhang, Wen Xu, Zhiqiang LinICSE 2023 · 被引用 80 次
