Demystifying Invariant Effectiveness for Securing Smart Contracts
Zhiyang Chen, Ye Liu, Sidi Mohamed Beillahi, Yi Li, Fan Long
摘要
Smart contract transactions associated with security attacks often exhibit distinct behavioral patterns compared with historical benign transactions before the attacking events. While many runtime monitoring and guarding mechanisms have been proposed to validate invariants and stop anomalous transactions on the fly, the empirical effectiveness of the invariants used remains largely unexplored. In this paper, we studied 23 prevalent invariants of 8 categories, which are either deployed in high-profile protocols or endorsed by leading auditing firms and security experts. Using these well-established invariants as templates, we developed a tool Trace2Inv which dynamically generates new invariants customized for a given contract based on its historical transaction data. We evaluated Trace2Inv on 42 smart contracts that fell victim to 27 distinct exploits on the Ethereum blockchain. Our findings reveal that the most effective invariant guard alone can successfully block 18 of the 27 identified exploits with minimal gas overhead. Our analysis also shows that most of the invariants remain effective even when the experienced attackers attempt to bypass them. Additionally, we studied the possibility of combining multiple invariant guards, resulting in blocking up to 23 of the 27 benchmark exploits and achieving false positive rates as low as 0.28%. Trace2Inv significantly outperforms state-of-the-art works on smart contract invariant mining and transaction attack detection in accuracy. Trace2Inv also surprisingly found two previously unreported exploit transactions.
CCS Concepts: • Security and privacy → Software security engineering; • Software and its engineering → Software testing and debugging.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Detecting Various DeFi Price Manipulations with LLM ReasoningJuantao Zhong, Daoyuan Wu, Ye Liu, Maoyi Xie 等ASE 2025 · 被引用 3 次
- Precise Static Identification of Ethereum Storage VariablesSifis Lagouvardos, Yannis Bollanos, Michael Debono, Neville Grech 等ICSE 2026 · 被引用 2 次
- HOUSTON: Real-Time Anomaly Detection of Attacks against Ethereum DeFi ProtocolsDongyu Meng, Fabio Gritti, Robert McLaughlin, Nicola Ruaro 等NDSS 2026 · 被引用 2 次
- Automated Attack Synthesis for Constant Product Market MakersSujin Han, Jinseo Kim, Sung-Ju Lee, Insu YunISSTA 2025
- Democratizing the Cryptocurrency Ecosystem by Just-In-Time Transformation of Mining ProgramsWei Liu, Zhenhua Li, Feng Qian, Feiyu Jin 等ASE 2025
它引用的顶会 Paper16
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Sereum: Protecting Existing Smart Contracts Against Re-Entrancy AttacksMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviNDSS 2019 · 被引用 298 次
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin 等ICSE 2020 · 被引用 260 次
- SMARTIAN: Enhancing Smart Contract Fuzzing with Static and Dynamic Data-Flow AnalysesJaeseung Choi, Doyeon Kim, Soomin Kim, Gustavo Grieco 等ASE 2021 · 被引用 164 次
- Ethainter: a smart contract security analyzer for composite vulnerabilitiesLexi Brent, Neville Grech, Sifis Lagouvardos, Bernhard Scholz 等PLDI 2020 · 被引用 163 次
相关 Paper
- Enforcing Control Flow Integrity on DeFi Smart ContractsZhiyang Chen, Sidi Mohamed Beillahi, Pasha Barahimi, Cyrus Minwalla 等ICSE 2026
- An Ever-evolving Game: Evaluation of Real-world Attacks and Defenses in Ethereum EcosystemShunfan Zhou, Zhemin Yang, Jie Xiang, Yinzhi Cao 等USENIX Security 2020
- Automated Inference on Financial Security of Ethereum Smart ContractsWansen Wang, Wenchao Huang, Zhaoyi Meng, Yan Xiong 等USENIX Security 2023
- Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker ContractsShuo Yang, Jiachi Chen, Mingyuan Huang, Zibin Zheng 等ICSE 2024 · 被引用 24 次
- Characterizing Transaction-Reverting Statements in Ethereum Smart ContractsLu Liu, Lili Wei, Wuqi Zhang, Ming Wen 等ASE 2021 · 被引用 25 次
