Towards Automatic Discovery of Denial of Service Weaknesses in Blockchain Resource Models
Feng Luo, Huangkun Lin, Zihao Li, Xiapu Luo, Ruijie Luo, Zheyuan He, Shuwei Song, Ting Chen, Wenxuan Luo
摘要
Denial-of-Service (DoS) attacks at the execution layer represent one of the most severe threats to blockchain systems, compromising availability by depleting the resources of victims. To counteract these attacks, many blockchains have implemented unique resource models that incorporate transaction fees. Nevertheless, historical incidents of DoS attacks demonstrate that these resource model designs remain inadequate. Although there are studies that manually craft DoS attacks on specific blockchains in isolation, none of them can discover DoS weaknesses in blockchains automatically. In this paper, we provide an insight into DoS weaknesses in blockchain resource models, and present a generic and systematic approach to uncover these weaknesses. In our approach, we first identify DoS weaknesses by DoSVER, a novel tool that reasons feasible DoS weaknesses against blockchain resource models by formal verification. The identified DoS weaknesses will be further validated by DoSDET, a new framework that automates the attack synthesis in exploiting the identified DoS weaknesses. We conduct a comprehensive and systematic evaluation by extensive experiments on nine diverse and widely-used blockchains, and discovered 12 DoS weaknesses with corresponding exploitation across the nine blockchains, 10 of which were unveiled for the first time. CCS Concepts • Security and privacy → Distributed systems security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- fAmulet: Finding Finalization Failure Bugs in Polygon zkRollupZihao Li, Xinghao Peng, Zheyuan He, Xiapu Luo 等CCS 2024 · 被引用 5 次
- Light into Darkness: Demystifying Profit Strategies Throughout the MEV Bot LifecycleFeng Luo, Zihao Li, Wenxuan Luo, Zheyuan He 等NDSS 2026 · 被引用 4 次
- When HTTP 402 Meets the Blockchain: Risks on Emerging x402 PaymentsQinying Wang, Yong Yang, Yuan Chen, Shouling Ji 等USENIX Security 2026
- The Perils of Flexibility: Uncovering Application-Layer Vulnerabilities in Cosmos SDK Customization PointsPengxiang Ma, Ningyu He, Zhongchun Cao, Zihao Li 等USENIX Security 2026
- Auspex: Unveiling Inconsistency Bugs of Transaction Fee Mechanism in BlockchainZheyuan He, Zihao Li, Jiahao Luo, Feng Luo 等USENIX Security 2025
它引用的顶会 Paper11
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- EOSAFE: Security Analysis of EOSIO Smart ContractsNingyu He, Ruiyi Zhang, Haoyu Wang, Lei Wu 等USENIX Security 2021 · 被引用 69 次
- Finding Consensus Bugs in Ethereum via Multi-transaction Differential FuzzingYoungseok Yang, Taesoo Kim, Byung-Gon ChunOSDI 2021 · 被引用 57 次
- eTainter: detecting gas-related vulnerabilities in smart contractsAsem Ghaleb, Julia Rubin, Karthik PattabiramanISSTA 2022 · 被引用 57 次
- SCVHunter: Smart Contract Vulnerability Detection Based on Heterogeneous Graph Attention NetworkFeng Luo, Ruijie Luo, Ting Chen, Ao Qiao 等ICSE 2024 · 被引用 38 次
相关 Paper
- BDoS: Blockchain Denial-of-ServiceMichael Mirkin, Yan Ji, Jonathan Pang, Ariah Klages-Mundt 等CCS 2020 · 被引用 1 次
- Following the "Thread": Toward Finding Manipulatable Bottlenecks in Blockchain ClientsShuohan Wu, Zihao Li, Hao Zhou, Xiapu Luo 等ISSTA 2024
- Broken Metre: Attacking Resource Metering in EVMDaniel Perez, Benjamin LivshitsNDSS 2020
- As Strong As Its Weakest Link: How to Break Blockchain DApps at RPC ServiceKai Li, Jiaqi Chen, Xianghong Liu, Yuzhe Richard Tang 等NDSS 2021
- Careless Retention and Management: Understanding and Detecting Data Retention Denial-of-Service Vulnerabilities in Java Web ContainersKeke Lian, Lei Zhang, Haoran Zhao, Yinzhi Cao 等USENIX Security 2025
