摘要
Smart contract has greatly improved the services and capabilities of blockchain,but it has become the weakest link of blockchain security because of its code nature.Therefore,efficient vulnerability detection of smart contract is the key to ensure the security of blockchain system.Oriented to Ethereum smart contract,the study solves the problems of redundant input and low coverage in the smart contract fuzz.In this paper,a taint analysis method based on EVM is proposed to reduce the invalid input,a dangerous operation database is designed to identify the dangerous input,and genetic algorithm is used to optimize the code coverage of the input,which construct the fuzzing framework for smart contract together.Finally,by comparing Oyente and ContractFuzzer,the performance and efficiency of the framework are proved.
基金
supported by Major Scientific and Technological Special Project of Guizhou Province(20183001)
Exploration and Practice on the Education Mode for Engineering Students Based on Technology,Literature and art Inter-disciplinary Integration with the Internet+Background(022150118004/001)
Open Foundation of Guizhou Provincial Key Laboratory of Public Big Data(2018BDKFJJ014)
Open Foundation of Guizhou Provincial Key Laboratory of Public Big Data(2018BDKFJJ019)
Open Foundation of Guizhou Provincial Key Laboratory of Public Big Data(2018BDKFJJ022).