conference-paper

Move Smart Contract Vulnerability Detection based on Resource-flow Analysis

Research footprint

At a glance

Citations
1
References
22
Comments
0
Paper overview

Abstract

The Move smart contract (MSC) is designed to enhance the type security of digital assets by utilizing a resource-based structure. However, vulnerabilities may be introduced during the development process. In response to the security threats faced by digital assets in the MSC, we have identified five resource-related vulnerabilities for the first time. Additionally, we have defined two test oracles and proposed a method to detect these vulnerabilities in the MSC using resource-flow analysis. Our method begins by analyzing the resource types present in the MSC. Based on the resource operation information within the contract function, we create a resource-flow graph. Next, the resource-flows are derived from the Resource-Flow Graph using a traversal algorithm, and they are then transformed into test cases. In the final step, the generated test cases are executed, and the vulnerabilities are detected by utilizing the proposed test oracles. Through a comprehensive case study, we showcase the various resource-related vulnerabilities and assess the feasibility of our method in detecting these vulnerabilities. The results demonstrate that our proposed method is effective in identifying resource-related vulnerabilities.

Record transparency

Publication details

DOI
10.1109/dsa59317.2023.00054
OpenAlex
W4388666793
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.