CRII: SaTC: Discerning the Upgradeability of Smart Contracts in Blockchains From a Security Perspective

CRII:SaTC:从安全角度辨别区块链智能合约的可升级性

基本信息

  • 批准号:
    2245627
  • 负责人:
  • 金额:
    $ 17.48万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2023
  • 资助国家:
    美国
  • 起止时间:
    2023-03-15 至 2024-12-31
  • 项目状态:
    已结题

项目摘要

Smart contracts in blockchains, which store cryptocurrencies and tokens worth billions of USD, have transformed many important aspects of our lives, such as finance and gaming. Smart contracts are widely believed to have strong security guarantees as they are immutable once deployed, not even the owner of the contract can change its code. However, a new type of smart contract, namely upgradeable smart contract (USC), allows developers to upgrade the logic of their smart contracts and practically breaks the security assumption. This special type of smart contract has become increasingly prominent and has been adopted by many major companies (e.g., Compound Finance and Opensea.io). Despite the importance, there exists no comprehensive research that studies the status quo of USCs in the wild and even worse, the emerging security risks that are associated with upgradeability. This project conducts a series of novel studies to discern the upgradeability of smart contracts in the real world. Specifically, it answers three essential research questions regarding the importance of USCs in the current market, different design patterns and their strengths and weaknesses, and more importantly, the real-world security risks with USCs. To do so, this project pioneers a practical static analysis-based approach to effectively detect USCs based on intrinsic characteristics, and perform further automatic behavior and security analyses. To differentiate USC design patterns, this project develops a complete taxonomy that can systematically characterize USCs at both syntactic and semantic levels. Moreover, the investigator conducts the first extensive and large-scale study on USCs to uncover and report unique designs and security risks in the real world. Eventually, this project creates the first comprehensive USC dataset that facilitates future research in this emerging direction.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
区块链中的智能合约存储了价值数十亿美元的加密货币和代币,已经改变了我们生活的许多重要方面,例如金融和游戏。人们普遍认为智能合约具有强大的安全保证,因为它们一旦部署就不可更改,即使是合约的所有者也无法更改其代码。然而,一种新型智能合约,即可升级智能合约(USC),允许开发人员升级其智能合约的逻辑,实际上打破了安全假设。这种特殊类型的智能合约变得越来越突出,并已被许多大公司采用(例如,Compound Finance 和 Opensea.io)。尽管很重要,但目前还没有全面的研究来研究 USC 的现状,更糟糕的是,还没有研究与可升级性相关的新兴安全风险。该项目进行了一系列新颖的研究,以辨别现实世界中智能合约的可升级性。具体来说,它回答了三个基本研究问题:USC 在当前市场中的重要性、不同的设计模式及其优缺点,更重要的是 USC 的现实安全风险。为此,该项目开创了一种基于静态分析的实用方法,可以根据内在特征有效检测 USC,并执行进一步的自动行为和安全分析。为了区分 USC 设计模式,该项目开发了一个完整的分类法,可以在句法和语义层面系统地表征 USC。此外,研究人员对 USC 进行了首次广泛和大规模的研究,以发现和报告现实世界中的独特设计和安全风险。最终,该项目创建了第一个综合的南加州大学数据集,促进了这一新兴方向的未来研究。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Proxy Hunting: Understanding and Characterizing Proxy-based Upgradeable Smart Contracts in Blockchains
代理狩猎:理解和表征区块链中基于代理的可升级智能合约
  • DOI:
    10.48550/arxiv.2310.20212
  • 发表时间:
    2024-09-14
  • 期刊:
  • 影响因子:
    0
  • 作者:
    William Edward Bodell;Sajad Meisami;Yue Duan
  • 通讯作者:
    Yue Duan
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Binghui Wang其他文献

State Estimation via Inference on a Probabilistic Graphical Model - A Different Perspective
通过概率图形模型推理进行状态估计 - 不同的视角
Microwave-Assisted Synthesis of Silver Nanoparticles in Alkalic Carboxymethyl Chitosan Solution
碱性羧甲基壳聚糖溶液中微波辅助合成纳米银粒子
  • DOI:
    10.4236/eng.2010.25050
  • 发表时间:
    2010-05-31
  • 期刊:
  • 影响因子:
    12.8
  • 作者:
    Binghui Wang;Xupin Zhuang;W. Deng;B. Cheng
  • 通讯作者:
    B. Cheng
Towards Adversarial Patch Analysis and Certified Defense against Crowd Counting
迈向对抗性斑块分析和针对人群计数的认证防御
High-Quality AlN Grown by a Combination of Substrate Pretreatment and Periodic Growth Mode Control
通过结合基底预处理和周期性生长模式控制生长高质量 AlN
  • DOI:
    10.1021/acs.cgd.3c00146
  • 发表时间:
    2023-05-31
  • 期刊:
  • 影响因子:
    0
  • 作者:
    S. Dong;Yanhui Xing;Xuguang Deng;C. Zeng;Chengcheng Zhi;Jiaming Weng;Wenbo Tang;Binghui Wang;Jiahao Li;Tong Liu;Jun Han;Baoshun Zhang;Z. Zeng
  • 通讯作者:
    Z. Zeng
Frequency Equation of Flexural Vibrating Cantilever Beam Considering the Rotary Inertial Moment of an Attached Mass
考虑附着质量转动惯量的弯曲振动悬臂梁频率方程

Binghui Wang的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Binghui Wang', 18)}}的其他基金

CAREER: Towards Trustworthy Machine Learning via Learning Trustworthy Representations: An Information-Theoretic Framework
职业:通过学习可信表示实现可信机器学习:信息理论框架
  • 批准号:
    2339686
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Continuing Grant
Collaborative Research: SHF: Small: LEGAS: Learning Evolving Graphs At Scale
协作研究:SHF:小型:LEGAS:大规模学习演化图
  • 批准号:
    2331302
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Understanding the Robustness of Graph Neural Networks against Graph Perturbations
CRII:SaTC:了解图神经网络对抗图扰动的鲁棒性
  • 批准号:
    2241713
  • 财政年份:
    2023
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant

相似海外基金

CRII: SaTC: Privacy vs. Accountability--Usable Deniability and Non-Repudiation for Encrypted Messaging Systems
CRII:SaTC:隐私与责任——加密消息系统的可用否认性和不可否认性
  • 批准号:
    2348181
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
  • 批准号:
    2327427
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Continuing Grant
SaTC: EDU: AI for Cybersecurity Education via an LLM-enabled Security Knowledge Graph
SaTC:EDU:通过支持 LLM 的安全知识图进行网络安全教育的人工智能
  • 批准号:
    2335666
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Continuing Grant
SaTC: CORE: Medium: Increasing user autonomy and advertiser and platform responsibility in online advertising
SaTC:核心:中:增加在线广告中的用户自主权以及广告商和平台责任
  • 批准号:
    2318290
  • 财政年份:
    2024
  • 资助金额:
    $ 17.48万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了