• Àüü
  • ÀüÀÚ/Àü±â
  • Åë½Å
  • ÄÄÇ»ÅÍ
´Ý±â

»çÀÌÆ®¸Ê

Loading..

Please wait....

±¹³» ³í¹®Áö

Ȩ Ȩ > ¿¬±¸¹®Çå > ±¹³» ³í¹®Áö > Çѱ¹Á¤º¸°úÇÐȸ ³í¹®Áö > Á¤º¸°úÇÐȸ³í¹®Áö (Journal of KIISE)

Á¤º¸°úÇÐȸ³í¹®Áö (Journal of KIISE)

Current Result Document : 1 / 6   ´ÙÀ½°Ç ´ÙÀ½°Ç

ÇѱÛÁ¦¸ñ(Korean Title) ÄÜÄݸ¯ Å×½ºÆà ±â¹Ý ½º¸¶Æ® ÄÁÆ®·¢Æ® º¸¾È¾àÁ¡ ºÐ¼®±â
¿µ¹®Á¦¸ñ(English Title) Smart Contract Weakness Analyzer Based on Concolic Testing
ÀúÀÚ(Author) ÀüÀμº   ¾ÈÁؼ±   Inseong Jeon   Joonseon Ahn  
¿ø¹®¼ö·Ïó(Citation) VOL 48 NO. 06 PP. 0668 ~ 0679 (2021. 06)
Çѱ۳»¿ë
(Korean Abstract)
ÀÌ´õ¸®¿òÀº ´ëÇ¥ÀûÀÎ ºí·ÏüÀÎ ±â¹Ý ¾ÏȣȭÆó Ç÷§ÆûÀ¸·Î, Æ©¸µ ¿ÏÀü ¾ð¾îÀÎ ¼Ö¸®µðƼ¸¦ Á¦°øÇÏ¿© ´Ù¾çÇÑ ÀÀ¿ëÀ» À§ÇÑ ½º¸¶Æ® ÄÁÆ®·¢Æ®¸¦ °³¹ßÇϴµ¥ È°¿ëµÉ ¼ö ÀÖ´Ù. º» ³í¹®Àº ÄÜÄݸ¯ Å×½ºÆà ±â¹ýÀ» »ç¿ëÇÏ¿© ½º¸¶Æ® ÄÁÆ®·¢Æ® ³»ÀÇ º¸¾È¾àÁ¡À» »çÀü¿¡ ã¾Æ³»´Â ºÐ¼®±â¸¦ Á¦½ÃÇÑ´Ù. ½Éº¼¸¯ ¼öÇà°ú Å×½ºÆà ±â¹ýÀÌ ÇÕÃÄÁø ÄÜÄݸ¯ Å×½ºÆÃÀº ÀϹÝÀûÀÎ Á¤Àû ºÐ¼®°ú ºñ±³ÇÏ¿© ¿ÀŽÀÌ ¾ø´Â ½Éº¼¸¯ ¼öÇàÀÇ ÀåÁ¡À» À¯ÁöÇϸ鼭, ½Éº¼¸¯ ¼öÇຸ´Ù ¼º´É ¸é¿¡¼­ È¿À²ÀûÀÎ ÀåÁ¡ÀÌ ÀÖ´Ù. ¶ÇÇÑ, °³¹ßµÈ ºÐ¼®±â´Â ÀÌ´õ¸®¿òÀÇ ½ÇÇà ȯ°æÀÎ °Ô½º Å×½ºÆ®³ÝÀ» »ç¿ëÇÏ¿© ½ÇÁ¦ÀûÀÎ ¼öÇà»óȲÀ» ÃÖ´ëÇÑ ¹Ý¿µÇÏ¿© µ¿ÀÛÇÑ´Ù. ºÐ¼®±â´Â Á¤¼ö ³Ñħ°ú 󸮵ÇÁö ¾ÊÀº ¿¹¿Ü º¸¾È¾àÁ¡ÀÇ °ËÃâÀ» Áö¿øÇϸç, ±¸Çö °á°ú¿¡ ´ëÇÏ¿© ±âÁ¸ ºÐ¼®±â¿ÍÀÇ ºñ±³¸¦ ÅëÇØ °³¹ßµÈ ºÐ¼®±âÀÇ ¼º´ÉÀ» ºÐ¼®ÇÏ¿´´Ù
¿µ¹®³»¿ë
(English Abstract)
Ethereum is a blockchain-based cryptocurrency platform that provides a Turing complete language, Solidity, which can be used to develop smart contracts for various applications. This paper present an analyzer that finds security weaknesses in smart contracts using the concolic testing framework. Concolic testing, which combines symbolic execution and testing, is more efficient than symbolic execution while retaining no false positiveness which is absent in static analysis. Also, the analyzer reflects actual execution context to the maximum extent possible using the Ethereum execution environment, the Geth testnet. The analyzer detects integer overflow and unhandled exception weakness. Also, this paper presents performance test results in comparison with a well known smart contract symbolic execution framework, Manticore.
Å°¿öµå(Keyword) ºí·ÏüÀΠ  ½º¸¶Æ® ÄÁÆ®·¢Æ®   ÄÜÄݸ¯ Å×½ºÆà  º¸¾È¾àÁ¡   ½Éº¼¸¯ ¼öÇà   blockchain   smart contract   concolic testing   security weakness   symbolic execution  
ÆÄÀÏ÷ºÎ PDF ´Ù¿î·Îµå