A blockchain network security testing method, system, device and storage medium

By generating automated attack packages through a cybersecurity testing platform and establishing an arsenal system, the shortcomings of blockchain system security testing are addressed, comprehensive vulnerability coverage and timely prevention are achieved, and the security and user trust of the blockchain system are improved.

CN115834111BActive Publication Date: 2026-04-07HANGZHOU QULIAN TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-29
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing technologies lack effective security testing schemes for blockchain systems, making it difficult to fully cover new vulnerabilities, resulting in insufficient security of blockchain systems and low user trust.

Method used

By receiving attack plans from security personnel through a network security testing platform, generating automated attack packages, and establishing an arsenal system, users can select and execute attack programs themselves. Combining static and dynamic sorting mechanisms, a comprehensive vulnerability testing and reward mechanism is provided to improve the security of the blockchain system.

Benefits of technology

It enables comprehensive vulnerability testing of the blockchain system, improves security, promptly identifies new vulnerabilities and alerts users to take precautions, thereby enhancing user trust and system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834111B_ABST
    Figure CN115834111B_ABST
Patent Text Reader

Abstract

This invention relates to the field of information technology, specifically to a blockchain network security testing method, system, device, and storage medium. The method includes the following steps: issuing account addresses and private keys to security personnel; receiving attack schemes submitted by security personnel; receiving automated attack programs developed by an administrator after verifying the attack schemes; uploading the automated attack package to a designated blockchain; issuing a smart contract to transfer the automated attack package to the arsenal system; receiving user registration information; receiving test requests submitted by users, the test requests including attack package numbers and the address of the blockchain system to be tested; and distributing token rewards based on the number of times the automated attack package is used. The beneficial technical effects of this invention include: by integrating the vulnerability testing results of multiple security personnel, this invention can more comprehensively cover security vulnerability testing, thereby improving the security of the blockchain system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information technology, in particular to a blockchain network security testing method, system, device and storage medium. BACKGROUND

[0002] The blockchain system can naturally establish a trusted proof between users, and has the characteristics of common maintenance, openness, transparency and traceability. Therefore, it has been widely applied, and more and more enterprises or groups have developed their own blockchain systems. Before using the blockchain, these users will have doubts about the security of the blockchain system. Because the blockchain system carries high-value assets. Therefore, it is particularly important to ensure the security of the blockchain system. However, there is currently no complete blockchain system security verification and evaluation method to comprehensively evaluate the blockchain system. In addition, the current blockchain systems are not interconnected. Many blockchain systems only test some common important vulnerabilities when performing security verification and evaluation. For example, double-spending attack and Sybil attack. However, while the blockchain technology is rapidly iterating, new and dangerous blockchain security vulnerabilities are also emerging. If only the previously discovered conventional vulnerabilities are tested when performing security verification and evaluation on the blockchain system, it will be difficult to truly ensure the security of the system, and it will also make users less trust, which is not conducive to the healthy development of the system. Therefore, it is necessary to study a security testing scheme for the blockchain system that can be updated continuously.

[0003] For example, Chinese patent CN114676052A, published on March 24, 2022, discloses a blockchain-based smart contract logic vulnerability detection method and device, relating to the field of blockchain. The method comprises: determining the state machine model of the smart contract in the blockchain, wherein the state machine model is a model generated based on the target clause information and the commitment model of the smart contract, wherein the commitment model is a model generated by a plurality of commitment information; based on the state machine model and the game theory, determining the Nash equilibrium of the smart contract and calculating the revenue of the Nash equilibrium; determining the logic vulnerability detection result of the smart contract according to the revenue of the Nash equilibrium. The technical solution solves the problem of low detection efficiency, but cannot solve the dynamic updating of vulnerability detection and cannot effectively protect the security of the blockchain system. SUMMARY

[0004] The technical problem to be solved by the present application is the lack of an effective scheme to protect the security of the blockchain system. A blockchain network security testing method, system, device and storage medium are proposed, which can dynamically provide network security testing for the blockchain system and improve the security of the blockchain system.

[0005] To solve the above technical problems, the application adopts the following technical solutions: a network security testing method of a blockchain, executed by a network security testing platform, comprising the following steps:

[0006] Receiving a registration application of a security personnel, issuing an account address and a private key to the security personnel;

[0007] Receiving an attack scheme and a scheme signature submitted by the security personnel for successfully attacking the blockchain system, wherein the attack scheme comprises attack steps and an attack script;

[0008] Receiving an automatic attack program, function description information and a maker signature submitted by an administrator, assigning a number to the automatic attack program, generating an automatic attack package, and uploading the automatic attack package to a specified blockchain;

[0009] Publishing an intelligent contract on the specified blockchain, periodically polling the blockchain, and carrying the discovered automatic attack package to an arsenal system established by the network security testing platform;

[0010] Receiving user registration information and assigning a user account to the user;

[0011] Receiving a test request submitted by the user, wherein the test request comprises an attack package number and an address of a blockchain system to be tested, and running the automatic attack program corresponding to the attack package number to attack the blockchain system to be tested;

[0012] Periodically rewarding the account address of the corresponding security personnel with tokens according to the number of times the automatic attack package is used.

[0013] As a preferred embodiment, the arsenal system statically sorts the automatic attack packages, and the static sorting method comprises:

[0014] Associating the automatic attack package with a vulnerability of the corresponding blockchain system;

[0015] Dividing the vulnerability of the blockchain system into a vulnerability risk level by an administrator;

[0016] Arranging the automatic attack packages in descending order according to the associated vulnerability risk level;

[0017] Arranging the automatic attack packages according to the first letter of the associated vulnerability name.

[0018] As a preferred embodiment, the arsenal system dynamically sorts the automatic attack packages, and the dynamic sorting method comprises:

[0019] If the uploading duration of the automatic attack package is less than a preset threshold, the automatic attack package is included in a priority display set;

[0020] Arranging the automatic attack packages in the priority display set in descending order according to the uploading time.

[0021] The automated attack package in the priority display set is displayed before other automated attack packages;

[0022] The administrator classifies the vulnerability of the blockchain system into a vulnerability danger level, which is expressed by a danger value, and the higher the vulnerability danger level, the greater the danger value;

[0023] The product of the use frequency of the automated attack package and the danger value is calculated as a sorting characteristic value;

[0024] The automated attack packages are arranged in descending order of the sorting characteristic value;

[0025] If the sorting characteristic values of the automated attack packages are the same, the automated attack package with an earlier upload time is arranged in front.

[0026] As preferred, the method for the selected automated attack package to attack the selected blockchain system comprises:

[0027] The weapon library system constructs an automatic attack smart contract, which records the number of the automated attack program and the platform user;

[0028] The weapon library system loads the automated attack program into the automatic attack smart contract and publishes the automatic attack smart contract on the selected blockchain system;

[0029] When the smart contract is executed, the automated attack program will be automatically executed.

[0030] As preferred, the network security test platform periodically counts the use frequency of the automated attack package in a period, and the product of the frequency, a preset reward coefficient and the danger value is taken as a reward amount, and the token corresponding to the reward amount is transferred to the account address of the corresponding security personnel.

[0031] As preferred, the network security test platform counts historical test information of multiple blockchain systems;

[0032] The blockchain system is associated with the number of the automated attack program that successfully implements the attack;

[0033] The security similarity of two blockchain systems is calculated;

[0034] When the blockchain system is successfully attacked by a new automated attack program, the network security test platform queries all the blockchain systems with a security similarity higher than a preset threshold value to the blockchain system that is successfully attacked;

[0035] Test suggestions are pushed to all blockchain systems obtained from the query. The test suggestions include the ID and functional description information of the automated attack program that successfully carried out the attack.

[0036] Preferred methods for calculating the security similarity between two blockchain systems include:

[0037] Obtain the IDs of the automated attack programs that successfully carried out attacks associated with the blockchain system and add them to the attack ID set;

[0038] Obtain the union and intersection of the attack ID sets of the two blockchain systems respectively;

[0039] The security similarity between two blockchain systems is determined by the ratio of the number of elements in the union and intersection to the number of elements in the union.

[0040] A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the method as claimed in any one of claims 1 to 7.

[0041] A computer-readable storage medium storing a computer program that, when executed by a processor, implements the method as claimed in any one of claims 1 to 7.

[0042] A blockchain cybersecurity testing system is provided for executing a blockchain cybersecurity testing method as described above, including an access module, an administrator module, a member module, an arsenal system, and a reward module.

[0043] The access module receives registration requests and attack plans from security personnel, issues account addresses and private keys to them, and the administrator module reads the attack plans received by the access module and displays them to the administrator. It also receives automated attack programs provided by the administrator, assigns numbers to these programs, and receives functional descriptions added by the administrator to form automated attack packages. These packages are then added to the arsenal system. The member module receives user registration requests, assigns accounts and private keys, and makes users platform users. The arsenal system receives invocation requests from platform users, including numbers and target blockchain systems. The arsenal system runs the automated attack program corresponding to the number on the target blockchain system. The reward module periodically issues token rewards to the corresponding security personnel's account addresses based on the number of times the automated attack packages are used.

[0044] Preferably, the arsenal system includes a sorting module, which performs static and dynamic sorting of automated attack packets. During static sorting, the sorting module executes the following steps:

[0045] Associate automated attack packages with vulnerabilities in corresponding blockchain systems;

[0046] Administrators classify the vulnerability severity levels of the blockchain system.

[0047] Automated attack packages are sorted in descending order of their associated vulnerability severity level;

[0048] Automated attack packages with the same vulnerability risk level are sorted alphabetically by the first letter of the associated vulnerability name;

[0049] When performing dynamic sorting, the sorting module executes the following steps:

[0050] If the upload time of the automated attack packet is less than the preset threshold, it will be included in the priority display set;

[0051] The automated attack packets within the collection will be displayed first, sorted in descending order of upload time.

[0052] Automated attack packages within a collection are prioritized and displayed before other automated attack packages.

[0053] The administrator classifies the vulnerabilities of the blockchain system into vulnerability risk levels, which are represented by a risk value. The higher the vulnerability risk level, the greater the risk value.

[0054] Calculate the product of the number of times the automated attack packet is used and its risk level, and use it as the ranking feature value;

[0055] Arrange automated attack packets in descending order according to their sorting feature values;

[0056] If the sorting characteristic values ​​of automated attack packets are the same, the automated attack packet uploaded earlier will be sorted first.

[0057] Preferably, the network security testing system further includes an intelligent perception module, which calculates the security similarity between blockchain systems. When a blockchain system is successfully attacked by a new automated attack program, the intelligent perception module queries all blockchain systems whose security similarity to the successfully attacked blockchain system is higher than a preset threshold. The intelligent perception module pushes test suggestions to all the queried blockchain systems. The test suggestions include the number and functional description information of the automated attack program that successfully carried out the attack.

[0058] The beneficial technical effects of the present invention include: 1) By receiving attack schemes and scheme signatures submitted by security personnel that have successfully attacked the blockchain system, the present invention integrates the vulnerability test results of multiple security personnel, which can more comprehensively cover security vulnerability testing.

[0059] 2) The administrator generates automated attack packages. The network security testing platform establishes an arsenal system, allowing users to select the automated attack packages they need to test and execute them automatically. The automatically executed attack programs help users quickly conduct security assessments.

[0060] 3) When a blockchain system is successfully attacked by a new automated attack program, query all blockchain systems whose security similarity to the successfully attacked blockchain system is higher than a preset threshold and push them to the system. This will enable users to be alerted to test and prevent new vulnerabilities in a timely manner, thereby improving the security of the blockchain system.

[0061] Other features and advantages of the present invention will be disclosed in detail in the following detailed description and accompanying drawings. Attached Figure Description

[0062] The invention will be further described below with reference to the accompanying drawings:

[0063] Figure 1 This is a schematic diagram of the network security testing method according to an embodiment of the present invention.

[0064] Figure 2 This is a schematic diagram of the automated attack packet static sorting method according to an embodiment of the present invention.

[0065] Figure 3 This is a schematic diagram of the automated attack packet dynamic sorting method according to an embodiment of the present invention.

[0066] Figure 4 This is a schematic diagram of the method for pushing test suggestions according to an embodiment of the present invention.

[0067] Figure 5 This is a schematic diagram of the method for calculating security similarity according to an embodiment of the present invention.

[0068] Figure 6 This is a schematic diagram of the network security testing system module connection according to an embodiment of the present invention.

[0069] Figure 7 This is a schematic diagram of a computer device according to an embodiment of the present invention.

[0070] Among them: 10. Access module, 20. Administrator module, 30. Member module, 40. Armory system, 50. Reward module, 60. Intelligent sensing module, 70. Computer equipment, 71. Memory, 72. Computer program, 73. Processor. Detailed Implementation

[0071] The technical solutions of the embodiments of the present invention will be explained and described below with reference to the accompanying drawings. However, the following embodiments are only preferred embodiments of the present invention and not all of them. Other embodiments obtained by those skilled in the art based on the embodiments in the implementation methods without creative effort are all within the protection scope of the present invention.

[0072] In the following description, terms such as “inner,” “outer,” “upper,” “lower,” “left,” and “right” are used only to indicate orientation or positional relationship for the convenience of describing the embodiments and simplifying the description, and are not intended to indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention.

[0073] The term "multiple" as used in this application refers to two or more. In the description of this application, unless otherwise stated, " / " indicates "or," for example, A / B can mean A or B; "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Furthermore, to clearly describe the technical solutions of this application, the terms "first," "second," etc., are used to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first," "second," etc., do not limit the quantity or execution order, and that "first," "second," etc., do not necessarily imply differences.

[0074] Before providing a detailed explanation of the embodiments of this application, the application scenarios of these embodiments will be described first.

[0075] A blockchain system comprises multiple nodes, each with its own transaction pool for storing transactions. When any node receives a transaction from a client, it shares the transaction with the other nodes, ensuring that all nodes store the transaction in their pools. This consistency across the transaction pools allows for processing of the transactions. Nodes are connected via a peer-to-peer (P2P) network, and each node's transaction pool is not identical. For any pending transaction in the pool, once consensus is reached among the nodes, the transaction can be executed and stored on the blockchain.

[0076] A transaction stored on the blockchain is said to have been confirmed by the blockchain network, allowing subsequent transaction steps to proceed. In a blockchain system, the consensus protocol is responsible for consistently ordering the transactions, resulting in a sorted transaction sequence. The state machine is only responsible for executing this sorted transaction sequence.

[0077] On the surface, once a consensus protocol determines the consistency of a transaction sequence, its consensus task is complete; the same state machine executing the same transaction sequence will produce the same result. However, state machines are not guaranteed to be secure. Problems at both the software and hardware levels can cause different nodes running the same state machine and executing the same transaction sequence to produce different results. In P2P-based communication networks, information transmission is not always timely or up-to-date. These factors lead to various vulnerabilities in blockchain networks that can be exploited by malicious nodes.

[0078] Examples include Sybil attacks and double-spending attacks. A Sybil attack refers to an attacker manipulating or impersonating multiple virtual identities on a blockchain. Sybil attacks are well-known in peer-to-peer (P2P), wired, and wireless network environments. In its basic form, a peer representing the attacker generates as many identities as possible and behaves as if she were multiple peers in the system, aiming to disrupt the system's normal behavior.

[0079] A double-spending attack, also known as a "double-spending attack," refers to an attacker repeatedly transferring a certain amount of tokens between accounts by initiating and reversing transactions, thus profiting from the same funds. There are five ways to carry out a double-spending attack: a 51% attack, a Finney attack, a Raceattack, a Vector76 attack, and an Alternative history attack. A 51% attack, also known as a Majority attack, achieves double-spending by controlling network computing power. If an attacker controls more than 50% of the network's computing power, they can reverse blocks during their control period, performing reverse transactions and achieving double-spending. The name "Finney" comes from Hal Finney, who was the first to describe a double-spending attack involving zero-confirmation (unconfirmed) transactions. A Finney attack primarily achieves double-spending by controlling the broadcast time of blocks, targeting merchants who accept zero-confirmation transactions. Suppose an attacker mines a block containing a transaction where address 1 transfers a certain number of tokens to address 2, even though both addresses belong to the attacker. Instead of broadcasting this block, the attacker immediately finds a merchant and, using address 1, sends these tokens to the merchant's address 3. After this transaction is broadcast, if the merchant accepts 0 confirmations, the attacker broadcasts their own previously mined block, making the self-mined transaction precede the merchant's. By controlling the block broadcast time, the attacker achieves a "double-spending" of the same token. Race attacks primarily achieve double-spending by controlling miner fees. For example, the attacker sends a certain number of tokens to a merchant (let's call this branch A). If the merchant accepts 0 confirmations, the attacker then sends this same amount of tokens to one of their own wallets (let's call this branch B). However, the attacker adds a higher miner fee to this self-mined transaction, significantly increasing the probability of it being included in the miner's block. If the attacker's transaction to themselves is pre-packaged, it precedes the transaction sent to the merchant. This means branch B's length exceeds branch A's, and the transaction on branch A will be rolled back. For the attacker, controlling miner fees allows for "double-spending" of the same token. The Vector76 attack is a combination of racial and Finney attacks, also known as a "one-confirmation attack," meaning that even with one confirmation, the transaction can still be rolled back. Combining more attack methods can potentially create new attack techniques.

[0080] With the widespread adoption of blockchain applications, the security of blockchain network systems has become an increasingly serious problem and challenge for the industry. Therefore, researching ways to improve the security of blockchain network systems and promptly identify vulnerabilities is an urgent research topic.

[0081] A blockchain cybersecurity testing method, executed by a cybersecurity testing platform, is described in the appendix. Figure 1 This includes the following steps:

[0082] Step A01) Receive the registration application from the security personnel and issue the account address and private key to the security personnel;

[0083] Step A02) Receive the attack plan and signature of the successful attack on the blockchain system submitted by the security personnel. The attack plan includes the attack steps and the attack script.

[0084] Step A03) Receive the automated attack program, function description information and creator signature submitted by the administrator, assign a number to the automated attack program, generate an automated attack package, and upload the automated attack package to the designated blockchain.

[0085] Step A04) Publish a smart contract on the designated blockchain. The smart contract periodically polls the blockchain and moves the discovered automated attack packets to the arsenal system established by the network security testing platform.

[0086] Step A05) Receive user registration information and assign user accounts to users;

[0087] Step A06) Receive the test request submitted by the user. The test request includes the attack package number and the address of the blockchain system to be tested. Run the automated attack program corresponding to the attack package number to attack the blockchain system to be tested.

[0088] Step A07) Periodically distribute token rewards to the corresponding security personnel's account addresses based on the number of times the automated attack package is used. By integrating the vulnerability testing results of multiple security personnel, an arsenal system 40 is established to provide testing services for other blockchain users, thereby improving the security of the blockchain system. The arsenal system 40 is free to providers of approved attack steps and scripts, and is available to other individuals, enterprises, and institutions for a fee, such as an annual fee. This economic model ensures the positive development of the overall system. This method runs on a specially established network security testing platform. Security personnel A submits a registration application to the network security testing platform and obtains an account address and private key. Security personnel A performs a double-spending attack on a certain blockchain system. The attack process is as follows:

[0089] Security personnel A used the same device to create two virtual blockchain nodes, both of which are full nodes, denoted as Full Node A and Full Node B respectively. Security personnel A directly connected Full Node A to a one-time confirmation payment e-wallet, and connected Full Node B to one or more well-functioning nodes.

[0090] Security agent A then made two transactions with the same token. One transaction, named Transaction 1, was sent to security agent A's own address in a one-confirmation, payable e-wallet. The other transaction, named Transaction 2, was sent to security agent A's own wallet address. Security agent A set the mining fee for Transaction 1 to be much higher than the mining fee for Transaction 2.

[0091] Security agent A begins mining on the branch containing transaction 1, which is named Branch 1. After mining a block, security agent A does not immediately broadcast it. Instead, they simultaneously send transaction 1 on full node A and transaction 2 on full node B. Since full node A is only connected to wallets, when the wallet node, which only accepts one confirmation and makes a payment, wants to broadcast transaction 1 to other peer nodes, node B, which connects to more nodes, has already broadcast transaction 2 to most nodes in the network. Statistically, transaction 2 is more likely to be deemed valid by the network, while transaction 1 is deemed invalid.

[0092] After transaction 2 is deemed valid, security personnel A immediately broadcasts the block they previously mined on branch 1 to the network. At this point, a wallet accepting payment upon confirmation will immediately transfer the token to security personnel A's wallet account. Security personnel A then immediately sells the token and receives the cash.

[0093] Because branch 2 connects to more nodes, miners will mine more blocks on this branch, meaning the chain length of branch 2 is greater than that of branch 1. Consequently, transactions on branch 1 will be rolled back, and the transaction information for payments made to security personnel A via a single-confirmation wallet will be cleared. However, security personnel A has already withdrawn the funds, achieving double-spending. The attack plan and its signature are then submitted to the network security testing platform. After reviewing the attack plan, the administrator generates a corresponding automated attack program. The administrator adds a functional description and the creator's signature. A number is assigned to the automated attack program, an automated attack package is generated, and the automated attack package is uploaded to the designated blockchain. The automated attack package is then transferred to the arsenal system established by the network security testing platform. The network security testing platform receives user registrations and assigns user accounts.

[0094] Users can view all automated attack packages in the arsenal system and select the one they wish to test. For example, they might choose an automated attack package designed for double-spending. The user fills out a test request, including the attack package number and the address of the blockchain system to be tested. The automated attack program corresponding to the attack package number then runs to attack the blockchain system. If the double-spending attack is successfully executed, it indicates that the submitted blockchain system lacks sufficient security; conversely, if it fails, it means the blockchain system can withstand this type of double-spending attack. Some automated attack packages in the arsenal system are free for users, while others require payment. The cybersecurity testing platform periodically rewards security personnel based on the number of times the automated attack packages are used.

[0095] The arsenal system statically sorts 40 pairs of automated attack packets; please refer to the appendix. Figure 2 Static sorting methods include:

[0096] Step B01) Associate the automated attack package with the corresponding vulnerability in the blockchain system;

[0097] Step B02) The administrator classifies the vulnerability risk level of the blockchain system.

[0098] Step B03) Sort the automated attack packages in descending order of their associated vulnerability severity level;

[0099] Step B04) Automated attack packages with the same vulnerability severity level are sorted alphabetically by the first letter of the associated vulnerability name. By associating automated attack packages with vulnerabilities, users can easily select the appropriate automated attack package based on the vulnerability. The categorization by severity level allows users to conduct network security testing as needed. For blockchain systems with lower network security requirements, only high-risk and medium-risk vulnerabilities need to be tested. Vulnerabilities with low severity can be selected as needed.

[0100] The arsenal system dynamically sorts 40 pairs of automated attack packets; please refer to the appendix. Figure 3 Dynamic sorting methods include:

[0101] Step C01) If the upload time of the automated attack packet is less than the preset threshold, it will be included in the priority display set;

[0102] Step C02) Prioritize displaying automated attack packets within the collection, sorted in descending order of upload time;

[0103] Step C03) Prioritize displaying automated attack packets within the set before other automated attack packets;

[0104] Step C04) The administrator classifies the vulnerabilities of the blockchain system into vulnerability risk levels. The vulnerability risk level is represented by a risk value. The higher the vulnerability risk level, the greater the risk value.

[0105] Step C05) Calculate the product of the number of times the automated attack packet is used and the danger level value, and use it as the ranking feature value;

[0106] Step C06) Sort the automated attack packets in descending order according to their sorting feature values;

[0107] (Step C07) If the sorting characteristic values ​​of automated attack packets are the same, the automated attack packet uploaded earlier will be sorted first. Vulnerability levels are classified as severe, high-risk, medium-risk, and low-risk, corresponding to danger values ​​of 4, 3, 2, and 1, respectively. If a vulnerability has never been discovered before, or its discovery time is short, it will be directly ranked first and added to the priority display set. If a vulnerability already exists, the sorting order will be determined by the product of the vulnerability level and the number of times the vulnerability has been used. Double-spending attacks are severe attacks, and the corresponding vulnerability level is classified as severe, i.e., the danger value is 4.

[0108] The method by which the selected automated attack package attacks the selected blockchain system includes: the arsenal system 40 constructs an automated attack smart contract, which records the serial number of the automated attack program and the platform user; the arsenal system 40 loads the automated attack program into the automated attack smart contract and publishes the automated attack smart contract on the selected blockchain system; when the smart contract is executed, the automated attack program will be executed automatically. Executing the automated attack program by the smart contract ensures that the attack program is executed correctly and without modification, thus allowing for prediction of the state of the blockchain system after a successful attack and providing a basis for mitigating the impact of the attack.

[0109] The cybersecurity testing platform periodically counts the number of times automated attack packets are used within a given period. The product of the number of uses, the preset reward coefficient, and the risk level is used as the reward amount. Tokens corresponding to the reward amount are then transferred to the account address of the corresponding security personnel.

[0110] The cybersecurity testing platform also has the function of pushing test suggestions; please refer to the appendix. Figure 4 Methods for pushing test suggestions include:

[0111] Step D01) The network security testing platform compiles historical test information from multiple blockchain systems;

[0112] Step D02) Associate the blockchain system with the number of the automated attack program that successfully carried out the attack;

[0113] Step D03) Calculate the security similarity between the two blockchain systems;

[0114] Step D04) After a blockchain system is successfully attacked by a new automated attack program, the network security testing platform queries all blockchain systems whose security similarity to the successfully attacked blockchain system is higher than a preset threshold.

[0115] Step D05) Push test suggestions to all the obtained blockchain systems. These suggestions include the ID and functional description of the automated attack program that successfully carried out the attack. For blockchain systems with high cybersecurity requirements, it is necessary to be aware of the latest attack types in a timely manner. If two blockchains are similar in type, when one blockchain system is successfully attacked, it is necessary to push the corresponding automated attack program ID and functional description to the other blockchain system to enable testing on more blockchain systems as quickly as possible and to take appropriate countermeasures. This improves the security of the blockchain system.

[0116] Please see the appendix Figure 5 Methods for calculating the security similarity between two blockchain systems include:

[0117] Step E01) Obtain the ID of the automated attack program that successfully carried out the attack associated with the blockchain system and add it to the attack ID set;

[0118] Step E02) Obtain the union and intersection of the two sets of attack IDs for the blockchain systems respectively;

[0119] Step E03) Count the number of elements in the union and intersection. The ratio of the number of elements in the intersection to the number of elements in the union is the security similarity between the two blockchain systems. This embodiment uses the similarity of the serial numbers of the automated attack programs that have been successfully executed in the past to characterize the similarity between the two blockchain systems, which can more effectively identify blockchain systems that may have the same vulnerabilities.

[0120] This embodiment also provides a blockchain network security testing system for performing a blockchain network security testing method as described above. Please refer to the appendix. Figure 6The system comprises an access module 10, an administrator module 20, a member module 30, an arsenal system 40, and a reward module 50. The access module 10 receives registration requests and attack plans from security personnel, and issues account addresses and private keys to them. The administrator module 20 reads the attack plans received by the access module 10 and displays them to the administrator. It also receives automated attack programs provided by the administrator, assigns numbers to these programs, and receives functional descriptions added by the administrator to form automated attack packages. These packages are then added to the arsenal system 40. The member module 30 receives user registration requests, assigns accounts and private keys, and makes users platform users. The arsenal system 40 receives call requests from platform users, including numbers and target blockchain systems. The arsenal system 40 runs the automated attack program corresponding to the number on the target blockchain system. The reward module 50 periodically distributes token rewards to the corresponding security personnel's account addresses based on the number of times the automated attack packages are used. By integrating the vulnerability testing results of multiple security personnel, the arsenal system 40 provides testing services to other blockchain users, thereby improving the security of the blockchain system.

[0121] The arsenal system 40 includes a sorting module that performs static and dynamic sorting of automated attack packets. During static sorting, the sorting module executes the following steps:

[0122] Associate automated attack packages with vulnerabilities in corresponding blockchain systems;

[0123] Administrators classify the vulnerability severity levels of the blockchain system.

[0124] Automated attack packages are sorted in descending order of their associated vulnerability severity level;

[0125] Automated attack packages with the same vulnerability severity level are sorted alphabetically by the first letter of the associated vulnerability name. This categorization of vulnerabilities and their severity levels makes it easier for users to find the automated attack packages they need.

[0126] When performing dynamic sorting, the sorting module executes the following steps:

[0127] If the upload time of the automated attack packet is less than the preset threshold, it will be included in the priority display set;

[0128] The automated attack packets within the collection will be displayed first, sorted in descending order of upload time.

[0129] Automated attack packages within a collection are prioritized and displayed before other automated attack packages.

[0130] The administrator classifies the vulnerabilities in the blockchain system into risk levels, which are represented by a risk value. The higher the risk level, the greater the risk value.

[0131] Calculate the product of the number of times the automated attack packet is used and its risk level, and use it as the ranking feature value;

[0132] Arrange automated attack packets in descending order according to their sorting feature values;

[0133] If automated attack packets have the same sorting characteristic value, the automated attack packet uploaded earlier will be sorted first. Dynamically sorting the newest and most dangerous automated attack packets to the top helps to test new attack schemes on the blockchain system in a timely manner, thus improving the security of the blockchain system.

[0134] When the arsenal system 40 launches a selected automated attack package against a selected blockchain system, it performs the following steps:

[0135] The arsenal system constructs automated attack smart contracts, which record the serial number of the automated attack program and the platform user.

[0136] The arsenal system loads automated attack programs into the automated attack smart contract and publishes the automated attack smart contract on a selected blockchain system;

[0137] When a smart contract is executed, the automated attack program will be executed automatically. Automated attack execution improves the efficiency of security testing, allowing users to quickly conduct security tests on blockchain networks.

[0138] The network security testing system also includes an intelligent perception module 60. The intelligent perception module 60 calculates the security similarity between blockchain systems. When a blockchain system is successfully attacked by a new automated attack program, the intelligent perception module 60 queries all blockchain systems whose security similarity with the successfully attacked blockchain system is higher than a preset threshold. The intelligent perception module 60 pushes test suggestions to all the queried blockchain systems. The test suggestions include the number and functional description information of the automated attack program that successfully carried out the attack.

[0139] The beneficial technical effects of this embodiment include: by integrating the vulnerability testing results of multiple security personnel, the present invention can more comprehensively cover security vulnerability testing and improve the security of the blockchain system; moreover, the automated attack program helps users to quickly conduct security assessments; and when new vulnerabilities appear, it can remind users to test and prevent them in a timely manner.

[0140] Figure 7 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 7As shown, the computer device 70 includes a processor 73, a memory 71, and a computer program 72 stored in the memory 71 and executable on the processor 73. When the processor 73 executes the computer program 72, it implements the steps in the proposal consensus execution method in the above embodiments.

[0141] Computer device 70 can be a general-purpose computer device or a special-purpose computer device. In a specific implementation, computer device 70 can be a server cluster including multiple servers, such as a blockchain system including multiple nodes. Those skilled in the art will understand that... Figure 7 The computer device 70 is merely an example and does not constitute a limitation on the computer device 70. It may include more or fewer components than shown in the figure, or combine certain components, or different components, such as input / output devices, network access devices, etc.

[0142] Processor 73 can be a Central Processing Unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.

[0143] In some embodiments, memory 71 may be an internal storage unit of computer device 70, such as a hard disk or RAM of computer device 70. In other embodiments, memory 71 may be an external storage device of computer device 70, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on computer device 70. Furthermore, memory 71 may include both internal and external storage units of computer device 70. Memory 71 is used to store operating system, application programs, boot loader, data, and other programs. Memory 71 may also be used to temporarily store data that has been output or will be output.

[0144] This application also provides a computer device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor executes the computer program to implement the steps in any of the above method embodiments.

[0145] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, can implement the steps in the various method embodiments described above.

[0146] This application provides a computer program product that, when run on a computer, causes the computer to perform the steps described in the various method embodiments above.

[0147] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above method embodiments of this application can be implemented by a computer program instructing related hardware. This computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or some intermediate form. The computer-readable medium can include at least: any entity or device capable of carrying the computer program code to a photographing device / terminal device, a recording medium, a computer memory, ROM (Read-Only Memory), RAM (Random Access Memory), CD-ROM (Compact Disc Read-Only Memory), magnetic tape, floppy disk, and optical data storage devices. The computer-readable storage medium mentioned in this application can be a non-volatile storage medium; in other words, it can be a non-transient storage medium.

[0148] It should be understood that all or part of the steps of the above embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented in whole or in part as a computer program product. The computer program product includes one or more computer instructions. The computer instructions can be stored in the above-described computer-readable storage medium.

[0149] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0150] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0151] In the embodiments provided in this application, it should be understood that the disclosed apparatus / computer devices and methods can be implemented in other ways. For example, the apparatus / computer device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0152] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0153] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Those skilled in the art should understand that the present invention includes, but is not limited to, the contents described in the accompanying drawings and the specific embodiments above. Any modifications that do not depart from the functional and structural principles of the present invention will be included within the scope of the claims.

Claims

1. A network security testing method for blockchain, executed by a network security testing platform, characterized in that, Includes the following steps: Receive registration applications from security personnel and issue account addresses and private keys to them; Receive a successful attack plan and signature of an attack on a blockchain system submitted by a security personnel. The attack plan includes attack steps and an attack script. The system receives the automated attack program, function description information, and creator signature submitted by the administrator; assigns a number to the automated attack program; generates an automated attack package; and uploads the automated attack package to the designated blockchain. The automated attack program is generated by the administrator after the attack scheme is reviewed. A smart contract is published on a designated blockchain. The smart contract periodically polls the blockchain and moves any discovered automated attack packets to the arsenal system established by the network security testing platform. Receive user registration information and assign user accounts to users; Receive a test request submitted by a user, the test request including an attack package number and the address of the blockchain system to be tested, and run the automated attack program corresponding to the attack package number to attack the blockchain system to be tested; Token rewards are periodically distributed to the account addresses of the corresponding security personnel based on the number of times the automated attack package is used. The network security testing platform compiles historical test information from multiple blockchain systems. The number of the automated attack program that successfully carried out the attack is associated with the blockchain system; Calculate the security similarity between two blockchain systems; When a blockchain system is successfully attacked by a new automated attack program, the network security testing platform queries all blockchain systems whose security similarity to the successfully attacked blockchain system is higher than a preset threshold. Test suggestions are pushed to all blockchain systems obtained from the query. The test suggestions include the ID and functional description information of the automated attack program that successfully carried out the attack. Methods for calculating the security similarity between two blockchain systems include: Obtain the IDs of the automated attack programs that successfully carried out attacks associated with the blockchain system and add them to the attack ID set; Obtain the union and intersection of the attack ID sets of the two blockchain systems respectively; The security similarity between two blockchain systems is determined by the ratio of the number of elements in the union and intersection to the number of elements in the union.

2. The network security testing method for blockchain according to claim 1, characterized in that, The arsenal system statically sorts automated attack packets, and the static sorting method includes: Associate automated attack packages with vulnerabilities in corresponding blockchain systems; Administrators classify the vulnerability severity levels of the blockchain system. Automated attack packages are sorted in descending order of their associated vulnerability severity level; Automated attack packages with the same vulnerability risk level are sorted alphabetically by the first letter of the associated vulnerability name.

3. A blockchain network security testing method according to claim 1 or 2, characterized in that, The arsenal system dynamically sorts automated attack packets, and the dynamic sorting method includes: If the upload time of the automated attack packet is less than the preset threshold, it will be included in the priority display set; The automated attack packets within the collection will be displayed first, sorted in descending order of upload time. Automated attack packages within a collection are prioritized and displayed before other automated attack packages. The administrator classifies the vulnerabilities of the blockchain system into vulnerability risk levels, which are represented by a risk value. The higher the vulnerability risk level, the greater the risk value. Calculate the product of the number of times the automated attack packet is used and its risk level, and use it as the ranking feature value; Arrange automated attack packets in descending order according to their sorting feature values; If the sorting characteristic values ​​of automated attack packets are the same, the automated attack packet uploaded earlier will be sorted first.

4. A blockchain network security testing method according to claim 1 or 2, characterized in that, The methods used by the selected automated attack packages to attack the selected blockchain systems include: The arsenal system constructs an automated attack smart contract, which records the serial number of the automated attack program and the platform user. The arsenal system loads automated attack programs into the automated attack smart contract and publishes the automated attack smart contract on a selected blockchain system. When the smart contract is executed, the automated attack program will be executed automatically.

5. A blockchain network security testing method according to claim 3, characterized in that, The network security testing platform periodically counts the number of times automated attack packets are used within a period, and uses the product of the number of times, the preset reward coefficient, and the danger level as the reward amount. Tokens corresponding to the reward amount are transferred to the account address of the corresponding security personnel.

6. A computer device, characterized in that, The computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the blockchain network security testing method as described in any one of claims 1 to 5.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the blockchain network security testing method as described in any one of claims 1 to 5.

8. A blockchain network security testing system, used to execute a blockchain network security testing method as described in any one of claims 1 to 5, characterized in that, The system includes an access module, an administrator module, a member module, an arsenal system, and a reward module. The access module receives registration requests and attack plans from security personnel, and issues account addresses and private keys to them. The administrator module reads the attack plans received by the access module and displays them to the administrator, receives automated attack programs provided by the administrator, assigns numbers to these programs, and receives functional descriptions added by the administrator to form automated attack packages. These automated attack packages are then added to the arsenal system. The member module receives user registration requests, assigns accounts and private keys, and makes users platform users. The arsenal system receives invocation requests from platform users, including numbers and target blockchain systems. The arsenal system runs the automated attack program corresponding to the number on the target blockchain system. The reward module periodically issues token rewards to the corresponding security personnel's account addresses based on the number of times the automated attack packages are used.

Citation Information

Patent Citations

  • Intelligent contract logic vulnerability detection method and device based on block chain

    CN114676052A

  • Mobile intelligent terminal testing case evaluation method based on grading model coefficient

    CN106201875A

  • Program bug testing method and related device

    CN111177729A