An adaptive genetic algorithm-based device and method for detecting integer overflow vulnerabilities in Ethereum smart contracts

CN117743157BActive Publication Date: 2026-09-29HENAN UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311734881.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-16
Publication Date
2026-09-29
Estimated Expiration
2043-12-16

AI Technical Summary

Technical Problem

[0009]本发明针对目前存在的以下问题:(1)现有以太坊智能合约检测工具代码覆盖率低,检测准确度低;(2)现有以太坊智能合约检测工具针对整数溢出漏洞的判断往往只集中在由加、乘和减操作引起的溢出,而缺乏对其他操作引起溢出的判断;提出一种基于自适应遗传算法的以太坊智能合约整数溢出漏洞检测装置及检测方法,具体设计了一种基于自适应遗传算法的漏洞检测方案,还设计了一种基于加,减,乘和移位操作进行整数溢出漏洞判定的测试预言机

Benefits of technology

[0080](1)现有使用模糊测试进行漏洞检测的工具代码覆盖率低下,生成的测试用例具有很大的盲目性和随机性。本发明将遗传算法改进为自适应遗传算法,能够根据父母个体的适应度来动态调整二者的交叉变异概率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117743157B_ABST
    Figure CN117743157B_ABST
Patent Text Reader

Abstract

The application discloses an Ethereum smart contract integer overflow vulnerability detection device and method based on an adaptive genetic algorithm, which comprises a fuzzy engine module, a transaction execution module, a tracking analysis module and a feedback module; the fuzzy engine module generates multiple test case individuals for all functions and parameters of a smart contract by using an adaptive genetic algorithm and sends the test case individuals to the transaction execution module; the transaction execution module executes the generated test case individuals in a virtual Ethereum execution environment through a smart contract; the tracking analysis module monitors the execution process of the smart contract and analyzes the execution process, including integer overflow vulnerability analysis; and the feedback module feeds back analysis information generated by the tracking analysis module to the fuzzy engine module. The application generates fuzzy test case individuals by using an adaptive genetic algorithm, improves the code coverage in the detection process, improves the detection rate of the tool on the vulnerability, and reduces the false negative rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Ethereum smart contract security detection technology, and in particular to an Ethereum smart contract integer overflow vulnerability detection device and method based on an adaptive genetic algorithm. Background Technology

[0002] Ethereum is one of the most popular smart contract platforms, and developing smart contracts on Ethereum is the first choice for many blockchain developers. However, unlike traditional software development, smart contract development requires special attention to security issues because smart contracts may involve important assets and confidential information, and once deployed to the blockchain, they cannot be modified. If a smart contract has security vulnerabilities, hackers can exploit these vulnerabilities to attack the smart contract and steal assets, causing significant losses to users.

[0003] Currently, symbolic execution and fuzzing are two main methods for detecting smart contract vulnerabilities. However, these methods have some limitations in practical use, such as low code coverage and low accuracy. For symbolic execution, because smart contracts often contain a large number of conditional branches and path explosion problems, it is difficult to achieve sufficiently high code coverage. Furthermore, symbolic execution requires manually injecting constraints, which often requires specialized knowledge and skills. For fuzzing, although it can automatically generate a large number of test cases, the high state dependency and non-determinism of smart contracts lead to inconsistent quality of test cases, low code coverage, and difficulty in guaranteeing detection accuracy.

[0004] Currently, there is some research on the security of Ethereum smart contracts both domestically and internationally. Vulnerability detection methods can be divided into symbolic execution and fuzzing.

[0005] Symbolic execution works by abstracting each variable in a smart contract as a symbolic variable and exploring the contract's execution paths. When the program reaches a conditional branch or loop statement, the symbolic execution system generates corresponding constraints based on the symbolic value of the current symbolic variable. A constraint solver then solves these constraints, analyzing the path for potential vulnerabilities by determining if a solution satisfying all constraints exists. Oyente was one of the earliest tools to use symbolic execution for smart contract vulnerability detection. It takes the smart contract bytecode and Ethereum state as input, constructs the contract's control flow graph based on the contract's control flow statements (such as conditional branches and loops), and uses symbolic execution to traverse different execution paths to capture potential security vulnerabilities. However, it also has drawbacks. The symbolic execution process can be affected by path explosion, making it impossible to completely traverse all possible execution paths, resulting in low code coverage.

[0006] The principle of fuzzing is to randomly generate a large number of test cases from the target application, provide these test cases to the target application, and execute them repeatedly. During execution, abnormal behavior or states of the program are monitored to discover vulnerabilities. Contractfuzzer was the first tool to use fuzzing technology to detect vulnerabilities in Ethereum smart contracts. It generates a set of candidate inputs for each function in the contract based on the ABI description. For multiple parameters in a function, it generates n candidate values ​​for each parameter and randomly combines all n candidate values ​​to produce the test input set for the function. This method of generating test cases is relatively straightforward, producing a large number of invalid test cases and exhibiting a degree of randomness; its detection efficiency is also insufficient. Confuzzius improves upon Contractfuzzer by introducing a genetic algorithm. Genetic operations such as crossover and mutation are used to generate new individuals as test cases, which to some extent guides and optimizes test case generation. However, traditional genetic algorithms require setting a series of fixed parameters, such as crossover and mutation probabilities. Randomly selecting crossover and mutation probabilities is obviously blind, which not only reduces the convergence rate of the genetic algorithm, but also causes premature convergence, resulting in instability of experimental results.

[0007] Furthermore, through research on testing oracles using existing vulnerability detection tools, we found that many tools only consider overflows caused by addition, multiplication, and subtraction operations for integer overflow vulnerabilities. However, other operations can also lead to integer overflows, such as shift operations. Figure 1 As shown.

[0008] In the smart contract described above, the `shiftLeft` function accepts two parameters, `num` and `shift`, and requests the caller to pay the transaction fee. It then shifts `num` left by `shift` bits, storing the result in the variable `newNum`; next, it multiplies `newNum` by 2, storing the result in the variable `result`, and transfers all received transaction fees to the caller via `payable`. However, if `num` is set to the maximum value of `uint`, 2**256-1, and an attempt is made to shift `newNum` to a value greater than 2**256-1, an integer overflow will occur. Summary of the Invention

[0009] This invention addresses the following existing problems: (1) Existing Ethereum smart contract detection tools have low code coverage and low detection accuracy; (2) Existing Ethereum smart contract detection tools often focus on overflows caused by addition, multiplication, and subtraction operations when judging integer overflow vulnerabilities, but lack judgment on overflows caused by other operations; This invention proposes an Ethereum smart contract integer overflow vulnerability detection device and detection method based on an adaptive genetic algorithm. Specifically, a vulnerability detection scheme based on an adaptive genetic algorithm is designed, and a test oracle for judging integer overflow vulnerabilities based on addition, subtraction, multiplication, and shift operations is also designed.

[0010] To achieve the above objectives, the present invention adopts the following technical solution:

[0011] This invention proposes an Ethereum smart contract integer overflow vulnerability detection device based on an adaptive genetic algorithm, comprising: a fuzzy engine module, a transaction execution module, a tracking and analysis module, and a feedback module;

[0012] The fuzzy engine module is used to generate multiple individual test cases for all functions and parameters of the smart contract using an adaptive genetic algorithm, and then sends the generated individual test cases to the transaction execution module.

[0013] The transaction execution module is used to execute individual test cases generated through smart contracts in a virtual Ethereum execution environment;

[0014] The tracking and analysis module is used to monitor the execution process of smart contracts and analyze the execution process, including: integer overflow vulnerability analysis;

[0015] The feedback module is used to feed back the analysis information generated by the tracking analysis module to the fuzzy engine module.

[0016] Furthermore, it also includes:

[0017] The compilation module is used to take the source code of the smart contract as input, perform a compilation operation to obtain the corresponding binary interface and EVM runtime bytecode of the smart contract program, and obtain all functions and parameters of the smart contract based on the binary interface.

[0018] Furthermore, the adaptive genetic algorithm includes:

[0019] 1) Generate individuals for the initial population based on the binary interface of the smart contract;

[0020] 2) Calculate the fitness of each individual using the following formula:

[0021] f(i)=αf branch (i)+βf RAW (i)

[0022] Where f branch (i) is branch coverage, obtained by calculating the number of unexplored code branches during the execution of a transaction; f RAW (i) is the data dependency, which is obtained by traversing the gene sequence of an individual and calculating the number of genes in the individual that are read-dependent or write-dependent; α+β=1;

[0023] 3) Calculate the fitness values ​​of all individuals in the population and sort them in ascending order;

[0024] 4) Calculate the probability of the individual ranked i being selected using the following formula:

[0025]

[0026] Among them, P min For the minimum selection probability, P max Let i be the individual's rank and N be the population size, representing the maximum selection probability.

[0027] 5) The probability of each individual in the population being selected is put into the wheel list for normalization.

[0028] 6) Select the parent individual based on the wheel list using a random roulette wheel method;

[0029] 7) Traverse the remaining list of individuals, extract the data dependencies of each individual, and compare them with the read and write operations of the parent individual; if there is a data dependency conflict, return the parent individual and the current individual as the parent individual; if there is no data dependency conflict, randomly select one from the current list of individuals as the parent individual using a random roulette wheel.

[0030] 8) Determine the crossover probability P between the parents based on their individual fitness. c :

[0031]

[0032] Where f max It is the maximum fitness value of the population, f min It is the minimum fitness value of the population; f avg f is the average fitness value of the population; f′ is the larger fitness value among the parent individuals, C1, C2, and C3 are all taken from (0,1), and C1>C2>C3;

[0033] 9) After performing the crossover operation, new individuals are generated. The fitness value of the new individuals is calculated, and the mutation probability P of the new individuals is calculated based on the fitness value. m :

[0034]

[0035] Where f is the fitness value of the individual to be mutated, M1, M2, and M3 are all taken from (0,1), and M1>M2>M3.

[0036] Furthermore, the encoding representation of the individual is as follows:

[0037] Each individual is encoded as an input sequence, and each input sequence consists of an "environment" and a "transaction", both of which are encoded as key-value maps;

[0038] The “environment” includes the timestamp and block number of the current block, as well as the call return value, data size, and external code size; among them, the call return value, data size, and external code size are encoded as a mapping array;

[0039] A “transaction” includes the address of the sending account, the transaction amount, the maximum gas value specified for contract execution, and the input data for contract execution. The input data is represented as an array of values, in which the first element is always used as a function representation, and the remaining elements represent function parameters. The calculation of the function representation uses a binary interface and extracts the first four bytes of the Keccak hash value based on the function signature.

[0040] Furthermore, the integer overflow vulnerability analysis includes:

[0041] Check if the smart contract contains the opcodes ADD, MUL, SUB, SHL, and SHR. If it does not contain them, it is assumed that there is no integer overflow vulnerability. If it does contain them, proceed to the next step.

[0042] Extract operands from the stack and use those operands to calculate the result of the arithmetic operation;

[0043] Check if the calculation result is the same as the result pushed onto the stack. If they are the same, it is assumed that there is no integer overflow vulnerability. If they are different, proceed to the next step.

[0044] Check if the calculation result flows into the SSTORE or CALL instruction. If it does, report an integer overflow vulnerability. If it does not, there is no integer overflow vulnerability.

[0045] Another aspect of this invention proposes a method for detecting integer overflow vulnerabilities in Ethereum smart contracts based on an adaptive genetic algorithm, comprising:

[0046] An adaptive genetic algorithm is used to generate multiple individual test cases for all functions and parameters of the smart contract.

[0047] Individual test cases generated through smart contract execution within a virtual Ethereum execution environment;

[0048] Monitor the execution process of smart contracts and perform integer overflow vulnerability analysis on the execution process;

[0049] The generated analysis information will be fed back.

[0050] Furthermore, before using an adaptive genetic algorithm to generate multiple individual test cases for all functions and parameters of the smart contract, the following steps are also included:

[0051] The source code of the smart contract is used as input to perform a compilation operation to obtain the corresponding binary interface and EVM runtime bytecode of the smart contract program. Based on the binary interface, all functions and parameters of the smart contract are obtained.

[0052] Furthermore, the adaptive genetic algorithm includes:

[0053] 1) Generate individuals for the initial population based on the binary interface of the smart contract;

[0054] 2) Calculate the fitness of each individual using the following formula:

[0055] f(i)=αf branch (i)+βf RAW (i)

[0056] Where f branch (i) is branch coverage, obtained by calculating the number of unexplored code branches during the execution of a transaction; f RAW (i) is the data dependency, which is obtained by traversing the gene sequence of an individual and calculating the number of genes in the individual that are read-dependent or write-dependent; α+β=1;

[0057] 3) Calculate the fitness values ​​of all individuals in the population and sort them in ascending order;

[0058] 4) Calculate the probability of the individual ranked i being selected using the following formula:

[0059]

[0060] Among them, P min For the minimum selection probability, P max Let i be the individual's rank and N be the population size, representing the maximum selection probability.

[0061] 5) The probability of each individual in the population being selected is put into the wheel list for normalization.

[0062] 6) Select the parent individual based on the wheel list using a random roulette wheel method;

[0063] 7) Traverse the remaining list of individuals, extract the data dependencies of each individual, and compare them with the read and write operations of the parent individual; if there is a data dependency conflict, return the parent individual and the current individual as the parent individual; if there is no data dependency conflict, randomly select one from the current list of individuals as the parent individual using a random roulette wheel.

[0064] 8) Determine the crossover probability P between the parents based on their individual fitness. c :

[0065]

[0066] Where f max It is the maximum fitness value of the population, f min It is the minimum fitness value of the population; f avg f is the average fitness value of the population; f′ is the larger fitness value among the parent individuals, C1, C2, and C3 are all taken from (0,1), and C1>C2>C3;

[0067] 9) After performing the crossover operation, new individuals are generated. The fitness value of the new individuals is calculated, and the mutation probability P of the new individuals is calculated based on the fitness value. m :

[0068]

[0069] Where f is the fitness value of the individual to be mutated, M1, M2, and M3 are all taken from (0,1), and M1>M2>M3.

[0070] Furthermore, the encoding representation of the individual is as follows:

[0071] Each individual is encoded as an input sequence, and each input sequence consists of an "environment" and a "transaction", both of which are encoded as key-value maps;

[0072] The “environment” includes the timestamp and block number of the current block, as well as the call return value, data size, and external code size; among them, the call return value, data size, and external code size are encoded as a mapping array;

[0073] A “transaction” includes the address of the sending account, the transaction amount, the maximum gas value specified for contract execution, and the input data for contract execution. The input data is represented as an array of values, in which the first element is always used as a function representation, and the remaining elements represent function parameters. The calculation of the function representation uses a binary interface and extracts the first four bytes of the Keccak hash value based on the function signature.

[0074] Furthermore, the integer overflow vulnerability analysis includes:

[0075] Check if the smart contract contains the opcodes ADD, MUL, SUB, SHL, and SHR. If it does not contain them, it is assumed that there is no integer overflow vulnerability. If it does contain them, proceed to the next step.

[0076] Extract operands from the stack and use those operands to calculate the result of the arithmetic operation;

[0077] Check if the calculation result is the same as the result pushed onto the stack. If they are the same, it is assumed that there is no integer overflow vulnerability. If they are different, proceed to the next step.

[0078] Check if the calculation result flows into the SSTORE or CALL instruction. If it does, report an integer overflow vulnerability. If it does not, there is no integer overflow vulnerability.

[0079] Compared with the prior art, the present invention has the following beneficial effects:

[0080] (1) Existing tools for vulnerability detection using fuzz testing have low code coverage, and the generated test cases are highly blind and random. This invention improves the genetic algorithm into an adaptive genetic algorithm, which can dynamically adjust the crossover and mutation probabilities of the two individuals based on the fitness of the parents.

[0081] When the fitness of individuals requiring crossover or mutation is lower than the average fitness of the population, the algorithm is prone to getting stuck in local optima. In this case, increasing the crossover and mutation probabilities enhances the mutation ability of weaker individuals, expands the search range, increases population diversity, and leads to more new gene combinations, thus helping to discover better solutions. Conversely, when the fitness of individuals requiring crossover or mutation is higher than the average fitness of the population, these individuals already possess good fitness and are considered superior individuals in the population. In this case, decreasing the crossover and mutation probabilities preserves the traits of these superior individuals and reduces the risk of introducing undesirable mutations.

[0082] Therefore, adaptive genetic algorithms can generate better and more excellent test individuals, improve code coverage during the detection process, and increase the tool's vulnerability detection rate.

[0083] (2) In the detection of integer overflow vulnerabilities, this invention detects addition, subtraction, multiplication, left shift and right shift operations, and adds an extra layer of judgment. Only when the overflow result is written to storage or used to send funds will it be considered harmful, thus reducing the false negative rate. Attached Figure Description

[0084] Figure 1 This is an example of an integer overflow vulnerability in a shift operation according to an embodiment of the present invention;

[0085] Figure 2This is a schematic diagram of the structure of an Ethereum smart contract integer overflow vulnerability detection device based on an adaptive genetic algorithm according to an embodiment of the present invention;

[0086] Figure 3 This is a flowchart of the adaptive genetic algorithm according to an embodiment of the present invention;

[0087] Figure 4 This is an example of an individual encoding representation in an embodiment of the present invention;

[0088] Figure 5 This is a flowchart illustrating the analysis of integer overflow vulnerabilities in an embodiment of the present invention.

[0089] Figure 6 The adaptive crossover probability (P) in this embodiment of the invention c ) Schematic diagram;

[0090] Figure 7 The adaptive mutation probability (P) of the embodiments of the present invention m ) Schematic diagram;

[0091] Figure 8 This is a flowchart illustrating an Ethereum smart contract integer overflow vulnerability detection method based on an adaptive genetic algorithm, according to an embodiment of the present invention. Detailed Implementation

[0092] The present invention will be further explained below with reference to the accompanying drawings and specific embodiments:

[0093] Figure 2This is an overall architecture for an Ethereum smart contract integer overflow vulnerability detection device based on an adaptive genetic algorithm, consisting of four parts: a fuzzy engine module, a transaction execution module, a tracing and analysis module, and a feedback module. Taking the smart contract's source code as input, a compilation operation is first performed to obtain the corresponding binary interface (ABI) and EVM runtime bytecode of the smart contract program. Specifically, the ABI specifies the names, parameter types, and return value types of each function in the contract, which is a necessary condition for the fuzzy engine module to generate test cases. The bytecode is executed in the EVM virtual machine and, in subsequent processes, is converted into opcodes through a decoding process, which is a necessary condition for the tracing and analysis module to specifically find and verify vulnerabilities in the smart contract when performing specific operations. Then, using the adaptive genetic algorithm introduced in the fuzzy engine module, diverse individual test cases are generated for all function parameters of the contract, and these individuals are sent to the transaction execution module. In the transaction execution module, the EVM virtual machine is a virtual Ethereum execution environment where these individual test cases are executed, and the execution process is sent to the tracing and analysis module for further processing. The tracing and analysis module monitors the contract's execution process and performs multiple analyses. For example, the analysis includes code coverage calculation during contract execution, data dependency analysis between execution entities, constraint solving analysis under complex contract execution paths, execution condition termination analysis, and vulnerability analysis using a vulnerability detector. The relevant analysis information is then provided to the fuzzy engine module via a feedback module. This process repeats until at least one of two termination conditions is met: a given number of descendant entities have been generated, or a given execution time has been exceeded. Finally, a detailed detection report is output, including information such as the code coverage of the detected contract, the types of vulnerabilities detected, and the time spent on detection.

[0094] The innovations of this invention are mainly concentrated in the fuzzy engine module and the execution tracing analysis module, which will be described in detail below.

[0095] 1. Fuzzy Engine Module

[0096] This module uses an adaptive genetic algorithm to generate more and better test case individuals for the population. The algorithm flow is as follows: Figure 3 As shown.

[0097] Before creating the initial population, we need to understand the concept of encoding. Since the basic operation object in the adaptive genetic algorithm is a string, encoding is a fundamental task. Through in-depth research on the vulnerable contract, we adopted a special encoding method, representing each individual as an input sequence. Each input consists of an "environment" and a "transaction." Both are encoded as key-value maps, which facilitates storage and simplifies subsequent information retrieval. The "environment" mainly contains the timestamp and block number of the current block, along with information such as the call return value, data size, and external code size. Among this information, the call return value, data size, and external code size are encoded as mapping arrays. The information in the "environment" preserves the specific state the contract is in during transaction execution. The "transaction" is more detailed, involving the sending account address (from), transaction amount (value), the maximum gas value specified for contract execution (gas limit), and the input data for contract execution (data). The input data is represented here as an array of values. In each value array, the first element always serves as a function representative, and the remaining elements represent function parameters. The function selector is calculated using the ABI, extracting the first four bytes of the Keccak (SHA-3) hash value based on the function signature. For example, if a function is declared as `transfer(address a, uint b)`, then the string `transfer(address, uint)` is used as the function's signature. After hashing and extracting the first four bytes, the result is the function's selector, which is 0x7d6cdd25. Figure 4 , is an example of an individual encoded representation.

[0098] After introducing the concept of encoding, we will introduce the specific process of the adaptive genetic algorithm:

[0099] (1) Generate individuals for the initial population based on the ABI of the smart contract;

[0100] (2) Using the formula f(i)=αf branch (i)+βf RAW (i)(α+β=1) is used to calculate the fitness of each individual, where f branch (i) is branch coverage, obtained by calculating the number of unexplored code branches during the execution of a transaction; f RAW(i) is data dependency, calculated by traversing the individual's gene sequence and counting the number of genes in the individual that have read or write dependencies. Here, a gene is a basic unit constituting a test case. It can be any part of an input sequence, such as a key-value pair in environmental information, like a block's timestamp or block number; or a transaction attribute, such as the sending account's address, transaction amount, or gas limit. A complete gene sequence represents an individual, i.e., a test case, and is composed of multiple genes (including environmental and transaction key-value pairs) arranged in a specific order.

[0101] (3) Calculate the fitness values ​​of all individuals in the population and sort them in ascending order. Assume the population size is N, and its fitness values ​​are f1, f2, ..., f N The ranking of individual i is r i Then there is

[0102] (4) Use a function p(i) to calculate the probability of the individual ranked i being selected. The selection probability is related to the individual's ranking. We need to ensure that higher-ranked, more outstanding individuals have a higher selection probability, while still allowing less outstanding individuals to have some selection opportunities. The specific formula is designed as follows:

[0103]

[0104] Among them, P min For the minimum selection probability, P max Let i be the probability of maximizing selection, i be the individual's rank, and N be the population size.

[0105] By adjusting the minimum selection probability P min And the maximum choice probability P max The value of P allows us to control the range of the selection probability. min A higher P value helps maintain population diversity, ensuring that even weaker individuals still have some selection opportunities. max The value helps improve search performance, giving better individuals a higher probability of selection, which helps in searching the solution space of the global optimum or a solution close to the optimum.

[0106] (5) The probability of each individual in the population being selected is put into a list and normalized. The specific formula is as follows:

[0107]

[0108]

[0109] Where P sum It is a summation operation of the probability of an individual being selected in the population.

[0110] The final wheel is a list containing the normalized probability value of each individual being selected.

[0111] (6) Create a data structure called "wheel". The size of the part of the wheel occupied by each individual is the normalized value in wheel. Generate a random number between 0 and 1. Select the individual that falls into the region of the parent individual.

[0112] (7) Traverse the remaining list of individuals, extract the data dependencies of each individual, and compare them with the read and write operations of the parent individual. If a data dependency conflict exists, return the parent individual and the current individual as the parent individuals; if no data dependency conflict exists, randomly select one individual from the current list as the parent individual using a random roulette wheel. A data dependency conflict means that the write operation of the parent individual intersects with the read operation of another individual, or the write operation of another individual intersects with the read operation of the parent individual. We believe that vulnerabilities are more likely to occur between two individuals with read-write dependencies.

[0113] (8) Determine the crossover probability between the parents based on their individual fitness. The adaptive crossover probability is as follows: Figure 5 As shown. The formula for calculating the adaptive crossover probability is as follows:

[0114]

[0115] Where f max It is the maximum fitness value of the population, f min It is the minimum fitness value of the population; f avg f is the average fitness value of the population; f′ is the larger fitness value of the two individuals to be crossed, C1, C2, and C3 are all taken from (0,1), and C1>C2>C3.

[0116] (9) After performing the crossover operation, new individuals are generated. The fitness value of the new individuals is calculated, and the mutation probability of the new individuals is calculated based on the fitness value. The adaptive mutation probability is as follows: Figure 6 As shown, the formula for calculating the adaptive mutation probability is as follows:

[0117]

[0118] Where f max It is the maximum fitness value of the population, f min It is the minimum fitness value of the population; f avg is the average fitness value of the population; f is the fitness value of the individual to be mutated, M1, M2, and M3 are all taken from (0,1), and M1>M2>M3.

[0119] When the fitness of individuals requiring crossover or mutation is lower than the average fitness of the population, the algorithm is prone to getting stuck in local optima. Increasing the crossover and mutation probabilities in this case enhances the mutation ability of weaker individuals, expands the search range, and increases population diversity. This leads to the emergence of more new gene combinations (gene combinations refer to the arrangement and configuration of genes in an individual. Each gene combination can produce different test behaviors; in the context of smart contracts, this involves different transaction combinations, environment settings, function call order, and parameter settings, etc. For example, a test case individual with a transaction amount of 100, after mutation to 200, is considered to have generated a new gene combination), which helps to discover better solutions. When the fitness of individuals requiring crossover or mutation is greater than the average fitness of the population, it indicates that these individuals already have good fitness and are excellent individuals in the population. In this case, reducing the crossover and mutation probabilities can preserve the traits of these excellent individuals and reduce the risk of introducing undesirable mutations. Therefore, adaptive genetic algorithms can generate better and more excellent test individuals, improve code coverage during the detection process, and increase the vulnerability detection rate of the tool.

[0120] 2. Tracking and Analysis Module

[0121] We designed a test oracle for integer overflow vulnerabilities, detecting addition, subtraction, multiplication, left shift, and right shift operations. An additional layer of checks is added afterward: the overflow result is only considered harmful if it is written to storage or used to send funds. The process flow is as follows: Figure 7 As shown, it specifically includes:

[0122] (a) Check if the contract contains the opcodes ADD, MUL, SUB, SHL, and SHR. If it does not contain them, it is assumed that there is no integer overflow vulnerability. If it does contain them, proceed to the next step.

[0123] (b) Remove operands from the stack and use them to compute the result of an arithmetic operation.

[0124] (c) Check whether the calculation result is the same as the result pushed onto the stack. If they are the same, it is considered that there is no integer overflow vulnerability. If they are different, proceed to the next step.

[0125] (d) Check if the calculation result flows into the SSTORE or a CALL instruction (because we consider it harmful only if the overflow result is written to storage or used to send funds). If it flows in, report the integer overflow vulnerability; if it does not flow in, there is no integer overflow vulnerability.

[0126] Based on the above embodiments, such as Figure 8As shown, this invention also proposes a method for detecting integer overflow vulnerabilities in Ethereum smart contracts based on an adaptive genetic algorithm, comprising:

[0127] S101: An adaptive genetic algorithm is used to generate multiple individual test cases for all functions and parameters of the smart contract;

[0128] S102: Individual test cases generated through smart contract execution in a virtual Ethereum execution environment;

[0129] S103: Monitor the execution process of smart contracts and perform integer overflow vulnerability analysis on the execution process;

[0130] S104: Feedback the generated analysis information.

[0131] Furthermore, prior to S101, it also includes:

[0132] The source code of the smart contract is used as input to perform a compilation operation to obtain the corresponding binary interface and EVM runtime bytecode of the smart contract program. Based on the binary interface, all functions and parameters of the smart contract are obtained.

[0133] Furthermore, the adaptive genetic algorithm includes:

[0134] S101.1: Generate individuals for the initial population based on the binary interface of the smart contract;

[0135] S101.2: Calculate the fitness of each individual using the following formula:

[0136] f(i)=αf branch (i)+βf RAW (i)

[0137] Where f branch (i) is branch coverage, obtained by calculating the number of unexplored code branches during the execution of a transaction; f RAW (i) is the data dependency, which is obtained by traversing the gene sequence of an individual and calculating the number of genes in the individual that are read-dependent or write-dependent; α+β=1;

[0138] S101.3: Calculate the fitness values ​​of all individuals in the population and sort them in ascending order;

[0139] S101.4: Calculate the probability of selection for the individual ranked i using the following formula:

[0140]

[0141] Among them, P min For the minimum selection probability, P maxLet i be the individual's rank and N be the population size, representing the maximum selection probability.

[0142] S101.5: Normalize the probability of each individual in the population being selected by putting it into the wheel list;

[0143] S101.6: Select the parent individual based on the wheel list using a random roulette wheel;

[0144] S101.7: Traverse the remaining list of individuals, extract the data dependency relationship of each individual, and compare it with the read and write operations of the parent individual; if there is a data dependency conflict, return the parent individual and the current individual as the parent individual; if there is no data dependency conflict, randomly select one from the current list of individuals as the parent individual using a random roulette wheel.

[0145] S101.8: Determine the crossover probability P between the parents based on their individual fitness. c :

[0146]

[0147] Where f max It is the maximum fitness value of the population, f min It is the minimum fitness value of the population; f avg f is the average fitness value of the population; f′ is the larger fitness value among the parent individuals, C1, C2, and C3 are all taken from (0,1), and C1>C2>C3;

[0148] S101.9: After performing the crossover operation, new individuals are generated. The fitness value of the new individuals is calculated, and the mutation probability P of the new individuals is calculated based on the fitness value. m :

[0149]

[0150] Where f is the fitness value of the individual to be mutated, M1, M2, and M3 are all taken from (0,1), and M1>M2>M3.

[0151] Furthermore, the encoding representation of the individual is as follows:

[0152] Each individual is encoded as an input sequence, and each input sequence consists of an "environment" and a "transaction", both of which are encoded as key-value maps;

[0153] The “environment” includes the timestamp and block number of the current block, as well as the call return value, data size, and external code size; among them, the call return value, data size, and external code size are encoded as a mapping array;

[0154] A “transaction” includes the address of the sending account, the transaction amount, the maximum gas value specified for contract execution, and the input data for contract execution. The input data is represented as an array of values, in which the first element is always used as a function representation, and the remaining elements represent function parameters. The calculation of the function representation uses a binary interface and extracts the first four bytes of the Keccak hash value based on the function signature.

[0155] Furthermore, the integer overflow vulnerability analysis includes:

[0156] S103.1: Check if the contract contains the opcodes ADD, MUL, SUB, SHL, and SHR. If not, it is assumed that there is no integer overflow vulnerability. If it does, proceed to the next step.

[0157] S103.2: Extract operands from the stack and use the operands to calculate the result of the arithmetic operation;

[0158] S103.3: Check if the calculation result is the same as the result pushed onto the stack. If they are the same, it is considered that there is no integer overflow vulnerability. If they are different, proceed to the next step of judgment.

[0159] S103.4: Check whether the calculation result flows into the SSTORE or CALL instruction. If it does, report an integer overflow vulnerability. If it does not, there is no integer overflow vulnerability.

[0160] In summary, this invention uses an adaptive genetic algorithm to generate test cases for fuzzing when performing vulnerability detection on Ethereum smart contracts. In detecting integer overflow vulnerabilities, it extends the existing test oracle by adding a judgment regarding overflow situations caused by shift operations.

[0161] The above description is only a preferred embodiment of the present invention. It should be noted that those skilled in the art can make several improvements and modifications without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A device for detecting integer overflow vulnerabilities in Ethereum smart contracts based on an adaptive genetic algorithm, characterized in that, include: Fuzzy engine module, transaction execution module, tracking and analysis module, and feedback module; The fuzzy engine module is used to generate multiple individual test cases for all functions and parameters of the smart contract using an adaptive genetic algorithm, and then sends the generated individual test cases to the transaction execution module. The transaction execution module is used to execute generated test case individuals through smart contracts in a virtual Ethereum execution environment; The tracking and analysis module is used to monitor the execution process of smart contracts and analyze the execution process, including: integer overflow vulnerability analysis; the integer overflow vulnerability analysis is used to detect addition, subtraction, multiplication, left shift, and right shift operations; The feedback module is used to feed back the analysis information generated by the tracking analysis module to the fuzzy engine module; The adaptive genetic algorithm includes: 1) Generate individuals for the initial population based on the binary interface of the smart contract; 2) Calculate the fitness of each individual using the following formula: in (i) is the branch coverage, which is obtained by calculating the number of code branches that an individual did not explore during the execution of a transaction; (i) is the data dependency, which is obtained by traversing the gene sequence of an individual and calculating the number of genes in the individual that are read-dependent or write-dependent; α+β = 1; 3) Calculate the fitness values ​​of all individuals in the population and sort them in ascending order; 4) Calculate the probability of the individual ranked i being selected using the following formula: in, To minimize the selection probability, Let i be the individual's rank and N be the population size, representing the maximum selection probability. 5) Normalize the probability of each individual in the population being selected by placing it into the wheel list; 6) Select the parent individual based on the wheel list using a random roulette wheel method; 7) Traverse the remaining list of individuals, extract the data dependencies of each individual, and compare them with the read and write operations of the parent individual; if there is a data dependency conflict, return the parent individual and the current individual as the parent individual; if there is no data dependency conflict, randomly select one from the current list of individuals as the parent individual using a random roulette wheel. 8) Determine the crossover probability between the parents based on their individual fitness. : in It is the maximum fitness value of the population. It is the minimum fitness value of the population; It is the average fitness value of the population; It is the largest fitness value among the parents. All are taken from (0,1), and ; 9) After performing the crossover operation, new individuals are generated. The fitness value of the new individuals is calculated, and the mutation probability of the new individuals is calculated based on the fitness value. : in It is the fitness value of the individual to be mutated. All are taken from (0,1), and .

2. The Ethereum smart contract integer overflow vulnerability detection device based on an adaptive genetic algorithm according to claim 1, characterized in that, Also includes: The compilation module is used to take the source code of the smart contract as input, perform a compilation operation to obtain the corresponding binary interface and EVM runtime bytecode of the smart contract program, and obtain all functions and parameters of the smart contract based on the binary interface.

3. The Ethereum smart contract integer overflow vulnerability detection device based on an adaptive genetic algorithm according to claim 1, characterized in that, The individual's encoding is represented as follows: Each individual is encoded as an input sequence, and each input sequence consists of an "environment" and a "transaction", both of which are encoded as key-value maps; The "environment" includes the timestamp and block number of the current block, as well as the call return value, data size, and external code size; the call return value, data size, and external code size are encoded as a mapping array. A "transaction" includes the address of the sending account, the transaction amount, the maximum gas value specified for contract execution, and the input data for contract execution. The input data is represented as an array of values, in which the first element is always used as a function representation, and the remaining elements represent function parameters. The calculation of the function representation uses a binary interface and extracts the first four bytes of the Keccak hash value based on the function signature.

4. The Ethereum smart contract integer overflow vulnerability detection device based on an adaptive genetic algorithm according to claim 2, characterized in that, The analysis of the integer overflow vulnerability includes: Check if the smart contract contains the opcodes ADD, MUL, SUB, SHL, and SHR. If it does not contain them, it is assumed that there is no integer overflow vulnerability. If it does contain them, proceed to the next step. Extract operands from the stack and use those operands to calculate the result of the arithmetic operation; Check if the calculation result is the same as the result pushed onto the stack. If they are the same, it is assumed that there is no integer overflow vulnerability. If they are different, proceed to the next step. Check if the calculation result flows into the SSTORE or CALL instruction. If it does, report an integer overflow vulnerability. If it does not, there is no integer overflow vulnerability.

5. A method for detecting integer overflow vulnerabilities in Ethereum smart contracts based on an adaptive genetic algorithm, characterized in that, include: An adaptive genetic algorithm is used to generate multiple individual test cases for all functions and parameters of the smart contract. Individual test cases generated through smart contract execution within a virtual Ethereum execution environment; Monitor the execution process of smart contracts and perform integer overflow vulnerability analysis on the execution process; the integer overflow vulnerability analysis is used to detect addition, subtraction, multiplication, left shift and right shift operations; The generated analysis information will be fed back. The adaptive genetic algorithm includes: 1) Generate individuals for the initial population based on the binary interface of the smart contract; 2) Calculate the fitness of each individual using the following formula: in (i) is the branch coverage, which is obtained by calculating the number of code branches that an individual did not explore during the execution of a transaction; (i) is the data dependency, which is obtained by traversing the gene sequence of an individual and calculating the number of genes in the individual that are read-dependent or write-dependent; α+β = 1; 3) Calculate the fitness values ​​of all individuals in the population and sort them in ascending order; 4) Calculate the probability of the individual ranked i being selected using the following formula: in, To minimize the selection probability, Let i be the individual's rank and N be the population size, representing the maximum selection probability. 5) Normalize the probability of each individual in the population being selected by placing it into the wheel list; 6) Select the parent individual based on the wheel list using a random roulette wheel method; 7) Traverse the remaining list of individuals, extract the data dependencies of each individual, and compare them with the read and write operations of the parent individual; if there is a data dependency conflict, return the parent individual and the current individual as the parent individual; if there is no data dependency conflict, randomly select one from the current list of individuals as the parent individual using a random roulette wheel. 8) Determine the crossover probability between the parents based on their individual fitness. : in It is the maximum fitness value of the population. It is the minimum fitness value of the population; It is the average fitness value of the population; It is the largest fitness value among the parents. All are taken from (0,1), and ; 9) After performing the crossover operation, new individuals are generated. The fitness value of the new individuals is calculated, and the mutation probability of the new individuals is calculated based on the fitness value. : in It is the fitness value of the individual to be mutated. All are taken from (0,1), and .

6. The method for detecting integer overflow vulnerabilities in Ethereum smart contracts based on an adaptive genetic algorithm according to claim 5, characterized in that, Before using an adaptive genetic algorithm to generate multiple individual test cases for all functions and parameters of the smart contract, the following steps are also included: The source code of the smart contract is used as input to perform a compilation operation to obtain the corresponding binary interface and EVM runtime bytecode of the smart contract program. Based on the binary interface, all functions and parameters of the smart contract are obtained.

7. The method for detecting integer overflow vulnerabilities in Ethereum smart contracts based on an adaptive genetic algorithm according to claim 5, characterized in that, The individual's encoding is represented as follows: Each individual is encoded as an input sequence, and each input sequence consists of an "environment" and a "transaction", both of which are encoded as key-value maps; The "environment" includes the timestamp and block number of the current block, as well as the call return value, data size, and external code size; the call return value, data size, and external code size are encoded as a mapping array. A "transaction" includes the address of the sending account, the transaction amount, the maximum gas value specified for contract execution, and the input data for contract execution. The input data is represented as an array of values, in which the first element is always used as a function representation, and the remaining elements represent function parameters. The calculation of the function representation uses a binary interface and extracts the first four bytes of the Keccak hash value based on the function signature.

8. The method for detecting integer overflow vulnerabilities in Ethereum smart contracts based on an adaptive genetic algorithm according to claim 6, characterized in that, The analysis of the integer overflow vulnerability includes: Check if the smart contract contains the opcodes ADD, MUL, SUB, SHL, and SHR. If it does not contain them, it is assumed that there is no integer overflow vulnerability. If it does contain them, proceed to the next step. Extract operands from the stack and use those operands to calculate the result of the arithmetic operation; Check if the calculation result is the same as the result pushed onto the stack. If they are the same, it is assumed that there is no integer overflow vulnerability. If they are different, proceed to the next step. Check if the calculation result flows into the SSTORE or CALL instruction. If it does, report an integer overflow vulnerability. If it does not, there is no integer overflow vulnerability.

Citation Information

Patent Citations

  • Ethereum smart contract security test method

    CN115114166A

  • Block chain intelligent contract vulnerability detection method and device based on hybrid fuzzy test

    CN115659335A