An intelligent contract malicious transaction detection and analysis method based on dynamic data storage

By adopting a method based on dynamic data storage in smart contract malicious transaction detection, using DNA computing technology and distributed edge nodes for transaction simulation and detection, the problems of low detection accuracy and slow efficiency in the existing technology are solved, and efficient and accurate malicious transaction detection and report generation are achieved, which significantly improves the security of smart contracts.

CN119538246BActive Publication Date: 2025-05-30BEIJING DINGXI YINGDONG TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411552030.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-01
Publication Date
2025-05-30
Estimated Expiration
2044-11-01

AI Technical Summary

Technical Problem

The existing smart contract malicious transaction detection methods have problems such as low accuracy, slow execution speed and inability to fully capture malicious behavior, especially in the utilization of data storage, management and distributed computing.

Method used

A smart contract malicious transaction detection and analysis method based on dynamic data storage is adopted. By extracting transaction hash from the block, obtaining transaction data and synchronous simulation in the virtual machine, intermediate data is generated. Then, DNA computing technology is used to perform high-density dynamic storage, establish a fast retrieval index structure, and reversely introduce the complete execution logic of the transaction. At the same time, the simulated execution tasks of transactions are processed in parallel by distributed edge nodes, and malicious transaction behavior is identified through the matching of the attack feature library.

Benefits of technology

It improves the accuracy and efficiency of malicious transaction detection, realizes high-density dynamic storage and rapid retrieval of intermediate data, enhances the security of smart contracts, and generates detailed detection reports.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119538246B_ABST
    Figure CN119538246B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage, which relates to the technical field of cloud computing. The method includes: extracting transaction hashes from blocks and obtaining transaction data from the blockchain according to the transaction hashes; synchronously simulating the transaction data in a virtual machine to generate intermediate data; during the execution simulation of the transaction, using DNA computing technology to perform high-density dynamic storage on the intermediate data, establishing an index structure for rapid retrieval, and inversely deducing the complete execution logic of the transaction; after completing data storage and logic inverse deduction, parallelly processing the simulation execution tasks of the transaction through distributed edge nodes, and identifying malicious transaction behaviors through matching with an attack feature library to generate a detection report. By introducing DNA computing technology, the present invention realizes high-density dynamic storage and rapid retrieval of intermediate data; by parallelly processing the simulation execution tasks of the transaction through distributed edge nodes, the efficiency of malicious transaction detection is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud computing, and particularly to a method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage. Background Art

[0002] With the rapid development of blockchain technology, smart contracts have gradually become the basis of decentralized applications. However, due to the transparency and automatic execution of smart contract code, malicious attackers often exploit vulnerabilities in smart contracts for attacks, resulting in huge property losses. Existing smart contract security analysis methods usually rely on static analysis and dynamic analysis tools, but these tools often have problems such as low accuracy, slow execution speed, and inability to comprehensively capture malicious behaviors.

[0003] The deficiencies of the prior art in detecting malicious transactions of smart contracts are as follows. First, existing smart contract detection mechanisms lack effective solutions for the storage and retrieval of intermediate data. Especially when a large number of transactions are executed, the bottleneck of data storage and management becomes more prominent. Second, when detecting malicious transaction behaviors, existing technologies often rely on single-node processing and do not fully utilize the advantages of distributed computing, so they cannot quickly and effectively lock malicious transaction behaviors. Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage, which solves the problem of low accuracy in improving the detection of malicious transactions during the execution of smart contract transactions.

[0006] To solve the above technical problems, the present invention provides the following technical solutions:

[0007] In a first aspect, an embodiment of the present invention provides a method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage, which includes extracting a transaction hash from a block and obtaining transaction data from the blockchain according to the transaction hash;

[0008] Synchronously simulating the transaction data in a virtual machine to generate intermediate data;

[0009] During the simulation execution of the transaction, using DNA computing technology to perform high-density dynamic storage on the intermediate data, establishing an index structure for fast retrieval, and inversely deducing the complete execution logic of the transaction;

[0010] After completing data storage and logic inverse deduction, parallelly processing the simulation execution tasks of the transaction through distributed edge nodes, and identifying malicious transaction behaviors through matching with an attack feature library;

[0011] Generating a detection report based on the detection results.

[0012] As a preferred solution of the malicious transaction detection and analysis method for smart contracts based on dynamic data storage according to the present invention, wherein: the transaction data includes transaction bytecode, initiator, recipient, and transaction amount.

[0013] As a preferred solution of the malicious transaction detection and analysis method for smart contracts based on dynamic data storage according to the present invention, wherein: synchronously simulate the transaction data in a virtual machine to generate intermediate data, including the following steps,

[0014] Initialize the virtual machine environment;

[0015] Map the transaction data to virtual memory and registers, decompose the transaction bytecode into individual instructions, and map the transaction initiator, recipient, and transaction amount to the virtual state;

[0016] Use an instruction interpreter to map each bytecode instruction into a specific operation, generating multiple potential execution paths. Considering the dynamic nature of smart contracts, each path represents a different logical branch;

[0017] Interpret and execute each bytecode instruction one by one through the virtual machine execution engine, and record the intermediate data including virtual memory state, virtual machine stack state, Gas consumption, and external call results.

[0018] As a preferred solution of the malicious transaction detection and analysis method for smart contracts based on dynamic data storage according to the present invention, wherein: use DNA computing technology to perform high-density dynamic storage on the intermediate data and establish an index structure for fast retrieval, including the following steps,

[0019] During the transaction simulation execution process, split the intermediate data into small blocks suitable for DNA encoding, define the encoding rules, map each data block to a DNA sequence, and add a check code and timestamp to each DNA sequence;

[0020] Compress a large amount of intermediate data into DNA sequences, design a dynamic storage and release mechanism, store data only when needed, and release the storage resources in a timely manner after the intermediate data is used;

[0021] Generate a unique retrieval tag for each DNA sequence according to the content of the data block;

[0022] Use a hash algorithm to generate an index for each DNA sequence, and through the parallel retrieval ability of DNA computing, compare multiple DNA tags simultaneously, find the DNA sequence that matches the query condition, and quickly extract the corresponding data block to obtain an index structure for fast retrieval.

[0023] As a preferred solution of the intelligent contract malicious transaction detection and analysis method based on dynamic data storage according to the present invention, wherein: based on the DNA sequence, the complete execution logic of the transaction is deduced backwards, including the following steps,

[0024] According to the timestamps in each DNA sequence, by analyzing the operation order of the bytecode, establish a logical order chain of execution, and construct a preliminary execution path;

[0025] By analyzing the changes in the stack and memory states of each operation step, identify key state updates and intermediate calculation results;

[0026] Parse the control flow through bytecode instructions to identify conditional branches and loop structures;

[0027] Analyze all external contract calls during the transaction process, and trace parameter passing, return values, and call logic;

[0028] Integrate the identification and analysis results into the preliminary execution path to reconstruct the execution path of the intelligent contract;

[0029] Based on the reconstructed execution path of the intelligent contract, deduce backwards the complete execution logic of the transaction.

[0030] As a preferred solution of the intelligent contract malicious transaction detection and analysis method based on dynamic data storage according to the present invention, wherein: the simulation execution tasks of the transaction are processed in parallel by distributed edge nodes, including the following steps,

[0031] Analyze the bytecode of the intelligent contract through a static analysis tool to identify logical boundaries, and block the bytecode instructions of the transaction based on the logical boundaries;

[0032] Allocate task blocks to each node according to the computing power and current load of the edge nodes;

[0033] After receiving the tasks, each edge node starts to execute the partial bytecode simulation tasks of the transaction, and collects and stores edge execution data including stack state, memory state, and function call conditions. During the execution process, data synchronization is performed between nodes through a coordination mechanism.

[0034] As a preferred solution of the intelligent contract malicious transaction detection and analysis method based on dynamic data storage according to the present invention, wherein: malicious transaction behaviors are identified through matching with an attack feature library, including the following steps,

[0035] Define attack types, including reentry attacks, integer overflows / underflows, and unchecked external calls;

[0036] Extract potential attack patterns by simulating attack scenarios;

[0037] Input the bytecodes of a large number of smart contracts into a static analysis tool, and extract the bytecode sequences of each vulnerability as attack features;

[0038] After standardizing the collected attack features, combine the attack patterns and attack types, and store them in the feature library to obtain the attack feature library;

[0039] Analyze the edge execution data to detect whether there are abnormal behaviors;

[0040] If no abnormal behavior is detected, directly generate a detection report;

[0041] If abnormal behavior is detected, use the attack features in the attack feature library to perform real-time matching on the edge execution data, identify the attack pattern, and lock the malicious transaction behavior.

[0042] As a preferred solution of the malicious transaction detection and analysis method for smart contracts based on dynamic data storage according to the present invention, wherein: generating a detection report based on the detection result means listing the types of malicious transaction behaviors and the specific bytecode sequences where abnormalities occur, showing the stack depth, memory state, function call situation, and Gas consumption caused by the abnormal behavior when the abnormality occurs, to obtain the detection report.

[0043] In a second aspect, an embodiment of the present invention provides a computer device, including a memory and a processor, where: when the computer program stored in the memory is executed by the processor, any step of the malicious transaction detection and analysis method for smart contracts based on dynamic data storage as described in the first aspect of the present invention is implemented.

[0044] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored, where: when the computer program is executed by the processor, any step of the malicious transaction detection and analysis method for smart contracts based on dynamic data storage as described in the first aspect of the present invention is implemented.

[0045] The beneficial effects of the present invention are as follows: By introducing DNA computing technology, high-density dynamic storage and fast retrieval of intermediate data are realized. DNA computing technology can not only compress and store intermediate data, but also, through timestamp and hash index structure, realize reverse derivation and fast retrieval of transaction execution logic. This dynamic storage mechanism ensures that data can be quickly accessed when needed and the storage resources can be released in a timely manner when not needed, improving the storage utilization rate. In addition, by using distributed edge nodes to parallelly process the simulation execution tasks of transactions, the efficiency of malicious transaction detection is greatly improved. Combined with the real-time matching of the attack feature library, the present invention can more quickly and accurately identify malicious transaction behaviors and generate detailed detection reports, greatly enhancing the security of smart contracts. Description of the Drawings

[0046] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0047] Figure 1 It is a flowchart of the intelligent contract malicious transaction detection and analysis method based on data dynamic storage in Embodiment 1.

[0048] Figure 2 It is a flowchart of identifying malicious transaction behaviors in Embodiment 1. Specific Embodiments

[0049] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will provide a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification.

[0050] Many specific details are set forth in the following description to facilitate a thorough understanding of the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0051] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present invention. The "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that mutually excludes other embodiments.

[0052] Embodiment 1, referring to Figure 1 and Figure 2 , is the first embodiment of the present invention. This embodiment provides an intelligent contract malicious transaction detection and analysis method based on data dynamic storage, including the following steps:

[0053] S1. Extract the transaction hash from the block and obtain the transaction data from the blockchain according to the transaction hash, including the following steps:

[0054] The transaction data includes transaction bytecode, initiator, recipient, and transaction amount.

[0055] It should be noted that before obtaining transaction data, it is necessary to synchronize the blockchain. According to the current business scenario, select an appropriate blockchain synchronization strategy, including full synchronization, incremental synchronization, and specified height synchronization. Full synchronization means synchronizing all block information of the blockchain starting from the genesis block, which is applicable to the initial startup or when it is necessary to rebuild the local blockchain state. Incremental synchronization means starting from the last stopped position and only synchronizing the newly added block information, which is applicable to daily operations and can improve the synchronization efficiency. Specified height synchronization means specifying to synchronize data starting from a certain block height according to user input or a configuration file, which is applicable to transaction analysis during a specific period.

[0056] It should be noted that by extracting the transaction hash from the block and obtaining the transaction data based on the transaction hash, the present invention can quickly locate and extract complete information related to a specific transaction, including transaction bytecode, initiator, recipient, and transaction amount, etc. This precise positioning and data extraction mechanism provides basic data for subsequent transaction simulation and detection, ensuring that the analysis of each transaction is based on a real and complete data source, thereby improving the accuracy and reliability of the analysis.

[0057] S2. Synchronously simulate the transaction data in the virtual machine to generate intermediate data, including the following steps:

[0058] A virtual machine is a technology that simulates a complete computer system through software (such as VirtualBox, Hyper-V, etc.), allowing multiple operating systems or applications to run on physical hardware, providing a hardware abstraction layer and isolation to improve resource utilization and system flexibility.

[0059] Initialize the virtual machine environment.

[0060] Specifically, start the virtual machine simulation execution unit. The virtual machine simulation execution unit is responsible for simulating the execution process of the smart contract in the virtual environment. The core modules of the virtual machine include virtual memory, register group, instruction interpreter, and execution engine. This virtual machine environment needs to be able to fully simulate the smart contract execution mechanism in the blockchain network to ensure that each bytecode instruction can be accurately executed.

[0061] Map the transaction data to the virtual memory and registers. The transaction bytecode is decomposed into individual instructions and is prepared to be interpreted and executed one by one in the virtual machine environment. The transaction initiator, recipient, and transaction amount are mapped to the virtual state to ensure that the contract execution in the virtual environment is consistent with the actual transaction scenario.

[0062] Using an instruction interpreter, each bytecode instruction is mapped into a specific operation (such as calling a function, updating storage, transferring money, etc.), generating multiple potential execution paths. Considering the dynamic nature of smart contracts (such as conditional branches, loops, calling other contracts, etc.), each path represents a different logical branch.

[0063] The virtual machine execution engine interprets and executes each bytecode instruction one by one, and records intermediate data including virtual memory status, virtual machine stack status, gas consumption, and external call results;

[0064] Specifically, after each bytecode instruction is executed, the variables stored in the virtual memory, the contract's storage data, the account balance, etc. will change with the execution of the instruction. These changes are captured to ensure that the memory state of each path can be fully recorded. Each element in the stack represents the number of operations currently executed or the intermediate result. For example, when a smart contract executes an addition operation, the stack state before and after the addition operation is recorded to ensure that the execution process of each path is clearly visible. The Gas consumption of each path will be carefully tracked, and the Gas consumption of each bytecode instruction will be recorded to ensure that the economy of the simulated execution is consistent with the actual execution. If the Gas consumption of a path exceeds the Gas limit of the transaction, the path will be marked as failed and terminated. Continued execution, when a contract calls an external contract (such as through bytecode instructions such as CALL (call instruction in Ethereum virtual machine EVM), DELEGATECALL (delegate call instruction)), the detailed information of the external call is recorded, including the address of the called contract, the passed parameters, the return value and status (success or failure) of the call. External contract calls also consume Gas. The system records the Gas consumption of each external call and includes it in the total Gas consumption, tracks the return value of the external call, and determines the subsequent execution logic of the contract based on the return value. For example, some contracts rely on the return value of the external contract to execute conditional branches. The results of each external call will be recorded in detail to ensure that the call results affect the subsequent path execution.

[0065] It should be noted that synchronous simulation in a virtual machine can accurately simulate the execution process of smart contracts and generate detailed intermediate data, such as virtual memory status, stack status, gas consumption, and external call results. This refined simulation can not only reproduce the execution process of smart contracts in a real environment, but also help track the details of each step of the operation, thereby providing a complete execution path and status data for subsequent malicious transaction detection, significantly improving the ability to analyze complex contract logic.

[0066] S3. During the transaction simulation execution process, DNA computing technology is used to perform high-density dynamic storage of intermediate data, establish an index structure for fast retrieval, and reverse the complete execution logic of the transaction, including the following steps:

[0067] S3.1. During the trading simulation execution process, split the intermediate data into small chunks suitable for DNA encoding, define the encoding rules. Specifically, the encoding rule is to map 3-bit binary data to 1 base, map each data chunk to a DNA sequence. The binary information (0 and 1) in each data chunk will be mapped to the DNA base sequence (A, T, C, G), and add a checksum and a timestamp to each DNA sequence. During the data storage and retrieval process, the checksum is used to verify the accuracy of the data and prevent errors;

[0068] It should be noted that DNA computing uses the four bases of DNA (A, T, C, G) as the information storage carrier, and can achieve a higher density than traditional storage devices;

[0069] Compress a large amount of intermediate data into DNA sequences, significantly reducing the storage space occupancy. Design a dynamic storage and release mechanism to store data only when needed, and release the storage resources in a timely manner after the intermediate data is used or analyzed;

[0070] Generate a unique retrieval tag for each DNA sequence according to the content of the data chunk, the trading execution timestamp, or the key logical nodes;

[0071] Use the hash algorithm to generate an index for each DNA sequence. Through the parallel retrieval ability of DNA computing, compare multiple DNA tags simultaneously, find the DNA sequence that matches the query condition, and quickly extract the corresponding data chunk to obtain a fast retrieval index structure.

[0072] It should be noted that using DNA computing technology for high-density dynamic storage of intermediate data greatly improves the density and efficiency of data storage. The storage capacity of DNA sequences far exceeds that of traditional storage media, and can decompose a large amount of intermediate data into small chunks and compress them. This not only solves the storage problem of a large amount of data generated during the execution of smart contracts, but also ensures that the data can be quickly retrieved through the index structure. The parallel retrieval ability of DNA computing can process multiple query requests simultaneously, greatly improving the retrieval speed of intermediate data, and providing technical support for real-time detection of malicious trading behaviors.

[0073] S3.2. According to the timestamp in each DNA sequence, establish an execution logic sequence chain by analyzing the operation order of the bytecode, and construct a preliminary execution path;

[0074] Specifically, all log data related to the execution of the smart contract is obtained through blockchain nodes or monitoring tools, including the transaction timestamp, bytecode instructions for each operation, stack status, memory status, Gas consumption, etc. Each operation step comes with a timestamp indicating its order in the entire contract execution. By analyzing the operation order of the bytecode, a logical execution order chain is established;

[0075] By analyzing the changes in the stack and memory status of each operation step, key state updates (such as storage writes, parameter passing) and intermediate calculation results are identified;

[0076] Specifically, gradually parse the stack changes of each operation, track the depth changes of the stack, and record the key operands. Monitor the changes in the memory status, especially the writes, reads, and modifications to the memory. Analyze the dynamic data involved in the process to determine the storage locations of state variables and important memory operations;

[0077] Parse the control flow through the bytecode (instructions such as JUMP or JUMPI (jump instruction or conditional jump instruction)) to identify conditional branches and loop structures;

[0078] Specifically, through the JUMPI instruction, identify the conditional judgments in the contract, and infer the branches of the execution path through the conditional values in the stack. Through the JUMP instruction, identify the loop structure, analyze the boundary conditions and iteration times of the loop. Combine the stack changes to determine the termination conditions of the loop;

[0079] Analyze all external contract calls during the transaction process, track parameter passing, return values, and call logic;

[0080] Specifically, identify the bytecode instructions of the external call, determine the target address of the call, record the parameters passed to the external contract, analyze the return value of the call, and determine how the return value affects the subsequent logic. Embed the external contract call into the main execution path to ensure that the logic of the external call is consistent with the main contract logic;

[0081] Integrate the identification and analysis results into the preliminary execution path to reconstruct the execution path of the smart contract;

[0082] Based on the reconstructed execution path of the smart contract, reverse-infer the complete execution logic of the transaction.

[0083] It should be noted that the reverse tracing process helps to trace the origin and execution path of malicious trading behaviors, especially in the face of complex contract attacks (such as re-entrancy attacks or multi-layer nested calls). By analyzing each operation in the execution path, the present invention can identify the specific location of malicious operations and their triggering conditions, providing strong technical support for the accurate detection and prevention of malicious trading behaviors. This reverse tracing analysis mechanism significantly improves the comprehensiveness and accuracy of transaction simulation, contributing to enhancing the security and reliability of smart contracts.

[0084] S4. After completing data storage and logical reverse tracing, the distributed edge nodes are used to parallelly process the simulation execution tasks of transactions, and malicious trading behaviors are identified through the matching of the attack feature library, including the following steps.

[0085] S4.1. Analyze the bytecode of the smart contract through a static analysis tool (such as Slither (a smart contract security analysis tool)) to identify logical boundaries (such as functions, loops, conditional branches, etc.), and divide the bytecode instructions of the transaction based on the logical boundaries.

[0086] Specifically, logical boundaries include structures such as functions, loops, and conditional branches. The entry point of a function is usually identified by a function selector (a 4-byte hash). In the bytecode, the selector of a function call can help us locate the starting position of the function. By identifying the entry and end points of the function, the bytecode can be divided into different function blocks. In the bytecode of a smart contract, conditional branches are usually implemented through the JUMPI instruction. JUMPI is a conditional jump instruction that determines whether to jump to a specified bytecode position based on the conditional value at the top of the stack. Identify the starting and ending points of the conditional branch to ensure the integrity of the branch structure. Loops in the bytecode usually use JUMP and JUMPI in combination. JUMP is an unconditional jump, often used for the back jump in the loop body. By analyzing the target position of the JUMP instruction and the jump condition, the loop structure can be identified, and the starting point, ending point, and their conditional judgment of the loop can be identified. External contract calls in the smart contract are presented by corresponding instructions in the bytecode. Through these instructions, the contract can call another external contract, pass parameters, and receive return values. By identifying these instructions, the logic of external calls can be divided into separate blocks to facilitate the analysis of cross-contract interaction logic.

[0087] According to the computing power and current load of the edge nodes, task blocks are allocated to each node. The goal of task allocation is to balance the load of each node and ensure the maximization of the efficiency of parallel execution.

[0088] After each edge node receives a task, it starts to execute a partial bytecode simulation task of the transaction, and collects and stores edge execution data including stack state, memory state, and function call situation. During the execution process, data synchronization is carried out among the nodes through a cooperation mechanism to ensure the state consistency between task blocks. Each edge node generates edge execution data when executing bytecodes, and a distributed hash table is used to manage the storage and sharing of edge execution data. The cooperation mechanism means that when a node needs to access the edge execution data of other nodes, it sends a data request through the DHT mechanism. In the case of cross-block dependencies, each node will regularly synchronize the execution state of its task block (such as the current stack and memory state) to other nodes that depend on this data.

[0089] It should be noted that by parallelly processing the simulation execution tasks of transactions through distributed edge nodes, the present invention can make full use of the computing resources of multiple nodes to achieve partial task parallel processing of transaction bytecodes. This distributed computing mode avoids the performance bottleneck of single-node processing, significantly improves the processing efficiency of transaction simulation, especially when facing a large number of transaction tasks, it can effectively shorten the simulation execution time. In addition, the cooperation mechanism among edge nodes ensures data synchronization and consistency, guaranteeing the accuracy of simulation processing. S4.2. Define attack types, including reentrancy attacks, integer overflow / underflow, and unchecked external calls;

[0090] Extract potential attack patterns by simulating attack scenarios;

[0091] Input the bytecodes of a large number of smart contracts into a static analysis tool, and output the vulnerability information of each contract, including vulnerability types, the bytecode sequences where they occur, and relevant information such as memory, stack, and Gas consumption. Extract the bytecode sequences of each vulnerability as attack features;

[0092] After standardizing the collected attack features, combine them with attack patterns and attack types, and store them in a feature library to obtain an attack feature library;

[0093] Specifically, the stack state includes collecting the current stack depth, the types and orders of operands. Stack operations are crucial during contract execution, and any abnormal stack behavior may indicate potential attacks, such as stack overflow or unexpected operand changes; the memory state includes recording the variable values in memory and their changes. By monitoring the memory state, abnormal behaviors such as illegal memory access and unauthorized data modification can be detected; function calls refer to tracking external function call situations, especially unchecked return values. Unchecked external function calls may lead to attack behaviors (such as reentrancy attacks);

[0094] Detect whether there are abnormal behaviors by analyzing the edge execution data;

[0095] If no abnormal behavior is detected, a detection report is directly generated;

[0096] If abnormal behavior is detected, the attack features in the attack feature library are used to perform real-time matching on the edge execution data, identify the attack pattern, and lock the malicious trading behavior;

[0097] Specifically, the feature of a reentry attack is that when a contract calls an external contract, the external contract calls the original contract again, resulting in the state not being updated in time. Reentry attack detection is triggered by monitoring the function call stack. If a second call occurs before the function call is completed, reentry attack detection is triggered, the reentry attack is identified, and the transaction simulation is terminated. The feature of integer overflow / underflow is that when the result of an arithmetic operation exceeds the representable range of the data type. Integer overflow detection is performed by monitoring the result of each arithmetic operation to check whether the result exceeds the boundary of the data type, identifying the integer overflow, and recording the exception. The feature of unchecked external calls is that after a contract calls an external contract, the return value is not checked. Unchecked external calls are monitored by checking the return value of each external call. If the return value is not checked, it is marked as a potential attack behavior, the unchecked call is identified, and the developer is prompted to fix it.

[0098] It should be noted that through the matching of the attack feature library, the present invention can quickly identify potential malicious behaviors in transactions. The features in the attack feature library are based on in-depth analysis and standardized extraction of malicious trading patterns, and can accurately match abnormal patterns that occur during the transaction execution process. Combining real-time transaction simulation and intermediate data analysis, attack behaviors such as reentry attacks and integer overflows can be detected in a timely manner during the transaction execution process, significantly improving the accuracy and response speed of malicious transaction detection and enhancing the security of smart contracts.

[0099] S5. Generating a detection report based on the detection result means listing the types of malicious trading behaviors and the specific bytecode sequences where anomalies occur, showing the stack depth, memory state, function call situation, and Gas consumption caused by the abnormal behavior when the anomaly occurs, to obtain the detection report.

[0100] It should be noted that by generating a detection report based on the detection result, the present invention can provide detailed and accurate detection feedback. The report not only lists the types of malicious trading behaviors, but also shows the specific bytecode sequences, stack depth, memory state, function call situation, and Gas consumption when the anomaly occurs. Through such a detailed report, users can clearly understand the specific details and scope of influence of the attack, thereby providing a basis for subsequent security protection or vulnerability repair, and greatly enhancing the auditability and transparency of smart contracts.

[0101] This embodiment also provides a computer device, which is applicable to the scenario of the malicious transaction detection and analysis method for smart contracts based on dynamic data storage, and includes: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the malicious transaction detection and analysis method for smart contracts based on dynamic data storage as proposed in the above embodiment.

[0102] The computer device can be a terminal. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covered on the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the computer device, or an external keyboard, a touchpad, or a mouse, etc.

[0103] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the malicious transaction detection and analysis method for smart contracts based on dynamic data storage as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Red-Only Memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc.

[0104] In summary, the present invention realizes high-density dynamic storage and fast retrieval of intermediate data by introducing DNA computing technology. The DNA computing technology can not only compress and store intermediate data, but also realize reverse derivation and fast retrieval of transaction execution logic through timestamps and hash index structures. This dynamic storage mechanism ensures fast access to data when needed and timely release of storage resources when not needed, improving storage utilization. In addition, by distributing the simulation execution tasks of transactions to edge nodes in parallel, the efficiency of malicious transaction detection is greatly improved. Combined with real-time matching of the attack feature library, the present invention can identify malicious transaction behaviors more quickly and accurately and generate detailed detection reports, greatly enhancing the security of smart contracts.

[0105] Example 2. Referring to Table 1, this is the second example of the present invention. To further verify the technical solution of the present invention, experimental simulation data of a malicious transaction detection and analysis method for smart contracts based on data dynamic storage is given.

[0106] To evaluate the effectiveness of the malicious transaction detection and analysis method for smart contracts based on data dynamic storage, a comparative experiment between an experimental group and a control group was designed. The experimental group used a malicious transaction detection method for smart contracts based on DNA computing technology to store and reverse-analyze the transaction data of smart contracts; the control group used a conventional detection method based on log recording and static analysis. The experimental objects were the transaction data on two smart contract platforms, simulating malicious transaction behaviors such as reentry attacks and integer overflow attacks respectively.

[0107] In the experimental preparation stage, the corresponding transaction hashes were first extracted from the blockchain network, and the complete transaction data, including basic information such as transaction bytecode, initiator, recipient, and transaction amount, was obtained according to the hash values. In the experimental group, a virtual machine was used to synchronously simulate the transaction data to generate detailed intermediate data. Subsequently, DNA computing technology was used to perform high-density dynamic storage on the intermediate data, and corresponding indexes and check codes were generated through DNA sequences to ensure that the data could be quickly retrieved in subsequent steps. At the same time, based on the timestamps and contents of the DNA sequences, the complete execution logic of the transaction was reverse-derived.

[0108] After the storage and reverse derivation were completed, the experimental group used distributed edge nodes to parallel-process the simulation execution tasks of transactions. Combining features such as reentry attacks and integer overflows in the attack feature library, malicious transactions were accurately identified and relevant detection reports were generated. The control group relied on traditional log recording and static analysis tools to gradually parse and detect the transaction data. During the experiment, key parameters such as data storage efficiency, reverse derivation time of transaction execution logic, and malicious transaction detection time were recorded for each group respectively.

[0109] Specifically, as shown in Table 1 below:

[0110] Table 1 Experimental Record Table

[0111]

[0112]

[0113] By comparing the data of the experimental group and the control group in Table 1, it can be clearly seen that the intelligent contract malicious transaction detection method using DNA computing technology in the experimental group shows significant advantages in various key parameters. First of all, in terms of data storage efficiency, the experimental group achieved a storage efficiency of 450MB per second by using DNA computing technology to compress intermediate data at high density, which is a 125% increase compared to 200MB of the control group. This significant improvement benefits from the storage and retrieval capabilities of DNA computing technology for large-scale data, greatly optimizing the storage problem of a large amount of intermediate data generated during transaction simulation.

[0114] Secondly, the reverse inference time of the transaction execution logic in the experimental group is only 15 seconds, while the control group requires 35 seconds. Through the index structure of timestamps and DNA sequences, the experimental group can quickly deduce the complete execution path of the transaction, greatly reducing the time cost of reverse inference analysis and improving efficiency.

[0115] In terms of malicious transaction detection time, the experimental group performs more prominently, only taking 8 seconds to complete the identification of malicious transactions, while the control group requires 25 seconds. The experimental group parallelizes tasks through distributed edge nodes and combines real-time matching of the attack feature library, significantly improving the detection speed and accuracy. In terms of memory occupancy, the storage mechanism of the experimental group is more efficient, only occupying 300MB of memory, while the control group requires 700MB, indicating that DNA computing technology is more resource-saving in data management.

[0116] In addition, the retrieval speed of intermediate data in the experimental group reached 5,000 data blocks per second, while the control group was only 2,000, showing the strong advantage of DNA computing technology in parallel retrieval capabilities. In terms of the accuracy rate of malicious transaction identification, the experimental group reached 98%, while the control group was only 70%, further proving the high accuracy of the present invention in malicious transaction detection.

[0117] In summary, the intelligent contract malicious transaction detection method based on DNA computing technology of the present invention has significant advantages in aspects such as data storage efficiency, reverse inference time, detection time, and resource occupancy, especially showing strong innovation and novelty in the real-time identification and detection accuracy of malicious transactions. These advantages not only effectively solve the problem of low data storage and analysis efficiency in existing detection methods, but also significantly improve the accuracy and speed of intelligent contract malicious transaction detection, providing a strong technical guarantee for the security of intelligent contracts.

[0118] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.

Claims

1. A method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage, characterized in that: include, Extract the transaction hash from the block and obtain the transaction data from the blockchain based on the transaction hash; Simulate transaction data synchronously in a virtual machine to generate intermediate data; During the transaction simulation execution process, DNA computing technology is used to store intermediate data in a high-density dynamic manner, establish an index structure for fast retrieval, and reverse the complete execution logic of the transaction; DNA computing technology is used to store intermediate data in a high-density dynamic manner and to establish an index structure for fast retrieval, including the following steps: During the transaction simulation execution, the intermediate data is split into small blocks suitable for DNA encoding, the encoding rules are defined, each data block is mapped to a DNA sequence, and a checksum and timestamp are added to each DNA sequence; Compress a large amount of intermediate data into DNA sequences, design a dynamic storage and release mechanism, store data only when needed, and release storage resources in time after the intermediate data is used; Generate a unique retrieval tag for each DNA sequence based on the content of the data block; A hash algorithm is used to generate an index for each DNA sequence. Through the parallel retrieval capability of DNA computing, multiple DNA tags are compared at the same time to find the DNA sequence that matches the query condition and quickly extract the corresponding data block to obtain a fast retrieval index structure. The complete execution logic of the transaction is deduced in reverse, including the following steps: According to the timestamp in each DNA sequence, by analyzing the operation sequence of the bytecode, a logical sequential chain of execution is established to construct a preliminary execution path; By analyzing the stack and memory state changes of each operation step, key state updates and intermediate calculation results are identified; Parse control flow through bytecode instructions and identify conditional branches and loop structures; Analyze all external contract calls during the transaction, track parameter passing, return values, and call logic; Integrate the identification and analysis results into the preliminary execution path and reconstruct the execution path of the smart contract; Based on the reconstruction of the execution path of the smart contract, the complete execution logic of the transaction can be deduced; After completing data storage and logic inversion, the simulated execution tasks of transactions are processed in parallel through distributed edge nodes, and malicious transaction behaviors are identified by matching the attack feature library; Based on the test results, a test report is generated.

2. The method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage as claimed in claim 1, characterized in that: The transaction data includes transaction bytecode, initiator, recipient and transaction amount.

3. The method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage as claimed in claim 2, characterized in that: The transaction data is synchronously simulated in the virtual machine to generate intermediate data, including the following steps: Initialize the virtual machine environment; Map transaction data to virtual memory and registers. The transaction bytecode is decomposed into instructions, and the transaction initiator, receiver, and transaction amount are mapped to virtual states. Using an instruction interpreter, each bytecode instruction is mapped into a specific operation, generating multiple potential execution paths. Considering the dynamic nature of smart contracts, each path represents a different logical branch. Each bytecode instruction is interpreted and executed one by one through the virtual machine execution engine, and intermediate data including virtual memory status, virtual machine stack status, Gas consumption and external call results are recorded.

4. The method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage as claimed in claim 3, characterized in that: The simulated execution task of parallel processing of transactions by distributed edge nodes includes the following steps: Analyze the bytecode of the smart contract through static analysis tools, identify logical boundaries, and divide the bytecode instructions of the transaction into blocks based on the logical boundaries; Assign task blocks to each node based on the computing power and current load of the edge node; After receiving the task, each edge node starts to execute part of the bytecode simulation task of the transaction, and collects and stores edge execution data including stack status, memory status and function call status. During the execution process, data is synchronized between nodes through a collaborative mechanism.

5. The method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage as claimed in claim 4, characterized in that: By matching the attack feature library, malicious transaction behaviors are identified, including the following steps: Define attack types, including reentrancy attacks, integer overflow / underflow, and unchecked external calls; Extract potential attack patterns by simulating attack scenarios; Input a large number of smart contract bytecodes into static analysis tools and extract the bytecode sequence of each vulnerability as attack features; After the collected attack features are standardized, they are combined with attack modes and attack types and stored in a feature library to obtain an attack feature library; Analyze edge execution data to detect abnormal behavior; If there is no abnormal behavior in the detection, a detection report is directly generated; If abnormal behavior is detected, the attack features in the attack feature library are used to match the edge execution data in real time, identify the attack mode, and lock down malicious transaction behavior.

6. The method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage as claimed in claim 5, characterized in that: Based on the detection results, generating a detection report means listing the type of malicious transaction behavior and the specific bytecode sequence where the exception occurred, displaying the stack depth, memory status, function call status and Gas consumption caused by the abnormal behavior when the exception occurred, and obtaining a detection report.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the smart contract malicious transaction detection and analysis method based on dynamic data storage as described in any one of claims 1 to 6 are implemented.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the steps of the method for detecting and analyzing malicious transactions of smart contracts based on dynamic data storage as described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Intelligent contract malicious transaction detection and analysis system and method based on data dynamic storage

    CN114491508A

  • Medical instrument inventory intelligent allocation supervision system based on Internet of Things

    CN118644182A

  • Storing digital data in DNA storage using blockchain and destination-side deduplication using smart contracts

    US20220237470A1