Intelligent contract vulnerability detection method and device based on granular ball calculation and weight path signature similarity
Through particle sphere calculation and weight path signature similarity detection, combined with reverse program slice analysis and word-vector mapping table, the problem of insufficient accuracy of smart contract vulnerability detection is solved, more efficient and accurate vulnerability detection is achieved, and the security evaluation of smart contracts is enhanced.
Patent Information
- Application Number
- CN202510045923.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-13
AI Technical Summary
The existing smart contract vulnerability detection methods are insufficient in terms of accuracy. Traditional program analysis methods rely on manual defined expert rules and are difficult to deal with the diversity and sensitivity of smart contract codes; deep learning methods fail to fully consider the impact of vulnerability-independent codes and ignore the semantics of custom names.
A smart contract vulnerability detection method based on particle sphere calculation and weight path signature similarity is adopted. A sensitive path collection is obtained through reverse program slice analysis, a program dependency graph is generated and PageRank value is calculated, a word-vector mapping table is constructed and the weight path information is fused, and the weight path signature is generated, and the similarity comparison with the vulnerability signature library is performed to identify potential vulnerabilities, and the defense mode is detected to judge the existence of the vulnerability.
It improves the accuracy and efficiency of vulnerability detection, reduces the rate of missed reports and false alarms, can cover areas where vulnerabilities may exist, enhances the detection capabilities of new and complex vulnerabilities, and provides a more reliable smart contract security assessment.
Smart Images

Figure CN119939602A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer technology, and in particular to a smart contract vulnerability detection method and device based on spherical calculation and weighted path signature similarity. Background Art
[0002] Blockchain technology has been widely used in many fields such as finance, supply chain management, and the Internet of Things. As the core component of blockchain, the security of smart contracts plays a decisive role in the stable operation of the entire system and the security of user assets. Therefore, the research on smart contract vulnerability security has become a key link in promoting the development and application of blockchain technology. Through in-depth research on smart contract vulnerabilities, hackers can be effectively prevented from exploiting vulnerabilities to attack, avoiding serious consequences such as economic losses and data leakage, which makes smart contract vulnerability detection a hot research direction.
[0003] At present, there are two main methods for smart contract vulnerability detection: traditional program analysis and deep learning. In the field of traditional program analysis, open source static analysis tools such as Slither parse contract code, build abstract syntax trees and control flow graphs, and use technologies such as symbolic execution and data flow analysis to find potential security issues. In the field of deep learning, the SaferSC model has pioneered the use of deep learning to detect smart contract vulnerabilities. It analyzes the opcodes of smart contracts and combines the LSTM network to build an Ethereum opcode sequence model, thereby realizing the identification and detection of smart contract vulnerabilities.
[0004] Although existing methods have achieved certain results in smart contract vulnerability detection, they still have obvious shortcomings in accuracy, which are manifested in the following aspects:
[0005] Limitations of traditional program analysis methods: Such methods are highly dependent on manually defined expert rules. On the one hand, smart contract codes are diverse and have different coding styles, which makes it extremely difficult to formulate unified and comprehensive rules; on the other hand, smart contracts mainly involve asset transactions, their operations are sensitive, and there are unique transfer functions such as call.value(), which leads to the fact that most contract vulnerabilities are logical vulnerabilities. It is almost impossible to manually define a complete vulnerability model.
[0006] The flaw of the deep learning method: This method does not fully consider the impact of vulnerability-irrelevant code. In smart contract projects, the proportion of vulnerability-related code is usually small, and sometimes a single statement can determine whether a contract has a vulnerability. However, when learning contract representation, if all codes are treated equally, due to the large proportion of vulnerability-irrelevant code, it is difficult for the model to learn the mapping relationship between effective vulnerability features and labels, which leads to deviations in vulnerability detection results.
[0007] Ignoring the semantics of custom contract names: Existing methods generally do not pay attention to the semantic importance of custom contract names (including function names and variable names). In fact, the naming of most contract variables has practical meanings, and many names that do not seem to be synonymous express similar meanings. However, traditional program analysis methods directly use normalization to erase the meaning of custom names, and deep learning methods also fail to consider the connection between different words. For example, variable names credit, balance, and contributions, and function names withdraw() and refund(). Summary of the invention
[0008] In order to solve the problems existing in the background technology, one aspect of the present invention provides a smart contract vulnerability detection method based on spherical calculation and weighted path signature similarity, comprising:
[0009] S1: Determine the sensitive functions in the smart contract source code according to the given sensitive word list, generate the control flow graph corresponding to each sensitive function, perform reverse program slicing analysis to obtain the set of all sensitive paths from the sensitive function entry to the sensitive word in the control flow graph, where the function where the sensitive word is located is called a sensitive function;
[0010] S2: Generate a program dependency graph of the sensitive function based on the abstract syntax tree and the control flow graph of the sensitive function. For each sensitive path in the sensitive path set, calculate the PageRank value of each node in the program dependency graph as the weight value of the node in the path, and generate a weight path corresponding to the sensitive path.
[0011] S3: Construct a smart contract word-vector mapping table through the granular ball algorithm, and generate a vector representation of each node in the sensitive path based on the word-vector mapping table; fuse the vector representation of each node in the sensitive path and the weight path information to obtain the weight path signature;
[0012] S4: The weighted path signature of each sensitive path is compared with the weighted path signatures in various vulnerability signature libraries for similarity. When there are N weighted path signatures in the vulnerability signature library whose similarity with the weighted path signature of the sensitive path is greater than the set threshold, the sensitive path is regarded as a potential vulnerability path of the vulnerability type corresponding to the vulnerability signature library;
[0013] S5: Detect whether the potential vulnerability path in the smart contract source code contains the defense mode of the corresponding vulnerability type. If not, it is determined that this type of vulnerability exists in the smart contract source code.
[0014] Another aspect of the present invention provides a smart contract vulnerability detection device based on granular calculation and weighted path signature similarity, comprising a processor and a memory; the memory is used to store a computer program; the processor is connected to the memory, and is used to execute the computer program stored in the memory, so that the smart contract vulnerability detection device based on granular calculation and weighted path signature similarity executes the smart contract vulnerability detection method based on granular calculation and weighted path signature similarity.
[0015] Another aspect of the present invention provides a computer-readable storage medium storing a program, which, when executed by a processor, implements the smart contract vulnerability detection method based on spherical calculation and weighted path signature similarity.
[0016] The present invention has at least the following beneficial effects
[0017] The present invention determines the sensitive functions in the smart contract source code according to a given sensitive word list, generates a control flow graph and performs reverse program slicing analysis, and can comprehensively obtain all sensitive path sets from the sensitive function entry to the sensitive word. Compared with the traditional method, this method is no longer limited to the surface code analysis, but goes deep into the code, more comprehensively covers the areas where vulnerabilities may exist, and greatly reduces the possibility of underreporting. Based on the abstract syntax tree and the control flow graph of the sensitive function, a program dependency graph is generated, and the PageRank value of each node in the sensitive path in the program dependency graph is calculated as the weight value to generate a weight path. This process fully considers the dependency relationship between nodes in the smart contract code and the importance of each node, changes the previous practice of treating all code nodes equally, makes vulnerability analysis more accurate, and effectively improves the detection accuracy. The granular ball algorithm is used to construct a smart contract word-vector mapping table, generate a vector representation for each node in the sensitive path, and fuse the weight path information to obtain the weight path signature. This innovative representation method can not only comprehensively characterize the characteristics of the smart contract code, but also fully consider the connection between words in the code, making up for the defect of the existing method ignoring the semantics of the contract custom name. By comparing the weighted path signatures of sensitive paths with various vulnerability signature libraries for similarity, potential vulnerability paths can be identified more accurately, the ability to detect new and complex vulnerabilities is enhanced, and the false alarm rate is reduced. After detecting the potential vulnerability path, the smart contract source code is further checked to see whether the path contains the defense mode of the corresponding vulnerability type. If not, it is determined that this type of vulnerability exists. This comprehensive detection method not only stops at discovering potential vulnerabilities, but also determines whether the smart contract has an effective defense mechanism, providing a more comprehensive and reliable basis for the security assessment of smart contracts. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1It is a schematic diagram of the method flow of the present invention. DETAILED DESCRIPTION
[0019] The following describes the embodiments of the present invention by specific examples, and those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the illustrations provided in the following embodiments only illustrate the basic concept of the present invention in a schematic manner, and the following embodiments and features in the embodiments can be combined with each other without conflict.
[0020] See also Figure 1 One aspect of the present invention provides a smart contract vulnerability detection method based on spherical computing and weighted path signature similarity, comprising:
[0021] S1: Determine the sensitive functions in the smart contract source code according to the given sensitive word list, generate the control flow graph corresponding to each sensitive function, perform reverse program slicing analysis to obtain the set of all sensitive paths from the sensitive function entry to the sensitive word in the control flow graph, where the function where the sensitive word is located is called a sensitive function;
[0022] Preferably, the step of obtaining a set of all sensitive paths from sensitive function entrances to sensitive words in the control flow graph includes:
[0023] S11: For each target code line containing sensitive words in the sensitive function, locate its basic block Cblock in the control flow graph through the line2Block function;
[0024] S12: For each basic block Cblock containing the target code line, traverse the control flow graph backward from the current basic block Cblock to obtain all its parent blocks bblocks(1);
[0025] S13: and initialize i=1;
[0026] S14: traverse each bblocks(i), add bblocks(i) to cPath, and determine whether bblocks(i) is the entry start of the sensitive function. If so, add cPath to pathSet and clear cPath; otherwise, traverse the control flow graph from bblocks(i) in reverse order to obtain all its parent blocks bblocks(i+1);
[0027] S15: Let i=i+1, repeat steps S14-S15 until bblocks(i) is empty, and output the sensitive path set pathSet.
[0028] Preferably, given the smart contract source code, firstly, based on the sensitive keyword library (Table 1 gives examples of vulnerability types and corresponding sensitive keywords) and regularized matching, static analysis technology is used to traverse the sensitive word positions and the functions where they are located (called sensitive functions). For each sensitive function, its control flow graph is generated using the existing tool cfgGen. Then, the sensitive positions contained in it are analyzed one by one. For each target code line, the basic block where it is located is located.
[0029] Table 1 Vulnerability types and sensitive keyword examples
[0030] Vulnerability Type Sensitive keywords Reentrancy Vulnerability call.value Self-destruction without access control selfdestruct() Abnormal disorder Delegatecall, send, .call, callcode tx.origin abuse Tx.origin Arithmetic loophole +,-,*, /
[0031] The following uses a simple smart contract example to illustrate the specific operation process of step S1 and its preferred implementation method.
[0032] Suppose we have the following simple smart contract code:
[0033]
[0034]
[0035] Determine sensitive functions based on sensitive keyword library and regularized matching
[0036] According to the given sensitive keyword library (Table 1), we use static analysis technology to traverse the smart contract source code forward.
[0037] For example, for the “reentrancy vulnerability”, the sensitive keyword is call.value, and msg.sender.call.value(balance)() appears in the withdraw function, so the withdraw function is determined to be a sensitive function.
[0038] For the "self-destruct operation without access control", the sensitive keyword is selfdestruct(). selfdestruct(payable(msg.sender)) appears in the selfDestructContract function, so the selfDestructContract function is also identified as a sensitive function.
[0039] Generate control flow graph for sensitive functions
[0040] For each identified sensitive function, its control flow graph is generated using the existing tool cfgGen.
[0041] Taking the withdraw function as an example, the generated control flow graph includes the flow from the function entry to each code line and the relationship between code blocks.
[0042] Get sensitive path collection
[0043] Take the code line if(msg.sender.call.value(balance)()) in the withdraw function that contains the sensitive word call.value as an example to illustrate the process of obtaining the sensitive path set:
[0044] S11: Locating basic blocks
[0045] The target code line containing the sensitive word is located in the basic block Cblock of the control flow graph through the line2Block function.
[0046] S12: Reverse traversal to obtain the parent block
[0047] For this basic block Cblock, traverse the control flow graph backward from the current basic block Cblock to obtain all its parent blocks bblocks(1).
[0048] S13: Initialization
[0049] Initialize i=1.
[0050] S14: Traversal and judgment
[0051] Traverse each bblocks(1), add bblocks(1) to cPath, and then determine whether bblocks(1) is the entry start of the sensitive function withdraw. If not, continue to traverse the control flow graph from bblocks(1) in reverse order to obtain all its parent blocks bblocks(2).
[0052] S15: Cycle operation
[0053] Let i=i+1, and repeat steps S14 and S15 until bblocks(i) is empty. The sensitive path set pathSet finally outputted includes all paths from the entry of the sensitive function withdraw to the code line containing the sensitive word call.value.
[0054] The same process also applies to the selfDestructContract function. By performing similar operations on the code line containing the sensitive word selfdestruct(), the sensitive path set from the function entry to the sensitive word is obtained.
[0055] Through the above steps, we have completed the operation of determining the sensitive functions in the smart contract source code according to the given sensitive word list and obtaining the sensitive path set from the sensitive function entry to the sensitive word.
[0056] The present invention determines the sensitive functions in the smart contract source code according to a given sensitive word list, generates a control flow chart and performs reverse program slicing analysis, which can comprehensively obtain all sensitive path sets from the sensitive function entry to the sensitive word. Compared with the traditional method, this method is no longer limited to surface code analysis, but goes deep into the code, more comprehensively covers the areas where vulnerabilities may exist, and greatly reduces the possibility of underreporting.
[0057] S2: Generate a program dependency graph of the sensitive function based on the abstract syntax tree and the control flow graph of the sensitive function. For each sensitive path in the sensitive path set, calculate the PageRank value of each node in the program dependency graph as the weight value of the node in the path, and generate a weight path corresponding to the sensitive path.
[0058] Preferably, the calculation of the PageRank value of each node in the sensitive path in the program dependency graph includes:
[0059] S21: Create an adjacency matrix A and a transition probability matrix M of size n×n; if there is an edge from node i to node j in the program dependency graph, then a ij is 1, otherwise a ij is 0; the state transition probability from node i to node j in the transition probability matrix Where n is the number of nodes in the program dependency graph; d out (i) represents the out-degree of node i;
[0060] S22: Initialize the PageRank value of each node The initial PageRank values of all nodes are represented by the vector R(0). Among them, r i Represents the initial PageRank value of the i-th node;
[0061] S23: Iteratively calculate the PageRank value of each node:
[0062]
[0063] Where α represents the damping factor, R(t) represents the PageRank value of all nodes after the tth iteration; M T represents the transposed matrix of the transition probability matrix M;
[0064] S24: Repeat step S23 until |R(t)-R(t-1)| is less than the set threshold, and obtain the PageRank value of each node.
[0065] In this embodiment, by calculating the PageRank value as the node weight, the relative importance of each node in the program dependency graph can be reflected. In smart contract vulnerability detection, important nodes may be more closely related to the generation of vulnerabilities. For example, in the code related to reentrancy vulnerabilities, the PageRank values of certain key function calls or conditional judgment nodes will be relatively high. By giving these nodes higher weights, more attention can be paid to these key nodes during vulnerability detection, thereby improving the accuracy of detection.
[0066] In this embodiment, the calculation of PageRank value is based on the program dependency graph, which reflects the dependency relationship between nodes in the code. This dependency relationship is very important in vulnerability detection, because vulnerabilities are often not caused by a single isolated node, but the result of multiple interdependent nodes working together. By considering the dependency relationship between nodes, the execution logic of the smart contract code can be analyzed more comprehensively, thereby more accurately identifying potential vulnerabilities.
[0067] The weighted path generated in this embodiment can more accurately describe the characteristics of the sensitive path. When the similarity is compared with the vulnerability signature library later, the weighted path signature can provide richer and more accurate information, making the detection results more reliable, reducing false positives and false negatives, and further improving the accuracy of smart contract vulnerability detection.
[0068] S3: Construct a smart contract word-vector mapping table through the granular ball algorithm, and generate a vector representation of each node in the sensitive path based on the word-vector mapping table; fuse the vector representation of each node in the sensitive path and the weight path information to obtain the weight path signature;
[0069] Preferably, the step of constructing a smart contract word-vector mapping table includes:
[0070] S301: Collect a large-scale smart contract data set, input the collected smart contract source code into the trained large prediction model, obtain the word vector representation of each word in the smart contract source code, and construct an initial word-vector mapping table based on the word vector representation of each word in the source code in the large-scale smart contract data set;
[0071] In this embodiment, a large-scale smart contract data set is collected, and the smart contract source code is input into a trained large language model (here Bert is selected, but other sequence models can also be used) to obtain the word vector representation of each word, such as "contract", "Simple", "uint", "balance" and other words have corresponding vectors. Based on the vector representation of the words in all the collected smart contract source codes, an initial word-vector mapping table is constructed.
[0072] S302: Consider all word vectors in the initial word-vector mapping table as an initial parent particle ball;
[0073] S303: Calculate the distance matrix between all word vectors in the parent sphere, and find the two word vectors a and b with the largest distance; traverse each word vector c in the parent sphere, if the cosine distance between word vector c and word vector a is greater than the cosine distance between word vector c and word vector b, then divide word vector c and word vector b into the same sub-sphere, otherwise divide word vector c and word vector a into the same sub-sphere;
[0074] S304: Calculate the average distances of all word vectors of the two sub-particle balls respectively, and perform weighted summation of the average distances of the two sub-particle balls according to the number of word vectors of the two sub-particle balls to obtain a weighted average distance;
[0075] S305: Determine whether the weighted average distance is less than the average distance of all word vectors of the parent particle ball. If so, keep the two child particles, otherwise do not keep them;
[0076] S306: traverse each obtained sub-particle ball, use each sub-particle ball as the parent particle ball in the next round of iteration, and repeat steps S33 to S36 until the number of particles no longer changes;
[0077] S307: After the division, all word vectors in each sphere are updated to the center vector of the sphere for re-representation to obtain a final word-vector mapping table.
[0078] Preferably, the calculating of the vector representation of each node in the sensitive path includes:
[0079] S311: convert each word of the target code line corresponding to each node in the inscription path into a vector representation through a word-vector mapping table;
[0080] S312: averaging the word vectors of all words in the target code line corresponding to each node to obtain a vector representation of the node.
[0081] Assume that in the above smart contract, a sensitive path is detected, and the target code behavior corresponding to one of the nodes is if(msg.sender.balance>=10); through the word-vector mapping table, the words "if", "msg.sender.balance", ">=", and "10" are converted into vector representations. These word vectors are averaged to obtain the vector representation of the node.
[0082] Preferably, the fusion of the vector representation of each node in the sensitive path and the weighted path information to obtain the weighted path signature includes: multiplying the vector representation of each node in the sensitive path by its corresponding weight value to obtain the weighted vector of each node: summing the weighted vectors of all nodes to obtain a weighted sum feature vector; and inputting the weighted sum feature vector into a mapping model to generate a weighted path signature of a fixed length.
[0083] Preferably, the mapping model includes: a hash algorithm, a multi-layer perceptron or a principal component analysis algorithm.
[0084] In this embodiment, the initial word-vector mapping table is optimized by the granular ball algorithm, and can be reasonably divided and adjusted according to the distance relationship between the word vectors, so that the word vectors in the same granular ball have higher similarity, thereby improving the accuracy and rationality of the word vector representation. Compared with the word vectors directly generated by the large language model, the word vectors processed by the granular ball algorithm can better reflect the semantic relationship between words, which helps to more accurately understand the semantic information of the code in the subsequent vulnerability detection. The vectors of all words in the target code line corresponding to the node are averaged, which can comprehensively consider the information of each word in the code line, comprehensively reflect the characteristics of the node, and avoid the problem of focusing on a single word and ignoring the overall semantics. The node vector representation is integrated with the weight information, which not only considers the semantic characteristics of the node itself, but also combines its importance in the program dependency relationship, so that the generated weight path signature can more comprehensively and accurately represent the characteristics of the sensitive path, and enhance the description ability of the vulnerability. The weight path signature of a fixed length is generated by the mapping model, so that the characteristics of different sensitive paths can be compared in a unified format, which is convenient for similarity comparison with the vulnerability signature library, and improves the efficiency and accuracy of vulnerability detection.
[0085] S4: The weighted path signature of each sensitive path is compared with the weighted path signatures in various vulnerability signature libraries for similarity. When there are N weighted path signatures in the vulnerability signature library whose similarity with the weighted path signature of the sensitive path is greater than the set threshold, the sensitive path is regarded as a potential vulnerability path of the vulnerability type corresponding to the vulnerability signature library;
[0086] Weighted path signatures are generated for sensitive paths of smart contracts, and there is a vulnerability signature library containing multiple vulnerability types, each of which has a corresponding set of weighted path signatures.
[0087] Suppose there is a smart contract. After the analysis in the previous steps, three sensitive paths are obtained, which are denoted as SP1, SP2, and SP3. Their corresponding weighted path signatures are SPS1, SPS2, and SPS3 respectively.
[0088] The vulnerability signature library contains two types of vulnerabilities: reentrancy vulnerabilities (RV) and arithmetic overflow vulnerabilities (AO). There are 5 weight path signatures in the reentrancy vulnerability signature library, namely RV_SPS1, RV_SPS2, RV_SPS3, RV_SPS4, and RV_SPS5; there are 3 weight path signatures in the arithmetic overflow vulnerability signature library, namely AO_SPS1, AO_SPS2, and AO_SPS3.
[0089] Set the similarity threshold to 0.7 (the similarity here can be calculated using methods such as cosine similarity).
[0090] For the weight path signature SPS1 of SP1:
[0091] Comparing the similarity with the signatures in the reentrancy vulnerability signature library, the calculated similarity between SPS1 and RV_SPS1 is 0.6, the similarity with RV_SPS2 is 0.55, the similarity with RV_SPS3 is 0.4, the similarity with RV_SPS4 is 0.3, and the similarity with RV_SPS5 is 0.65, all of which are less than 0.7.
[0092] Comparing the similarity with the signatures in the arithmetic overflow vulnerability signature library, the similarity between SPS1 and AO_SPS1 is 0.75, the similarity with AO_SPS2 is 0.3, and the similarity with AO_SPS3 is 0.2. Because there is a signature (namely AO_SPS1) with a similarity greater than 0.7 with SPS1, SP1 is considered a potential vulnerability path of the arithmetic overflow vulnerability type.
[0093] For the weight path signature SPS2 of SP2:
[0094] Comparing the similarity with the signatures in the reentrancy vulnerability signature library, it is calculated that the similarity between SPS2 and RV_SPS3 is 0.8, and the similarity with RV_SPS5 is 0.72, and there are two cases where the similarity is greater than 0.7. Therefore, SP2 is regarded as a potential vulnerability path of the reentrancy vulnerability type.
[0095] For the weight path signature SPS3 of SP3:
[0096] The similarity comparison with all signatures in the reentrancy vulnerability signature library and the arithmetic overflow vulnerability signature library showed that all similarities were less than 0.7, so SP3 was not considered as a potential vulnerability path for any known vulnerability type.
[0097] The present invention can accurately determine whether the sensitive path in the smart contract may have known types of vulnerabilities based on the existing vulnerability feature information by comparing the weight path signature of the sensitive path with the signature in the vulnerability signature library for similarity. As in the above example, SP1 may have an arithmetic overflow vulnerability and SP2 may have a reentry vulnerability through comparison, which helps developers to discover potential security risks in a timely manner. The method is based on signature comparison, which greatly reduces the workload and time cost of detection compared to a comprehensive and non-targeted analysis of the entire smart contract. Only by comparing the generated weight path signature, it is possible to quickly determine whether there is a potential vulnerability, which improves the efficiency of vulnerability detection and is suitable for large-scale application in actual projects. With the continuous deepening of vulnerability research and the discovery of new vulnerabilities, only new vulnerability types and their corresponding weight path signatures need to be added to the vulnerability signature library, and the method can be used to detect smart contracts and identify new types of potential vulnerabilities. It has good scalability and can adapt to changing security requirements. Determining the vulnerability type corresponding to the potential vulnerability path provides developers with a clear vulnerability direction. Developers can conduct detailed review and repair of relevant code areas in smart contracts based on this information, thereby improving the efficiency and accuracy of vulnerability repair.
[0098] S5: Detect whether the potential vulnerability path in the smart contract source code contains the defense mode of the corresponding vulnerability type. If not, it is determined that this type of vulnerability exists in the smart contract source code.
[0099] Assume that in the previous step, we determined that a potential vulnerability path is a "reentrancy vulnerability" type through the similarity comparison of weighted path signatures. The following examples are given from the case where there is a defense mode and the case where there is no defense mode. Assume that after the previous analysis, it is determined that the path where the code of msg.sender.call.value(10)() in the withdraw function is located is a potential vulnerability path for the reentrancy vulnerability. For reentrancy vulnerabilities, a common defense mode is to use a state variable to mark whether the function is being executed to prevent reentry when the function is not executed. However, there is no such defense mode in the withdraw function of this contract. Therefore, according to step S5, it is determined that there is a reentrancy vulnerability in the source code of the smart contract. Assume that the path where msg.sender.call.value(10)() in the withdraw function is located is also determined to be a potential vulnerability path for the reentrancy vulnerability. However, the isWithdrawing state variable is used in this contract to mark whether a withdrawal operation is in progress. Check the variable at the beginning of the function, and return directly if the withdrawal is in progress to avoid reentrancy; reset the variable to false at the end of the function. This method is a defense mode for reentrancy vulnerabilities. Therefore, according to step S5, it is determined that there is no reentrancy vulnerability in the smart contract source code.
[0100] This embodiment not only relies on the identification of potential vulnerability paths, but also deeply checks whether there are corresponding defense modes, avoiding the situation where the vulnerability is misjudged just because the code structure or operation mode is similar to a known vulnerability. In this way, it is possible to more accurately determine whether a specific type of vulnerability really exists in the smart contract, reduce the false alarm rate, and provide developers with more reliable vulnerability detection results. During the detection process, if it is found that there is a potential vulnerability path but no corresponding defense mode, this clearly prompts the developer to improve the code and add appropriate defense mechanisms. If there is a defense mode, it means that the developer has considered the relevant security risks and taken measures when writing the code, which helps the developer to confirm the security of his code. This provides a clear guidance direction for developers to optimize the smart contract code and promotes the security improvement of smart contracts. Combining the previous step of identifying potential vulnerability paths and this step of checking defense modes, a complete process from vulnerability identification to defense mechanism inspection is formed. This comprehensive evaluation method can more comprehensively consider the security of smart contracts. Compared with the simple vulnerability detection method, it provides richer and deeper security information, which helps to ensure the stable operation of smart contracts in the blockchain system and protect the asset security of users and the reliability of the system.
[0101] Another aspect of the present invention provides a smart contract vulnerability detection device based on granular calculation and weighted path signature similarity, comprising a processor and a memory; the memory is used to store a computer program; the processor is connected to the memory, and is used to execute the computer program stored in the memory, so that the smart contract vulnerability detection device based on granular calculation and weighted path signature similarity executes the smart contract vulnerability detection method based on granular calculation and weighted path signature similarity.
[0102] Another aspect of the present invention provides a computer-readable storage medium storing a program, which, when executed by a processor, implements the smart contract vulnerability detection method based on spherical calculation and weighted path signature similarity.
[0103] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0104] In summary, the present invention determines the sensitive functions in the smart contract source code according to a given sensitive word list, generates a control flow graph and performs reverse program slicing analysis, so as to comprehensively obtain all sensitive path sets from the sensitive function entry to the sensitive word. Compared with the traditional method, this method is no longer limited to the surface code analysis, but goes deep into the code, covers the areas where vulnerabilities may exist more comprehensively, and greatly reduces the possibility of underreporting. Based on the abstract syntax tree and the control flow graph of the sensitive function, a program dependency graph is generated, and the PageRank value of each node in the sensitive path in the program dependency graph is calculated as the weight value to generate a weight path. This process fully considers the dependency relationship between nodes in the smart contract code and the importance of each node, changes the previous practice of treating all code nodes equally, makes vulnerability analysis more accurate, and effectively improves the detection accuracy. The granular ball algorithm is used to construct a smart contract word-vector mapping table, generate a vector representation for each node in the sensitive path, and fuse the weight path information to obtain the weight path signature. This innovative representation method can not only comprehensively characterize the characteristics of the smart contract code, but also fully consider the connection between words in the code, making up for the defect of the existing method of ignoring the semantics of the contract custom name. By comparing the weighted path signatures of sensitive paths with various vulnerability signature libraries for similarity, potential vulnerability paths can be identified more accurately, the ability to detect new and complex vulnerabilities is enhanced, and the false alarm rate is reduced. After detecting the potential vulnerability path, the smart contract source code is further checked to see whether the path contains the defense mode of the corresponding vulnerability type. If not, it is determined that this type of vulnerability exists. This comprehensive detection method not only stops at discovering potential vulnerabilities, but also determines whether the smart contract has an effective defense mechanism, providing a more comprehensive and reliable basis for the security assessment of smart contracts.
[0105] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the purpose and scope of the technical solution, which should be included in the scope of the claims of the present invention.
Claims
1. A smart contract vulnerability detection method based on spherical computing and weighted path signature similarity, characterized in that: include: S1: Determine the sensitive functions in the smart contract source code according to the given sensitive word list, generate the control flow graph corresponding to each sensitive function, perform reverse program slicing analysis to obtain the set of all sensitive paths from the sensitive function entry to the sensitive word in the control flow graph, where the function where the sensitive word is located is called a sensitive function; S2: Generate a program dependency graph of the sensitive function based on the abstract syntax tree and the control flow graph of the sensitive function. For each sensitive path in the sensitive path set, calculate the PageRank value of each node in the program dependency graph as the weight value of the node in the path, and generate a weight path corresponding to the sensitive path. S3: Construct a smart contract word-vector mapping table through the granular ball algorithm, and generate a vector representation of each node in the sensitive path based on the word-vector mapping table; fuse the vector representation of each node in the sensitive path and the weight path information to obtain the weight path signature; S4: The weighted path signature of each sensitive path is compared with the weighted path signatures in various vulnerability signature libraries for similarity. When there are N weighted path signatures in the vulnerability signature library whose similarity with the weighted path signature of the sensitive path is greater than the set threshold, the sensitive path is regarded as a potential vulnerability path of the vulnerability type corresponding to the vulnerability signature library; S5: Detect whether the potential vulnerability path in the smart contract source code contains the defense mode of the corresponding vulnerability type. If not, it is determined that this type of vulnerability exists in the smart contract source code.
2. According to claim 1, a smart contract vulnerability detection method based on spherical computing and weighted path signature similarity is characterized in that: The acquisition of all sensitive path sets from sensitive function entrances to sensitive words in the control flow graph includes: S11: For each target code line containing sensitive words in the sensitive function, locate its basic block Cblock in the control flow graph through the line2Block function; S12: For each basic block Cblock containing the target code line, traverse the control flow graph backward from the current basic block Cblock to obtain all its parent blocks bblocks(1); S13: and initialize i=1; S14: traverse each bblocks(i), add bblocks(i) to cPath, and determine whether bblocke(i) is the entry start of the sensitive function. If so, add cPath to pathSet and clear cPath; otherwise, traverse the control flow graph from bblocke(i) in reverse order to obtain all its parent blocks bblocke(i+1); S15: Let i=i+1, and repeat steps S14-S15 until bblocke(i) is empty, and output the sensitive path set pathSet.
3. According to claim 1, a smart contract vulnerability detection method based on spherical computing and weighted path signature similarity is characterized in that: The calculation of the PageRank value of each node in the program dependency graph in the sensitive path includes: S21: Create an adjacency matrix A and a transition probability matrix M of size n×n; if there is an edge from node i to node j in the program dependency graph, then a ij is 1, otherwise a ij is 0; the state transition probability from node i to node j in the transition probability matrix Where n is the number of nodes in the program dependency graph; d out (i) represents the out-degree of node i; S22: Initialize the PageRank value of each node The initial PageRank values of all nodes are represented by the vector R(0). Among them, r i Represents the initial PageRank value of the i-th node; S23: Iteratively calculate the PageRank value of each node: Among them, α represents the damping factor, R(t) represents the PageRank value of all nodes after the tth iteration; M T represents the transposed matrix of the transition probability matrix M; S24: Repeat step S23 until |R(t)-R(t-1)| is less than the set threshold, and obtain the PageRank value of each node.
4. According to claim 1, a smart contract vulnerability detection method based on spherical computing and weighted path signature similarity is characterized in that: The construction of the smart contract word-vector mapping table includes: S301: Collect a large-scale smart contract data set, input the collected smart contract source code into the trained large prediction model, obtain the word vector representation of each word in the smart contract source code, and construct an initial word-vector mapping table based on the word vector representation of each word in the source code in the large-scale smart contract data set; S302: Consider all word vectors in the initial word-vector mapping table as an initial parent particle ball; S303: Calculate the distance matrix between all word vectors in the parent sphere, and find the two word vectors a and b with the largest distance; traverse each word vector c in the parent sphere, if the cosine distance between word vector c and word vector a is greater than the cosine distance between word vector c and word vector b, then divide word vector c and word vector b into the same sub-sphere, otherwise divide word vector c and word vector a into the same sub-sphere; S304: Calculate the average distances of all word vectors of the two sub-particle balls respectively, and perform weighted summation of the average distances of the two sub-particle balls according to the number of word vectors of the two sub-particle balls to obtain a weighted average distance; S305: Determine whether the weighted average distance is less than the average distance of all word vectors of the parent particle ball. If so, keep the two child particles, otherwise do not keep them; S306: traverse each obtained sub-particle ball, use each sub-particle ball as the parent particle ball in the next round of iteration, and repeat steps S33 to S36 until the number of particles no longer changes; S307: After the division, all word vectors in each sphere are updated to the center vector of the sphere for re-representation to obtain a final word-vector mapping table.
5. According to claim 1, a smart contract vulnerability detection method based on spherical computing and weighted path signature similarity is characterized in that: The vector representation of each node in the calculation sensitive path includes: S311: convert each word of the target code line corresponding to each node in the inscription path into a vector representation through a word-vector mapping table; S312: averaging the word vectors of all words in the target code line corresponding to each node to obtain a vector representation of the node.
6. According to claim 1, a smart contract vulnerability detection method based on spherical computing and weighted path signature similarity is characterized in that: The method of fusing the vector representation of each node in the sensitive path and the weighted path information to obtain the weighted path signature includes: multiplying the vector representation of each node in the sensitive path by its corresponding weight value to obtain the weighted vector of each node; summing the weighted vectors of all nodes to obtain a weighted sum feature vector; and inputting the weighted sum feature vector into a mapping model to generate a weighted path signature of a fixed length.
7. The method for detecting smart contract vulnerabilities based on spherical computing and weighted path signature similarity according to claim 6, characterized in that: The mapping model includes: a hash algorithm, a multi-layer perceptron or a principal component analysis algorithm.
8. A smart contract vulnerability detection device based on spherical computing and weighted path signature similarity, characterized in that: It comprises a processor and a memory; the memory is used to store a computer program; the processor is connected to the memory and is used to execute the computer program stored in the memory, so that the smart contract vulnerability detection device based on granular calculation and weighted path signature similarity executes the smart contract vulnerability detection method based on granular calculation and weighted path signature similarity described in any one of claims 1 to 7.
9. A computer-readable storage medium storing a program, characterized in that: When the program is executed by the processor, the smart contract vulnerability detection method based on spherical calculation and weighted path signature similarity as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Intelligent contract multi-vulnerability detection method and system based on source code graph representation learning
CN113360915A
Software supply chain security assessment method and system based on static analysis
CN118364462A
Source code vulnerability detection and positioning method and device, equipment and storage medium
CN118709191A
Directed fuzzing for vulnerability detection
US20240184892A1
System for information flow security inference through program slicing
US9378377B1
Cited By
Private data processing method based on trusted data space
CN120162829A