Block chain attack detection method and device based on quantitative semantic specification
Through detection methods based on quantitative semantic regulations, the quantitative results in the Ethereum transaction semantic log are calculated in real time, which solves the problem that the existing technology cannot detect and identify potential attack behaviors on the blockchain platform in real time, and achieves efficient and dynamic attack recognition and response.
Patent Information
- Application Number
- CN202510473963.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
It is difficult for existing technology to detect and identify potential attacks on the Ethereum blockchain platform in real time, especially when the contract is running, the attack cannot be detected in time, and traditional methods cannot monitor malicious transactions outside the contract.
The detection method based on quantitative semantic regulations is adopted, and the importance of each minimum atomic formula is quantified by defining the MFTOL language subset of the formal specifications modeled by Ethereum attacks, and the quantization formula is defined through logical operators to form a complete quantitative calculation method for attack rules, and the quantitative results in the Ethereum transaction semantic log are calculated in real time to determine whether there is a risk that the target transaction is used for predefined attacks.
Real-time monitoring and identification of potential attacks are realized, and timely measures can be taken to prevent attacks. Compared with static detection, it has stronger dynamic response capabilities, can comprehensively monitor all transaction activities, identify attack behaviors inside and outside the contract, and provide high-quality attack identification results.
Smart Images

Figure CN119996090A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Ethereum attack transaction detection, and in particular to a blockchain attack detection method and device based on quantified semantic specification. Background Art
[0002] Blockchain technology is an advanced distributed ledger system that provides a complete computing environment and supports the storage and execution of autonomous programs such as smart contracts. Its essence is a database maintained by multiple nodes. These nodes use cryptographic algorithms to ensure the security and integrity of data, and all nodes have the same copy. Since there is no single control center, the blockchain system is highly decentralized and anonymous. As a new type of distributed computing model, blockchain is widely used in digital currency, finance, e-commerce and other fields. However, security risk events in the blockchain financial field are emerging in an endless stream, and system security remains an important challenge.
[0003] The frequent occurrence of dangerous transactions in the blockchain financial sector is closely related to the decentralized blockchain platform and Turing-complete smart contracts. The openness and transparency of these platforms allow anyone to deploy smart contracts and initiate transactions, but this also brings security risks. Attackers can take advantage of the characteristics of transactions and vulnerabilities in smart contracts to initiate specific transactions by calling their own deployed attack contracts to manipulate the system status and obtain improper benefits. For example, attackers can use vulnerabilities in smart contracts to implement transaction-level attacks such as reentrancy attacks and price manipulation, thereby causing losses to users' funds.
[0004] On the Ethereum decentralized platform, there are vulnerabilities in the contract code, or in the transaction execution level, smart contract interaction level, or the Ethereum protocol itself. After discovering these vulnerabilities, attackers will deploy a contract containing attack behaviors, initiate malicious transactions by calling the contract, and use this transaction to interact with the Ethereum network status, causing huge financial losses. At the same time, due to the strong anonymity and heterogeneity of decentralized platforms such as Ethereum, it is difficult to locate and identify the attacking account that initiates malicious transactions.
[0005] The high frequency of major security attacks on the blockchain further emphasizes the urgency and necessity of developing security monitoring tools for blockchain financial systems. First, with the widespread application of blockchain technology, the number and complexity of financial transactions have increased significantly, and traditional monitoring methods are difficult to meet the real-time and efficient needs. Secondly, transaction-level attacks not only affect the financial security of individual users, but may also have a negative impact on the trust of the entire ecosystem, and even trigger larger-scale market fluctuations. Therefore, it is necessary to establish an effective Ethereum transaction security monitoring mechanism that can identify and respond to potential attack incidents in a timely manner, thereby protecting user interests and maintaining market stability and security.
[0006] Figure 1 A malicious attack process on Ethereum is presented. On the Ethereum decentralized platform, there are vulnerabilities in the contract code, or vulnerabilities in the transaction execution level, smart contract interaction level, or the Ethereum protocol itself. After the attacker discovers these vulnerabilities, he will deploy a contract containing attack behaviors, initiate malicious transactions by calling the contract, and use this transaction to interact with the Ethereum network status, causing huge financial losses. At the same time, due to the strong anonymity and heterogeneity of decentralized platforms such as Ethereum, it is difficult to locate and identify the attack account that initiates malicious transactions.
[0007] Figure 2 A blockchain attack detection scheme is shown. This scheme detects whether there are loopholes by statically scanning and analyzing the blockchain contract code, thereby determining whether there is a risk of blockchain attack. However, this scheme has two limitations: on the one hand, it can only detect blockchain attacks performed by calling smart contracts; on the other hand, it only relies on static code scanning before the contract runs, and cannot detect attacks in time when the contract is running. Figure 3 A schematic diagram showing another detection scheme for blockchain attacks. Figure 3 As shown in FIG. 1 , another existing detection scheme for blockchain attacks is to input the transaction log of the blockchain into a traditional runtime monitoring tool to obtain the identification result of the blockchain attack. However, the traditional runtime monitoring tool is a qualitative protocol detection method with a small detection range of attacks and can only detect completed attacks, but not attempted attacks. Summary of the invention
[0008] The purpose of the present invention is to address the deficiencies of the prior art and to propose a detection method and device for blockchain attacks based on quantitative semantic specifications.
[0009] The objective of the present invention is achieved through the following technical solutions:
[0010] According to a first aspect, a method for detecting blockchain attacks based on quantitative semantic specification is provided, comprising:
[0011] A subset of the MFTOL language that defines a formal specification for Ethereum attack modeling, which defines the logical operators and minimal atomic formulas contained in the specification;
[0012] Add adaptive weights to basic events, advanced events, and parameter comparison operators in the minimum atomic formula to quantify the importance of each minimum atomic formula to the inferred detection results;
[0013] Define quantized formulas for the logical operators in the proposed MFOTL language subset to form a complete quantitative calculation method for attack specifications;
[0014] The quantified results in the Ethereum transaction semantic log are calculated according to the quantified attack specification to determine whether there is a risk that the target transaction is used for a predefined attack.
[0015] Furthermore, the subset of the MFTOL language that defines the formal specification for modeling Ethereum attacks is specifically: using the MFTOL logical language to describe potential behavior patterns of Ethereum attacks, including reentrancy attacks, sandwich attacks, direct price tampering attacks, indirect price tampering attacks, and call injection attacks.
[0016] Furthermore, the minimum atomic formula includes: all basic event items, advanced event items, basic parameter comparison operations, and advanced parameter comparison operations; the logical operator acts on the minimum atomic formula or the result of multiple minimum atomic formulas after logical operations.
[0017] Furthermore, the adaptive weights are added to the basic events, advanced events and parameter comparison operators in the minimum atomic formula as follows: Represents basic events and basic parameter comparison operations. Additional weight c a ;use Indicates advanced event and advanced parameter comparison operations. Additional weight c b ; Among them, the weight c a 、c b are adaptive constants. For different attack specifications, the weight c a 、c b Adaptive calculation, but for a specific attack, the weight c a 、c b is a fixed constant; and for each attack specification, the range of the specification calculation result must be limited to between 0 and 1. The rules are as follows:
[0018]
[0019]
[0020]
[0021] in, Indicates that all the weights c are added a The sum of the weights of the items, Indicates that all the weights c are added b The sum of the weights of the items; according to and Defined by the importance and Specific value;
[0022] Furthermore, the definition of the quantization formula specifically includes: defining a calculation operator ,in, Represents a specific attack specification and its sub-specifications; Represents a set of n events The semantic log composed of All need to be calculated to get a quantized value; Represents in semantic log The i-th event set in , which targets the regulations quantified results.
[0023] Furthermore, in the quantization formula, when the semantic log The i-th event set in Does not conform to the atomic formula hour, ;
[0024] When semantic logging The i-th event set in Conforms to a specific atomic formula The following definitions apply:
[0025] When semantic logging The i-th event set in Conforms to a specific atomic formula , and the atomic formula belong When, define:
[0026]
[0027]
[0028] in, Representation semantic log The i-th event set in Conforms to the atomic formula .
[0029] When semantic logging The i-th event set in Conforms to the atomic formula , and the atomic formula belong When, define:
[0030]
[0031]
[0032] ¬ indicates the negation operation.
[0033] Furthermore, the semantic log is calculated The i-th event set in conform to When, define:
[0034]
[0035] in, It is used to measure that in the interval 𝐼, The sooner it is satisfied, the greater its contribution to the satisfaction of the whole formula;
[0036] Computational semantic log The i-th event set in conform to When, define:
[0037]
[0038] in, It is used to measure that the faster 𝜑atm is satisfied in the interval 𝐼, the greater its contribution to the satisfaction of the entire formula;◆ I Represents "previously existed", specifically refers to the range of the forward search time interval I; ◇ I stands for "exists after", specifically refers to the range of the backward search time interval I;
[0039] Computational semantic log The i-th event set in When the AND logic combination of the two formulas is met, the definition is:
[0040]
[0041] Furthermore, the maximum value of the quantified results in the Ethereum transaction semantic log is calculated according to the quantified attack specification to determine whether there is a risk that the target transaction is used in a predefined attack. Specifically, given the semantic log , Attack Protocol and a quantized threshold , calculate each The event collection in The quantitative results , for all , if it satisfies its maximum value , it means that the currently monitored transaction constitutes an attack.
[0042] According to another aspect of the specification, a blockchain attack detection system based on quantitative semantic specification is also provided, including:
[0043] A formal specification semantics determination unit, configured to define a subset of the MFTOL language for the formal specification of Ethereum attack modeling, the subset defining the logical operators and minimal atomic formulas included in the specification;
[0044] an atomic formula quantization unit, configured to attach adaptive weights to basic events, advanced events, and parameter comparison operators in a minimum atomic formula, thereby quantifying the importance of each minimum atomic formula to the inferred detection result;
[0045] The logic operator quantization unit defines the quantization formula for the logic operators in the proposed MFOTL language subset, forming a complete quantitative calculation method for attack specifications;
[0046] The risk monitoring unit is configured to calculate the quantified result in the Ethereum transaction semantic log according to the quantified attack specification, and determine whether there is a risk that the target transaction is used for a predefined attack.
[0047] According to another aspect of the specification, there is also provided a device for detecting blockchain attacks based on quantified semantic conventions, comprising a memory and one or more processors, wherein the memory stores executable code, and when the processor executes the executable code, the method for detecting blockchain attacks based on quantified semantic conventions is implemented.
[0048] The beneficial effects of the present invention are as follows: First, compared with the static contract vulnerability detection scheme, it can capture potential attack risks in real time through dynamic monitoring at the transaction level. Once an abnormality is found, timely measures can be taken, such as suspending transactions, notifying administrators, or triggering emergency responses, to ensure that the attack is quickly contained. Static detection mainly focuses on vulnerability detection before contract deployment and cannot respond to dynamic attacks at runtime, so it has great limitations in dealing with real-time attacks. Second, compared with the static contract vulnerability detection scheme, this method can comprehensively monitor all transaction activities, not only can it identify attacks conducted through contracts, but also can effectively detect malicious transaction behaviors outside contracts. Traditional static vulnerability detection can only identify known vulnerabilities in contracts and cannot provide effective protection against attacks outside contracts. Third, compared with the scheme of dynamic transaction detection based on traditional formal methods, this method can not only detect more attacks, but also monitor attempted attacks, providing high-quality identification results for Ethereum attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 A flowchart of an Ethereum attack is shown;
[0050] Figure 2 A schematic diagram showing a detection scheme for a blockchain attack;
[0051] Figure 3 A schematic diagram showing another detection scheme for blockchain attacks;
[0052] Figure 4 A schematic diagram showing an Ethereum attack detection method provided by an embodiment of this specification;
[0053] Figure 5 A flow chart showing a method for detecting an Ethereum attack provided by an embodiment of this specification;
[0054] Figure 6 A structural diagram of an Ethereum attack detection system provided by an embodiment of this specification is shown;
[0055] Figure 7 A schematic diagram of an Ethereum attack detection device provided in an embodiment of this specification is shown. DETAILED DESCRIPTION
[0056] The specific implementation modes of the present invention are further described in detail below with reference to the accompanying drawings.
[0057] Due to the widespread use of blockchain, some attacks on Ethereum have emerged. Ethereum attacks refer to malicious actions against the Ethereum network or applications based on Ethereum in order to disrupt its normal operation, steal assets or obtain illegal benefits.
[0058] In order to solve the above technical problems, the embodiments of this specification provide a method for detecting blockchain attacks based on quantitative semantic specifications. Figure 4 A schematic diagram of a blockchain attack detection method based on quantitative semantic conventions provided in an embodiment of this specification is shown. Figure 4 As shown, the core idea of the method is to define a subset of the MFTOL language for formal specifications of Ethereum attack modeling, including logical operators and minimum atomic formulas contained in the specifications. Adaptive weights are added to basic events, advanced events, and parameter comparison operators in the minimum atomic formula to quantify the importance of each minimum atomic formula to the inferred detection results. Quantitative formulas are defined for the logical operators in the proposed MFOTL language subset to form a quantitative calculation method for a complete attack specification. The quantitative results in the Ethereum transaction semantic log are calculated according to the quantified attack specification to determine whether there is a risk that the target transaction is used for a predefined attack. In different embodiments, the predetermined attack can be different types of blockchain attacks. Furthermore, in different embodiments, the risk of the target transaction being used for different types of blockchain attacks can be determined based on the transaction semantics, complex semantics, and different identification rules of multiple function calls.
[0059] A method for detecting blockchain attacks based on quantitative semantic specifications provided by an embodiment of this specification will be described in detail below. Figure 5 The flowchart of a method for detecting blockchain attacks based on quantitative semantic conventions provided in an embodiment of this specification is shown. Figure 5 As shown, the method comprises the following steps:
[0060] Step S01, defining a subset of the MFTOL language of the formal specification for Ethereum attack modeling, where the subset defines the logical operators and minimum atomic formulas contained in the specification;
[0061] Step S02, adding adaptive weights to the basic events, advanced events and parameter comparison operators in the minimum atomic formula, so as to quantify the importance of each minimum atomic formula to the inferred detection result;
[0062] Step S03, defining a quantitative formula for the logical operators in the proposed MFOTL language subset to form a complete quantitative calculation method for the attack specification;
[0063] Step S04, calculating the quantified result in the Ethereum transaction semantic log according to the quantified attack specification, and determining whether there is a risk that the target transaction is used for a predefined attack.
[0064] First, in step S01, a subset of the MFTOL language for the formal specification of Ethereum attack modeling is defined, which defines the logical operators and minimum atomic formulas contained in the specification. The formal specification of Ethereum attacks uses the Metric-First-Order-Temporal-Logic logic language to describe the potential behavior patterns of Ethereum attacks. It specifically includes attack specifications for five types of attacks: reentrancy attack, sandwich attack, direct price tampering attack, indirect price tampering attack, and call injection attack.
[0065] In actual production scenarios, there are often different types of blockchain attacks, such as reentrancy (RE) attacks, direct price manipulation (IPM) attacks, call injection (CI) attacks, etc. Therefore, in different embodiments, the specific methods for determining whether there is a risk that the target transaction is used for a predetermined attack may be different.
[0066] In a specific embodiment, the attack specification for the reentrancy attack can be expressed as:
[0067] REENTRANCY-ATTACK:=Order(o1)⋀Depth(d1)⋀Call(s1,r1,f1)⋀◇ [0.20] [Order(o2)⋀Depth(d2)⋀Inverse(o1,o2)]⋀◇ [0.20] [Order(o3)⋀Depth(d3)⋀SameCall(func,o1,o3)]⋀d2>d1⋀d3>d2
[0068] The attack protocol includes basic semantic items, advanced semantic items and parameter comparison operations. The basic semantic items and advanced semantic items both contain specific function names and their corresponding parameters. The parameter comparison operations include basic parameter comparison and advanced parameter comparison, wherein the basic parameter comparison refers to comparing the size of the parameters in the basic semantic items, and the advanced parameter comparison refers to comparing the size of the parameters in the advanced semantic items. There is no comparison between the parameters in the basic semantics and the parameters in the advanced semantics.
[0069] In the above specific reentrancy attack embodiment, the attack protocol includes: basic semantics 1: Order(o1); basic semantics 2: Depth(d1); basic semantics 3: Call(s1,r1,f1); basic semantics 4: Order(o2); basic semantics 5: Depth(d2); advanced semantics 1: Inverse(o1,o2); basic semantics 6: Order(o3); basic semantics 7: Depth(d3); advanced semantics 2: SameCall(func,o1,o3); basic parameter comparison 1: d2>d1; basic parameter comparison 2: d3>d2. Among them, basic semantics 4, basic semantics 5, and advanced semantics 1 are simultaneously [0.20] Modification, basic semantics 6, basic semantics 7, advanced semantics 2 are simultaneously modified by another◇ [0.20] Modification.
[0070] In a specific embodiment, step S01 can obtain the minimum atomic formula range and the logical operator range. Specifically, the minimum atomic formula includes: all basic event items, advanced event items, basic parameter comparison operations, and advanced parameter comparison operations. Logical operators can act on the results of the minimum atomic formula or multiple minimum atomic formulas after logical operations, including logical and, logical not, I "I happened before",◇ I "Occurs after I". A subset of the attack specification is the set consisting of the minimal atomic formula, the AND of the specification, the NOT of the specification, the occurrence of the specification within an interval of I before, and the occurrence of the specification within an interval of I after.
[0071] In different embodiments, basic event items, advanced event items, basic parameter comparison operations, and advanced parameter comparison operations may be different, but are all covered in these categories; the use of logical operators may be different, but are all included in the scope of all logical operators mentioned above.
[0072] Thereafter, in step S02, adaptive weights may be added to the basic events, advanced events, and parameter comparison operators in the minimum atomic formula, thereby quantifying the importance of each minimum atomic formula to the inferred detection result. Represents basic events and basic parameter comparison operations. Additional weight c a ;use Indicates advanced event and advanced parameter comparison operations. Additional weight c b Among them, the weight c a 、c b are adaptive constants. For different attack specifications, the weight c a 、c b The calculation can be performed by the method described below.
[0073] Additional weight c a The number of items can be expressed as , calculated by adding the number of basic event items in the attack specification to the number of basic parameter comparison operations; the additional weight c b The number of items can be expressed as ,The calculation method is ,the number of high-level event items in the attack specification plus the number of ,high-level parameter comparison operations.
[0074] In a specific embodiment, according to the above specific reentry attack specification, , .
[0075] For each attack specification, the range of the specification calculation result must be limited to between 0 and 1. Define the following rules:
[0076]
[0077]
[0078]
[0079] in, Indicates that all the weights c are added a The sum of the weights of the items, Indicates that all the weights c are added b The sum of the weights of the items; according to and Defined by the importance and Specific value.
[0080] In the above specific embodiment of the reentry attack, due to is less important than ,Based on experience and sampling experiment results, this attack is defined , ,ensure . Thus, the weights can be adaptively calculated ; Weights can be calculated adaptively This is used to measure the importance of different events and parameters in inferring the results of the attack protocol.
[0081] Thereafter, in step S03, a quantitative formula can be defined for the logical operators in the proposed MFOTL language subset to form a complete quantitative calculation method for the attack specification. ,in, Represents a specific attack specification and its sub-specifications; Represents a set of n events The semantic log composed of All need to be calculated to get a quantized value; Represents in semantic log The i-th event set in , which targets the regulations quantified results.
[0082] In one possible implementation, when the semantic log The i-th event set in Conforms to the atomic formula , and the atomic formula belong When, define:
[0083]
[0084] in, Representation semantic log The i-th event set in Conforms to the atomic formula .
[0085] In one possible implementation, when the semantic log The i-th event set in Conforms to the atomic formula , and the atomic formula belong When, define:
[0086]
[0087] In one possible implementation, when the semantic log The i-th event set in Does not conform to the atomic formula When, define:
[0088]
[0089] In one possible implementation, when the semantic log The i-th event set in Conforms to the atomic formula , and the atomic formula belong When, define:
[0090]
[0091] In one possible implementation, when the semantic log The i-th event set in Conforms to the atomic formula , and the atomic formula belong When, define:
[0092]
[0093] In one possible implementation, the semantic log is calculated The i-th event set in conform to When, define:
[0094]
[0095] in, Indicates the timestamp of the occurrence of the i-th event, represents the timestamp of the jth event. It is used to measure that in the interval 𝐼, The sooner it is satisfied, the greater its contribution to the satisfaction of the whole formula.
[0096] In one possible implementation, the semantic log is calculated The i-th event set in conform to When, define:
[0097]
[0098] in, It is used to measure that in the interval 𝐼, The sooner it is satisfied, the greater its contribution to the satisfaction of the whole formula.
[0099] In one possible implementation, the semantic log is calculated The i-th event set in When the AND logic combination of the two formulas is met, the definition is:
[0100]
[0101] In a specific embodiment, given a semantic log for:
[0102] := Order(1); Depth(1) ; Call(0x1exxxx,0x8exxxx,2e0c0b38);
[0103] := Order(2); Depth(2) ; Call(0x8exxxx,0x7bxxxx,5a4e1a);
[0104] := Order(3); Depth(2) ; Call(0x8exxxx,0x1exxxx,5a4b4c); Inverse(1,3);
[0105] := Order(4); Depth(3) ; Call(0x1exxxx,0x8exxxx,2e0c0b38);SameCall(1,4);
[0106] In this specific embodiment, we first calculate The specific calculation process is:
[0107] The first step is to ,get =0.022, =0.022, get =0.022; according to ,get , , , Etc. According to ,get .4. ;
[0108] The second step is based on get, ,
[0109] ,
[0110] ,
[0111] ,
[0112] according to get, =0.022+0.022+0.022+0.022+0.022+0.36+0.022+0.022+0.34+0.022+0.022=0.898.
[0113] In this specific embodiment, the second calculation is The specific calculation process is:
[0114] The first step is to ,get =0.022, =0.022, get =0.022; according to ,get , , , wait.
[0115] The second step is based on get, =0.022+0.022+0.022=0.066.
[0116] In this specific embodiment, the calculation is then The specific calculation process is:
[0117] The first step is to ,get =0.022, =0.022, get =0.022; according to ,get , , , wait.
[0118] The second step is based on get, =0.022+0.022+0.022=0.066.
[0119] In this specific embodiment, the calculation is then The specific calculation process is:
[0120] The first step is to ,get =0.022, =0.022, get =0.022; according to ,get , , , wait.
[0121] The second step is based on get, =0.022+0.022+0.022=0.066.
[0122] Thereafter, in step S04, the maximum value of the quantified results in the Ethereum transaction semantic log can be calculated according to the quantified attack specification to determine whether there is a risk that the target transaction is used for a predefined attack. Specifically, given a semantic log , Attack Protocol and a quantized threshold According to the above method, calculate each The event collection in The quantitative results , for all , if it satisfies its maximum value , it means that the currently monitored transaction constitutes an attack.
[0123] In the above specific embodiment, the maximum value , set the threshold to 0.8, satisfying the maximum value The condition indicates that the currently monitored transaction constitutes a reentrancy attack.
[0124] In a specific embodiment, 25 transaction semantic logs containing the above five types of attacks were obtained, and the mentioned attack specification quantification methods were practiced. The specific results are shown in the table:
[0125]
[0126] It can be seen from the results of this embodiment that each attack type requires a different threshold adjustment to optimize its performance. Obviously, at certain thresholds, all attack types can completely mark all positive samples (indicated by *), but this usually leads to an increase in FN, which is undesirable. For example, for reentry attacks, all positive samples (TP=8) are marked at a threshold of 0.7, but there are 2 false positives. However, all sandwich attacks and call injection attacks are successfully detected at a threshold of 0.8, and no false positives are reported. In general, in this embodiment, the method proposed in this specification can effectively monitor attacks in Ethereum transactions and effectively protect the security of Ethereum.
[0127] On the other hand, corresponding to the above method process, the embodiment of this specification also discloses a blockchain attack detection system based on quantitative semantic specification. Figure 6 The structure diagram of a blockchain attack detection system based on quantitative semantic conventions is shown in the embodiment of this specification. Figure 6 As shown, the system includes:
[0128] The formal specification semantics determination unit D01 is configured to define a subset of the MFTOL language of the formal specification for Ethereum attack modeling, where the subset defines the logical operators and minimum atomic formulas included in the specification;
[0129] The atomic formula quantification unit D02 is configured to add adaptive weights to the basic events, advanced events and parameter comparison operators in the minimum atomic formula, so as to quantify the importance of each minimum atomic formula to the inferred detection result;
[0130] The logic operator quantization unit D03 is configured to define quantization formulas for the logic operators in the proposed MFOTL language subset to form a complete quantitative calculation method for the attack specification;
[0131] The risk monitoring unit D04 is configured to calculate the quantified result in the Ethereum transaction semantic log according to the quantified attack specification, and determine whether there is a risk that the target transaction is used for a predefined attack.
[0132] Corresponding to the aforementioned embodiment of a method for detecting blockchain attacks based on quantified semantic specifications, the present invention also provides an embodiment of a device for detecting blockchain attacks based on quantified semantic specifications.
[0133] See also Figure 7 , a detection device for blockchain attacks based on quantified semantic specifications provided by an embodiment of the present invention includes a memory and one or more processors, wherein the memory stores executable codes, and when the processor executes the executable codes, it is used to implement a detection method for blockchain attacks based on quantified semantic specifications in the above embodiment.
[0134] The embodiment of the detection device for blockchain attacks based on quantified semantic specification provided by the present invention can be applied to any device with data processing capability, and the device with data processing capability can be a device or apparatus such as a computer. The device embodiment can be implemented by software, or by hardware or a combination of software and hardware. Taking software implementation as an example, as a device in a logical sense, it is formed by the processor of any device with data processing capability in which it is located reading the corresponding computer program instructions in the non-volatile memory into the memory for execution. From the hardware level, if Figure 7 As shown, it is a hardware structure diagram of a blockchain attack detection device based on quantized semantic specification provided by the present invention, in which any device with data processing capability is located, except Figure 7 In addition to the processor, memory, network interface, and non-volatile memory shown, any device with data processing capabilities in which the apparatus in the embodiments is located may also include other hardware, generally based on the actual functions of the device with data processing capabilities, which will not be described in detail.
[0135] The implementation process of the functions and effects of each unit in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.
[0136] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The device embodiment described above is only schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of the present invention. Ordinary technicians in this field can understand and implement it without paying creative work.
[0137] An embodiment of the present invention also provides a computer-readable storage medium having a program stored thereon. When the program is executed by a processor, a method for detecting blockchain attacks based on quantified semantic specifications in the above embodiment is implemented.
[0138] The computer-readable storage medium may be an internal storage unit of any device with data processing capability described in any of the aforementioned embodiments, such as a hard disk or a memory. The computer-readable storage medium may also be an external storage device of any device with data processing capability, such as a plug-in hard disk, a smart media card (SMC), an SD card, a flash card, etc. equipped on the device. Furthermore, the computer-readable storage medium may also include both an internal storage unit and an external storage device of any device with data processing capability. The computer-readable storage medium is used to store the computer program and other programs and data required by any device with data processing capability, and may also be used to temporarily store data that has been output or is to be output.
[0139] The present invention also provides a computer program product, including a computer program, which, when executed by a processor, implements the method for detecting blockchain attacks based on quantitative semantic specifications.
[0140] Those skilled in the art will readily appreciate other embodiments of the present application after considering the description and practicing the contents disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present application. The description and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the claims.
[0141] It should be understood that the above general description and the detailed description below are only exemplary and explanatory and cannot limit the present application. The present application is not limited to the precise structure described above and shown in the drawings, and various modifications and changes can be made without departing from the scope thereof. The scope of the present application is limited only by the attached claims.
Claims
1. A method for detecting blockchain attacks based on quantitative semantic specification, characterized in that: The method comprises the following steps: A subset of the MFTOL language that defines a formal specification for Ethereum attack modeling, which defines the logical operators and minimal atomic formulas contained in the specification; Add adaptive weights to basic events, advanced events, and parameter comparison operators in the minimum atomic formula to quantify the importance of each minimum atomic formula to the inferred detection results; Define quantization formulas for the logical operators in the proposed MFOTL language subset to form a complete attack specification quantization calculation method; The quantitative results in the Ethereum transaction semantic log are calculated according to the quantified attack specification to determine whether there is a risk that the target transaction is used for a predefined attack.
2. According to a method for detecting blockchain attacks based on quantitative semantic specification according to claim 1, it is characterized in that: The MFTOL language that defines the formal specification for modeling Ethereum attacks is specifically: using the MFTOL logical language to describe the potential behavior patterns of Ethereum attacks, including reentrancy attacks, sandwich attacks, direct price tampering attacks, indirect price tampering attacks, and call injection attacks.
3. According to a method for detecting blockchain attacks based on quantitative semantic specification according to claim 1, it is characterized in that: minimal atomic formula The attack specification is a specification that cannot be broken down into smaller granularities, including: all basic event items, advanced event items, basic parameter comparison operations, and advanced parameter comparison operations; the logical operator acts on the minimum atomic formula or the result of multiple minimum atomic formulas after logical operations.
4. According to a method for detecting blockchain attacks based on quantitative semantic specification according to claim 1, it is characterized in that: The specific method of adding adaptive weights to the basic events, advanced events, and parameter comparison operators in the minimum atomic formula is as follows: Represents basic events and basic parameter comparison operations. Additional weight c a ;use Indicates advanced event and advanced parameter comparison operations. Additional weight c b ; Among them, the weight c a 、c b are adaptive constants. For different attack specifications, the weight c a 、c b Adaptive calculation: For each attack specification, the range of the specification calculation result is limited to between 0 and 1, and all the weights c are added. a The sum of the weights of the items represents all items with added weight c b The sum of the weights of the items adds up to 1.
5. According to a method for detecting blockchain attacks based on quantitative semantic specification according to claim 1, it is characterized in that: The definition of the quantization formula specifically includes: defining a calculation operator ,in, Represents a specific attack specification and its sub-specifications; Represents a set of n events The semantic log composed of All need to be calculated to get a quantized value; Represents in semantic log The i-th event set in , which targets the regulations quantified results.
6. According to a method for detecting blockchain attacks based on quantitative semantic specification according to claim 5, it is characterized in that: In the quantified formula, when the semantic log The i-th event set in Does not conform to the atomic formula hour, ; When semantic logging The i-th event set in Conforms to a specific atomic formula The attack rules according to the atomic formula include the following forms: When semantic logging The i-th event set in Conforms to a specific atomic formula , and the atomic formula belong When, define: ; ; in, Representation semantic log The i-th event set in Conforms to the atomic formula ; Represents basic events and basic parameter comparison operations, c a for Additional weight; When semantic logging The i-th event set in Conforms to the atomic formula , and the atomic formula belong When, define: ; ; in, Indicates advanced events and advanced parameter comparison operations, c b for Additional weights, ¬, represent the negation operation.
7. According to claim 5, a method for detecting blockchain attacks based on quantitative semantic specification is characterized in that: Computational semantic log The i-th event set in conform to When, define: ; in, Indicates the timestamp of the occurrence of the i-th event, represents the timestamp of the jth event. Used to measure contribution, in the interval 𝐼, The sooner it is satisfied, the greater its contribution to the satisfaction of the whole formula; Computational semantic log The i-th event set in conform to When, define: ; in, Used to measure contribution, in the interval 𝐼, The sooner it is satisfied, the greater its contribution to the satisfaction of the entire formula;◆ I is the range of the forward search time interval I; I is the range of the backward search time interval I; Computational semantic log The i-th event set in When the AND logic combination of the two formulas is met, the definition is: 。 8. According to claim 1, a method for detecting blockchain attacks based on quantitative semantic specification is characterized in that: The method of calculating the quantified results in the Ethereum transaction semantic log according to the quantified attack specification to determine whether there is a risk that the target transaction is used for a predefined attack is as follows: , Attack Protocol and a quantized threshold , calculate each The event collection in The quantitative results , for all , if its maximum value is greater than the threshold , it means that the currently monitored transaction constitutes an attack.
9. A detection system for blockchain attacks based on quantitative semantic specification according to any one of claims 1 to 8, characterized in that: include: Formal specification semantics determination unit, atomic formula quantification unit, logical operator quantification unit and risk monitoring unit; The formal specification semantics determination unit is configured to define a subset of the MFTOL language of the formal specification for Ethereum attack modeling, the subset defining the logical operators and minimum atomic formulas contained in the specification; The atomic formula quantization unit is configured to add adaptive weights to basic events, advanced events, and parameter comparison operators in the minimum atomic formula, thereby quantifying the importance of each minimum atomic formula to the inferred detection result; The logic operator quantization unit is configured to define a quantization formula for the logic operators in the proposed MFOTL language subset to form a complete quantization calculation method for the attack specification; The risk monitoring unit is configured to calculate the quantified result in the Ethereum transaction semantic log according to the quantified attack specification, and determine whether there is a risk that the target transaction is used for a predefined attack.
10. A detection device for blockchain attacks based on quantitative semantic specification, comprising a memory and one or more processors, wherein the memory stores executable code, characterized in that: When the processor executes the executable code, a method for detecting blockchain attacks based on quantified semantic specification as described in any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Language-independent smart contract verification method and device, electronic equipment and storage medium
CN116842496A
Apparatus and method for obtaining vulnerable transaction sequence in smart contract
US20220358223A1