Intelligent contract vulnerability detection method, system and equipment based on time sequence scene

By building a timing scenario diagram of smart contracts and combining graph convolution technology, the problem of high path explosion and false alarm rates in the existing smart contract vulnerability detection methods is solved, and higher detection accuracy and efficiency are achieved.

CN120124076AActive Publication Date: 2025-06-10YANTAI UNIV
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510621721.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-06-10
Estimated Expiration
2045-05-15

AI Technical Summary

Technical Problem

Among the existing smart contract vulnerability detection methods, static analysis methods such as symbol execution and intermediate representation have problems such as path explosion, execution timeout, insufficient path coverage and high false alarm rates.

Method used

A smart contract vulnerability detection method based on timing scenarios is adopted to construct a control flow diagram by disassembling the bytecode of the smart contract, extracting the path and aggregating common parts of the fragments to form a timing scenario diagram. Then, the opcode is updated, feature dimensionality reduction and mapping processing are performed, and the path vulnerability detection results are integrated with graph convolution technology.

Benefits of technology

Significantly improves the accuracy, accuracy, recall and F1 scores of smart contract vulnerability detection, especially in detecting integer overflow, reentry and block dependency vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124076A_ABST
    Figure CN120124076A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent contract vulnerability detection in electrical digital processing, in particular to an intelligent contract vulnerability detection method, system and device based on a time sequence scene. In order to solve the problem of low accuracy of intelligent contract vulnerability detection in the prior art, the method comprises the following steps: firstly, constructing a control flow graph on an operation code level, extracting an execution scene containing time sequence information by traversing a path of the control flow graph, and further aggregating nodes with public part fragments to obtain a time sequence scene graph; secondly, an innovative operation code updating method and a feature dimension reduction method are designed, and a dimension reduction time sequence scene graph is obtained; and finally, combining the node feature vectors with the adjacent matrixes of the corresponding paths, and integrating path vulnerability detection results through graph convolution processing to obtain an intelligent contract vulnerability detection result. The method is applied to detection of integer overflow vulnerabilities, reentry vulnerabilities and block dependence vulnerabilities in smart contracts, and can significantly improve the accuracy, precision, recall rate and F1 score.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent contract vulnerability detection in digital signal processing, and in particular to an intelligent contract vulnerability detection method, system and device based on a timing scenario. Background Art

[0002] The prior art often uses static analysis methods for intelligent contract vulnerability detection. The static analysis methods mainly include symbolic execution and intermediate representation. The symbolic execution method symbolizes program variables and systematically explores all possible execution paths to analyze the abnormal behavior of the program. Although symbolic execution tools such as Oyente and Mythril have a high accuracy rate for vulnerability detection, for complex intelligent contracts, the "path explosion" problem is very likely to occur. Therefore, symbolic execution tools face a series of problems such as timeout during the execution process, insufficient actual path coverage, and false negatives in the detection results. The intermediate representation method transforms the source code or bytecode of an intelligent contract into a more suitable abstract form for analysis, and then performs rule analysis on this intermediate form to discover security problems in the contract. Although intermediate representation tools such as the Smartcheck method transform intelligent contracts into an intermediate form that is more conducive to vulnerability detection, during the process of intermediate representation, context information and semantic details may be lost, resulting in false positives in vulnerability detection and low accuracy of vulnerability detection. Summary of the Invention

[0003] The object of the present invention is to provide an intelligent contract vulnerability detection method, system and device based on a timing scenario.

[0004] The technical solution of the present invention is as follows: An intelligent contract vulnerability detection method based on a timing scenario includes the following operations: S1. Disassemble the bytecode of the intelligent contract to be detected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of the jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and use the path that has a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph; S2. Update the opcode of each node in the timing scenario graph according to the opcode format and type to obtain an updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain a dimensionality-reduced timing scenario graph; S3. Perform feature mapping processing on each node in the dimensionality-reduced time-series scenario graph to obtain node feature vectors; concatenate all node feature vectors belonging to the same path in the dimensionality-reduced time-series scenario graph to obtain path feature vectors for each path; based on the node connection relationships on the same path in the dimensionality-reduced time-series scenario graph, obtain the adjacency matrix for each path; the adjacency matrix and path feature vector for each path are processed by graph convolution to obtain path vulnerability detection results; based on the path vulnerability detection results, obtain the intelligent contract vulnerability detection results.

[0005] During the aggregation process in S1, in the order of the length of the common part segments from small to large, the common part segments in the corresponding paths to be abstracted are aggregated into a single node in turn.

[0006] The operations for updating the operation codes of each basic block in the time-series scenario graph in S2 include: deleting the numerical suffixes of consecutive operation codes with the same mnemonic prefix, and / or mapping multiple operation codes associated with the same vulnerability to the same operation code according to the corresponding functions.

[0007] The specific operation of feature dimensionality reduction processing in S2 is: combine adjacent operation codes in each node of the updated time-series scenario graph to obtain several operation code combinations for each node, delete those that are all ordinary operation codes, and / or delete the operation code combinations starting with the termination operation code to obtain the dimensionality-reduced time-series scenario graph.

[0008] The specific operation of feature mapping processing in S3 is: assign corresponding values according to the number of occurrences of the operation code combinations in the nodes of the dimensionality-reduced time-series scenario graph to obtain operation code combination vectors; concatenate all operation code combination vectors according to the order of the operation code combinations in the nodes to obtain node feature vectors.

[0009] During the graph convolution processing in S3, the adjacency matrix corresponding to the output of the previous layer is added to the initial adjacency matrix to obtain an updated adjacency matrix, which is used as the adjacency matrix for the input of the current layer.

[0010] In S3, if the current vulnerability exists in the path vulnerability detection results, then the current vulnerability exists in the intelligent contract vulnerability detection results; if the current vulnerability does not exist in all path vulnerability detection results, then the current vulnerability does not exist in the intelligent contract vulnerability detection results.

[0011] An intelligent contract vulnerability detection system based on a time-series scenario, used to implement the above-mentioned intelligent contract vulnerability detection method based on a time-series scenario, includes the following operations: The timing scenario graph generation module is used to disassemble the bytecode of the smart contract to be inspected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and regard the path with a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph; The dimensionality reduction timing scenario graph generation module is used to update the opcode of each node in the timing scenario graph according to the opcode format and type to obtain an updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain a dimensionality reduction timing scenario graph; The smart contract vulnerability detection result generation module is used to perform feature mapping processing on each node in the dimensionality reduction timing scenario graph to obtain a node feature vector; splice all the node feature vectors belonging to the same path in the dimensionality reduction timing scenario graph to obtain a path feature vector for each path; based on the node connection relationship on the same path in the dimensionality reduction timing scenario graph, obtain the adjacency matrix of each path; the adjacency matrix and path feature vector of each path are processed by graph convolution to obtain a path vulnerability detection result; based on the path vulnerability detection result, obtain the smart contract vulnerability detection result.

[0012] An intelligent contract vulnerability detection device based on timing scenarios includes a processor and a memory. Among them, when the processor executes the computer program stored in the memory, the above-mentioned intelligent contract vulnerability detection method based on timing scenarios is implemented.

[0013] A computer-readable storage medium is used to store a computer program. Among them, when the computer program is executed by a processor, the above-mentioned intelligent contract vulnerability detection method based on timing scenarios is implemented.

[0014] The beneficial effects of the present invention are as follows: An intelligent contract vulnerability detection method based on a timing scenario provided by the present invention first constructs a control flow graph at the opcode level, extracts execution scenarios containing timing information by traversing the paths of the control flow graph, and further aggregates nodes with common partial segments to obtain a timing scenario graph; then, an innovative opcode update method and a feature dimensionality reduction method are designed to retain semantic information and the timing features inside the nodes while reducing the dimension, resulting in a dimensionality-reduced timing scenario graph; finally, each node in the dimensionality-reduced timing scenario graph is subjected to feature mapping processing to obtain a node feature vector, which is combined with the adjacency matrix of each path obtained based on the connection relationship of the nodes on the same path in the dimensionality-reduced timing scenario graph, and through graph convolution processing, the path vulnerability detection results are integrated to obtain the intelligent contract vulnerability detection result; this method is applied to intelligent contract vulnerability detection, especially to the detection of integer overflow vulnerabilities, reentrancy vulnerabilities, and block dependency vulnerabilities in intelligent contracts, and can significantly improve the accuracy, precision, recall rate, and F1 score. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] By reading the detailed description of the preferred embodiments below, the solutions and advantages of the present application will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention.

[0016] In the drawings: Figure 1 is a schematic diagram of the detection method flow in this embodiment; Figure 2 is a process diagram of node opcode feature dimensionality reduction in this embodiment; Figure 3 is a process diagram of generating the intelligent contract vulnerability detection result in this embodiment; Figure 4 is a summary diagram of the accuracy, precision, recall rate, and F1 score of various detection methods in the detection of integer overflow vulnerabilities, reentrancy vulnerabilities, and block dependency vulnerabilities in this embodiment; in Figure 4 , (a) is a summary diagram of the accuracy, precision, recall rate, and F1 score of various detection methods in integer overflow vulnerabilities, (b) is a summary diagram of the accuracy, precision, recall rate, and F1 score of various detection methods in reentrancy vulnerabilities, and (c) is a summary diagram of the accuracy, precision, recall rate, and F1 score of various detection methods in block dependency vulnerabilities; Figure 5 is a diagram of an intelligent contract vulnerability detection case in this embodiment; in Figure 5 , (a) is a schematic diagram of all paths in the timing scenario graph, and (b) is the vulnerability detection result of all paths in the timing scenario graph. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings.

[0018] This embodiment provides a method for detecting vulnerabilities in smart contracts based on timing scenarios. Refer to Figure 1 , including the following operations: S1. Disassemble the bytecode of the smart contract to be detected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of the jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and use the path that has a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph; S2. Update the opcode of each node in the timing scenario graph according to the opcode format and type to obtain an updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain a dimensionality-reduced timing scenario graph; S3. Perform feature mapping processing on each node in the dimensionality-reduced timing scenario graph to obtain a node feature vector; splice all the node feature vectors belonging to the same path in the dimensionality-reduced timing scenario graph to obtain a path feature vector for each path; based on the node connection relationship on the same path in the dimensionality-reduced timing scenario graph, obtain the adjacency matrix for each path; the adjacency matrix and path feature vector for each path are processed by graph convolution to obtain a path vulnerability detection result; based on the path vulnerability detection result, obtain a smart contract vulnerability detection result. The specific steps are as follows.

[0019] S1. Disassemble the bytecode of the smart contract to be detected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of the jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and use the path that has a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph.

[0020] Construct a control flow graph based on the bytecode of the smart contract to be detected, and obtain all the paths (execution scenarios) existing in the control flow graph to form a path set; abstract the common partial segments that each path in the path set has with other paths, that is, the continuously repeated code segments are abstracted as common partial segments, and aggregate them into a single node to obtain a timing scenario graph, thereby reducing the scenario complexity.

[0021] First, since the version span of current Solidity smart contracts covers multiple iterative versions such as 0.4.+ to 0.8.+, there are differences in syntax specifications between different versions. To effectively address potential source code adjustment issues during the contract version iteration process and avoid interference from syntax differences at the source code level, this embodiment constructs a control flow graph of the smart contract at the opcode level. Specifically, the bytecode of the smart contract to be inspected is disassembled into an opcode sequence, the opcode sequence is divided into basic blocks according to instruction contents such as jump instructions and termination instructions, and the jump relationships between basic blocks are established based on the address parameters of the jump instructions to obtain the control flow graph, which facilitates directly analyzing the original bytecode on the blockchain, effectively breaking through the syntax limitations brought by Solidity version differences, and enhancing the version universality of the detection method. Given a smart contract c, the control flow graph generated at the opcode level , where and represent the node set and edge set of the CFG respectively. The nodes of the CFG are basic blocks, and the edges are the jump relationships between basic blocks.

[0022] Then, to obtain all execution scenarios of the smart contract, this embodiment obtains all paths from the root node to all tail nodes in the control flow graph, forming a path set. The detailed process of obtaining can be seen in the execution logic code in Table 1. The input of the execution logic code in Table 1 is the control flow graph CFG of the smart contract, and the output is all execution scenarios of the CFG. Among them, in the first line, the node with a unique in-degree of 0 in the CFG is obtained and defined as the root node; in the second line, the sets of visited nodes, the current execution scenario, and all execution scenarios are initialized; in the third line, the recursive function GetScenarios for obtaining execution scenarios is called to obtain the paths (execution scenarios) of the smart contract starting from the root node; in the fourth line, all paths of the smart contract are returned. Next, the operation process of the recursive function GetScenarios for obtaining execution scenarios is introduced in detail. The input of the function is the CFG of the smart contract, the root node is n root , the set of visited nodes V, the set of current execution scenarios S, and the set of all execution scenarios S all, at lines 6 and 7, add the root node to the current execution scenario and the visited nodes; then use the function isTargetExist to determine whether there is a subsequent jump target for the root node, that is, whether it is a leaf node (line 8); if it is a leaf node, it means that a scenario has been completely obtained, then add this scenario to the set of all scenarios (line 9); if it is not a leaf node, then loop to judge its jump target node (line 11); at lines 11 and 12, use the function IsInLoop to determine whether the jump target node is in a loop structure. If it is in a loop structure, retain the loop structure and use the function GetExitNode to obtain the exit node of the loop structure as the entry node for the next recursion (line 13); at line 15, find unvisited nodes through the set of visited nodes; at line 16, call the recursive function GetScenarios to continue obtaining the execution scenarios of unvisited target nodes. For each complete scenario obtained, perform a backtracking operation to remove the visited branch from the current execution scenario set (line 17) for traversing the next path. When all paths have been visited, the recursion ends.

[0023] Table 1 Logical code for obtaining all paths to form a path set 。

[0024] Finally, reduce the scenario complexity. Traverse each path in the path set, and regard the path that has a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain the timing scenario graph. The above common partial segments do not include the root node to streamline the scenario path; and in the above aggregation process, the common partial segments in the corresponding path to be abstracted are aggregated into a single node in the order of the length of the common partial segments from small to large. For specific operation details, refer to the logical code in Table 2. The input of the logical code in Table 2 is all execution scenarios (path set) of a smart contract ,and the output is the aggregated execution scenario (timing scenario graph).

[0025] Table 2 Node aggregation logical code for obtaining the timing scenario graph 。

[0026] In the logical code of Table 2, the first line initializes four core data structures for storing the filtered scenario list 、list of consecutive common subsequences 、list of deduplicated common subsequences and the finally aggregated scenario list ; Since all scenarios of the smart contract start from the program start node, and this node cannot distinguish semantics, the scenario list without the start node is obtained through lines 2 - 4. ; Specifically, line 2 traverses all scenarios in the smart contract, and line 3 calls the function RemoveRoot to remove the start node and assign it to , to eliminate the interference of the root node on the common subsequence analysis; in practical applications, there is an inclusion relationship between consecutive common subsequences. To avoid long paths covering the common subsequences in short paths, it is necessary to ensure that shorter scenarios are processed first; therefore, in line 5; the function SortByLength is called to sort the original scenarios (all paths in the path set) in ascending order of path length; then, in line 6, the function GetLongestSeqs is called to obtain all consecutive common subsequences with a length greater than 1 (the common partial segments in the paths that have common partial segments with other paths) from the sorted scenarios; in the execution scenario graph, different scenarios may contain duplicate consecutive code segments, and these duplicate segments will generate the same common subsequences; by eliminating these redundant sequences, the list can be effectively streamlined; therefore, in line 7, the function DedupSeqs is called to remove duplicates from the list of common subsequences to obtain ; Lines 8 - 13 aggregate all scenarios of the smart contract according to the deduplicated consecutive common subsequences; first, traverse all scenarios of the smart contract (line 8), that is, traverse all paths in the path set and check whether it contains any subsequence in (lines 9 and 10). If it exists (if the path to be abstracted is found), then in line 11, the function AggregateSeq is called to aggregate the subsequence (the common partial segment without the root node) into a single node and return the aggregated scenario s; after the aggregation is completed, in line 14, the aggregated scenario s is stored in the sequence ; Finally, all aggregated scenarios are returned (line 16).

[0027] The timing scenario graph has the following characteristics: Generalization - The timing scenario graph (CTSG) is constructed at the opcode level, breaking through the dependence on source code and supporting dual parsing of smart contract source code and opcode; Integrity - CTSG is constructed from the CFG of the smart contract, completely containing all potential paths of program execution, ensuring that all scenarios of program execution are covered; Timing - The execution scenario is constructed by sorting the opcode addresses inside the nodes in ascending order and the order of control flow edges between nodes, so that the logical timing of the original program is retained in CTSG; Efficiency - Aggregate common execution subsequences (common partial segments), optimizing the spatial complexity of the graph structure while maintaining information integrity and improving the message propagation efficiency.

[0028] S2. Update the operation codes of each node in the timing scenario graph according to the operation code format and type to obtain an updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain a dimensionality-reduced timing scenario graph.

[0029] Update the operation codes of each node in the timing scenario graph according to the operation code format and type, streamline the number of operation codes to obtain an updated timing scenario graph; and perform feature dimensionality reduction processing on each node in the updated timing scenario graph to remove the operation code combinations that are ineffective for vulnerability detection and further reduce the feature dimension to obtain a dimensionality-reduced timing scenario graph.

[0030] First, in order to further reduce the subsequent feature dimension and improve the training efficiency and generalization ability of the subsequent graph convolutional network, in this embodiment, the operation codes of each node in the timing scenario graph are updated according to the operation code format and type to obtain an updated timing scenario graph.

[0031] During the process of updating the operation codes of each node in the updated timing scenario graph, for consecutive operation codes with the same mnemonic prefix, such as the PUSH0 - PUSH32 series, and CREATE and CREATE2, remove their numerical suffixes, and thus uniformly map them to basic operators such as "PUSH" and "CREATE" to reduce feature redundancy; or / and map multiple operation codes associated with the same vulnerability to the same operation code according to the corresponding functions. Specifically, for the instruction set with a strong correlation with potential vulnerabilities, classify them according to functions and use a simplified operation code expression; for example, multiple operation codes related to block state dependence are uniformly abstracted as "CONSTANT", and operation codes related to storage read and write are merged into "STORAGE" to extract key features related to vulnerabilities; or / and modify the operation codes in the old version format to the operation codes in the new version format. This is because the iteration of the EVM historical version has caused some changes in the naming of operation codes. Update the operation code names in the old version to the latest operation code names. For example, map the old version instructions such as "SUICIDE" and "SHA3" to the standard names such as "SELFDESTRUCT" and "KECCAK256" respectively to ensure the consistency of the operation code expressions of different versions of smart contracts. By updating the operation codes of each node in the timing scenario graph, the total amount of operation codes in the timing scenario graph is streamlined. Refer to Table 3 to obtain a dimensionality-reduced timing scenario graph, which helps to reduce the dimension during the subsequent construction of feature vectors.

[0032] Table 3 Update rules in the operation codes of each node in the updated timing scenario graph 。

[0033] Next, perform feature dimensionality reduction on each node in the updated timing scenario graph to obtain a dimensionality-reduced timing scenario graph. The operation of feature dimensionality reduction is specifically as follows: According to the execution order of the operation codes in the nodes of the updated timing scenario graph, combine adjacent operation codes to obtain several operation code combinations. Delete those that are all ordinary operation codes (i.e., operation codes that are related to vulnerabilities and not termination operation codes), or / and delete the operation code combinations starting with termination operation codes, so as to achieve the feature dimensionality reduction of the nodes (basic blocks) in the timing scenario graph, thereby filtering out irrelevant operation code pairs. In this way, without losing important features and reducing feature sparsity, the dimension of the feature space is reduced to obtain a dimensionality-reduced timing scenario graph. Figure 2 shows an example of the process of reducing the features of node operation codes. Figure 2 In it, the red operation codes are vulnerability-related operation codes (such as PUSH in Table 4), the blue operation codes are ordinary operation codes (i.e., operation codes that are not related to vulnerabilities and not termination operation codes, such as LOG), and the gray operation codes are termination operation codes (termination operation codes include STOP, RETURN, REVERT, INVALID, SELFDESTRUCT).

[0034] Table 4 Examples of operation codes related to smart contract vulnerabilities .

[0035] Finally, the dimension of the operation codes in the dimensionality-reduced timing scenario graph can be obtained by the following formula: Dimension = 2 * OP all * OP vul - OP vul * OP vul - OP termin * OP vul , where the total number of operation codes in the node is OP all , the number of vulnerability-related operation codes is OP vul , the number of termination operation codes is OP termin , the dimensional space of all features is OP all * OP all , and the number of pairs of operation codes where both are not related to vulnerabilities is (OP all - OP vul ) * (OP all - OP vul ), and the number of invalid operation code pairs where the first is a termination operation code is OP termin * OP vul .

[0036] S3. Perform feature mapping processing on each node in the dimensionality-reduced time-series scenario graph to obtain node feature vectors; concatenate all the node feature vectors belonging to the same path in the dimensionality-reduced time-series scenario graph to obtain the path feature vector for each path; based on the node connection relationships on the same path in the dimensionality-reduced time-series scenario graph, obtain the adjacency matrix for each path; the adjacency matrix and path feature vector for each path are processed by graph convolution to obtain the path vulnerability detection result; based on the path vulnerability detection result, obtain the smart contract vulnerability detection result.

[0037] Perform feature mapping processing on each node in the dimensionality-reduced time-series scenario graph to obtain node feature vectors, and combine them with the adjacency matrix obtained for each path based on the node connection relationships on the same path in the dimensionality-reduced time-series scenario graph. After graph convolution processing, this method can reduce the feature dimension while enhancing the information density and improving the feature extraction accuracy. Integrate the path vulnerability detection results to obtain the smart contract vulnerability detection result.

[0038] First, perform feature mapping processing on each node in the dimensionality-reduced time-series scenario graph to obtain node feature vectors. The specific operation of the feature mapping processing is as follows: assign corresponding values according to the occurrence times of the opcode combinations in the nodes of the dimensionality-reduced time-series scenario graph to obtain the opcode combination vectors; concatenate all the opcode combination vectors according to the order of the opcode combinations in the nodes to obtain the node feature vectors.

[0039] Then, concatenate all the node feature vectors belonging to the same path in the dimensionality-reduced time-series scenario graph in the path execution order to obtain the path feature vector for each path.

[0040] Meanwhile, based on the node connection relationships on the same path in the dimensionality-reduced time-series scenario graph, obtain the adjacency matrix for each path and extract the edge features in the path.

[0041] Finally, the adjacency matrix and path feature vector for each path are processed by graph convolution to obtain the path vulnerability detection result. The above graph convolution processing can be implemented by training a GCN network. During the dataset labeling process, for each path of the smart contract, set labels according to different vulnerability types (such as integer overflow, re-entrancy attack, block dependency). During the labeling process, first analyze each path independently and generate vulnerability labels. If there is a vulnerability, label it as 1; if there is no vulnerability, label it as 0, and obtain the labeling result of the smart contract based on the summary of the labels for each path.

[0042] The above graph convolution process includes two key stages. First is the feature propagation stage, where through the normalized adjacency matrix, node features spread along the graph structure. Second is the information aggregation stage, where in each convolution, the features of neighboring nodes are fused with its own features to update the node representation. After multiple layers are stacked, node features will gradually incorporate information from more distant neighbors. To improve the effect of graph convolution processing, during the graph convolution process, the adjacency matrix corresponding to the output of the previous layer is added to the initial adjacency matrix to obtain an updated adjacency matrix, which serves as the input adjacency matrix for the current layer.

[0043] The graph convolution is calculated through the following formula: , represents the feature vector of the l+ first layer, represents the feature vector matrix of the l layer, represents the path feature vector at the initial path, is the updated adjacency matrix, which is the sum of the adjacency matrix of the l+ first layer and the initial adjacency matrix, used to retain the node's own features; represents the degree matrix of, realizes the standardization of the adjacency matrix to balance the influence of nodes with different degrees on the result; represents the learnable weight matrix of the l layer, realizing the linear transformation of the feature space, represents the activation function, enhancing the model's non-linear expression ability.

[0044] Finally, based on the path vulnerability detection results, the smart contract vulnerability detection results are obtained. If the current vulnerability exists in the path vulnerability detection results, then the current vulnerability exists in the smart contract vulnerability detection results, and the existence result of the current vulnerability is marked as 1; if the current vulnerability does not exist in all path vulnerability detection results, then the current vulnerability does not exist in the smart contract vulnerability detection results, and the existence result of the current vulnerability is marked as 0.

[0045] Figure 3 is a process of obtaining the smart contract vulnerability detection results based on the path vulnerability detection results. Among them, Figure 3 the dimensionality reduction time series scenario of contains four paths: S1, S2, S3, and S4, Figure 3 the marking results of the path vulnerability detection results of show that S1 does not have three types of vulnerabilities: integer overflow, reentrancy, and block dependency, S2 only has an integer overflow vulnerability, S3 has both integer overflow and reentrancy vulnerabilities, and S4 only has a reentrancy vulnerability; since none of the 4 paths have a block dependency vulnerability, so Figure 3In the intelligent contract vulnerability detection results, the block dependency vulnerability label is set to 0, while at least one path of the remaining vulnerability types is marked as 1, so the corresponding label is set to 1. The marking of scenario features refines the features of intelligent contracts, which is beneficial to accurately locate the specific scenario where the vulnerability lies.

[0046] To verify the effectiveness of the detection method in this embodiment (hereinafter referred to as the method in this embodiment), the following experiments were conducted.

[0047] Experimental purpose. To verify the performance of the method in this embodiment, experiments were designed based on a real intelligent contract dataset on Ethereum in the experiment and the experimental results were analyzed to answer the following research questions (RQs): RQ1: How does the method in this embodiment compare with current mainstream static analysis vulnerability detection tools? RQ2: What is the impact of each component in the method in this embodiment on the final vulnerability detection effect? RQ3: How is the vulnerability location ability of the method in this embodiment compared with other deep learning methods?

[0048] Experimental environment. All experiments were conducted on a server running the Ubuntu 22.04 version operating system. The server is equipped with 2 Intel(R) Xeon(R) Silver 4210R CPUs @ 2.40GHz and 250GB of physical memory. The experimental tool is a Python-based intelligent contract vulnerability detection tool, so the experimental environment is Python 3.6.5. In addition, in the experiment, a 5-minute timeout was set for the vulnerability detection of each source file.

[0049] Dataset. To ensure the comprehensiveness of the experiment and the authority of the data, a high-quality dataset was constructed. The main data sources are as follows: The latest smart contract dataset released by Zheng Zibin et al. in 2023 was adopted. This dataset is highly relevant to the current Ethereum ecosystem and can reflect the characteristics of smart contracts in actual operation. The dataset contains a total of 21,212 manually annotated smart contract samples, covering multiple Solidity versions and having high reliability. At the same time, 3,000 real contracts on the official Ethereum website were collected from existing technologies (including SmartCheck, SmartBugs, Securify, Smartian, and Sailfish, etc.). These contracts have been analyzed by multiple research teams and contain confirmed vulnerability instances, providing guarantees for the authenticity and diversity of the dataset. On this basis, using automatic analysis tools such as Oyente and combined with manual annotation, the above data was further screened and annotated, and finally a comprehensive dataset containing 24,212 smart contracts was formed. Among them, the typical vulnerabilities identified include: 1,490 integer overflow vulnerabilities, 2,499 reentrancy vulnerabilities, and 1,574 block dependency vulnerabilities. For the dataset, in the experiment, it was randomly allocated according to the ratio of 8:2, where 80% was used as the training set and 20% was used as the test set, and accuracy, precision, recall, and F1-score metrics were used to evaluate the experimental results.

[0050] Experimental settings. For RQ1, first, three advanced static analysis vulnerability detection methods, namely Smartcheck, Oyente, and Mythril, were selected for comparison to verify the effectiveness of the method in this embodiment in the vulnerability detection task. Subsequently, four classic deep learning models, namely LSTM, Bi-LSTM, GRU, and Vanilla-RNN, were compared to analyze the influence of different modeling methods on the detection effect. For RQ2, the main innovation points of the method in this embodiment lie in the construction of the temporal scenario graph and the feature dimensionality reduction method. To evaluate the influence of these two core modules on the vulnerability detection effect, the following comparative experiments were designed based on the complete method: 1. Analyze the temporal scenario graph (CTSG) and the feature dimensionality reduction method simultaneously: Replace CTSG with the control flow graph CFG, and at the same time adopt the original non-dimensionality-reduced feature extraction method to analyze the overall contribution of CTSG and feature dimensionality reduction; 2. Analyze only CTSG: Use CFG to replace CTSG and keep the feature dimensionality reduction method unchanged to verify the contribution of CTSG; 3. Analyze only the feature dimensionality reduction method: Keep CTSG unchanged and adopt the non-dimensionality-reduced feature extraction method to evaluate the influence of the feature dimensionality reduction method on the detection performance; By comparing the detection performance under different experimental settings, the respective contributions of CTSG and the feature dimensionality reduction method can be quantified, and their promotion effects on the vulnerability detection effect can be further verified.

[0051] For RQ3, existing deep learning methods mainly perform vulnerability detection at the contract level. Their analysis dimension is limited to the overall features of smart contracts and it is difficult to accurately determine the execution scenario where the vulnerability lies. However, the method of this embodiment performs vulnerability detection at the execution scenario level of the contract, which can further locate the vulnerability position. To verify the vulnerability location ability of the method of this embodiment, in the experiment, first, a smart contract with an integer overflow vulnerability in the dataset was taken as an example for overall analysis, and then a real smart contract on the chain was selected as a case to analyze its vulnerability detection and location process in detail.

[0052] Answer results regarding effectiveness (for RQ1). In the experiment, the method of this embodiment was compared with existing vulnerability detection methods in three specific types of smart contract vulnerabilities (including: integer overflow, reentrancy, and block dependency vulnerabilities), and the experimental results were evaluated based on accuracy, precision, recall, and F1 score metrics. The method of this embodiment was compared with three classic non-deep learning methods, namely Smartcheck, Oyente, and Mythril. Secondly, four commonly used deep learning models, LSTM, Bi-LSTM, GRU, and Vanilla-RNN, were selected and each of them was compared with the method of this embodiment. Finally, according to the experimental results, the effectiveness of the method of this embodiment in smart contract vulnerability detection was analyzed to answer RQ1. The experimental results are shown in Table 5 and Figure 4 。

[0053] Table 5 Comparison of various detection methods in terms of accuracy (Acc), precision (Pre), recall (Rec), and F1 score (F1) metrics for integer overflow vulnerability (Overflow), reentrancy vulnerability, and block dependency vulnerability (Block Dependency) detection 。

[0054] In the experiment, the method of this embodiment was compared with advanced non-deep learning methods Smartcheck, Oyente, and Mythril, and the performance is shown in the upper half of Table 5. In terms of accuracy, it is worth noting that the accuracy of the method of this embodiment reached 95.08%, which is 18.00% higher than that of Mythril with the highest accuracy. In addition, for reentry vulnerabilities and block dependency vulnerabilities, the detection accuracies of the method of this embodiment are as high as 95.62% and 94.74% respectively, both significantly superior to traditional non-deep learning vulnerability detection methods. In terms of precision, first of all, compared with the method of this embodiment, traditional non-deep learning methods performed mediocrely in the detection of three types of vulnerabilities, with the highest precision only being 58.06%, while the highest precision of the method of this embodiment is as high as 97.37%, which is 39.31% higher compared. Secondly, the detection precisions of traditional non-deep learning methods vary greatly for these three types of vulnerabilities, with the lowest precision being only 23.80%. Finally, on average, the detection precision of the method of this embodiment for these three types of vulnerabilities exceeds 95%, while the detection precisions of traditional non-deep learning methods do not exceed 60%. In addition, in terms of recall rate and F1 score, the comparison between the method of this embodiment and the three non-deep learning methods is similar to the comparison of accuracy and precision. To more intuitively compare the differences between the method of this embodiment and the three non-deep learning methods, the data was visualized in this article, as Figure 4 shown, Figure 4 in which (a), (b), and (c) in

[0055] are the detection effects of integer overflow vulnerability, reentry vulnerability, and block dependency vulnerability in sequence. The visualization results further verify the advantages of the method of this embodiment in terms of vulnerability detection accuracy, precision, recall rate, and F1 score. Figure 4 shown, Figure 4The x-axis represents the detection methods, where 1, 2, 3, 4, 5, 6, 7, 8 respectively represent the method of this embodiment, Vanilla-RNN, GRU, Bi-LSTM, LSTM, Mythril, Oyente, Smartcheck. The y-axis represents the metrics, including accuracy, precision, recall, and F1-score. The z-axis represents the values. The visualization result graph is as Figure 4 shown. The precision of the deep learning methods is better than that of the non-deep learning methods, but still lower than that of the method of this embodiment. When detecting three types of vulnerabilities, the method of this embodiment always performs the best.

[0056] Generally speaking, compared with the non-deep learning methods, the deep learning methods have improved in terms of accuracy, precision, recall, and F1-score, but are still lower than the method of this embodiment. This further proves the effectiveness of the method of this embodiment in detecting smart contract vulnerabilities. The method of this embodiment can significantly improve the accuracy, precision, recall, and F1-score of the prior art in detecting integer overflow, reentrancy, and block dependency vulnerabilities.

[0057] Answer results regarding the construction of CTSG and the advantages of feature dimensionality reduction (for RQ2). Ablation experiments were conducted in the experiment to analyze and verify the contributions of CTSG construction and feature dimensionality reduction in vulnerability detection. Specifically, taking the complete method of this embodiment as the benchmark, three control experiments were designed, and taking the detection of integer overflow vulnerabilities as an example, their overall and individual contributions were studied respectively. The components of each experiment are shown in Table 6.

[0058] Table 6 Components of the method of this embodiment and its variants .

[0059] To evaluate the overall impact of CTSG and feature dimensionality reduction methods on the performance of the method of this embodiment, CFG was used to replace CTSG in the experiment, and the feature extraction method without dimensionality reduction was adopted. This variant is denoted as WGR, where WGR is the abbreviation of without CTSG and feature dimensionality reduction. The experimental results are shown in Table 7. Compared with the method of this embodiment, the performance of WGR has decreased significantly, and the accuracy, precision, recall, and F1-score have decreased by 25.99%, 27.15%, 25.21%, and 27.34% respectively. This shows that the combined effect of CTSG and feature dimensionality reduction methods can significantly improve the performance of the method of this embodiment.

[0060] Table 7 Comparison of accuracy (Acc), precision (Pre), recall (Rec), and F1 score (F1) metrics between the method of this embodiment and its variants 。

[0061] To evaluate the role of CTSG in the method of this embodiment, CFG is used to replace CTSG while keeping the feature dimensionality reduction method unchanged. This variant is denoted as WSG, where WSG is the abbreviation of without CTSG. The experimental results are shown in Table 4. The accuracy, precision, recall, and F1 score of WSG are improved compared with those of WGR, but the four metrics are still on average 17.47% lower than those of the method of this embodiment, which indicates that compared with CFG, CTSG can significantly improve the vulnerability detection ability of the method of this embodiment.

[0062] To evaluate the impact of feature dimensionality reduction on the effect of detecting vulnerabilities in the method of this embodiment, CTSG is kept unchanged and an unreduced feature extraction method is adopted. This variant is denoted as WDR, where WDR is the abbreviation of without feature dimensionality reduction. The experimental results are shown in Table 4, and the accuracy, precision, recall, and F1 score of the method of this embodiment are improved compared with those of WDR. Therefore, feature dimensionality reduction has a significant impact on the performance improvement of the method of this embodiment.

[0063] Reply results regarding the localization effect (for RQ3). To further illustrate the localization ability of the method of this embodiment, a vulnerability detection case of an on-chain smart contract is provided in the experiment. There is an integer overflow vulnerability in smart contract case 1, but it only appears in specific execution scenarios, such as Figure 5 as shown in (a). Through the constructed CTSG, it contains six paths (scenarios) S1 - S6, where each number represents the starting PC value of a basic block, and a node with multiple numbers represents an aggregated node. After being detected by the method of this embodiment, the vulnerability prediction labels corresponding to each scenario are obtained: [(S1, 0), (S2, 0), (S3, 0), (S4, 0), (S5, 0), (S6, 1)], as Figure 5 shown in (b). Among them, the scenario label without vulnerability is 0, and the scenario label with vulnerability is 1. The results show that the method of this embodiment accurately locates the vulnerability to scenario S6, while other scenarios are correctly marked as safe. Further, through the obtained vulnerable scenarios, the specific executed code block can be located according to the PC value of the basic block. This case intuitively demonstrates the localization ability of the method of this embodiment at the scenario level in smart contract vulnerability detection, improving the fine-grainedness of vulnerability detection.

[0064] This embodiment also provides an intelligent contract vulnerability detection system based on a timing scenario, which is used to implement the above-mentioned intelligent contract vulnerability detection method based on a timing scenario, and includes the following operations: A timing scenario graph generation module, which is used to disassemble the bytecode of the intelligent contract to be detected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and regard the path with a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph; A dimensionality-reduced timing scenario graph generation module, which is used to update the opcode of each node in the timing scenario graph according to the opcode format and type to obtain an updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain a dimensionality-reduced timing scenario graph; An intelligent contract vulnerability detection result generation module, which is used to perform feature mapping processing on each node in the dimensionality-reduced timing scenario graph to obtain a node feature vector; splice all node feature vectors belonging to the same path in the dimensionality-reduced timing scenario graph to obtain a path feature vector for each path; based on the node connection relationship on the same path in the dimensionality-reduced timing scenario graph, obtain the adjacency matrix of each path; the adjacency matrix and path feature vector of each path are processed by graph convolution to obtain a path vulnerability detection result; based on the path vulnerability detection result, obtain an intelligent contract vulnerability detection result.

[0065] This embodiment also provides an intelligent contract vulnerability detection device based on a timing scenario, which includes a processor and a memory. Among them, when the processor executes the computer program stored in the memory, it implements the above-mentioned intelligent contract vulnerability detection method based on a timing scenario.

[0066] This embodiment also provides a computer-readable storage medium for storing a computer program. Among them, when the computer program is executed by a processor, it implements the above-mentioned intelligent contract vulnerability detection method based on a timing scenario.

[0067] An intelligent contract vulnerability detection method based on a timing scenario provided in this embodiment first constructs a control flow graph at the opcode level, extracts execution scenarios containing timing information by traversing the paths of the control flow graph, and further aggregates nodes with common partial segments to obtain a timing scenario graph. Then, an innovative opcode update method and a feature dimension reduction method are designed. While reducing the dimension, semantic information and the timing features inside the nodes are retained to obtain a dimension-reduced timing scenario graph. Finally, each node in the dimension-reduced timing scenario graph is subjected to feature mapping processing to obtain a node feature vector, which is combined with the adjacency matrix of each path obtained based on the connection relationship of the nodes on the same path in the dimension-reduced timing scenario graph. After graph convolution processing, the path vulnerability detection results are integrated to obtain the intelligent contract vulnerability detection result. This method is applied to the detection of intelligent contract vulnerabilities, especially to the detection of integer overflow vulnerabilities, reentry vulnerabilities, and block dependency vulnerabilities in intelligent contracts, and can significantly improve the accuracy, precision, recall rate, and F1 score.

Claims

1. A smart contract vulnerability detection method based on time sequence scenario, characterized in that: The following operations are included: S1. Decompile the bytecode of the smart contract to be inspected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of the jump instruction, and obtain a control flow graph; Obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and take the paths that have common segments with other paths as paths to be abstracted; Aggregate the common segments in the path to be abstracted into a single node to obtain a temporal scene graph; S2. According to the format and type of the operation code, the operation code of each node in the time sequence scene graph is updated to obtain an updated time sequence scene graph; and feature dimensionality reduction processing is performed on each node in the updated time sequence scene graph to obtain a reduced dimensionality time sequence scene graph; S3, performing feature mapping processing on each node in the dimension-reduced time-series scene graph to obtain a node feature vector; In the dimension-reduced time-series scene graph, all node feature vectors belonging to the same path are concatenated to obtain the path feature vector of each path; Based on the node connection relationship on the same path in the dimensionality-reduced time-series scene graph, the adjacency matrix of each path is obtained; The adjacency matrix and path feature vector of each path are processed by graph convolution to obtain the path vulnerability detection result; Based on the path vulnerability detection results, the smart contract vulnerability detection results are obtained.

2. The method for detecting smart contract vulnerabilities based on time series scenarios according to claim 1 is characterized in that: During the aggregation process in S1, the common part fragments in the corresponding to-be-abstracted paths are aggregated into a single node in order of the length of the common part fragments from small to large.

3. The smart contract vulnerability detection method based on time sequence scenario according to claim 1 is characterized in that: The operation of updating the opcode of each basic block in the timing scenario graph in S2 includes: deleting the numerical suffix of consecutive opcodes with the same mnemonic prefix, or / and mapping multiple opcodes associated with the same vulnerability to the same corresponding opcode according to the corresponding function.

4. According to claim 1, the smart contract vulnerability detection method based on time sequence scenario is characterized in that: The specific operation of feature dimensionality reduction processing in S2 is: combining adjacent operation codes in each node of the update time series scene graph to obtain several operation code combinations for each node, deleting all common operation codes, and / or deleting operation code combinations starting with a termination operation code to obtain a reduced dimensionality time series scene graph.

5. According to claim 1, the smart contract vulnerability detection method based on time sequence scenario is characterized in that: The operations of feature mapping processing in S3 are as follows: assign corresponding values ​​according to the number of occurrences of the operation code combination in the node of the reduced-dimensional time series scene graph to obtain the operation code combination vector; according to the order of the operation code combination in the node, all the operation code combination vectors are spliced ​​to obtain the node feature vector.

6. The method for detecting smart contract vulnerabilities based on time sequence scenarios according to claim 1 is characterized in that: During the S3 graph convolution process, the adjacency matrix corresponding to the output of the previous layer is added to the initial adjacency matrix to obtain the updated adjacency matrix, which is used as the adjacency matrix of the current layer input.

7. The method for detecting smart contract vulnerabilities based on time series scenarios according to claim 1 is characterized in that: In S3, if the current vulnerability exists in the path vulnerability detection result, then the current vulnerability exists in the smart contract vulnerability detection result; if the current vulnerability does not exist in all path vulnerability detection results, then the current vulnerability does not exist in the smart contract vulnerability detection result.

8. A smart contract vulnerability detection system based on a time sequence scenario, used to implement the smart contract vulnerability detection method based on a time sequence scenario according to claim 1, characterized in that: The following operations are included: The timing scene graph generation module is used to disassemble the bytecode of the smart contract to be inspected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between the basic blocks according to the address parameters of the jump instruction, and obtain the control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and take the path that has a common part fragment with other paths as the path to be abstracted; Aggregate the common segments in the path to be abstracted into a single node to obtain a temporal scene graph; A dimension reduction time sequence scene graph generation module is used to update the operation code of each node in the time sequence scene graph according to the operation code format and type to obtain an updated time sequence scene graph; perform feature dimension reduction processing on each node in the updated time sequence scene graph to obtain a dimension reduction time sequence scene graph; The smart contract vulnerability detection result generation module is used to perform feature mapping processing on each node in the reduced-dimensional time-series scene graph to obtain a node feature vector; In the dimension-reduced time-series scene graph, all node feature vectors belonging to the same path are concatenated to obtain the path feature vector of each path; Based on the node connection relationship on the same path in the dimensionality reduction time series scene graph, the adjacency matrix of each path is obtained; the adjacency matrix and path feature vector of each path are processed by graph convolution to obtain the path vulnerability detection result; based on the path vulnerability detection result, the smart contract vulnerability detection result is obtained.

9. A smart contract vulnerability detection device based on a time sequence scenario, characterized in that: It includes a processor and a memory, wherein when the processor executes the computer program stored in the memory, it implements the smart contract vulnerability detection method based on the timing scenario as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: Used to store a computer program, wherein when the computer program is executed by a processor, the method for detecting smart contract vulnerabilities based on a timing scenario as described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Intelligent contract vulnerability detection method based on neural network

    CN116702157A

  • Intelligent contract vulnerability detection method, system and equipment based on vulnerability subgraph

    CN117201138A

  • Vulnerability detection method and device for smart contract, and storage medium

    US12093399B1

  • Smart contract vulnerability detection method and system, and electronic device

    WO2024131508A1