Intelligent contract vulnerability detection method, system and device based on timing scenarios

By constructing a control flow diagram and performing feature dimensionality reduction and graph convolution processing, the problems of path explosion and information loss in existing smart contract vulnerability detection are solved, and efficient vulnerability detection effect is achieved.

CN120124076BActive Publication Date: 2025-07-08YANTAI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510621721.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-07-08
Estimated Expiration
2045-05-15

AI Technical Summary

Technical Problem

Among the existing smart contract vulnerability detection methods, symbol execution tools are prone to path explosion problems, resulting in execution timeout and insufficient path coverage, while intermediate representation methods may lose context information and semantic details, resulting in low vulnerability detection accuracy.

Method used

A smart contract vulnerability detection method based on timing scenarios is used to construct a control flow diagram, extract the path set and aggregate the common part of the fragments, generate the timing scenario diagram, perform feature dimension reduction and mapping processing, and vulnerability detection is performed in combination with graph convolution.

Benefits of technology

Significantly improves the accuracy, accuracy, recall and F1 score of smart contract vulnerability detection, especially in integer overflow, reentry and block-dependent vulnerability detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124076B_ABST
    Figure CN120124076B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of intelligent contract vulnerability detection in digital signal processing, specifically to an intelligent contract vulnerability detection method, system and device based on timing scenarios; in order to solve the problem of low accuracy of intelligent contract vulnerability detection in the prior art, the present invention first constructs a control flow graph at the opcode level, and extracts execution scenarios containing timing information by traversing the paths of the control flow graph, and further aggregates nodes with common partial segments to obtain a timing scenario graph; then, an innovative opcode update method and a feature dimensionality reduction method are designed to obtain a dimensionality-reduced timing scenario graph; finally, the node feature vectors are combined with the adjacency matrix of the corresponding paths, and after graph convolution processing, the path vulnerability detection results are integrated to obtain the intelligent contract vulnerability detection results; this method is applied to the detection of integer overflow vulnerabilities, re-entrancy vulnerabilities and block dependency vulnerabilities in intelligent contracts, and can significantly improve the accuracy, precision, recall rate and F1 score.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent contract vulnerability detection in digital signal processing, and specifically to an intelligent contract vulnerability detection method, system and device based on a timing scenario. Background Art

[0002] The prior art often uses static analysis methods for intelligent contract vulnerability detection. Static analysis methods mainly include symbolic execution and intermediate representation. The symbolic execution method symbolizes program variables and systematically explores all possible execution paths to analyze the abnormal behavior of the program. Although symbolic execution tools such as Oyente and Mythril have a high vulnerability detection accuracy rate, for complex intelligent contracts, the "path explosion" problem is very likely to occur. Therefore, symbolic execution tools face a series of problems such as timeout during the execution process, insufficient actual path coverage, and false negatives in the detection results. The intermediate representation method converts the source code or bytecode of an intelligent contract into a more suitable abstract form for analysis, and then performs rule analysis on this intermediate form to discover security issues in the contract. Although intermediate representation tools such as the Smartcheck method convert intelligent contracts into an intermediate form that is more conducive to vulnerability detection, during the process of intermediate representation, context information and semantic details may be lost, resulting in false positives in vulnerability detection and low accuracy of vulnerability detection. Summary of the Invention

[0003] The purpose of the present invention is to provide an intelligent contract vulnerability detection method, system and device based on a timing scenario.

[0004] The technical solution of the present invention is as follows:

[0005] An intelligent contract vulnerability detection method based on a timing scenario includes the following operations:

[0006] S1. Disassemble the bytecode of the intelligent contract to be detected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of the jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and use the path that has a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph;

[0007] S2. Update the opcode of each node in the timing scenario graph according to the opcode format and type to obtain an updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain a dimensionality-reduced timing scenario graph;

[0008] S3. Perform feature mapping processing on each node in the dimensionality-reduced time-series scenario graph to obtain node feature vectors; concatenate all the node feature vectors belonging to the same path in the dimensionality-reduced time-series scenario graph to obtain the path feature vector for each path; based on the node connection relationships on the same path in the dimensionality-reduced time-series scenario graph, obtain the adjacency matrix for each path; the adjacency matrix and path feature vector for each path are processed by graph convolution to obtain the path vulnerability detection result; based on the path vulnerability detection result, obtain the smart contract vulnerability detection result.

[0009] During the aggregation process in S1, in the order of the lengths of the common part segments from small to large, the common part segments in the corresponding paths to be abstracted are aggregated into a single node in sequence.

[0010] The operations for updating the operation codes of each basic block in the time-series scenario graph in S2 include: deleting the numerical suffixes of consecutive operation codes with the same mnemonic prefix, and / or mapping multiple operation codes associated with the same vulnerability to the same corresponding operation code according to the corresponding functions.

[0011] The specific operation of feature dimensionality reduction processing in S2 is: combine adjacent operation codes in each node of the updated time-series scenario graph to obtain several operation code combinations for each node, delete the operation code combinations that are all ordinary operation codes, and / or delete the operation code combinations starting with the termination operation code to obtain the dimensionality-reduced time-series scenario graph.

[0012] The specific operation of feature mapping processing in S3 is: assign corresponding values according to the occurrence times of the operation code combinations in the nodes of the dimensionality-reduced time-series scenario graph to obtain the operation code combination vectors; concatenate all the operation code combination vectors according to the order of the operation code combinations in the nodes to obtain the node feature vectors.

[0013] During the process of graph convolution processing in S3, the adjacency matrix corresponding to the output of the previous layer is added to the initial adjacency matrix to obtain the updated adjacency matrix, which is used as the adjacency matrix for the input of the current layer.

[0014] In S3, if the current vulnerability exists in the path vulnerability detection result, then the current vulnerability exists in the smart contract vulnerability detection result; if the current vulnerability does not exist in all the path vulnerability detection results, then the current vulnerability does not exist in the smart contract vulnerability detection result.

[0015] A smart contract vulnerability detection system based on a time-series scenario, used to implement the above-mentioned smart contract vulnerability detection method based on a time-series scenario, includes the following operations:

[0016] The timing scenario graph generation module is used to disassemble the bytecode of the smart contract to be inspected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and regard the path that has a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph;

[0017] The dimensionality reduction timing scenario graph generation module is used to update the opcode of each node in the timing scenario graph according to the opcode format and type to obtain an updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain a dimensionality reduction timing scenario graph;

[0018] The smart contract vulnerability detection result generation module is used to perform feature mapping processing on each node in the dimensionality reduction timing scenario graph to obtain a node feature vector; splice all the node feature vectors belonging to the same path in the dimensionality reduction timing scenario graph to obtain a path feature vector for each path; based on the node connection relationship on the same path in the dimensionality reduction timing scenario graph, obtain the adjacency matrix of each path; the adjacency matrix and path feature vector of each path are processed by graph convolution to obtain a path vulnerability detection result; based on the path vulnerability detection result, obtain the smart contract vulnerability detection result.

[0019] An intelligent contract vulnerability detection device based on a timing scenario includes a processor and a memory. Among them, when the processor executes the computer program stored in the memory, the above-mentioned intelligent contract vulnerability detection method based on a timing scenario is implemented.

[0020] A computer-readable storage medium is used to store a computer program. Among them, when the computer program is executed by a processor, the above-mentioned intelligent contract vulnerability detection method based on a timing scenario is implemented.

[0021] The beneficial effects of the present invention are as follows:

[0022] An intelligent contract vulnerability detection method based on a timing scenario provided by the present invention first constructs a control flow graph at the opcode level, extracts execution scenarios containing timing information by traversing the paths of the control flow graph, and further aggregates nodes with common partial fragments to obtain a timing scenario graph. Then, an innovative opcode update method and a feature dimensionality reduction method are designed to retain semantic information and internal timing features of nodes while reducing dimensions, resulting in a dimensionality-reduced timing scenario graph. Finally, each node in the dimensionality-reduced timing scenario graph is subjected to feature mapping processing to obtain a node feature vector, which is combined with an adjacency matrix of each path obtained based on the connection relationship of nodes on the same path in the dimensionality-reduced timing scenario graph. After graph convolution processing, the path vulnerability detection results are integrated to obtain the intelligent contract vulnerability detection result. This method is applied to intelligent contract vulnerability detection, especially to the detection of integer overflow vulnerabilities, reentrancy vulnerabilities, and block dependency vulnerabilities in intelligent contracts, and can significantly improve accuracy, precision, recall, and F1 score. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] By reading the detailed description of the preferred embodiments below, the solutions and advantages of the present application will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention.

[0024] In the drawings:

[0025] Figure 1 is a schematic diagram of the detection method process in this embodiment;

[0026] Figure 2 is a process diagram of node opcode feature dimensionality reduction processing in this embodiment;

[0027] Figure 3 is a process diagram of generating intelligent contract vulnerability detection results in this embodiment;

[0028] Figure 4 is a summary diagram of accuracy, precision, recall, and F1 score for multiple detection methods in the detection of integer overflow vulnerabilities, reentrancy vulnerabilities, and block dependency vulnerabilities in this embodiment; in Figure 4 ,(a) is a summary diagram of accuracy, precision, recall, and F1 score for multiple detection methods in integer overflow vulnerabilities, (b) is a summary diagram of accuracy, precision, recall, and F1 score for multiple detection methods in reentrancy vulnerabilities, and (c) is a summary diagram of accuracy, precision, recall, and F1 score for multiple detection methods in block dependency vulnerabilities;

[0029] Figure 5 is a diagram of an intelligent contract vulnerability detection case in this embodiment; in Figure 5Among them, (a) is a schematic diagram of all paths in the timing scenario diagram, and (b) is the detection result of all path vulnerabilities in the timing scenario diagram. Specific implementation mode

[0030] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings.

[0031] This embodiment provides an intelligent contract vulnerability detection method based on a timing scenario. See Figure 1 , including the following operations:

[0032] S1. Disassemble the bytecode of the smart contract to be inspected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of the jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and regard the path with a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph;

[0033] S2. Update the opcode of each node in the timing scenario graph according to the opcode format and type to obtain an updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain a dimensionality-reduced timing scenario graph;

[0034] S3. Perform feature mapping processing on each node in the dimensionality-reduced timing scenario graph to obtain a node feature vector; splice all node feature vectors belonging to the same path in the dimensionality-reduced timing scenario graph to obtain a path feature vector for each path; based on the node connection relationship on the same path in the dimensionality-reduced timing scenario graph, obtain the adjacency matrix of each path; the adjacency matrix and path feature vector of each path are processed by graph convolution to obtain a path vulnerability detection result; based on the path vulnerability detection result, obtain an intelligent contract vulnerability detection result, and the specific steps are as follows.

[0035] S1. Disassemble the bytecode of the smart contract to be inspected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of the jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and regard the path with a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph.

[0036] Construct a control flow graph based on the bytecode of the smart contract to be inspected, and obtain all the paths (execution scenarios) existing in the control flow graph to form a path set; aggregate the common partial fragments existing between each path in the path set and other paths, that is, abstract the repeatedly occurring consecutive code fragments as common partial fragments, and aggregate them into a single node to obtain a timing scenario graph, thereby reducing the scenario complexity.

[0037] First, since the version span of the current Solidity smart contract covers multiple iterative versions such as 0.4.+ to 0.8.+, there are differences in the syntax specifications between different versions. To effectively address the possible source code adjustment issues during the contract version iteration process and avoid the interference of syntax differences at the source code level, this embodiment constructs a control flow graph of the smart contract at the opcode level. Specifically, disassemble the bytecode of the smart contract to be inspected into an opcode sequence, divide the opcode sequence into basic blocks according to instruction contents such as jump instructions and termination instructions, and establish the jump relationship between basic blocks according to the address parameters of the jump instructions to obtain the control flow graph, which is convenient for directly analyzing the original bytecode on the blockchain, effectively breaking through the syntax limitations brought by Solidity version differences, and improving the version universality of the detection method. Given a smart contract c, the control flow graph generated by it at the opcode level , where and respectively represent the node set and edge set of the CFG. The nodes of the CFG are basic blocks, and the edges are the jump relationships between basic blocks.

[0038] Then, to obtain all the execution scenarios of the smart contract, this embodiment obtains all the paths from the root node to all the tail nodes in the control flow graph to form a path set. The detailed acquisition process can be seen in the execution logic code in Table 1. The input of the execution logic code in Table 1 is the control flow graph CFG of the smart contract, and the output is all the execution scenarios of the CFG. Among them, in the first line, obtain the node with a unique in-degree of 0 in the CFG and define it as the root node; in the second line, initialize the set of visited nodes, the current execution scenario, and the set of all execution scenarios; in the third line, call the recursive function GetScenarios for obtaining execution scenarios, starting from the root node to obtain the paths (execution scenarios) of the smart contract; in the fourth line, return all the paths of the smart contract. Next, the operation process of the recursive function GetScenarios for obtaining execution scenarios will be introduced in detail. The input of the function is the CFG of the smart contract, and the root node is n root , the set of visited nodes V, the current execution scenario set S, and the set of all execution scenarios S all, at lines 6 and 7, add the root node to the current execution scenario and the visited nodes; then use the function isTargetExist to determine whether there is a subsequent jump target for the root node, that is, whether it is a leaf node (line 8); if it is a leaf node, it means that a scenario has been fully obtained, then add this scenario to the set of all scenarios (line 9); if it is not a leaf node, then loop to judge its jump target node (line 11); at lines 11 and 12, use the function IsInLoop to determine whether the jump target node is in a loop structure. If it is in a loop structure, keep the loop structure and use the function GetExitNode to obtain the exit node of the loop structure as the entry node for the next recursion (line 13); at line 15, find unvisited nodes through the set of visited nodes; at line 16, call the recursive function GetScenarios to continue obtaining the execution scenarios of unvisited target nodes. For each fully obtained scenario, perform a backtracking operation to remove the visited branches from the current execution scenario set (line 17) for traversing the next path. When all paths have been visited, the recursion ends.

[0039] Table 1 Logic code for obtaining all paths to form a path set

[0040] 。

[0041] Finally, reduce the scenario complexity. Traverse each path in the path set, and regard the path that has a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain the timing scenario graph. The above common partial segments do not include the root node to streamline the scenario path; and in the above aggregation process, the common partial segments in the corresponding path to be abstracted are aggregated into a single node in the order of the length of the common partial segments from small to large. For specific operation details, refer to the logic code in Table 2. The input of the logic code in Table 2 is all execution scenarios (path set) of a smart contract , and the output is the aggregated execution scenario (timing scenario graph).

[0042] Table 2 Node aggregation logic code for obtaining the timing scenario graph

[0043] 。

[0044] In the logic code of Table 2, the first line initializes four core data structures for storing the filtered scenario list 、 list of consecutive common subsequences 、 list of deduplicated common subsequences and the final aggregated scenario list ; Since all scenarios of the smart contract start from the program start node, and this node cannot distinguish semantics, the scenario list without the start node is obtained through lines 2-4. ; Specifically, line 2 traverses all scenarios in the smart contract, and line 3 calls the function RemoveRoot to remove the start node and assign it to , to eliminate the interference of the root node on the common subsequence analysis; in practical applications, there is an inclusion relationship between consecutive common subsequences. To avoid long paths covering the common subsequences in short paths, it is necessary to ensure that shorter scenarios are processed first; therefore, in line 5; the function SortByLength is called to sort the original scenarios (all paths in the path set) in ascending order of path length; then, in line 6, the function GetLongestSeqs is called to obtain all consecutive common subsequences with a length greater than 1 (the common partial segments in the paths that have common partial segments with other paths) from the sorted scenarios; in the execution scenario graph, different scenarios may contain duplicate consecutive code segments, and these duplicate segments will generate the same common subsequences; by eliminating these redundant sequences, the list can be effectively streamlined; therefore, in line 7, the function DedupSeqs is called to deduplicate the list of common subsequences to obtain ; Lines 8-13 aggregate all scenarios of the smart contract according to the deduplicated consecutive common subsequences; first, traverse all scenarios of the smart contract (line 8), that is, traverse all paths in the path set and check whether it contains any subsequence in (lines 9 and 10). If it exists (if the path to be abstracted is found), then in line 11, the function AggregateSeq is called to aggregate the subsequence (the common partial segment without the root node) into a single node and return the aggregated scenario s; after the aggregation is completed, in line 14, the aggregated scenario s is stored in the sequence ; Finally, all aggregated scenarios are returned (line 16).

[0045] The temporal scenario graph has the following characteristics: Generalization - The temporal scenario graph (CTSG) is constructed at the opcode level, breaking through the dependence on source code and supporting dual parsing of smart contract source code and opcode; Integrity - CTSG is constructed from the CFG of the smart contract, completely containing all potential paths of program execution, ensuring that all scenarios of program execution are covered; Temporality - The execution scenario is constructed by sorting the internal opcode addresses of nodes in ascending order and the order of control flow edges between nodes, so that the logical time sequence of the original program is retained in CTSG; Efficiency - Aggregate common execution subsequences (common partial segments), optimizing the spatial complexity of the graph structure while maintaining information integrity and improving the message propagation efficiency.

[0046] S2. Update the operation codes of each node in the timing scenario graph according to the operation code format and type to obtain an updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain a dimensionality-reduced timing scenario graph.

[0047] Update the operation codes of each node in the timing scenario graph according to the operation code format and type, streamline the number of operation codes to obtain an updated timing scenario graph; and perform feature dimensionality reduction processing on each node in the updated timing scenario graph to remove the operation code combinations that are ineffective for vulnerability detection, further reducing the feature dimension to obtain a dimensionality-reduced timing scenario graph.

[0048] First, in order to further reduce the subsequent feature dimension and improve the training efficiency and generalization ability of the subsequent graph convolutional network, in this embodiment, the operation codes of each node in the timing scenario graph are updated according to the operation code format and type to obtain an updated timing scenario graph.

[0049] During the process of updating the operation codes of each node in the updated timing scenario graph, for consecutive operation codes with the same mnemonic prefix, such as the PUSH0 - PUSH32 series, and CREATE and CREATE2, remove their numerical suffixes, thus uniformly mapping them to basic operators such as "PUSH" and "CREATE", reducing feature redundancy; or / and map multiple operation codes associated with the same vulnerability to the same operation code according to the corresponding functions. Specifically, for the instruction set with a strong correlation with potential vulnerabilities, classify them according to functions and use a simplified operation code expression; for example, multiple operation codes related to block state dependence are uniformly abstracted as "CONSTANT", and operation codes related to storage read and write are merged into "STORAGE" to extract key features related to vulnerabilities; or / and modify the old version format operation codes to new version operation codes. This is because the iteration of EVM historical versions has caused changes in the naming of some operation codes. Update the old version operation code names to the latest operation code names. For example, map the old version instructions such as "SUICIDE" and "SHA3" to the standard names such as "SELFDESTRUCT" and "KECCAK256" respectively to ensure the consistency of the operation code expressions of different version smart contracts. By updating the operation codes of each node in the timing scenario graph, the total amount of operation codes in the timing scenario graph is streamlined. See Table 3 to obtain a dimensionality-reduced timing scenario graph, which helps to reduce the dimension during the subsequent construction of feature vectors.

[0050] Table 3 Update rules in the operation codes of each node in the updated timing scenario graph

[0051] 。

[0052] Next, perform feature dimensionality reduction on each node in the updated timing scenario graph to obtain a reduced-dimensional timing scenario graph. The specific operation of feature dimensionality reduction is as follows: According to the execution order of the operation codes in the nodes of the updated timing scenario graph, combine adjacent operation codes to obtain several operation code combinations, delete those that are all ordinary operation codes (neither belonging to the operation codes related to vulnerabilities nor to termination operation codes), or / and delete the operation code combinations starting with termination operation codes, so as to implement the feature dimensionality reduction of the nodes (basic blocks) in the timing scenario graph, thereby filtering out irrelevant operation code pairs. In this way, without losing important features and reducing feature sparsity, the dimension of the feature space is reduced to obtain a reduced-dimensional timing scenario graph. Figure 2 shows an example of the process of reducing the feature of node operation codes. Figure 2 In it, the red operation codes are operation codes related to vulnerabilities (such as PUSH in Table 4), the blue operation codes are ordinary operation codes (operation codes that are neither related to vulnerabilities nor termination operation codes, such as LOG), and the gray operation codes are termination operation codes (termination operation codes include STOP, RETURN, REVERT, INVALID, SELFDESTRUCT).

[0053] Table 4 Examples of operation codes related to smart contract vulnerabilities

[0054] .

[0055] Finally, the dimension of the operation codes in the reduced-dimensional timing scenario graph can be obtained by the following formula: Dimension = 2 * OP all * OP vul - OP vul * OP vul - OP termin * OP vul , where the total number of all operation codes in the node is OP all , the number of operation codes related to vulnerabilities is OP vul , the number of termination operation codes is OP termin , the dimension space of all features is OP all * OP all , the number of pairs of operation codes where both operation codes are not related to vulnerabilities is (OP all - OP vul ) * (OP all - OP vul ), and the number of invalid operation code pairs where the first one is a termination operation code is OP termin * OP vul .

[0056] S3. Perform feature mapping processing on each node in the dimensionality-reduced time-series scenario graph to obtain node feature vectors; splice all the node feature vectors belonging to the same path in the dimensionality-reduced time-series scenario graph to obtain the path feature vector of each path; based on the node connection relationship on the same path in the dimensionality-reduced time-series scenario graph, obtain the adjacency matrix of each path; the adjacency matrix and path feature vector of each path are processed by graph convolution to obtain the path vulnerability detection result; based on the path vulnerability detection result, obtain the intelligent contract vulnerability detection result.

[0057] Perform feature mapping processing on each node in the dimensionality-reduced time-series scenario graph to obtain node feature vectors, and combine them with the adjacency matrix of each path obtained based on the node connection relationship on the same path in the dimensionality-reduced time-series scenario graph. After graph convolution processing, this method can reduce the feature dimension while increasing the information density and improving the feature extraction accuracy. Integrate the path vulnerability detection results to obtain the intelligent contract vulnerability detection result.

[0058] First, perform feature mapping processing on each node in the dimensionality-reduced time-series scenario graph to obtain node feature vectors. The specific operation of the feature mapping processing is as follows: assign corresponding values according to the occurrence times of the opcode combinations in the nodes of the dimensionality-reduced time-series scenario graph to obtain the opcode combination vectors; splice all the opcode combination vectors according to the order of the opcode combinations in the nodes to obtain the node feature vectors.

[0059] Then, splice all the node feature vectors belonging to the same path in the dimensionality-reduced time-series scenario graph in the path execution order to obtain the path feature vector of each path.

[0060] At the same time, based on the node connection relationship on the same path in the dimensionality-reduced time-series scenario graph, obtain the adjacency matrix of each path and extract the edge features in the path.

[0061] Finally, the adjacency matrix and path feature vector of each path are processed by graph convolution to obtain the path vulnerability detection result. The above graph convolution processing can be realized by training a GCN network. During the dataset labeling process, for each path of the intelligent contract, set labels according to different vulnerability types (such as integer overflow, re-entrancy attack, block dependency). During the labeling process, first analyze each path independently and generate vulnerability labels. If there is a vulnerability, mark it as 1, and if there is no vulnerability, mark it as 0, and obtain the labeling result of the intelligent contract according to the summary of the labels of each path.

[0062] The above graph convolution process includes two key stages. First is the feature propagation stage. Through the normalized adjacency matrix, node features spread along the graph structure. Second is the information aggregation stage. In each convolution, the features of neighboring nodes are fused with its own features to update the node representation. After multiple layers are stacked, node features will gradually fuse the information of more distant neighbors. To improve the effect of graph convolution processing, during the graph convolution process, the adjacency matrix corresponding to the output of the previous layer is added to the initial adjacency matrix to obtain an updated adjacency matrix, which is used as the adjacency matrix input for the current layer.

[0063] The graph convolution is calculated through the following formula:

[0064] ,

[0065] represents the feature vector of the l+ first layer, represents the feature vector matrix of the l layer, represents the initial path feature vector of the path, is the updated adjacency matrix, which is the sum of the adjacency matrix of the l+ first layer and the initial adjacency matrix, used to retain the features of the node itself; represents the degree matrix of, realizes the standardization of the adjacency matrix to balance the influence of nodes with different degrees on the result; represents the learnable weight matrix of the l layer, realizing the linear transformation of the feature space, represents the activation function, enhancing the non-linear expression ability of the model.

[0066] Finally, based on the path vulnerability detection results, the smart contract vulnerability detection results are obtained. If the current vulnerability exists in the path vulnerability detection results, then the current vulnerability exists in the smart contract vulnerability detection results, and the existence result of the current vulnerability is marked as 1; if the current vulnerability does not exist in all path vulnerability detection results, then the current vulnerability does not exist in the smart contract vulnerability detection results, and the existence result of the current vulnerability is marked as 0.

[0067] Figure 3 is a process of obtaining the smart contract vulnerability detection results based on the path vulnerability detection results. Among them, Figure 3 the dimensionality reduction time series scenario of contains four paths: S1, S2, S3, and S4, Figure 3 the marking results of the path vulnerability detection results of show that S1 does not have three types of vulnerabilities: integer overflow, reentrancy, and block dependency, S2 only has integer overflow vulnerability, S3 has both integer overflow and reentrancy vulnerabilities, and S4 only has reentrancy vulnerability; since none of the 4 paths have block dependency vulnerabilities, soFigure 3 In the intelligent contract vulnerability detection result, the block dependency vulnerability label is set to 0, while at least one path of the remaining vulnerability types is marked as 1, so the corresponding label is set to 1. The marking of scenario features refines the features of intelligent contracts, which is beneficial to accurately locate the specific scenario where the vulnerability lies.

[0068] To verify the effectiveness of the detection method in this embodiment (hereinafter referred to as the method in this embodiment), the following experiments were conducted.

[0069] Experimental purpose. To verify the performance of the method in this embodiment, experiments were designed based on a real intelligent contract dataset on Ethereum in the experiment and the experimental results were analyzed to answer the following research questions (RQs): RQ1: How does the method in this embodiment compare with current mainstream static analysis vulnerability detection tools? RQ2: How does each component in the method in this embodiment affect the final vulnerability detection effect? RQ3: How is the vulnerability location ability of the method in this embodiment compared with other deep learning methods?

[0070] Experimental environment. All experiments were conducted on a server running the Ubuntu 22.04 version operating system. The server is equipped with 2 Intel(R) Xeon(R) Silver 4210R CPUs @ 2.40GHz and 250GB of physical memory. The experimental tool is a Python-based intelligent contract vulnerability detection tool, so the experimental environment is Python 3.6.5. In addition, in the experiment, a 5-minute timeout was set for the vulnerability detection of each source file.

[0071] Dataset. To ensure the comprehensiveness of the experiment and the authority of the data, a high-quality dataset was constructed. The main data sources are as follows: The latest smart contract dataset released by Zheng Zibin et al. in 2023 was adopted. This dataset is highly relevant to the current Ethereum ecosystem and can reflect the characteristics of actually running smart contracts. The dataset contains a total of 21,212 manually annotated smart contract samples, covering multiple Solidity versions, and has high reliability. At the same time, 3,000 real contracts on the official Ethereum website were collected from existing technologies (including SmartCheck, SmartBugs, Securify, Smartian, and Sailfish, etc.). These contracts have been analyzed by multiple research teams and contain confirmed vulnerability instances, which guarantee the authenticity and diversity of the dataset. On this basis, automatic analysis tools such as Oyente were used, combined with manual annotation, to further screen and annotate the above data. Finally, a comprehensive dataset containing 24,212 smart contracts was formed. Among them, the typical vulnerabilities identified include: 1,490 integer overflow vulnerabilities, 2,499 reentrancy vulnerabilities, and 1,574 block dependency vulnerabilities. For the dataset, in the experiment, it was randomly allocated according to the ratio of 8:2, where 80% was used as the training set and 20% was used as the test set, and accuracy, precision, recall, and F1-score metrics were used to evaluate the experimental results.

[0072] Experimental settings. For RQ1, first, three advanced static analysis vulnerability detection methods, namely Smartcheck, Oyente, and Mythril, were selected for comparison to verify the effectiveness of the method in this embodiment in the vulnerability detection task. Subsequently, four classic deep learning models, namely LSTM, Bi-LSTM, GRU, and Vanilla-RNN, were compared to analyze the influence of different modeling methods on the detection effect. For RQ2, the main innovation points of the method in this embodiment lie in the construction of the temporal scenario graph and the feature dimension reduction method. To evaluate the influence of these two core modules on the vulnerability detection effect, the following comparative experiments were designed based on the complete method: 1. Analyze the temporal scenario graph (CTSG) and the feature dimension reduction method simultaneously: Replace CTSG with the control flow graph CFG, and at the same time adopt the original non-dimension-reduced feature extraction method to analyze the overall contribution of CTSG and feature dimension reduction; 2. Analyze only CTSG: Use CFG to replace CTSG and keep the feature dimension reduction method unchanged to verify the contribution of CTSG; 3. Analyze only the feature dimension reduction method: Keep CTSG unchanged and adopt the non-dimension-reduced feature extraction method to evaluate the influence of the feature dimension reduction method on the detection performance; By comparing the detection performance under different experimental settings, the respective contributions of CTSG and the feature dimension reduction method can be quantified, and further verify their role in improving the vulnerability detection effect.

[0073] For RQ3, existing deep learning methods mainly conduct vulnerability detection at the contract level. Their analysis dimension is limited to the overall characteristics of smart contracts and it is difficult to accurately determine the execution scenario where the vulnerability lies. However, the method of this embodiment conducts vulnerability detection at the execution scenario level of the contract, which can further locate the vulnerability position. To verify the vulnerability location ability of the method of this embodiment, in the experiment, first, a smart contract with an integer overflow vulnerability in the dataset was taken as an example for overall analysis, and then a real smart contract on the chain was selected as a case to analyze the vulnerability detection and location process in detail.

[0074] Answer results regarding effectiveness (for RQ1). In the experiment, the method of this embodiment was compared with existing vulnerability detection methods in three specific types of smart contract vulnerabilities (including: integer overflow, reentrancy, and block dependency vulnerabilities), and the experimental results were evaluated based on accuracy, precision, recall, and F1 score metrics. The method of this embodiment was compared with three classic non-deep learning methods, namely Smartcheck, Oyente, and Mythril. Secondly, four commonly used deep learning models, LSTM, Bi-LSTM, GRU, and Vanilla-RNN, were selected and compared with the method of this embodiment respectively. Finally, according to the experimental results, the effectiveness of the method of this embodiment in smart contract vulnerability detection was analyzed to answer RQ1. The experimental results are shown in Table 5 and Figure 4 。

[0075] Table 5 Comparison of various detection methods in terms of accuracy (Acc), precision (Pre), recall (Rec), and F1 score (F1) metrics for integer overflow vulnerability (Overflow), reentrancy vulnerability, and block dependency vulnerability (Block Dependency) detection

[0076] 。

[0077] In the experiment, the method of this embodiment was compared with the advanced non-deep learning methods Smartcheck, Oyente, and Mythril, and the performance is shown in the upper half of Table 5. In terms of accuracy, it is worth noting that the accuracy of the method of this embodiment reached 95.08%, which is 18.00% higher than that of Mythril with the highest accuracy. In addition, for reentry vulnerabilities and block dependency vulnerabilities, the detection accuracies of the method of this embodiment are as high as 95.62% and 94.74% respectively, both significantly superior to traditional non-deep learning vulnerability detection methods. In terms of precision, first of all, compared with the method of this embodiment, traditional non-deep learning methods performed mediocrely in the detection of three types of vulnerabilities, with the highest precision only being 58.06%, while the highest precision of the method of this embodiment is as high as 97.37%, which is 39.31% higher. Secondly, the detection precisions of traditional non-deep learning methods vary greatly for these three types of vulnerabilities, with the lowest precision being only 23.80%. Finally, on average, the detection precision of the method of this embodiment for these three types of vulnerabilities exceeds 95%, while the detection precisions of traditional non-deep learning methods do not exceed 60%. In addition, in terms of recall rate and F1 score, the comparison between the method of this embodiment and the three non-deep learning methods is similar to the comparison of accuracy and precision. To more intuitively compare the differences between the method of this embodiment and the three non-deep learning methods, the data was visualized in this article, as shown in Figure 4 shown Figure 4 in (a), (b), and (c) of which are the detection effects of integer overflow vulnerability, reentry vulnerability, and block dependency vulnerability in sequence. The visualization results further verify the advantages of the method of this embodiment in terms of vulnerability detection accuracy, precision, recall rate, and F1 score.

[0078] In the experiment, the method of this embodiment was further compared with other methods based on neural network models. LSTM, Bi-LSTM, GRU, and Vanilla-RNN were selected as comparison models. The experimental results are shown in the lower half of Table 5. The precision of the deep learning method has improved compared with the traditional non-deep learning method, but it is still lower than the precision of the method of this embodiment. The highest precision of the deep learning method is 78.67%, still showing a certain gap compared with the method of this embodiment. In addition, to more intuitively compare the effects of traditional static analysis methods and deep learning methods in vulnerability detection and highlight the advantages of the method of this embodiment, we visualized the experimental results, as shown in Figure 4 shown Figure 4The x-axis represents the detection methods, where 1, 2, 3, 4, 5, 6, 7, and 8 represent the method of this embodiment, Vanilla-RNN, GRU, Bi-LSTM, LSTM, Mythril, Oyente, and Smartcheck respectively. The y-axis represents the metrics, including accuracy, precision, recall, and F1-score. The z-axis represents the values. The visualization result graph is as Figure 4 shown. The precision of the deep learning methods is better than that of the non-deep learning methods, but still lower than that of the method of this embodiment. When detecting three types of vulnerabilities, the method of this embodiment always performs the best.

[0079] Generally speaking, compared with the non-deep learning methods, the deep learning methods have improved in terms of accuracy, precision, recall, and F1-score, but still lower than the method of this embodiment. This further proves the effectiveness of the method of this embodiment in detecting smart contract vulnerabilities. The method of this embodiment can significantly improve the accuracy, precision, recall, and F1-score of the prior art in detecting integer overflow, reentrancy, and block dependency vulnerabilities.

[0080] Answer results regarding the construction of CTSG and the advantages of feature dimensionality reduction (for RQ2). Ablation experiments were conducted in the experiment to analyze and verify the contributions of CTSG construction and feature dimensionality reduction in vulnerability detection. Specifically, taking the complete method of this embodiment as the benchmark, three control experiments were designed, and taking the detection of integer overflow vulnerabilities as an example, their overall and individual contributions were studied respectively. The components of each experiment are shown in Table 6.

[0081] Table 6 Components of the method of this embodiment and its variants

[0082] .

[0083] To evaluate the overall impact of CTSG and feature dimensionality reduction methods on the performance of the method of this embodiment, CFG was used to replace CTSG in the experiment, and the feature extraction method without dimensionality reduction was adopted. This variant is denoted as WGR, where WGR is the abbreviation of without CTSG and feature dimensionality reduction. The experimental results are shown in Table 7. Compared with the method of this embodiment, the performance of WGR has decreased significantly, and the accuracy, precision, recall, and F1-score have decreased by 25.99%, 27.15%, 25.21%, and 27.34% respectively, which indicates that the combined effect of CTSG and feature dimensionality reduction methods can significantly improve the performance of the method of this embodiment.

[0084] Table 7 Comparison of accuracy (Acc), precision (Pre), recall (Rec), and F1-score (F1) metrics between the method of this embodiment and its variants

[0085] 。

[0086] To evaluate the role of CTSG in the method of this embodiment, CFG is used to replace CTSG while keeping the feature dimensionality reduction method unchanged. This variant is denoted as WSG, where WSG is the abbreviation of without CTSG. The experimental results are shown in Table 4. The accuracy, precision, recall, and F1-score of WSG are improved compared with WGR, but the four metrics are still on average 17.47% lower than the method of this embodiment, indicating that CTSG can significantly improve the vulnerability detection ability of the method of this embodiment compared with CFG.

[0087] To evaluate the impact of feature dimensionality reduction on the effect of detecting vulnerabilities in the method of this embodiment, CTSG is kept unchanged and an unpreprocessed feature extraction method is adopted. This variant is denoted as WDR, where WDR is the abbreviation of without feature dimensionality reduction. The experimental results are shown in Table 4. The accuracy, precision, recall, and F1-score of the method of this embodiment are improved compared with WDR. Therefore, feature dimensionality reduction has a significant impact on the performance improvement of the method of this embodiment.

[0088] Reply results regarding the localization effect (for RQ3). To further illustrate the localization ability of the method of this embodiment, a vulnerability detection case of an on-chain smart contract is provided in the experiment. There is an integer overflow vulnerability in smart contract case 1, but it only appears in specific execution scenarios, such as Figure 5 shown in (a). Through the constructed CTSG, there are six paths (scenarios) S1 - S6, where each number represents the starting PC value of a basic block, and a node with multiple numbers represents an aggregated node. After being detected by the method of this embodiment, the vulnerability prediction labels corresponding to each scenario are obtained: [(S1, 0), (S2, 0), (S3, 0), (S4, 0), (S5, 0), (S6, 1)], as Figure 5 shown in (b), where the scenario label without vulnerability is 0 and the scenario label with vulnerability is 1. The results show that the method of this embodiment accurately locates the vulnerability to scenario S6, while other scenarios are correctly marked as safe. Further, through the obtained vulnerable scenarios, the specific executed code block can be located according to the PC value of the basic block. This case intuitively demonstrates the localization ability of the method of this embodiment at the scenario level in smart contract vulnerability detection, improving the granularity of vulnerability detection.

[0089] This embodiment also provides an intelligent contract vulnerability detection system based on a timing scenario, which is used to implement the above-mentioned intelligent contract vulnerability detection method based on a timing scenario, and includes the following operations:

[0090] A timing scenario graph generation module, which is used to disassemble the bytecode of the intelligent contract to be detected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and regard the path with a common partial segment with other paths as the path to be abstracted; aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph;

[0091] A reduced-dimensional timing scenario graph generation module, which is used to update the opcode of each node in the timing scenario graph according to the opcode format and type to obtain an updated timing scenario graph; perform feature reduction processing on each node in the updated timing scenario graph to obtain a reduced-dimensional timing scenario graph;

[0092] An intelligent contract vulnerability detection result generation module, which is used to perform feature mapping processing on each node in the reduced-dimensional timing scenario graph to obtain a node feature vector; splice all node feature vectors belonging to the same path in the reduced-dimensional timing scenario graph to obtain a path feature vector for each path; based on the node connection relationship on the same path in the reduced-dimensional timing scenario graph, obtain the adjacency matrix of each path; the adjacency matrix and path feature vector of each path are processed by graph convolution to obtain a path vulnerability detection result; based on the path vulnerability detection result, obtain an intelligent contract vulnerability detection result.

[0093] This embodiment also provides an intelligent contract vulnerability detection device based on a timing scenario, which includes a processor and a memory. Among them, when the processor executes the computer program stored in the memory, it implements the above-mentioned intelligent contract vulnerability detection method based on a timing scenario.

[0094] This embodiment also provides a computer-readable storage medium for storing a computer program. Among them, when the computer program is executed by a processor, it implements the above-mentioned intelligent contract vulnerability detection method based on a timing scenario.

[0095] An intelligent contract vulnerability detection method based on a timing scenario provided in this embodiment first constructs a control flow graph at the opcode level, extracts execution scenarios containing timing information by traversing the paths of the control flow graph, and further aggregates nodes with common partial segments to obtain a timing scenario graph; then, designs an innovative opcode update method and a feature dimensionality reduction method, which while reducing the dimension, retain semantic information and the timing features inside the nodes to obtain a dimensionality-reduced timing scenario graph; finally, performs feature mapping processing on each node in the dimensionality-reduced timing scenario graph to obtain node feature vectors, combines them with the adjacency matrix of each path obtained based on the connection relationships of the nodes on the same path in the dimensionality-reduced timing scenario graph, and through graph convolution processing, integrates the path vulnerability detection results to obtain the intelligent contract vulnerability detection result; this method is applied to the detection of intelligent contract vulnerabilities, especially to the detection of integer overflow vulnerabilities, reentry vulnerabilities, and block dependency vulnerabilities in intelligent contracts, and can significantly improve the accuracy, precision, recall rate, and F1 score.

Claims

1. An intelligent contract vulnerability detection method based on a timing scenario, characterized in that, It includes the following operations: S1. Disassemble the bytecode of the smart contract to be inspected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of the jump instructions, and obtain the control flow graph; Obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and regard the path that has a common partial segment with other paths as the path to be abstracted; Aggregate the common partial segments in the path to be abstracted into a single node to obtain the timing scenario graph; S2. Update the opcode of each node in the timing scenario graph according to the opcode format and type to obtain the updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain the dimensionality-reduced timing scenario graph; S3. Perform feature mapping processing on each node in the dimensionality-reduced timing scenario graph to obtain the node feature vector; Concatenate all the node feature vectors belonging to the same path in the dimensionality-reduced timing scenario graph to obtain the path feature vector of each path; Based on the node connection relationship on the same path in the dimensionality-reduced timing scenario graph, obtain the adjacency matrix of each path; The adjacency matrix and path feature vector of each path are processed by graph convolution to obtain the path vulnerability detection result; Based on the path vulnerability detection result, obtain the smart contract vulnerability detection result.

2. The intelligent contract vulnerability detection method based on a timing scenario according to claim 1, wherein During the aggregation in S1, the common partial segments in the corresponding paths to be abstracted are sequentially aggregated into a single node in the order of increasing length of the common partial segments.

3. The intelligent contract vulnerability detection method based on a timing scenario according to claim 1, characterized in that The operation of updating the opcode of each basic block in the updated timing scenario graph in S2 includes: deleting the numerical suffix of consecutive opcodes with the same mnemonic prefix, and / or mapping multiple opcodes associated with the same vulnerability to the same opcode according to the corresponding function.

4. The intelligent contract vulnerability detection method based on a timing scenario according to claim 1, characterized in that The specific operation of feature dimensionality reduction processing in S2 is: combine adjacent opcodes in each node of the updated timing scenario graph to obtain several opcode combinations of each node, delete the opcode combinations that are all ordinary opcodes, and / or delete the opcode combinations starting with the termination opcode to obtain the dimensionality-reduced timing scenario graph.

5. The intelligent contract vulnerability detection method based on a timing scenario according to claim 1, wherein The specific operation of feature mapping processing in S3 is: assign corresponding values according to the occurrence times of the opcode combinations in the nodes of the dimensionality-reduced timing scenario graph to obtain the opcode combination vector; concatenate all the opcode combination vectors according to the order of the opcode combinations in the nodes to obtain the node feature vector.

6. The intelligent contract vulnerability detection method based on a timing scenario according to claim 1, characterized in that During the graph convolution processing in S3, the adjacency matrix corresponding to the output of the previous layer is added to the initial adjacency matrix to obtain the updated adjacency matrix, which is used as the adjacency matrix input for the current layer.

7. The intelligent contract vulnerability detection method based on a timing scenario according to claim 1, characterized in that In S3, if the current vulnerability exists in the path vulnerability detection result, then the current vulnerability exists in the smart contract vulnerability detection result; if the current vulnerability does not exist in all the path vulnerability detection results, then the current vulnerability does not exist in the smart contract vulnerability detection result.

8. An intelligent contract vulnerability detection system based on a timing scenario, which is used to implement the intelligent contract vulnerability detection method based on a timing scenario described in claim 1, and is characterized in that, It includes the following operations: The timing scenario graph generation module is used to disassemble the bytecode of the smart contract to be inspected into an opcode sequence, divide the opcode sequence into basic blocks, establish the jump relationship between basic blocks according to the address parameters of jump instructions, and obtain a control flow graph; obtain all paths from the root node to the tail node in the control flow graph to form a path set; traverse each path in the path set, and regard the path with a common partial segment with other paths as the path to be abstracted; Aggregate the common partial segments in the path to be abstracted into a single node to obtain a timing scenario graph; The dimensionality reduction timing scenario graph generation module is used to update the opcode of each node in the timing scenario graph according to the opcode format and type to obtain an updated timing scenario graph; perform feature dimensionality reduction processing on each node in the updated timing scenario graph to obtain a dimensionality reduction timing scenario graph; The smart contract vulnerability detection result generation module is used to perform feature mapping processing on each node in the dimensionality reduction timing scenario graph to obtain a node feature vector; Concatenate all node feature vectors belonging to the same path in the dimensionality reduction timing scenario graph to obtain a path feature vector for each path; Based on the node connection relationship on the same path in the dimensionality reduction timing scenario graph, obtain the adjacency matrix of each path; the adjacency matrix of each path and the path feature vector are processed by graph convolution to obtain a path vulnerability detection result; based on the path vulnerability detection result, obtain a smart contract vulnerability detection result.

9. An intelligent contract vulnerability detection device based on a timing scenario, characterized in that, It includes a processor and a memory. Among them, when the processor executes the computer program stored in the memory, it implements the timing scenario-based smart contract vulnerability detection method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, It is used to store a computer program. Among them, when the computer program is executed by a processor, it implements the timing scenario-based smart contract vulnerability detection method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Intelligent contract vulnerability detection method based on neural network

    CN116702157A

  • Intelligent contract vulnerability detection method, system and equipment based on vulnerability subgraph

    CN117201138A