Vulnerability detection method and device, electronic equipment and computer readable medium
By performing syntax analysis and feature information extraction of the smart contract source code, generating vulnerability ontology information and applying detection constraints, the problem of low efficiency and accuracy of smart contract vulnerability detection is solved, and efficient vulnerability positioning and repair are achieved.
Patent Information
- Application Number
- CN202311014645.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-11
- Publication Date
- 2025-07-11
Smart Images

Figure CN120296737A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer technologies, and particularly to a vulnerability detection method, apparatus, electronic device, and computer-readable medium. Background Art
[0002] Vulnerabilities in smart contracts are currently the main hidden dangers affecting the security of blockchain systems. Due to the characteristics of smart contracts such as being easy to write and deploy and unable to be modified after being uploaded to the blockchain, it is very difficult to repair security vulnerabilities in a timely manner after the smart contracts are running. How to ensure the security of a large number of smart contracts and blockchain applications has become the core issue considered by forward-looking enterprises and individuals in the blockchain industry. Current smart contract vulnerability detection methods mainly include methods such as feature string matching, symbolic execution, formal verification, and deep learning techniques. Then, according to the detected vulnerabilities, the smart contracts are repaired and maintained.
[0003] However, the inventors have found that when using the above methods for vulnerability detection, the following technical problems often exist:
[0004] First, the symbolic execution technology generally needs to be used in cooperation with the Fuzz technology, and due to the influence of constraint solving performance, there are few mature applications at present. Formal verification relies on classical logical reasoning techniques and must set relatively abstract reasoning rules. The types of vulnerabilities verified are affected by the reasoning rules, resulting in a low detection rate of vulnerabilities and low detection efficiency, and thus a long time-consuming for vulnerability detection. The smart contract vulnerability detection based on deep learning depends on a large number of training samples. When the samples are few, the generalization ability of the trained model is poor, resulting in a low accuracy rate of vulnerability detection.
[0005] Second, when matching vulnerability features, using the method of feature string matching can only identify some simple vulnerability forms, and the efficiency of string matching is low, and the detection efficiency and accuracy for vulnerabilities in commonly used smart contract programming languages are low.
[0006] Third, for the identified vulnerabilities, the causes of the vulnerabilities are not considered, resulting in difficulty in judging whether the identified vulnerabilities are correct, and the specific positions of the vulnerabilities are not accurately located, thus resulting in a long time-consuming and low efficiency for the repair and maintenance of smart contracts.
[0007] The above information disclosed in this background art section is only used to enhance the understanding of the background of the inventive concept, and thus, it may include information that does not form the prior art known to those of ordinary skill in the art in this country. Summary of the Invention
[0008] This disclosure is in part for introducing concepts in a concise form, which will be described in detail in the following detailed implementation section. This disclosure is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0009] Some embodiments of this disclosure provide a vulnerability detection method, apparatus, electronic device, and computer-readable medium to solve one or more of the technical problems mentioned in the above background section.
[0010] In a first aspect, some embodiments of this disclosure provide a vulnerability detection method, which includes: performing syntax parsing on the contract source code of a target smart contract to obtain the syntax information corresponding to the contract source code; extracting information from the syntax information to obtain the feature information of the target smart contract; generating vulnerability ontology information based on the feature information and various preset reference data type information; determining various vulnerability detection constraint information corresponding to various preset vulnerability types; and performing vulnerability detection on the vulnerability ontology information according to the various vulnerability detection constraint information to obtain a set of vulnerability information corresponding to the target smart contract.
[0011] In a second aspect, some embodiments of this disclosure provide a vulnerability detection apparatus, including: a parsing unit configured to perform syntax parsing on the contract source code of a target smart contract to obtain the syntax information corresponding to the contract source code; an extraction unit configured to extract information from the syntax information to obtain the feature information of the target smart contract; an input unit configured to generate vulnerability ontology information based on the feature information and various preset reference data type information; a determination unit configured to determine various vulnerability detection constraint information corresponding to various preset vulnerability types; and a detection unit configured to perform vulnerability detection on the vulnerability ontology information according to the various vulnerability detection constraint information to obtain a set of vulnerability information corresponding to the target smart contract.
[0012] In a third aspect, some embodiments of this disclosure provide an electronic device, including: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement the method described in any implementation manner of the first aspect.
[0013] In a fourth aspect, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the computer program is executed by a processor, it implements the method described in any implementation manner of the first aspect.
[0014] The above embodiments of the present disclosure have the following beneficial effects: Through the vulnerability detection method of some embodiments of the present disclosure, the detection rate and accuracy of vulnerability detection are improved, and the time consumption of vulnerability detection is reduced. Specifically, the reasons for the low detection rate and accuracy of vulnerability detection and the long time consumption are as follows: Symbolic execution technology generally needs to be used in cooperation with Fuzz technology, and due to the influence of constraint solving performance, there are few mature applications at present. Formal verification relies on classical logical reasoning technology, and relatively abstract reasoning rules must be set. The types of vulnerabilities verified are affected by the reasoning rules, resulting in a low detection rate and low detection efficiency of vulnerabilities, and a long time consumption for vulnerability detection. The intelligent contract vulnerability detection based on deep learning relies on a large number of training samples. When the samples are few, the generalization ability of the trained model is poor, resulting in a low accuracy of vulnerability detection. Based on this, the vulnerability detection method of some embodiments of the present disclosure, first, performs syntax parsing on the contract source code of the target intelligent contract to obtain the syntax information corresponding to the above contract source code. Thus, the syntax information corresponding to the target intelligent contract can be obtained. Then, information extraction is performed on the above syntax information to obtain the feature information of the above target intelligent contract. Thus, the feature information corresponding to the target intelligent contract can be obtained for constructing a vulnerability ontology. After that, according to the above feature information and each preset reference data type information, vulnerability ontology information is generated. Thus, the ontology information corresponding to the target intelligent contract can be obtained. Next, each vulnerability detection constraint information corresponding to each preset vulnerability type is determined. Thus, each vulnerability detection constraint information for performing vulnerability detection on the target intelligent contract can be obtained. Finally, according to the above each vulnerability detection constraint information, vulnerability detection is performed on the above vulnerability ontology information to obtain a set of vulnerability information corresponding to the above target intelligent contract. Thus, each vulnerability information of each vulnerability included in the target intelligent contract can be obtained. Also, because the vulnerability ontology information can be constructed according to the extracted feature information of the target intelligent contract, and the target intelligent contract is deduced for vulnerabilities according to each vulnerability detection constraint information and the vulnerability ontology information, so as to obtain each vulnerability information included in the target intelligent contract, thereby improving the detection rate and accuracy of vulnerability detection and reducing the time consumption of vulnerability detection. Description of the Drawings
[0015] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages and aspects of the various embodiments of the present disclosure will become more obvious. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the elements and elements are not necessarily drawn to scale.
[0016] Figure 1 is a flowchart of some embodiments of the vulnerability detection method according to the present disclosure;
[0017] Figure 2 is a flowchart of some embodiments of the vulnerability detection device according to the present disclosure;
[0018] Figure 3 It is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed implementation manners
[0019] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.
[0020] In addition, it should be noted that for the sake of convenience of description, only parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.
[0021] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.
[0022] It should be noted that the modifications of "one" and "plural" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless clearly specified otherwise in the context, it should be understood as "one or more".
[0023] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0024] The present disclosure will be described in detail below with reference to the drawings and in combination with embodiments.
[0025] Figure 1 Flow 100 of some embodiments of a vulnerability detection method according to the present disclosure is shown. The vulnerability detection method includes the following steps:
[0026] Step 101, perform syntax parsing on the contract source code of the target smart contract to obtain the syntax information corresponding to the contract source code.
[0027] In some embodiments, an execution entity (such as a computing device) of the vulnerability detection method may perform syntax parsing on the contract source code of a target smart contract to obtain syntax information corresponding to the contract source code. Among them, the above-mentioned target smart contract may be a smart contract to be subjected to vulnerability detection. The above-mentioned contract source code may be the Solidity-based source code of the above-mentioned target smart contract. The above-mentioned syntax information may be an abstract syntax tree corresponding to the above-mentioned contract source code. In practice, the above-mentioned execution entity may use an abstract syntax tree parsing tool, AST explorer, to perform syntax parsing on the contract source code of the target smart contract to obtain syntax information corresponding to the contract source code.
[0028] Step 102: Extract information from the syntax information to obtain feature information of the target smart contract.
[0029] In some embodiments, the above-mentioned execution entity may extract information from the above-mentioned syntax information to obtain feature information of the above-mentioned target smart contract. Among them, the above-mentioned feature information may represent the contract name, contract version information, each function information, and each keyword information list extracted from the above-mentioned contract source code. In practice, the above-mentioned execution entity may extract information from the above-mentioned syntax information in various ways to obtain feature information of the above-mentioned target smart contract.
[0030] In some optional implementation manners of some embodiments, the above-mentioned execution entity may extract information from the above-mentioned syntax information through the following steps to obtain feature information of the above-mentioned target smart contract:
[0031] First step, extract the contract name, contract version information, and each function information from the above-mentioned syntax information. Among them, the function information in the above-mentioned each function information may be the code of each method function included in the above-mentioned contract source code. In practice, the above-mentioned execution entity may use the JsonPath tool to extract the contract name, contract version information, and each function information from the above-mentioned syntax information.
[0032] Second step, generate each keyword information list corresponding to the above-mentioned each function information according to the above-mentioned each function information. Among them, the above-mentioned keyword information list may represent each keyword with a sequential position relationship extracted from the function information and the position information corresponding to each keyword. The above-mentioned keyword may be any string in the function. The above-mentioned keyword information list may include each keyword information. The above-mentioned keyword information may represent the keyword and the position information corresponding to the keyword. As an example, the code corresponding to the function information may be determined as a string list, and the above-mentioned position information may be the subscript of the first letter or the last letter of the keyword in the string list. In practice, the above-mentioned execution entity may generate each keyword information list corresponding to the above-mentioned each function information in various ways according to the above-mentioned each function information.
[0033] In the third step, determine the above-mentioned contract name, the above-mentioned contract version information, the above-mentioned function information, and the above-mentioned keyword information list as the feature information of the above-mentioned target smart contract.
[0034] In some optional implementation manners of some embodiments, for each function information in the above-mentioned function information, the above-mentioned execution subject may perform the following steps to generate the keyword information list corresponding to each function information according to the above-mentioned function information:
[0035] In the first step, obtain each keyword and the position information corresponding to each keyword from the above-mentioned function information. In practice, the above-mentioned execution subject may obtain each keyword and the position information corresponding to each keyword from the above-mentioned function information in various ways.
[0036] In the second step, generate a keyword information list according to the above-mentioned keywords and the above-mentioned position information. In practice, the above-mentioned execution subject may generate a keyword information list according to the above-mentioned keywords and the above-mentioned position information in various ways.
[0037] In some optional implementation manners of some embodiments, the above-mentioned execution subject may obtain each keyword and the position information corresponding to each keyword from the above-mentioned function information through the following steps:
[0038] In the first step, perform word segmentation on the above-mentioned function information to obtain each function keyword. Among them, the above-mentioned function keywords may be each word or phrase obtained through word segmentation. In practice, the above-mentioned execution subject may use a word segmentation tool to perform word segmentation on the above-mentioned function information to obtain each function keyword. The above-mentioned word segmentation tool may be the jieba word segmentation tool.
[0039] In the second step, perform preprocessing on the above-mentioned function keywords to obtain the preprocessed function keywords. Among them, the above-mentioned preprocessing may include removing stop words and special symbols. In practice, for each function keyword in the above-mentioned function keywords, if the above-mentioned execution subject determines that the function keyword exists in the pre-stored preprocessing word list, the above-mentioned function keyword is deleted.
[0040] In the third step, vectorize each of the obtained function keywords to obtain respective keyword vectors. In practice, the above-mentioned execution entity can input each of the obtained function keywords into the vector representation layer of a pre-trained keyword extraction model to obtain respective keyword vectors. Among them, the above-mentioned pre-trained keyword extraction model can be a trained named entity recognition model. The above-mentioned vector representation layer can be the BERT layer of the above-mentioned named entity recognition model. The above-mentioned respective keyword vectors can be respective vector representations of each of the function keywords obtained through the BERT layer.
[0041] In the fourth step, extract features from each of the obtained keyword vectors to obtain respective feature vectors corresponding to each of the above-mentioned keyword vectors. In practice, the above-mentioned execution entity can input each of the obtained keyword vectors into the bidirectional feature extraction layer of the above-mentioned pre-trained keyword extraction model to obtain respective feature vectors corresponding to each of the above-mentioned keyword vectors. Among them, the above-mentioned bidirectional feature extraction layer can be a bidirectional long short-term memory network layer (BiLSTM). The above-mentioned respective feature vectors can be respective vectors corresponding to each of the keyword vectors obtained through the feature extraction layer.
[0042] In the fifth step, based on the obtained respective feature vectors, perform label prediction on each of the above-mentioned function keywords to obtain respective labels corresponding to each of the above-mentioned function keywords. In practice, the above-mentioned execution entity can input each of the obtained feature vectors into the label prediction layer of the above-mentioned pre-trained keyword extraction model to obtain respective labels corresponding to each of the above-mentioned feature vectors. Among them, the above-mentioned label prediction layer can be a conditional random field network layer. The above-mentioned respective labels can represent named entity labels corresponding to each of the above-mentioned function keywords. For example, the above-mentioned named entity labels can include B-X, I-X, O. The above-mentioned B-X can represent the label corresponding to the start position of the entity. The above-mentioned I-X can represent the label corresponding to the end position of the entity. The above-mentioned O indicates that the corresponding function keyword does not belong to any entity.
[0043] In the sixth step, based on each of the above-mentioned function keywords and each of the above-mentioned labels, determine each keyword and respective position information corresponding to each of the above-mentioned keywords. In practice, the above-mentioned execution entity can input the above-mentioned respective feature vectors and the above-mentioned respective labels into the output layer of the above-mentioned pre-trained keyword extraction model to obtain each keyword and respective position information corresponding to each of the above-mentioned keywords. Among them, the above-mentioned output layer can be a network layer that outputs the function keywords corresponding to the labels representing entities among the above-mentioned respective labels and the function keyword position subscripts.
[0044] The relevant content of the above technical solution is an inventive point of the embodiments of the present disclosure, which solves the second technical problem mentioned in the background art, "low efficiency and accuracy of vulnerability detection". The factors that lead to low efficiency and accuracy of vulnerability detection are often as follows: When matching vulnerability features, the method of feature string matching can only identify some simple vulnerability forms, and the efficiency of string matching is low. The efficiency and accuracy of detecting vulnerabilities in commonly used smart contract programming languages are low. If the above factors are solved, the effect of improving the efficiency and accuracy of vulnerability detection can be achieved. To achieve this effect, the present disclosure introduces a keyword extraction model. The keyword extraction model is used to perform named entity recognition on vulnerability feature words. The accuracy and efficiency of identifying vulnerability feature words are improved. Thereby, the efficiency and accuracy of vulnerability detection are improved.
[0045] In some optional implementation manners of some embodiments, the above execution entity may generate a keyword information list according to the above respective keywords and the above respective position information through the following steps:
[0046] First step, for each keyword in the above respective keywords, perform the following steps:
[0047] First sub-step, determine the vulnerability type information corresponding to the above keyword. Among them, the above vulnerability type information may be the vulnerabilities that the above keyword may trigger and the corresponding codes of the vulnerabilities. In practice, the above execution entity may query the vulnerability type information corresponding to the above keyword in the vulnerability type information and keyword relationship table to obtain the vulnerability type information corresponding to the above keyword. The vulnerability type information and keyword relationship table may represent the corresponding relationship between vulnerability type information and keywords. As an example, when the above keyword is "call value balances" or "the balances beforecall.value", the use of the above keyword may trigger a reentrancy vulnerability, and the vulnerability type information corresponding to the above keyword may be the reentrancy vulnerability and the corresponding code of the reentrancy vulnerability.
[0048] Second sub-step, determine the keyword, the position information corresponding to the above keyword, and the above vulnerability type information as keyword information.
[0049] Second step, determine the respective keyword information determined as a keyword information list.
[0050] Step 103, generate vulnerability ontology information according to the feature information and each preset reference data type information.
[0051] In some embodiments, the above-mentioned execution entity may generate vulnerability ontology information according to the above-mentioned characteristic information and each preset reference data type information. Among them, each of the above-mentioned preset reference data type information may be each ontology class. For example, each of the above-mentioned ontology classes may include each contract class and each vulnerability class. Each of the above-mentioned contract classes may include a function class and a contract class. Each of the above-mentioned vulnerability classes may include a reentrancy vulnerability class, an integer overflow vulnerability class, an undeclared function visibility vulnerability class, an unchecked message call return value vulnerability class, a delegate call to an untrusted contract vulnerability class, a vulnerability class using tx.origin authorization, a timestamp dependency vulnerability class, a wrong constructor name vulnerability class, an unexpected ether vulnerability class, a chain-based weak randomness vulnerability class, and a precision loss vulnerability class. The above-mentioned vulnerability ontology information may represent the relationships between each contract class and each vulnerability class, the relationships between each contract class, the relationships between each vulnerability class, and the relationships between each entity corresponding to each ontology class. In practice, the above-mentioned execution entity may generate vulnerability ontology information in various ways according to the above-mentioned characteristic information and each preset reference data type information.
[0052] In some optional implementation manners of some embodiments, the above-mentioned execution entity may generate vulnerability ontology information according to the above-mentioned characteristic information and each preset reference data type information through the following steps:
[0053] First step, determine each of the above-mentioned preset reference data type information as a first reference data type information set. Among them, the above-mentioned first reference data type information set may be a set composed of each preset reference data type information.
[0054] Second step, for each first reference data type information in the above-mentioned first reference data type information set, perform the following steps:
[0055] First sub-step, determine each of the first reference data type information in the above-mentioned first reference data type information set that is different from the above-mentioned first reference data type information as a second reference data type information set. Among them, the above-mentioned second reference data type information set may be a set composed of each of the first reference data type information in the above-mentioned first reference data type information set that is different from the above-mentioned first reference data type information.
[0056] The second sub-step is to determine the respective association information between the above first reference data type information and each second reference data type information in the above second reference data type information set. Among them, the above association information can characterize the relationship between the first reference data type information and the second reference data type information. For example, when the first reference data type information is a contract type and the second reference data type information is a vulnerability type, the association information between the contract type and the vulnerability type can be hasVoluntarily (indicating that the contract may contain various vulnerabilities). In practice, the above execution entity can obtain the respective association information between the above first reference data type information and each second reference data type information in the above second reference data type information set by querying the respective preset reference data type information and respective relationship information corresponding to the first reference data type information in the preset reference data type information relationship table. The above preset reference data type information relationship table can characterize the association relationship between any two preset reference data type information in the respective preset reference data type information.
[0057] The third sub-step is to determine the above respective association information as an association information set. Among them, the above association information set can be a set composed of the respective association information between the respective preset reference data type information.
[0058] The third step is to combine the above respective preset reference data type information and the determined respective association information sets into an initial vulnerability ontology model. Among them, the above initial vulnerability ontology model can characterize the relationship between the respective preset reference data type information. In practice, the above execution entity can use the ontology development tool Protégé to combine the above respective preset reference data type information and the determined respective association information sets into an initial vulnerability ontology model.
[0059] The fourth step is to determine the contract name included in the above feature information and each function name included in each function information as a label information set. Among them, the above label information set can be a set composed of the contract name and each function name extracted from the above contract source code.
[0060] The fifth step is to perform the following steps for each label information in the above label information set:
[0061] The first sub-step is to determine the preset reference data type information corresponding to the above label information from each of the above preset reference data type information. In practice, in response to determining that the above label information is a contract name, the execution entity may determine the preset reference data type information corresponding to the contract class in each of the above preset reference data type information as the preset reference data type information corresponding to the above label information. In response to determining that the above label information is a function name, the execution entity may determine the preset reference data type information corresponding to the function class in each of the above preset reference data type information as the preset reference data type information corresponding to the above label information.
[0062] The second sub-step is to determine the label attribute information corresponding to the above label information according to the contract version information and each keyword information list included in the above feature information. Among them, the above label attribute information may represent each attribute value corresponding to the above label information. The above label attribute information may include contract version information or a keyword information list. In practice, in response to determining that the above label information is a contract name, the execution entity may determine the above contract version information as the label attribute information corresponding to the above label information. In response to determining that the above label information is a function name, the execution entity may determine the keyword information list corresponding to the above function name as the label attribute information corresponding to the above label information.
[0063] The third sub-step is to determine the label information, the preset reference data type information corresponding to the above label information, and the label attribute information corresponding to the above label information as entity information. Among them, the above entity information may be an instance corresponding to a vulnerability class or a contract class.
[0064] The sixth step is to input the determined entity information into the above initial vulnerability ontology model to obtain vulnerability ontology information. In practice, the execution entity may input the determined entity information into the above initial vulnerability ontology model through the Cellfie module in the ontology development tool Protégé to obtain vulnerability ontology information.
[0065] Step 104: Determine the vulnerability detection constraint information corresponding to each preset vulnerability type.
[0066] In some embodiments, the above-mentioned execution entity may determine respective vulnerability detection constraint information corresponding to each preset vulnerability type. Among them, the above-mentioned preset vulnerability types may include method misuse vulnerability type, function misdefinition vulnerability type, sequential dependency vulnerability type, and result review vulnerability type. The above-mentioned method misuse vulnerability type may be a vulnerability caused by incorrect method calls. For example, the above-mentioned method misuse vulnerability type may include timestamp dependency vulnerability, chain-based weak randomness vulnerability, delegate call to untrusted contract vulnerability, and vulnerability of using tx.origin for authorization. The above-mentioned function misdefinition vulnerability type may be a vulnerability caused by incorrect function definition. For example, the above-mentioned function misdefinition vulnerability type may include unstated function visibility vulnerability and incorrect constructor name vulnerability. The above-mentioned sequential dependency vulnerability type may be a vulnerability caused by certain operations in the smart contract not being executed in the specified order. For example, the above-mentioned sequential dependency vulnerability type may include reentrancy vulnerability and vulnerability of not checking the return value of message calls. The above-mentioned result review vulnerability type may be a vulnerability caused by not checking certain operations in the smart contract. For example, the above-mentioned result review vulnerability type may include integer overflow vulnerability and precision loss vulnerability. The above-mentioned vulnerability detection constraint information may be a rule function for detecting vulnerabilities in the above-mentioned vulnerability ontology information. In practice, the above-mentioned execution entity may determine respective vulnerability detection constraint information corresponding to each preset vulnerability type through various means.
[0067] In some alternative implementation manners of some embodiments, for each preset vulnerability type among the above-mentioned preset vulnerability types, the above-mentioned execution entity may determine respective vulnerability detection constraint information corresponding to each preset vulnerability type through the following steps:
[0068] First step, in response to determining that the above-mentioned preset vulnerability type is the method misuse vulnerability type, determine respective vulnerability detection constraint information corresponding to the above-mentioned method misuse vulnerability type according to respective method call keyword information corresponding to the above-mentioned method misuse vulnerability type. Among them, the above-mentioned method call keyword information may be keywords or phrases for calling special methods. For example, delegatecall, block.timestamp. In practice, for each method call keyword information among the above-mentioned method call keyword information, the above-mentioned execution entity may input the above-mentioned method call keyword information into a first preset expression to obtain vulnerability detection constraint information corresponding to the above-mentioned method call keyword information. The above-mentioned first preset expression may be (method some xsd:integer). The above-mentioned method may represent method call keyword information. The above-mentioned some xsd:integer may be a fixed rule of the inference tool.
[0069] Second, in response to determining that the above preset vulnerability type is a function error definition vulnerability type, based on each function definition keyword information corresponding to the function error definition vulnerability type, determine each vulnerability detection constraint information corresponding to the function error definition vulnerability type. Among them, the above function definition keyword information may be keywords for defining functions. For example, the above function definition keyword information may be "public", "internal", "external", or "private". In practice, for each function definition keyword information among the above function definition keyword information, the above execution entity may input the above function definition keyword information into a second preset expression to obtain the vulnerability detection constraint information corresponding to the above function definition keyword information. The above second preset expression may be (statement some xsd:integer). The above statement may represent function definition keyword information.
[0070] Third, in response to determining that the above preset vulnerability type is a sequential dependency vulnerability type, based on each first keyword position relationship information corresponding to the sequential dependency vulnerability type, determine each vulnerability detection constraint information corresponding to the sequential dependency vulnerability type. Among them, the above first keyword position relationship information may represent the sequential order of keywords representing operations. For example, the keywords representing operations may be keywords corresponding to transfers and keywords corresponding to balance comparisons. The balance comparison operation should be before the transfer operation, that is, the keyword corresponding to the balance comparison (balances) is before the keyword corresponding to the transfer (call, value). In practice, for each first keyword position relationship information among the above first keyword position relationship information, first, the above execution entity may input each keyword and the position information corresponding to each keyword included in the above first keyword position relationship information into a third preset expression to obtain each keyword expression. Then, the obtained keyword expressions can be combined into the vulnerability detection constraint information corresponding to the above first keyword position relationship information. The above third preset expression may be (variable some xsd:integer location). The above variable may represent the keyword included in the first keyword position relationship information. The above location may represent the position information corresponding to the keyword.
[0071] Fourthly, in response to determining that the above-mentioned preset vulnerability type is a result review vulnerability type, according to each second keyword position relationship information corresponding to the above-mentioned result review vulnerability type, determine each vulnerability detection constraint information corresponding to the above-mentioned result review vulnerability type. Among them, the above-mentioned second keyword position relationship information can represent the position sequence of each keyword representing an operation. Among them, the above-mentioned keyword representing an operation can be the symbol and number of arithmetic operations, and the function return value. For example, after a multiplication operation, it is necessary to check whether the operation result overflows. That is, the security check keyword (assert) is after the multiplication operation keyword (*). In practice, for each second keyword position relationship information in the above-mentioned various second keyword position relationship information, first, the above-mentioned execution subject can input each keyword and the corresponding position information included in the above-mentioned second keyword position relationship information into the above-mentioned third preset expression to obtain each keyword expression. Then, the obtained keyword expressions can be combined into the vulnerability detection constraint information corresponding to the above-mentioned second keyword position relationship information.
[0072] Step 105, perform vulnerability detection on the vulnerability ontology information according to each vulnerability detection constraint information to obtain a set of vulnerability information corresponding to the target smart contract.
[0073] In some embodiments, the above-mentioned execution subject can perform vulnerability detection on the above-mentioned vulnerability ontology information according to each vulnerability detection constraint information to obtain a set of vulnerability information corresponding to the above-mentioned target smart contract. Among them, the above-mentioned vulnerability ontology information can include each entity information. The above-mentioned set of vulnerability information can be each vulnerability detected from the above-mentioned target smart contract, and the corresponding position information and vulnerability cause information of each vulnerability. The corresponding position information of the vulnerability can be the subscript of the starting character and the subscript of the ending character of the vulnerability in the contract source code. The above-mentioned vulnerability cause information can represent the reason for causing the vulnerability. The above-mentioned vulnerability cause information can include the entity name, entity label attribute information, vulnerability name, class to which the entity corresponding to the entity name belongs, and vulnerability detection constraint information corresponding to the vulnerability. In practice, the above-mentioned execution subject can use various methods to perform vulnerability detection on the above-mentioned vulnerability ontology information according to each vulnerability detection constraint information to obtain a set of vulnerability information corresponding to the above-mentioned target smart contract.
[0074] In some optional implementation manners of some embodiments, the above-mentioned execution subject can perform vulnerability detection on the above-mentioned vulnerability ontology information according to each vulnerability detection constraint information through the following steps to obtain a set of vulnerability information corresponding to the above-mentioned target smart contract:
[0075] First step, for each entity information included in the above-mentioned vulnerability ontology information, perform the following steps:
[0076] The first sub-step is to determine the set of vulnerabilities, the set of vulnerability location information, and the set of vulnerability cause information existing in the above entity information according to the above various vulnerability detection constraint information. Among them, the vulnerabilities in the above vulnerability set correspond to the vulnerability location information in the above vulnerability location information set, and the vulnerabilities in the above vulnerability set correspond to the vulnerability cause information in the above vulnerability cause information set. The above vulnerability set can represent each vulnerability included in the above entity information. The above vulnerability location information set can represent each location information corresponding to each vulnerability included in the above entity information. The above vulnerability cause information set can represent each vulnerability cause information corresponding to each vulnerability included in the above entity information. In practice, the above execution subject can use the reasoning tool HermiT to determine the set of vulnerabilities, the set of vulnerability location information, and the set of vulnerability cause information existing in the above entity information according to the above various vulnerability detection constraint information.
[0077] The second sub-step is to determine the vulnerability information of the above entity information by using the above vulnerability set, the above vulnerability location information set, and the above vulnerability cause information set.
[0078] In the second step, determine the determined various vulnerability information as a vulnerability information set.
[0079] In some optional implementation manners of some embodiments, for each vulnerability detection constraint information in the above various vulnerability detection constraint information, the above execution subject can, through the following steps, determine the set of vulnerabilities, the set of vulnerability location information, and the set of vulnerability cause information existing in the above entity information according to the above various vulnerability detection constraint information:
[0080] In the first step, determine the detection result corresponding to the above vulnerability detection constraint information according to the tag information, the preset reference data type information, and the tag attribute information included in the above entity information. Among them, the above detection result can represent whether the above entity information has a vulnerability corresponding to the above vulnerability detection constraint information. In practice, the above execution subject can use the reasoning tool HermiT to determine the detection result corresponding to the above vulnerability detection constraint information according to the tag information, the preset reference data type information, and the tag attribute information included in the above entity information.
[0081] In the second step, in response to determining that the above detection result represents that the above entity information has a vulnerability corresponding to the above vulnerability detection constraint information, perform the following steps:
[0082] In the first sub-step, add the vulnerability corresponding to the above vulnerability detection constraint information to the vulnerability set.
[0083] The second sub-step is to determine the vulnerability location information of the above-mentioned vulnerability according to the above-mentioned tag information and tag attribute information. In practice, the above-mentioned execution entity may determine the respective keyword position information corresponding to each keyword that satisfies the above-mentioned vulnerability detection constraint information in the keyword information list included in the above-mentioned tag attribute information and the above-mentioned tag information as the vulnerability location information of the above-mentioned vulnerability.
[0084] The third sub-step is to add the above-mentioned vulnerability location information to the vulnerability location information set.
[0085] The fourth sub-step is to generate the vulnerability cause information of the above-mentioned vulnerability according to the above-mentioned vulnerability detection constraint information, the above-mentioned tag information and the above-mentioned tag attribute information. In practice, the above-mentioned execution entity may combine the above-mentioned tag information, the above-mentioned tag attribute information, the vulnerability name of the above-mentioned vulnerability, the class of the above-mentioned tag information, and the above-mentioned vulnerability detection constraint information into the above-mentioned vulnerability cause information.
[0086] The fifth sub-step is to add the above-mentioned vulnerability cause information to the vulnerability cause information set.
[0087] The relevant content of the above technical solution is an inventive point of an embodiment of the present disclosure, which solves the third technical problem mentioned in the background art, "the time-consuming and low efficiency of repairing and maintaining smart contracts". The factors that lead to the long time-consuming and low efficiency of repairing and maintaining smart contracts are often as follows: for the identified vulnerabilities, the causes of the vulnerabilities are not considered, resulting in difficulty in judging whether the identified vulnerabilities are correct, and the specific locations of the vulnerabilities are not accurately located. If the above factors are solved, the time-consuming of repairing and maintaining smart contracts can be reduced, and the efficiency of repairing and maintaining smart contracts can be improved. To achieve this effect, the present disclosure introduces vulnerability location information and vulnerability cause information. When detecting vulnerabilities in smart contracts, after detecting the existence of vulnerabilities, the corresponding location information and cause information of the vulnerabilities are generated. Since the vulnerability ontology information is constructed based on each function in the smart contract, each keyword in each function, and the position information of each keyword. When performing vulnerability reasoning, when it is determined that there is a vulnerability in the entity information in the vulnerability ontology information, the positions of each keyword in the entity information in the contract source code can be quickly located, so that the location of the vulnerability can be quickly located and the cause of the vulnerability can be determined. Thus, the time-consuming of locating the vulnerability and the time-consuming of judging whether the detected vulnerability is accurate are reduced. Furthermore, the time-consuming of repairing and maintaining smart contracts is reduced, and the efficiency of repairing and maintaining smart contracts is improved.
[0088] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: Through the vulnerability detection method of some embodiments of the present disclosure, the detection rate and accuracy of vulnerability detection are improved, and the time consumed for vulnerability detection is reduced. Specifically, the reasons for the low detection rate and accuracy of vulnerability detection and the long time consumption are as follows: Symbolic execution technology generally needs to be used in cooperation with Fuzz technology, and due to the influence of constraint solving performance, there are few mature applications at present. Formal verification relies on classical logical reasoning technology, and relatively abstract reasoning rules must be set. The types of vulnerabilities to be verified are affected by the reasoning rules, resulting in a low detection rate and low detection efficiency of vulnerabilities, and a long time consumption for vulnerability detection. The intelligent contract vulnerability detection based on deep learning relies on a large number of training samples. When the samples are few, the generalization ability of the trained model is poor, resulting in a low accuracy of vulnerability detection. Based on this, the vulnerability detection method of some embodiments of the present disclosure first parses the contract source code of the target intelligent contract to obtain the syntax information corresponding to the above contract source code. Thus, the syntax information corresponding to the target intelligent contract can be obtained. Then, information extraction is performed on the above syntax information to obtain the feature information of the above target intelligent contract. Thus, the feature information corresponding to the target intelligent contract can be obtained for constructing a vulnerability ontology. After that, according to the above feature information and various preset reference data type information, vulnerability ontology information is generated. Thus, the ontology information corresponding to the target intelligent contract can be obtained. Next, each vulnerability detection constraint information corresponding to each preset vulnerability type is determined. Thus, each vulnerability detection constraint information for performing vulnerability detection on the target intelligent contract can be obtained. Finally, according to the above various vulnerability detection constraint information, vulnerability detection is performed on the above vulnerability ontology information to obtain a set of vulnerability information corresponding to the above target intelligent contract. Thus, each vulnerability information of each vulnerability included in the target intelligent contract can be obtained. Also, because the vulnerability ontology information can be constructed based on the feature information of the extracted target intelligent contract, and the target intelligent contract is deduced according to each vulnerability detection constraint information and the vulnerability ontology information, so as to obtain each vulnerability information included in the target intelligent contract, thereby improving the detection rate and accuracy of vulnerability detection and reducing the time consumed for vulnerability detection.
[0089] Further referring to Figure 2 , as an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a vulnerability detection device. These device embodiments correspond to Figure 1 the method embodiments shown, and the device can be specifically applied to various electronic devices.
[0090] As shown in Figure 2As shown in the figure, the vulnerability detection device 200 of some embodiments includes: a parsing unit 201, an extraction unit 202, a generation unit 203, a determination unit 204, and a detection unit 205. Among them, the parsing unit 201 is configured to perform syntax parsing on the contract source code of the target smart contract to obtain the syntax information corresponding to the contract source code; the extraction unit 202 is configured to perform information extraction on the syntax information to obtain the feature information of the target smart contract; the generation unit 203 is configured to generate vulnerability ontology information according to the feature information and various preset reference data type information; the determination unit 204 is configured to determine various vulnerability detection constraint information corresponding to each preset vulnerability type; the detection unit 205 is configured to perform vulnerability detection on the vulnerability ontology information according to the various vulnerability detection constraint information to obtain a set of vulnerability information corresponding to the target smart contract.
[0091] It can be understood that the various units described in the device 200 correspond to the respective steps in the method described in the reference Figure 1 Therefore, the operations, features, and beneficial effects described above for the method also apply to the device 200 and the units included therein, and will not be repeated here.
[0092] Next, refer to Figure 3 , which shows a schematic structural diagram of an electronic device (such as a computing device) 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0093] As Figure 3 shown, the electronic device 300 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 301, which may perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 302 or the program loaded from the storage device 308 into the random access memory (RAM) 303. In the RAM 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the ROM 302, and the RAM 303 are connected to each other through a bus 304. The input / output (I / O) interface 305 is also connected to the bus 304.
[0094] Generally, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or wiredly to exchange data. AlthoughFigure 3 An electronic device 300 is shown with various devices, but it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had. Figure 3 Each block shown in may represent a device or, as needed, multiple devices.
[0095] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product that includes a computer program carried on a computer-readable medium, the computer program including program code for performing the methods shown in the flowcharts. In such some embodiments, the computer program may be downloaded and installed from a network via a communication device 309, or installed from a storage device 308, or installed from a ROM 302. When the computer program is executed by a processing device 301, the above functions defined in the methods of some embodiments of the present disclosure are performed.
[0096] It should be noted that the computer-readable medium described in some embodiments of the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. And in some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0097] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LANs"), wide area networks ("WANs"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0098] The above computer-readable medium can be included in the above electronic device; or can exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the electronic display device, the electronic device: performs syntax parsing on the contract source code of the target smart contract to obtain the syntax information corresponding to the contract source code; performs information extraction on the above syntax information to obtain the feature information of the above target smart contract; generates vulnerability ontology information according to the above feature information and each preset reference data type information; determines each vulnerability detection constraint information corresponding to each preset vulnerability type; and performs vulnerability detection on the above vulnerability ontology information according to the above each vulnerability detection constraint information to obtain a set of vulnerability information corresponding to the above target smart contract.
[0099] Computer program code for performing the operations of some embodiments of the present disclosure can be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages - such as Java, Smalltalk, C++; and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network - including a local area network (LAN) or a wide area network (WAN) - or can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).
[0100] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0101] The units described in some embodiments of the present disclosure can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes a parsing unit, an extraction unit, a generation unit, a determination unit, and a detection unit. Among them, the names of these units do not constitute a limitation on the unit itself in some cases. For example, the determination unit can also be described as "the unit for determining each vulnerability detection constraint information corresponding to each preset vulnerability type".
[0102] The functions described above can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Arrays (FPGAs), Application Specific Integrated Circuits (ASICs), Application Specific Standard Products (ASSPs), Systems on Chip (SOCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0103] The above description is only some preferred embodiments of the present disclosure and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, technical solutions formed by mutually replacing the above features with (but not limited to) technical features having similar functions disclosed in the embodiments of the present disclosure.
Claims
1. A vulnerability detection method, comprising: Performing syntax parsing on the contract source code of a target smart contract to obtain syntax information corresponding to the contract source code; Performing information extraction on the syntax information to obtain feature information of the target smart contract; Generating vulnerability ontology information based on the feature information and various preset reference data type information; Determining various vulnerability detection constraint information corresponding to various preset vulnerability types; Performing vulnerability detection on the vulnerability ontology information according to the various vulnerability detection constraint information to obtain a set of vulnerability information corresponding to the target smart contract.
2. The method according to claim 1, wherein, The performing information extraction on the syntax information to obtain the feature information of the target smart contract includes: Extracting a contract name, contract version information, and various function information from the syntax information; Generating respective keyword information lists corresponding to the various function information according to the various function information; Determining the contract name, the contract version information, the various function information, and the various keyword information lists as the feature information of the target smart contract.
3. The method according to claim 2, wherein, The generating respective keyword information lists corresponding to the various function information according to the various function information includes: For each function information in the various function information, performing the following steps: Obtaining various keywords and respective position information corresponding to the various keywords from the function information; Generating a keyword information list according to the various keywords and the respective position information.
4. The method according to claim 3, wherein, The generating a keyword information list according to the various keywords and the respective position information includes: For each keyword in the various keywords, performing the following steps: Determining vulnerability type information corresponding to the keyword; Determining the keyword, the position information corresponding to the keyword, and the vulnerability type information as keyword information; Determining the determined various keyword information as a keyword information list.
5. The method according to claim 2, wherein, The generating vulnerability ontology information based on the feature information and various preset reference data type information includes: Determining the various preset reference data type information as a first set of reference data type information; For each first reference data type information in the first set of reference data type information, performing the following steps: Determining various first reference data type information different from the first reference data type information in the first set of reference data type information as a second set of reference data type information; Determining respective association information between the first reference data type information and the various second reference data type information in the second set of reference data type information; Determining the various association information as an association information set; Combining the various preset reference data type information and the determined various association information sets into an initial vulnerability ontology model; Determining the contract name included in the feature information and the various function names included in the various function information as a label information set; For each label information in the label information set, performing the following steps: Determining the preset reference data type information corresponding to the label information from the various preset reference data type information; Determine the label attribute information corresponding to the label information according to the contract version information and each keyword information list included in the feature information; Determine the label information, the preset reference data type information corresponding to the label information, and the label attribute information corresponding to the label information as entity information; Input the determined entity information into the initial vulnerability ontology model to obtain vulnerability ontology information.
6. The method according to claim 1, wherein The determination of each vulnerability detection constraint information corresponding to each preset vulnerability type includes: For each preset vulnerability type in the various preset vulnerability types, perform the following steps: In response to determining that the preset vulnerability type is a method misuse vulnerability type, determine each vulnerability detection constraint information corresponding to the method misuse vulnerability type according to each method call keyword information corresponding to the method misuse vulnerability type; In response to determining that the preset vulnerability type is a function misdefinition vulnerability type, determine each vulnerability detection constraint information corresponding to the function misdefinition vulnerability type according to each function definition keyword information corresponding to the function misdefinition vulnerability type; In response to determining that the preset vulnerability type is a sequential dependency vulnerability type, determine each vulnerability detection constraint information corresponding to the sequential dependency vulnerability type according to each first keyword position relationship information corresponding to the sequential dependency vulnerability type; In response to determining that the preset vulnerability type is a result review vulnerability type, determine each vulnerability detection constraint information corresponding to the result review vulnerability type according to each second keyword position relationship information corresponding to the result review vulnerability type.
7. The method according to claim 5, wherein The vulnerability ontology information includes each entity information; And The vulnerability detection of the vulnerability ontology information according to the various vulnerability detection constraint information to obtain a vulnerability information set corresponding to the target smart contract includes: For each entity information included in the vulnerability ontology information, perform the following steps: According to the various vulnerability detection constraint information, determine the vulnerability set, the vulnerability location information set, and the vulnerability cause information set existing in the entity information, where the vulnerabilities in the vulnerability set correspond to the vulnerability location information in the vulnerability location information set, and the vulnerabilities in the vulnerability set correspond to the vulnerability cause information in the vulnerability cause information set; Determine the vulnerability information of the entity information as the vulnerability set, the vulnerability location information set, and the vulnerability cause information set; Determine the determined various vulnerability information as a vulnerability information set.
8. A vulnerability detection device, comprising: A parsing unit configured to perform syntax parsing on the contract source code of the target smart contract to obtain the syntax information corresponding to the contract source code; An extraction unit configured to perform information extraction on the syntax information to obtain the feature information of the target smart contract; A generation unit configured to generate vulnerability ontology information according to the feature information and each preset reference data type information; A determination unit configured to determine each vulnerability detection constraint information corresponding to each preset vulnerability type; The detection unit is configured to perform vulnerability detection on the vulnerability ontology information according to the respective vulnerability detection constraint information, so as to obtain a set of vulnerability information corresponding to the target smart contract.
9. An electronic device, comprising: One or more processors; A storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, the method according to any one of claims 1-7 is implemented.