Intelligent contract vulnerability detection method and device, computer equipment and storage medium
Through the large language model, the code of the smart contract warehouse is recognized and completed, combined with abstract syntax trees and function call graphs, the detection problem of access control vulnerabilities in the uncompiled warehouse is solved, and efficient vulnerability detection is achieved.
Patent Information
- Application Number
- CN202510440664.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-07-25
AI Technical Summary
Existing smart contract vulnerability detection tools cannot accurately locate problem code in uncompiled smart contract warehouses, making it difficult for uncompiled warehouses with access control vulnerabilities to be effectively screened.
Through a large language model, the code content of the smart contract warehouse is identified, the target function is extracted, and the code snippet is completed, the target smart contract is generated, and the abstract syntax tree and function call graph are used for vulnerability detection to determine access control vulnerabilities.
It realizes accurate positioning of problem codes and completing them in an uncompiled smart contract warehouse, effectively detecting access control vulnerabilities, and improving the accuracy and efficiency of detection.
Smart Images

Figure CN120372623A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of blockchain technology, and particularly to a method, device, computer device, and storage medium for detecting vulnerabilities in smart contracts. Background Art
[0002] A smart contract repository is a repository that contains source code, documentation, configuration files, and other development components required for building and deploying smart contracts. There are a large number of open-source smart contract repositories on various code hosting platforms, and developers often need to reuse the code in the repositories during custom development.
[0003] However, in the face of security risks such as access control vulnerabilities in smart contracts, existing smart contract vulnerability detection tools usually require the target contract to be compilable in order to generate an abstract representation of the program for subsequent analysis. They cannot accurately locate the problem code in non-compilable smart contract repositories, resulting in non-compilable repositories with access control vulnerabilities being difficult to effectively screen, increasing the potential risks of smart contract applications.
[0004] Regarding the problem in the related art that it is impossible to accurately locate the problem code in non-compilable smart contract repositories, resulting in non-compilable repositories with access control vulnerabilities being difficult to effectively screen, no effective solution has been proposed yet. Summary of the Invention
[0005] In this embodiment, a method, device, computer device, and storage medium for detecting vulnerabilities in smart contracts are provided to solve the problem in the related art that it is impossible to accurately locate the problem code in non-compilable smart contract repositories, resulting in non-compilable repositories with access control vulnerabilities being difficult to effectively screen.
[0006] In a first aspect, in this embodiment, a method for detecting vulnerabilities in smart contracts is provided, including:
[0007] Identifying the code content of a smart contract repository through a large language model to obtain the target functions in the smart contract repository; the target functions include preset operations associated with smart contracts;
[0008] Completing the code snippet corresponding to the target function to obtain a target smart contract corresponding to the code snippet;
[0009] Detecting vulnerabilities in the target smart contract, and judging whether the target smart contract has an access control vulnerability according to the detection result.
[0010] In some of these embodiments, the preset operations include at least one of a self-destruction function, a transfer operation, an external contract call, and a state variable modification.
[0011] In some of these embodiments, completing the code snippet corresponding to the objective function to obtain the target smart contract corresponding to the code snippet includes:
[0012] Extracting the code snippet corresponding to the objective function from the source code in the smart contract repository;
[0013] Inputting the code snippet into a large language model for completion processing to obtain the target smart contract corresponding to the code snippet.
[0014] In some of these embodiments, after inputting the code snippet into a large language model for completion processing to obtain the target smart contract corresponding to the code snippet, it includes:
[0015] When the compilation of the target smart contract fails, feeding back the compilation error information of the target smart contract to the large language model; the compilation error information is used to instruct the large language model to correct the target smart contract.
[0016] In some of these embodiments, detecting vulnerabilities in the target smart contract and determining whether there is an access control vulnerability in the target smart contract according to the detection result includes:
[0017] Compiling the target smart contract to obtain the abstract syntax tree of the target smart contract;
[0018] Based on the abstract syntax tree, constructing a function call graph corresponding to the target smart contract;
[0019] Detecting each target function node in the function call graph and determining whether there is an access control vulnerability in the target smart contract according to the detection result.
[0020] In some of these embodiments, detecting each target function node in the function call graph and determining whether there is an access control vulnerability in the target smart contract according to the detection result includes:
[0021] Based on the node information stored in each target function node in the function call graph, determining whether there is an access control mechanism in the target function node; the node information includes the function-level control flow graph and key function information corresponding to the target function node;
[0022] When it is detected that there is an access control mechanism in the target function node, it is determined that there is no access control vulnerability in the target smart contract.
[0023] In some of these embodiments, after determining whether there is an access control mechanism for each of the target function nodes based on the node information stored in the function call graph, the method further includes:
[0024] When it is detected that the target function node does not have the access control mechanism, perform risk operation identification on the target function node;
[0025] When there is a risk operation among the preset operations in the target function node, determine that the target smart contract has the access control vulnerability; the risk operations include at least one of a transfer operation without state change, a modification of a state variable without transfer behavior, a low-level external contract call, and a self-destruction operation.
[0026] In a second aspect, in this embodiment, a smart contract vulnerability detection device is provided, including:
[0027] An identification module, configured to identify the code content of the smart contract repository to obtain the target functions in the smart contract repository; the target functions include preset operations associated with the smart contract;
[0028] A completion module, configured to complete the code segment corresponding to the target function to obtain a target smart contract corresponding to the code segment;
[0029] A detection module, configured to perform vulnerability detection on the target smart contract, and determine whether the target smart contract has an access control vulnerability according to the detection result.
[0030] In a third aspect, in this embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the computer program, the smart contract vulnerability detection method described in the first aspect above is implemented.
[0031] In a fourth aspect, in this embodiment, a storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the smart contract vulnerability detection method described in the first aspect above is implemented.
[0032] Compared with the related art, the smart contract vulnerability detection method, device, computer device, and storage medium provided in this embodiment identify the code content of the smart contract repository to obtain the target function in the smart contract repository; the target function includes preset operations associated with the smart contract; complete the code snippet corresponding to the target function to obtain the target smart contract corresponding to the code snippet; detect vulnerabilities in the target smart contract, and determine whether the target smart contract has access control vulnerabilities according to the detection results, solving the problem that it is impossible to accurately locate the problem code in the non-compilable smart contract repository, resulting in the difficulty of effectively screening the non-compilable repository with access control vulnerabilities, and realizing the accurate location and completion of the problem code in the non-compilable smart contract repository, so as to effectively detect whether the non-compilable smart contract repository has access control vulnerabilities.
[0033] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects, and advantages of this application more concise and understandable. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] The drawings described herein are used to provide a further understanding of this application and constitute a part of this application. The illustrative embodiments and descriptions of this application are used to explain this application and do not constitute an improper limitation of this application. In the drawings:
[0035] Figure 1 is a hardware structure block diagram of a terminal device for the smart contract vulnerability detection method provided in an embodiment of this application;
[0036] Figure 2 is a flowchart of the smart contract vulnerability detection method provided in an embodiment of this application;
[0037] Figure 3 is a flowchart of the code completion method provided in an embodiment of this application;
[0038] Figure 4 is a flowchart of the access control vulnerability detection method provided in an embodiment of this application;
[0039] Figure 5 is a flowchart of the smart contract vulnerability detection method provided in a preferred embodiment of this application;
[0040] Figure 6 is a structure block diagram of the smart contract vulnerability detection device provided in an embodiment of this application.
[0041] In the figure: 102, processor; 104, memory; 106, transmission device; 108, input / output device; 10, identification module; 20, completion module; 30, detection module. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] To understand the purpose, technical solution and advantages of this application more clearly, the following describes and explains this application in conjunction with the accompanying drawings and embodiments.
[0043] Unless otherwise defined, the technical terms or scientific terms involved in this application shall have the general meaning understood by those with ordinary skills in the technical field to which this application belongs. In this application, words such as "a", "one", "a kind of", "the", "these" and the like do not indicate a limitation in quantity, and they can be singular or plural. The terms "include", "comprise", "have" and any variants thereof involved in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product or device that includes a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent in these processes, methods, products or devices. The terms "connection", "connection", "coupling" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether directly or indirectly connected. The "multiple" involved in this application refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, and B exists alone. Usually, the character " / " indicates that the objects associated before and after are an "or" relationship. The terms "first", "second", "third" and the like involved in this application only distinguish similar objects and do not represent a specific sorting of the objects.
[0044] The method embodiment provided in this embodiment can be executed on a terminal, a computer or a similar computing device. For example, running on a terminal Figure 1 is the hardware structure block diagram of the terminal of the smart contract vulnerability detection method of this embodiment. As Figure 1 shown, the terminal may include one or more ( Figure 1 only one is shown in Figure 1 a) processor 102 and a memory 104 for storing data, wherein the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA. The above terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown Figure 1 is only schematic and does not limit the structure of the above terminal. For example, the terminal may further include more or fewer components than
[0045] The memory 104 can be used to store computer programs, such as software programs and modules of application software, such as the computer program corresponding to the intelligent contract vulnerability detection method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories can be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.
[0046] The transmission device 106 is used to receive or send data via a network. The above network includes the wireless network provided by the communication provider of the terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0047] In this embodiment, an intelligent contract vulnerability detection method is provided. Figure 2 It is the flowchart of the intelligent contract vulnerability detection method in this embodiment, as Figure 2 shown, and this process includes the following steps:
[0048] Step S210, identify the code content of the intelligent contract repository through a large language model to obtain the target function in the intelligent contract repository; the target function contains preset operations associated with the intelligent contract.
[0049] Step S220, complete the code segment corresponding to the target function to obtain the target intelligent contract corresponding to the code segment.
[0050] Step S230, perform vulnerability detection on the target intelligent contract, and determine whether the target intelligent contract has an access control vulnerability according to the detection result.
[0051] Specifically, a filtering operation is pre - performed on the smart contract repository to exclude non - production code in the smart contract repository according to the repository directory structure, such as non - production code related to the test directory, reusable code library, interfaces for defining contracts, etc., so as to screen out the code content related to the operation of the smart contract. Then, the large - language model is used to identify the target functions in the filtered code content, so that only the key code needs to be extracted for analysis, which is applicable to complex smart contract scenarios and improves the analysis efficiency. Among them, the target function refers to a sensitive function that affects aspects such as system security, asset transfer, function interaction, and data status. The target function usually includes preset operations associated with the smart contract, and the preset operations include self - destruct functions, transfer operations, external contract calls, and state variable modifications, etc.
[0052] Furthermore, the code snippet corresponding to the target function is extracted from the source code of the smart contract repository, and the code snippet is completed through the large - language model to obtain the target smart contract corresponding to the code snippet, so as to obtain a complete and compilable smart contract.
[0053] After that, the target smart contract is compiled by a compiler to obtain the Abstract Syntax Tree (AST) of the target smart contract. The abstract syntax tree represents the intermediate representation of the syntax structure of the smart contract code in a tree - like structure, so as to provide the code logical structure. Based on the function call information in the abstract syntax tree, a Function Call Graph (FCG) corresponding to the target smart contract is constructed. The function call graph is a directed graph used to represent the call relationship between functions. The function call graph contains multiple target function nodes, and the node information stored in each target function node in the function call graph is obtained, including the function - level control flow graph and key function information corresponding to the target function node, etc. The key function information includes but is not limited to function name, function type, function visibility, and whether it is a sensitive function. Based on the node information stored in each target function node, it is judged whether there is an access control mechanism for the target function node.
[0054] Among them, if it is detected that there is an access control mechanism for the target function node, it is determined as a secure function, and there is no access control vulnerability in the target smart contract; on the contrary, risk operation identification is performed on the target function node. If there are risk operations in the preset operations for the target function node, such as transfer operations without state changes, state variable modifications without transfer behavior, low - level external contract calls, and self - destruct operations, etc., it is determined that there is an access control vulnerability in the target smart contract.
[0055] Exemplarily, an uncompilable smart contract repository is obtained from the GitHub platform. The objective function of the smart contract repository is extracted through a large language model to obtain a code snippet containing preset operations in a certain smart contract source file, and the code snippet is completed through the large language model to obtain a target smart contract. The target smart contract is compiled. If the compilation fails, the compilation error information of the target smart contract is fed back to the large language model to instruct the large language model to correct the target smart contract until the output target smart contract is successfully compiled. The abstract syntax tree of the target smart contract is generated through the Solidity compiler. Based on the function call information in the abstract syntax tree, the static analysis tool Slither is used to construct the function call graph corresponding to the target smart contract, and the donate function in the function call graph is analyzed. If it is detected that the function does not verify the permissions of the function caller and there is a self-destruction operation, it is marked that the target smart contract has an access control vulnerability.
[0056] Facing security risks such as access control vulnerabilities in smart contracts, existing smart contract vulnerability detection tools usually require the target contract to be compilable in order to generate an abstract representation of the program for subsequent analysis, and it is impossible to accurately locate the problem code in an uncompilable smart contract repository, resulting in uncompilable repositories with access control vulnerabilities being difficult to effectively screen, increasing the potential risks of smart contract applications.
[0057] Compared with the prior art, in this application, the code content of the smart contract repository is identified to obtain the target function in the smart contract repository; the target function includes preset operations associated with the smart contract; the code snippet corresponding to the target function is completed to obtain the target smart contract corresponding to the code snippet; the target smart contract is detected for vulnerabilities, and it is judged whether the target smart contract has an access control vulnerability according to the detection result, solving the problem that it is impossible to accurately locate the problem code in an uncompilable smart contract repository, resulting in uncompilable repositories with access control vulnerabilities being difficult to effectively screen, and realizing accurately locating the problem code in an uncompilable smart contract repository and completing it, so as to effectively detect whether the uncompilable smart contract repository has an access control vulnerability, thus eliminating the need to configure a compilation environment and solving the compilation dependency problem by directly analyzing the smart contract repository.
[0058] In some of these embodiments, the preset operations include at least one of a self-destruction function, a transfer operation, an external contract call, and a state variable modification.
[0059] Specifically, the target function refers to a sensitive function that affects aspects such as system security, asset transfer, function interaction, and data status. The target function usually includes preset operations associated with the smart contract, and the preset operations include a self-destruction function, a transfer operation, an external contract call, and a state variable modification, etc.
[0060] Among them, the self-destruction function is used to completely remove the smart contract from the blockchain and transfer the funds held by the smart contract to a specified address; the transfer operation refers to the transfer of funds between different accounts; the external contract call is used to call other contracts to achieve interaction and cooperation between different contracts; the state variable modification refers to changing the value of the internal state variable of the contract, which is used to record various state information of the contract, such as the contract owner, transaction count, etc. The state variable modification will affect the subsequent logical execution of the contract.
[0061] Through this embodiment, setting the preset operations to include the self-destruction function, transfer operation, external contract call, and state variable modification can accurately screen out the target functions in the warehouse code content through large language model analysis, which helps to improve the accuracy of locating the problem code.
[0062] In some of the embodiments, as Figure 3 shown, completing the code snippet corresponding to the target function in step S220 to obtain the target smart contract corresponding to the code snippet includes the following steps:
[0063] Step S221, extract the code snippet corresponding to the target function from the source code of the smart contract warehouse;
[0064] Step S222, input the code snippet into the large language model for completion processing to obtain the target smart contract corresponding to the code snippet.
[0065] Specifically, through the semantic positioning of the large language model, determine the function signature of the target function, and according to the function signature, extract the code snippet corresponding to the target function from the source code of the smart contract warehouse, and input the code snippet into the large language model for completion processing to obtain the target smart contract corresponding to the code snippet.
[0066] Among them, after the large language model outputs the completed code, determine whether the completed code can be successfully compiled. If the compilation fails, feedback the compilation error information to the large language model to indicate the large language model to correct the code supplementation process; if the compilation is successful, perform subsequent vulnerability detection on the target smart contract.
[0067] Through this embodiment, extract the code snippet corresponding to the target function from the source code of the smart contract warehouse, input the code snippet into the large language model for completion processing to obtain the target smart contract corresponding to the code snippet, and realize the completion of the code snippet, so as to effectively detect whether there is an access control vulnerability in the non-compilable smart contract warehouse.
[0068] In some of the embodiments, after inputting the code snippet into the large language model for completion processing to obtain the target smart contract corresponding to the code snippet, it includes the following steps:
[0069] When the compilation of the target smart contract fails, the compilation error information of the target smart contract is fed back to the large language model; the compilation error information is used to instruct the large language model to correct the target smart contract.
[0070] Specifically, after the large language model performs the completion process, if the output target smart contract fails to compile, record the compilation error information of the target smart contract, and feed back the compilation error information to the large language model to instruct the large language model to correct the target smart contract until a target smart contract that can be successfully compiled is output, or a preset number of iterations is reached. For example, the preset number of iterations is 5 times.
[0071] The above compilation error information includes syntax errors in the code, parameter or variable type errors, scope errors, version errors, etc. For example, when calling a function, the type of the passed parameter is inconsistent with the type of the parameter defined in the function, or an undefined variable or function is used in the current scope, or the syntax used in the current contract code is incompatible with the current compiler version, etc. It should be noted that according to common compilation error types, corresponding correction methods can be preset in advance, that is, for different error types, detection step guidelines are set for the large language model to check and correct according to the correct ideas, effectively improving the correction efficiency.
[0072] Through this embodiment, when the compilation of the target smart contract fails, the compilation error information of the target smart contract is fed back to the large language model to instruct the large language model to correct the target smart contract, so that through the self-feedback mechanism, the stable output of the large language model can be ensured, avoiding the inability to compile the code after completion, and helping to improve the success rate of non-compiled repository analysis.
[0073] In some of the embodiments, as Figure 4 shown, the vulnerability detection of the target smart contract in step S230, and judging whether the target smart contract has an access control vulnerability according to the detection result includes the following steps:
[0074] Step S231, compile the target smart contract to obtain the abstract syntax tree of the target smart contract;
[0075] Step S232, based on the abstract syntax tree, construct a function call graph corresponding to the target smart contract;
[0076] Step S233, detect each target function node in the function call graph, and judge whether the target smart contract has an access control vulnerability according to the detection result.
[0077] Specifically, the target smart contract is compiled through Solidity compiler, Vyper compiler, etc., to obtain the abstract syntax tree of the target smart contract. The abstract syntax tree is an intermediate representation form that represents the syntax structure of the smart contract code in a tree structure and is used to provide the code logic structure.
[0078] Furthermore, according to the function call information in the abstract syntax tree, a function call graph corresponding to the target smart contract is constructed. Through a suitable static analysis tool, such as Slither, Mythril, and Solhint, etc., a corresponding function-level control flow graph (Function-level Control FlowGraph, CFG) is generated for each target function node in the function call graph. The function-level control flow graph is a directed graph used to represent the internal control flow structure of a function, and the function-level control flow graph corresponding to the target function node and the key function information are stored in the corresponding nodes. The key function information includes function name, function type, function visibility, and whether it is a sensitive function, etc., so as to provide an accurate program logic representation for vulnerability detection.
[0079] After that, for each target function node in the function call graph, analyze the function-level control flow graph and key function information stored in each node on its call chain to detect whether the function has an access control mechanism, that is, whether the identity of the corresponding function caller is checked. If there is a check, it is determined as a secure function, that is, the target smart contract does not have an access control vulnerability; otherwise, risk operation identification needs to be performed on the target function node. If there is a risk operation, it can be determined that the target smart contract has an access control vulnerability.
[0080] Through this embodiment, the target smart contract is compiled to obtain the abstract syntax tree of the target smart contract. Based on the abstract syntax tree, a function call graph corresponding to the target smart contract is constructed, and each target function node in the function call graph is detected. According to the detection results, it is judged whether the target smart contract has an access control vulnerability, so as to perform logical verification in combination with static analysis technology on the basis of using the large language model to extract and complete the code, and achieve high-precision vulnerability detection.
[0081] In some of these embodiments, detecting each target function node in the function call graph and judging whether the target smart contract has an access control vulnerability according to the detection results in step S233 includes the following steps:
[0082] Based on the node information stored in each target function node in the function call graph, judge whether the target function node has an access control mechanism; the node information includes the function-level control flow graph and key function information corresponding to the target function node;
[0083] When it is detected that there is an access control mechanism in the target function node, it is determined that the target smart contract does not have an access control vulnerability.
[0084] Specifically, obtain the node information stored in each target function node in the function call graph. The node information includes the function-level control flow graph corresponding to the target function node and key function information. The key function information includes function name, function type, function visibility, and whether it is a sensitive function, etc.
[0085] Furthermore, analyze the node information stored in each target function node to detect whether there is an access control mechanism in the function, that is, whether to check the identity of the corresponding function caller. Among them, if there is a check on the identity of the corresponding function caller, it indicates that there is an access control mechanism in the corresponding function, and it is determined as a secure function.
[0086] Through this embodiment, based on the node information stored in each target function node in the function call graph, determine whether there is an access control mechanism in the target function node. The node information includes the function-level control flow graph corresponding to the target function node and key function information, and when it is detected that there is an access control mechanism in the target function node, it is determined that the target smart contract does not have an access control vulnerability, thereby improving the accuracy of vulnerability detection.
[0087] In some of these embodiments, after determining whether there is an access control mechanism in the target function node based on the node information stored in each target function node in the function call graph, the above smart contract vulnerability detection method further includes the following steps:
[0088] When it is detected that there is no access control mechanism in the target function node, perform risk operation identification on the target function node;
[0089] When there is a risk operation in the preset operations in the target function node, it is determined that the target smart contract has an access control vulnerability; the risk operations include at least one of a transfer operation without state change, a modification of a state variable without transfer behavior, a low-level external contract call, and a self-destruction operation.
[0090] Specifically, if it is detected that there is no access control mechanism in the target function node, that is, the identity of the corresponding function caller is not checked, then perform risk operation identification on the target function node to determine whether there is a risk operation in the preset operations in the target function node.
[0091] Among them, risky operations include transfer operations without state changes, modification of state variables without transfer actions, low-level external contract calls, and self-destruction operations. Transfer operations without state changes refer to situations where, when a smart contract performs a transfer operation, the state variables of the contract are not updated or checked accordingly, leaving vulnerabilities that can be exploited by attackers, potentially resulting in reentrancy attacks. Modification of state variables without transfer actions refers to modifying state variables in a smart contract without involving actual transfer actions. For example, a state variable used to record user permissions is maliciously modified, leading to privilege escalation or abuse, enabling attackers to gain additional control over the contract and execute unauthorized operations. Low-level external contract calls refer to smart contracts using the underlying function call mechanism to call other external contracts. Since the code and behavior of external contracts cannot be fully trusted, such calls pose relatively high risks. Self-destruction operations refer to permanently deleting a smart contract from the blockchain through specific functions or instructions and transferring the funds held by the contract to a specified address. This operation is irreversible and highly risky.
[0092] Furthermore, when there are no risky operations in the target function node, it is determined that the target smart contract does not have an access control vulnerability. When there is any risky operation in the target function node, it is determined that the target smart contract has an access control vulnerability.
[0093] Through this embodiment, when it is detected that the target function node does not have an access control mechanism, risk operation identification is performed on the target function node. When there is a risk operation among the preset risks in the target function node, it is determined that the target smart contract has an access control vulnerability, thereby accurately detecting contract vulnerabilities.
[0094] The following describes and illustrates this embodiment through preferred embodiments.
[0095] Figure 5 is a flowchart of the smart contract vulnerability detection method of this preferred embodiment, as Figure 5 shown. The smart contract vulnerability detection method includes the following steps:
[0096] Step S510, perform a filtering operation on the smart contract repository, and exclude non-production code in the smart contract repository according to the repository directory structure;
[0097] Step S520, use a large language model to identify the filtered code content to obtain the target functions in the smart contract repository; the target functions include at least one preset operation among self-destruction functions, transfer operations, external contract calls, and state variable modifications;
[0098] Step S530, use a large language model to complete the code snippet corresponding to the target function to obtain the target smart contract corresponding to the code snippet;
[0099] Step S540: Compile the target smart contract to obtain the abstract syntax tree of the target smart contract, and based on the abstract syntax tree, construct a function call graph corresponding to the target smart contract;
[0100] Step S550: Based on the node information stored in each target function node in the function call graph, determine whether there is an access control mechanism for the target function node; the node information includes the function-level control flow graph and key function information corresponding to the target function node;
[0101] Step S560: When it is detected that there is an access control mechanism for the target function node, determine that the target smart contract does not have an access control vulnerability;
[0102] Step S570: When it is detected that there is no access control mechanism for the target function node and the target function node has a risk operation in the preset operations, determine that the target smart contract has an access control vulnerability; the risk operations include at least one of a transfer operation without state change, a modification of a state variable without transfer behavior, a low-level external contract call, and a self-destruction operation.
[0103] In this embodiment, a filtering operation is performed on the smart contract repository, non-production code in the smart contract repository is excluded according to the repository directory structure, and the filtered code content is identified by a large language model to obtain the target functions in the smart contract repository. The target functions include at least one preset operation among self-destruction functions, transfer operations, external contract calls, and state variable modifications.
[0104] Furthermore, the code snippet corresponding to the target function is completed by a large language model to obtain the target smart contract corresponding to the code snippet. The target smart contract is compiled to obtain the abstract syntax tree of the target smart contract. Based on the abstract syntax tree, a function call graph corresponding to the target smart contract is constructed, and based on the function-level control flow graph and key function information stored in each target function node in the function call graph, it is determined whether there is an access control mechanism for the target function node. Among them, when it is detected that there is an access control mechanism for the target function node, it is determined that the target smart contract does not have an access control vulnerability, and when it is detected that there is no access control mechanism for the target function node and the target function node has a risk operation in the preset operations, it is determined that the target smart contract has an access control vulnerability. The risk operations include at least one of a transfer operation without state change, a modification of a state variable without transfer behavior, a low-level external contract call, and a self-destruction operation. This solves the problem that it is impossible to accurately locate the problem code in an uncompilable smart contract repository, resulting in the difficulty of effectively screening an uncompilable repository with access control vulnerabilities. On the basis of using a large language model to extract and complete the code, combined with static analysis technology for logical verification, high-precision vulnerability detection is achieved.
[0105] It should be noted that the steps shown in the above process or the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0106] In this embodiment, an intelligent contract vulnerability detection device is also provided. This device is used to implement the above-mentioned embodiments and preferred implementation manners, and those that have been described will not be repeated here. The following terms such as "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0107] Figure 6 is a structural block diagram of the intelligent contract vulnerability detection device of this embodiment, as Figure 6 shown, this device includes:
[0108] An identification module 10, configured to identify the code content of the intelligent contract repository to obtain the target functions in the intelligent contract repository; the target functions include preset operations associated with the intelligent contract;
[0109] A completion module 20, configured to complete the code segment corresponding to the target function to obtain a target intelligent contract corresponding to the code segment;
[0110] A detection module 30, configured to perform vulnerability detection on the target intelligent contract, and determine whether there is an access control vulnerability in the target intelligent contract according to the detection result.
[0111] Through the device provided in this embodiment, the code content of the intelligent contract repository is identified to obtain the target functions in the intelligent contract repository; the target functions include preset operations associated with the intelligent contract; the code segment corresponding to the target function is completed to obtain a target intelligent contract corresponding to the code segment; vulnerability detection is performed on the target intelligent contract, and it is determined whether there is an access control vulnerability in the target intelligent contract according to the detection result, which solves the problem that it is impossible to accurately locate the problem code in an uncompilable intelligent contract repository, resulting in the difficulty of effectively screening an uncompilable repository with an access control vulnerability, and realizes accurately locating the problem code in an uncompilable intelligent contract repository and completing it, so as to effectively detect whether there is an access control vulnerability in the uncompilable intelligent contract repository.
[0112] In some of these embodiments, the completion module 20 is further configured to extract the code segment corresponding to the target function from the source code of the intelligent contract repository; input the code segment into a large language model for completion processing to obtain a target intelligent contract corresponding to the code segment.
[0113] In some of these embodiments, on the basis of Figure 6 , the device further includes a correction module, configured to feed back the compilation error information of the target smart contract to the large language model when the compilation of the target smart contract fails; the compilation error information is used to instruct the large language model to correct the target smart contract.
[0114] In some of these embodiments, the detection module 30 is further configured to compile the target smart contract to obtain the abstract syntax tree of the target smart contract; based on the abstract syntax tree, construct a function call graph corresponding to the target smart contract; detect each target function node in the function call graph, and determine whether the target smart contract has an access control vulnerability according to the detection result.
[0115] In some of these embodiments, the detection module 30 is further configured to determine whether there is an access control mechanism for each target function node based on the node information stored in each target function node in the function call graph; the node information includes the function-level control flow graph and key function information corresponding to the target function node; when it is detected that there is an access control mechanism for the target function node, it is determined that the target smart contract does not have an access control vulnerability.
[0116] In some of these embodiments, on the basis of Figure 6 , the device further includes a risk identification module, configured to perform risk operation identification on the target function node when it is detected that the target function node does not have an access control mechanism; when the target function node has a risk operation among the preset operations, it is determined that the target smart contract has an access control vulnerability; the risk operations include at least one of a transfer operation without state change, a modification of a state variable without a transfer behavior, a low-level external contract call, and a self-destruction operation.
[0117] It should be noted that the above-mentioned various modules can be functional modules or program modules, and can be implemented either by software or by hardware. For the modules implemented by hardware, the above-mentioned various modules can be located in the same processor; or the above-mentioned various modules can also be located in different processors in any combination form.
[0118] In this embodiment, a computer device is further provided, including a memory and a processor, where a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0119] Optionally, the above computer device may further include a transmission device and input / output devices, where the transmission device is connected to the above processor, and the input / output devices are connected to the above processor.
[0120] Optionally, in this embodiment, the above-mentioned processor may be configured to execute the following steps by a computer program:
[0121] S1. Identify the code content of the smart contract repository to obtain the target functions in the smart contract repository; the target functions include preset operations associated with the smart contract.
[0122] S2. Complete the code snippet corresponding to the target function to obtain the target smart contract corresponding to the code snippet.
[0123] S3. Detect vulnerabilities in the target smart contract, and determine whether there are access control vulnerabilities in the target smart contract according to the detection results.
[0124] It should be noted that the specific examples in this embodiment may refer to the examples described in the above-mentioned embodiment and optional implementation manners, and will not be elaborated in this embodiment.
[0125] In addition, in combination with the smart contract vulnerability detection method provided in the above-mentioned embodiment, a storage medium may also be provided in this embodiment to implement it. A computer program is stored on the storage medium; when the computer program is executed by the processor, any one of the smart contract vulnerability detection methods in the above-mentioned embodiment is implemented.
[0126] It should be understood that the specific embodiments described here are only used to explain this application, rather than to limit it. According to the embodiments provided in this application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of this application.
[0127] Obviously, the accompanying drawings are only some examples or embodiments of this application. For those of ordinary skill in the art, this application can also be applied to other similar situations according to these drawings without creative work. In addition, it can be understood that although the work done during the development process here may be complex and time-consuming, for those of ordinary skill in the art, certain design, manufacturing, or production changes based on the technical content disclosed in this application are only conventional technical means and should not be regarded as insufficient disclosure of this application.
[0128] The term "embodiment" in this application means that the specific features, structures, or characteristics described in combination with the embodiment may be included in at least one embodiment of this application. The phrase appears in various positions in the specification does not necessarily mean the same embodiment, nor does it mean being independent or alternative to other embodiments and mutually exclusive. Those of ordinary skill in the art can clearly or implicitly understand that the embodiments described in this application can be combined with other embodiments without conflict.
[0129] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the scope of patent protection. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. An intelligent contract vulnerability detection method, characterized in that, Including: Identifying the code content of the smart contract repository through a large language model to obtain the target functions in the smart contract repository; The target functions include preset operations associated with smart contracts; Completing the code snippet corresponding to the target function to obtain the target smart contract corresponding to the code snippet; Performing vulnerability detection on the target smart contract, and judging whether the target smart contract has an access control vulnerability according to the detection result.
2. The intelligent contract vulnerability detection method according to claim 1, characterized in that The preset operations include at least one of a self-destruction function, a transfer operation, an external contract call, and a state variable modification.
3. The intelligent contract vulnerability detection method according to any one of claims 1 to 2, characterized in that, The step of completing the code snippet corresponding to the target function to obtain the target smart contract corresponding to the code snippet includes: Extracting the code snippet corresponding to the target function from the source code of the smart contract repository; Inputting the code snippet into a large language model for completion processing to obtain the target smart contract corresponding to the code snippet.
4. The intelligent contract vulnerability detection method according to claim 3, wherein, After the step of inputting the code snippet into a large language model for completion processing to obtain the target smart contract corresponding to the code snippet, it includes: When the target smart contract fails to compile, feeding back the compilation error information of the target smart contract to the large language model; the compilation error information is used to instruct the large language model to correct the target smart contract.
5. The intelligent contract vulnerability detection method according to claim 1, characterized in that The step of performing vulnerability detection on the target smart contract and judging whether the target smart contract has an access control vulnerability according to the detection result includes: Compiling the target smart contract to obtain the abstract syntax tree of the target smart contract; Based on the abstract syntax tree, constructing a function call graph corresponding to the target smart contract; Detecting each target function node in the function call graph, and judging whether the target smart contract has the access control vulnerability according to the detection result.
6. The intelligent contract vulnerability detection method according to claim 5, wherein The step of detecting each target function node in the function call graph and judging whether the target smart contract has the access control vulnerability according to the detection result includes: Based on the node information stored in each target function node in the function call graph, judging whether the target function node has an access control mechanism; the node information includes the function-level control flow graph and key function information corresponding to the target function node; When it is detected that the target function node has an access control mechanism, it is determined that the target smart contract does not have the access control vulnerability.
7. The intelligent contract vulnerability detection method according to claim 5, wherein, After judging whether the target function node has an access control mechanism based on the node information stored in each target function node in the function call graph, the method further includes: When it is detected that the target function node does not have the access control mechanism, performing risk operation identification on the target function node; When the target function node has a risk operation in the preset operations, it is determined that the target smart contract has the access control vulnerability; the risk operations include at least one of a transfer operation without state change, a state variable modification without transfer behavior, a low-level external contract call, and a self-destruction operation.
8. An intelligent contract vulnerability detection device, characterized in that, Including: An identification module, configured to identify the code content of the smart contract repository to obtain the target function in the smart contract repository; The target function includes preset operations associated with the smart contract; A completion module, configured to complete the code snippet corresponding to the target function to obtain a target smart contract corresponding to the code snippet; A detection module, configured to detect vulnerabilities in the target smart contract, and determine whether there is an access control vulnerability in the target smart contract according to the detection result.
9. A computer device, comprising a memory and a processor, characterized in that, A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps of the smart contract vulnerability detection method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the smart contract vulnerability detection method according to any one of claims 1 to 7 are implemented.