Intelligent contract code auditing method and device, computer equipment and storage medium
By using a large language model and CodeQL analysis algorithm, an abstract syntax tree database is constructed to identify target information in smart contract code, solving the problem of low efficiency in existing smart contract code auditing technologies and achieving efficient and accurate code auditing.
Patent Information
- Application Number
- CN202510846243.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-10-24
AI Technical Summary
Existing technologies for smart contract code auditing are inefficient and inaccurate, failing to achieve efficient and accurate smart contract code auditing.
By analyzing smart contract code and related data using a large language model, target information is identified, an abstract syntax tree database is constructed and enhanced, and code vulnerabilities are identified using CodeQL analysis algorithms.
It improves the efficiency and accuracy of smart contract code auditing, can adapt to different smart contracts, and enhances processing flexibility.
Smart Images

Figure CN120832672A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a smart contract code auditing method and device, a computer device and a storage medium. BACKGROUND
[0002] A smart contract is an automatically executed computer program that runs based on blockchain technology and defines and automatically executes contract terms through code. Once deployed, a smart contract cannot be modified at will, and directly controls the flow of digital assets. Security vulnerabilities or logical defects hidden in the code may cause irreparable asset losses. Therefore, it is necessary to audit the smart contract in advance.
[0003] In existing auditing methods, manual code auditing is usually used to obtain relatively accurate audit results, or online processing with the aid of a computer device is used, but the current online processing process relies on human-computer interaction to achieve. Therefore, the above methods have the problems of low processing efficiency and high cost, and cannot achieve efficient and accurate smart contract code auditing.
[0004] In view of the problem in the related art that efficient and accurate smart contract code auditing cannot be achieved, no effective solution has been proposed so far. SUMMARY
[0005] A smart contract code auditing method, device, computer device and storage medium are provided in the present embodiment to solve the problem in the related art that efficient and accurate smart contract code auditing cannot be achieved.
[0006] In a first aspect, a smart contract code auditing method is provided in the present embodiment, comprising:
[0007] obtaining a smart contract code to be audited and associated data of the smart contract code;
[0008] analyzing the smart contract code and the associated data of the smart contract code by a large language model to obtain target information in the smart contract code; the target information includes a target method and a target variable;
[0009] performing vulnerability identification on the smart contract code based on the target information in the smart contract code to obtain a corresponding identification result.
[0010] In some embodiments, the analysis process of the large language model comprises:
[0011] analyzing the smart contract code and the associated data of the smart contract code to obtain a plurality of key behaviors and a plurality of key variables corresponding to the smart contract code;
[0012] determine whether each of the key behaviors and each of the key variables has a security risk;
[0013] determine that the key behavior having the security risk is the target method, and the key variable having the security risk is the target variable.
[0014] In some embodiments, the vulnerability identification of the smart contract code based on the target information in the smart contract code comprises:
[0015] constructing an abstract syntax tree database corresponding to the smart contract code; the abstract syntax tree database comprises a plurality of syntax nodes;
[0016] enhancing the abstract syntax tree database based on the target information in the smart contract code;
[0017] vulnerability identification of the smart contract code based on the enhanced abstract syntax tree database.
[0018] In some embodiments, the construction of the abstract syntax tree database corresponding to the smart contract code comprises:
[0019] parsing the smart contract code to be audited to obtain a corresponding parsing result;
[0020] Converting the smart contract code into a corresponding abstract syntax tree database based on the parsing result.
[0021] In some embodiments, the enhancing of the abstract syntax tree database based on the target information in the smart contract code comprises:
[0022] determining a plurality of syntax nodes in the abstract syntax tree database corresponding to the target information;
[0023] adding a label to each of the syntax nodes corresponding to the target information.
[0024] In some embodiments, the vulnerability identification of the smart contract code based on the enhanced abstract syntax tree database comprises:
[0025] determining that an external variable corresponding to the smart contract code is a source point;
[0026] determining that a target function corresponding to the syntax node with the label is a sink point;
[0027] based on the source point and the sink point, analyzing the enhanced abstract syntax tree database through a code analysis algorithm;
[0028] According to the analysis result, it is determined whether the smart contract code has a code vulnerability.
[0029] In some embodiments, the method further includes:
[0030] When the analysis result indicates that the call chain of the target function uses the parameters of the target function, it is determined that the smart contract code has a code vulnerability.
[0031] In a second aspect, an embodiment of the present disclosure provides a smart contract code auditing apparatus, comprising:
[0032] An acquisition module is configured to acquire a smart contract code to be audited and associated information of the smart contract code.
[0033] An analysis module is configured to analyze the smart contract code and the associated information of the smart contract code by using a large language model to obtain target information in the smart contract code; the target information includes a target method and a target variable.
[0034] An identification module is configured to identify a vulnerability in the smart contract code based on the target information in the smart contract code to obtain a corresponding identification result.
[0035] In a third aspect, an embodiment of the present disclosure provides a computer device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the smart contract code auditing method of the first aspect when executing the computer program.
[0036] In a fourth aspect, an embodiment of the present disclosure provides a storage medium having a computer program stored thereon, and the program is executable by a processor to implement the smart contract code auditing method of the first aspect.
[0037] Compared with the related art, the smart contract code auditing method, apparatus, computer device, and storage medium provided in the embodiments can acquire a smart contract code to be audited and associated information of the smart contract code, analyze the smart contract code and the associated information of the smart contract code by using a large language model to obtain target information in the smart contract code, identify a vulnerability in the smart contract code based on the target information in the smart contract code to obtain a corresponding identification result, solve the problem that efficient and accurate smart contract code auditing cannot be achieved, improve the efficiency and accuracy of smart contract code auditing, and directly adapt to different smart contracts to improve the flexibility of processing.
[0038] The details of one or more embodiments of the application are set forth in the accompanying drawings and the description below. Other features, objects, and advantages of the application will be apparent from the description and drawings, and from the claims. BRIEF DESCRIPTION OF DRAWINGS
[0039] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and serve to explain the principles of the application. In the drawings:
[0040] Figure 1 is a hardware structure block diagram of a terminal device of the smart contract code auditing method provided by an embodiment of the application;
[0041] Figure 2 is a flowchart of the smart contract code auditing method provided by an embodiment of the application;
[0042] Figure 3 is a flowchart of the large language model analysis method provided by an embodiment of the application;
[0043] Figure 4 is a flowchart of the smart contract code vulnerability identification method provided by an embodiment of the application;
[0044] Figure 5 is a flowchart of the smart contract code auditing method provided by a preferred embodiment of the application;
[0045] Figure 6 is a structure block diagram of the smart contract code auditing device provided by an embodiment of the application.
[0046] In the figure: 102, processor; 104, memory; 106, transmission device; 108, input and output device; 10, acquisition module; 20, analysis module; 30, identification module. DETAILED DESCRIPTION
[0047] In order to more clearly understand the purpose, technical scheme and advantages of the application, the application is described and explained below in conjunction with the drawings and embodiments.
[0048] Unless otherwise defined, technical terms or scientific terms used in the present application shall have the same meaning as those commonly understood by a person of ordinary skill in the art to which the present application belongs. The terms "one", "a", "an", "the", "these", and similar terms in the present application do not indicate quantity of limitation, and they can be singular or plural. The terms "include", "contain", "have", and any variants thereof in the present application are intended to cover non-exclusive inclusion; for example, a process, method, and system, product or device containing a series of steps or modules (units) are not limited to the listed steps or modules (units), but can include steps or modules (units) not listed, or can include other steps or modules (units) inherent to the process, method, product or device. The terms "connect", "connect", "couple" and similar terms in the present application are not limited to physical or mechanical connection, but can include electrical connection, whether direct or indirect. The term "multiple" in the present application refers to two or more. The term "and / or" describes the association between the associated objects, which means that there can be three relationships, for example, "A and / or B" can mean that A exists alone, A and B exist together, and B exists alone. Generally, the character " / " represents an "or" relationship between the objects before and after. The terms "first", "second", "third" and the like in the present application are only used to distinguish similar objects, and do not represent a specific order of the objects.
[0049] The method embodiments provided in the present embodiment can be executed in a terminal, a computer or a similar computing device. For example, the method embodiments are executed on a terminal, Figure 1 is a hardware structure block diagram of the terminal of the smart contract code auditing method of the present embodiment. As shown in Figure 1 , the terminal can include one or more (only one in Figure 1 ) processor 102 and memory 104 for storing data, wherein the processor 102 can include but not limited to processing devices such as microprocessor MCU or programmable logic device FPGA. The above terminal can also include a transmission device 106 for communication function and an input and output device 108. Those skilled in the art can understand that Figure 1 The structure shown is only schematic, which does not limit the structure of the above terminal. For example, the terminal can include more or less components than those shown in Figure 1 , or have a different configuration from that shown in Figure 1 .
[0050] The memory 104 can be used to store computer programs, such as software programs of application software and modules, such as the computer program corresponding to the smart contract code auditing method in the embodiment. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, that is, implements the method described above. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor 102, which can be connected to the terminal through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0051] The transmission device 106 is used to receive or send data via a network. The above-mentioned network includes a wireless network provided by a communication provider of the terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC) which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (Radio Frequency, RF) module which is used to communicate with the Internet in a wireless manner.
[0052] In the embodiment, a smart contract code auditing method is provided, Figure 2 The flowchart of the smart contract code auditing method of the embodiment is shown in FIG. 2, which includes the following steps: Figure 2
[0053] In step S210, the smart contract code to be audited and the associated data of the smart contract code are obtained.
[0054] In step S220, the smart contract code and the associated data of the smart contract code are analyzed by a large language model to obtain target information in the smart contract code; the target information includes a target method and a target variable.
[0055] In step S230, based on the target information in the smart contract code, a vulnerability in the smart contract code is identified to obtain a corresponding identification result.
[0056] Specifically, the smart contract code to be audited and the associated data of the smart contract code are obtained. The associated data of the smart contract code includes but is not limited to product documents, user manuals, design specifications, service level agreements (Service Level Agreement, SLA), threat models related to the product implemented by the smart contract.
[0057] By means of a large language model, the smart contract code and the associated data of the smart contract code are analyzed, such as a generative pre-trained transformer (GPT) or Llama, to understand the key behaviors and key events of the product implemented by the smart contract, and to obtain target information in the smart contract code based on the analysis of the key behaviors and key events, the target information including target methods and target variables.
[0058] Among them, the target method refers to a dangerous method that has an impact on security, such as a method that directly returns the current price of a certain currency when the smart contract is used as a price oracle; the target variable refers to a dangerous variable that has an impact on security, such as storing user deposits in variables such as deposits in the smart contract, which is a dangerous variable.
[0059] Further, an abstract syntax tree database corresponding to the smart contract code is constructed, the abstract syntax tree database including a plurality of syntax nodes, the abstract syntax tree database is enhanced based on the target information in the smart contract code, and based on the enhanced abstract syntax tree database, vulnerabilities in the smart contract code are identified to obtain corresponding identification results, which are provided to developers or security researchers for analysis. In other embodiments, a control flow graph corresponding to the smart contract code can be built to analyze whether the target method has a loop call, unauthorized access, or abnormal jump, etc. to identify vulnerabilities in the smart contract code, or a model is trained based on historical vulnerability data to identify suspicious patterns in the target method and / or target variable, i.e. features such as method call frequency and variable modification position are extracted from the target information to detect whether the code structure has vulnerabilities through the model.
[0060] In existing auditing methods, manual code auditing is usually used to obtain relatively accurate audit results, or online processing with the aid of computer equipment, but the current online processing process relies on human-computer interaction to achieve. Therefore, the above methods have the problems of low processing efficiency and high cost, and cannot achieve efficient and accurate smart contract code auditing.
[0061] Compared with the prior art, the smart contract code to be audited and the associated information of the smart contract code are obtained; the target information in the smart contract code is obtained by analyzing the smart contract code and the associated information of the smart contract code through a large language model; the target information includes a target method and a target variable; and the smart contract code is identified for vulnerabilities based on the target information in the smart contract code to obtain a corresponding identification result. Based on this, by using a large language model as a semantic understanding tool, the target method and the target variable are accurately obtained, and the vulnerabilities of the smart contract code are identified based on the obtained target method and target variable, which helps to improve the auditing efficiency and accuracy, solves the problem that efficient and accurate smart contract code auditing cannot be achieved, improves the efficiency and accuracy of smart contract code auditing, and can directly adapt to different smart contracts, that is, dangerous methods and dangerous variables can be identified for different protocols, improving the flexibility of processing.
[0062] In some embodiments, as shown in Figure 3 the analysis process of the large language model includes the following steps:
[0063] Step S221, the smart contract code and the associated information of the smart contract code are analyzed to obtain a plurality of key behaviors and a plurality of key variables corresponding to the smart contract code;
[0064] Step S222, it is judged whether each key behavior and each key variable exist security risks;
[0065] Step S223, the key behavior with the security risk is determined as the target method, and the key variable with the security risk is determined as the target variable.
[0066] Specifically, by using a large language model (such as GPT, Llama), the smart contract code and the associated information of the smart contract code are analyzed to understand the key behaviors and key events of the product implemented by the smart contract, and it is judged whether the obtained key behaviors and key events exist security risks, the key behavior with the security risk is determined as the target method, and the key variable with the security risk is determined as the target variable.
[0067] The target method refers to a dangerous method that affects security, such as a method that directly returns the current price of a certain currency when the smart contract is used as a price oracle; the target variable refers to a dangerous variable that affects security, such as storing user deposits in variables such as deposits in the smart contract, which is a dangerous variable.
[0068] By analyzing the smart contract code and the associated information of the smart contract code in this embodiment, a plurality of key behaviors and a plurality of key variables corresponding to the smart contract code are obtained, it is judged whether each key behavior and each key variable has a security risk, the key behavior with a security risk is determined as the target method, and the key variable with a security risk is determined as the target variable, so as to accurately analyze and obtain the target method and the target variable through semantic understanding of the large language model.
[0069] In some embodiments, as shown in Figure 4 The target information in the smart contract code is used to identify vulnerabilities in the smart contract code in step S230, including the following steps:
[0070] In step S231, an abstract syntax tree database corresponding to the smart contract code is constructed; the abstract syntax tree database includes a plurality of syntax nodes;
[0071] In step S232, the abstract syntax tree database is enhanced based on the target information in the smart contract code;
[0072] In step S233, the vulnerabilities in the smart contract code are identified based on the enhanced abstract syntax tree database.
[0073] Specifically, the smart contract code to be audited is parsed to obtain a corresponding parsing result, and the smart contract code is converted into a corresponding abstract syntax tree database based on the parsing result, the abstract syntax tree database includes a plurality of syntax nodes, and each node corresponds to a syntax structure in the smart contract code.
[0074] Further, a plurality of syntax nodes corresponding to the target information in the abstract syntax tree database are determined, each syntax node corresponding to the target information is marked, such as using attribute marking, adding a danger label, etc., and the enhanced abstract syntax tree database is analyzed using CodeQL analysis or other static code analysis algorithms. In other embodiments, the enhanced abstract syntax tree database can be converted into a graph structure and analyzed using a graph neural network. Then, according to the analysis result, it is judged whether the smart contract code has a code vulnerability.
[0075] Through this embodiment, an abstract syntax tree database corresponding to the smart contract code is constructed, the abstract syntax tree database includes a plurality of syntax nodes, the abstract syntax tree database is enhanced based on the target information in the smart contract code, and the vulnerabilities in the smart contract code are identified based on the enhanced abstract syntax tree database, so that in the smart contract code auditing scenario, CodeQL analysis is performed based on the accurately obtained target method and target variable, so as to fully exert the code analysis capability of CodeQL analysis and accurately analyze the code vulnerability.
[0076] In some embodiments, the constructing the abstract syntax tree database corresponding to the smart contract code in step S231 includes the following steps:
[0077] parsing the smart contract code to be audited to obtain a corresponding parsing result;
[0078] Converting the smart contract code into a corresponding abstract syntax tree database based on the parsing result.
[0079] Specifically, the smart contract code to be audited is parsed by a Solidity compiler to convert the smart contract code into a corresponding abstract syntax tree (AST), each syntax structure is identified as a specific type of AST node, and the AST node is the basic unit of the abstract syntax tree, and each AST node is divided into corresponding labels, such as ForStatement, TryCatchClause, etc.
[0080] Further, the AST nodes and their connection relationships are serialized into the database format of CodeQL, each node contains type labels and attributes, etc., to construct the abstract syntax tree database corresponding to the smart contract code.
[0081] Through the embodiment, the smart contract code to be audited is parsed to obtain a corresponding parsing result, and the smart contract code is converted into a corresponding abstract syntax tree database based on the parsing result, so as to realize accurate construction of the abstract syntax tree database.
[0082] In some embodiments, the enhancing the abstract syntax tree database based on the target information in the smart contract code in step S232 includes the following steps:
[0083] Determine a plurality of syntax nodes in the abstract syntax tree database corresponding to the target information;
[0084] Adding a label to each syntax node corresponding to the target information.
[0085] Specifically, in the abstract syntax tree database corresponding to the smart contract code, a plurality of syntax nodes corresponding to the target information are located, including a syntax node corresponding to a target method and a syntax node corresponding to a target variable, and a corresponding label is generated for each syntax node corresponding to the target information, and the label is attached to the corresponding syntax in the abstract syntax tree database.
[0086] For example, the target variable is the deposits variable, the syntax corresponding to the deposits variable in the abstract syntax tree database is located, and a new label "Danger" is generated for the deposits variable. The new label "Danger" is attached to the syntax corresponding to the deposits variable in the abstract syntax tree database.
[0087] Through the embodiment, the plurality of syntax nodes corresponding to the target information in the abstract syntax tree database are determined, and a label is added to each syntax node corresponding to the target information. In this way, the syntax nodes corresponding to the target information in the abstract syntax tree database are accurately identified, the abstract syntax tree database is enhanced, and the accuracy of subsequent vulnerability identification is improved.
[0088] In some embodiments, the vulnerability identification of the smart contract code based on the enhanced abstract syntax tree database in step S233 includes the following steps:
[0089] The external variable corresponding to the smart contract code is determined as a source point.
[0090] The target function corresponding to the syntax node with the label is determined as a sink point.
[0091] Based on the source point and the sink point, the enhanced abstract syntax tree database is analyzed by a code analysis algorithm.
[0092] According to the analysis result, it is judged whether the smart contract code has a code vulnerability.
[0093] Specifically, when CodeQL analysis is used, the external variable corresponding to the smart contract code is taken as the source point, such as the parameter of the external function, the parameter of the public function, etc. The target function corresponding to the syntax node with the label is taken as the sink point. Based on the source point and the sink point, the enhanced abstract syntax tree database is analyzed by the CodeQL analysis algorithm.
[0094] Further, based on the source point and the sink point, the enhanced abstract syntax tree database is analyzed by the CodeQL analysis algorithm, and according to the analysis result, it is judged whether the smart contract code has a code vulnerability. When the analysis result represents that the call chain of the target function uses the parameter of the target function, it is determined that the smart contract code has a code vulnerability, otherwise, it is indicated that the smart contract code to be audited does not have a code vulnerability.
[0095] By this embodiment, the external variable corresponding to the smart contract code is determined as a source point, the target function corresponding to the syntax node with the label is determined as a sink point, and the enhanced abstract syntax tree database is analyzed based on the source point and the sink point through the code analysis algorithm. Then, according to the analysis result, it is judged whether the smart contract code has a code vulnerability. In this way, the vulnerability identification of the smart contract code is realized through the CodeQL analysis algorithm, and the accuracy of vulnerability identification is improved.
[0096] In some embodiments, the smart contract code auditing method further includes the following steps:
[0097] When the analysis result indicates that the call chain of the target function uses the parameters of the target function, it is determined that the smart contract code has a code vulnerability.
[0098] Specifically, if the enhanced abstract syntax tree database is analyzed by the CodeQL analysis algorithm, and the analysis result indicates that the call chain of the target function uses the parameters of the target function, it is determined that the smart contract code to be audited has a code vulnerability.
[0099] For example, it is detected that a parameter provided by a user can arbitrarily affect the currency price of a price oracle, or it is detected that user A can affect the deposit of user B, and it is determined that the corresponding smart contract code has a code vulnerability.
[0100] Through this embodiment, when the analysis result indicates that the call chain of the target function uses the parameters of the target function, it is determined that the smart contract code has a code vulnerability, and accurate vulnerability identification is realized.
[0101] The preferred embodiments will be described and explained below.
[0102] Figure 5 The flowchart of the smart contract code auditing method of the preferred embodiments is shown in FIG. 1, which includes the following steps: Figure 5
[0103] Step S510, obtaining the smart contract code to be audited and the associated data of the smart contract code;
[0104] Step S520, analyzing the smart contract code and the associated data of the smart contract code through a large language model to obtain a plurality of key behaviors and a plurality of key variables corresponding to the smart contract code;
[0105] Step S530, judging whether each key behavior and each key variable has a security risk, determining the key behavior with the security risk as a target method, and determining the key variable with the security risk as a target variable;
[0106] In step S540, an abstract syntax tree database corresponding to the smart contract code is constructed; the abstract syntax tree database includes a plurality of syntax nodes.
[0107] In step S550, the abstract syntax tree database is enhanced based on the target method and the target variable in the smart contract code.
[0108] In step S560, the target function corresponding to the smart contract code is determined as a source point, and the target function corresponding to the syntax node with the label is determined as a sink point.
[0109] In step S570, the enhanced abstract syntax tree database is analyzed based on the source point and the sink point through a code analysis algorithm.
[0110] In step S580, it is determined whether the smart contract code has a code vulnerability according to the analysis result; when the analysis result represents that the call chain of the target function uses the parameters of the target function, it is determined that the smart contract code has a code vulnerability.
[0111] Through the embodiment, the smart contract code to be audited and the associated data of the smart contract code are obtained, the smart contract code and the associated data of the smart contract code are analyzed, a plurality of key behaviors and a plurality of key variables corresponding to the smart contract code are obtained, and it is determined whether each key behavior and each key variable has a security risk, the key behavior having the security risk is determined as the target method, and the key variable having the security risk is determined as the target variable.
[0112] Further, the abstract syntax tree database corresponding to the smart contract code is constructed, the abstract syntax tree database includes a plurality of syntax nodes, the abstract syntax tree database is enhanced based on the target method and the target variable in the smart contract code. The target function corresponding to the smart contract code is determined as a source point, and the target function corresponding to the syntax node with the label is determined as a sink point, the enhanced abstract syntax tree database is analyzed based on the source point and the sink point through a code analysis algorithm, and then it is determined whether the smart contract code has a code vulnerability according to the analysis result; when the analysis result represents that the call chain of the target function uses the parameters of the target function, it is determined that the smart contract code has a code vulnerability. The problem that efficient and accurate smart contract code auditing cannot be achieved is solved, the efficiency and accuracy of smart contract code auditing are improved, and different smart contracts can be directly adapted, and the flexibility of processing is improved.
[0113] It should be noted that the steps shown in the above flow or the flowchart of the accompanying drawings can be executed in a computer system such as a group of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0114] In the present embodiment, an intelligent contract code auditing apparatus is also provided, which is used to implement the above-mentioned embodiments and preferred embodiments, and has been described above and will not be repeated. The terms "module", "unit", "sub-unit" and the like used below can be a combination of software and / or hardware that implements a predetermined function. Although the apparatus described in the following embodiments is preferably implemented in software, hardware, or a combination of software and hardware is also possible and is contemplated.
[0115] Figure 6 is a structural block diagram of the intelligent contract code auditing apparatus of the present embodiment, as Figure 6 shown, the apparatus comprises:
[0116] The acquisition module 10 is configured to acquire the intelligent contract code to be audited and the associated information of the intelligent contract code.
[0117] The analysis module 20 is configured to analyze the intelligent contract code and the associated information of the intelligent contract code by using a large language model to obtain target information in the intelligent contract code; the target information includes a target method and a target variable.
[0118] The identification module 30 is configured to identify vulnerabilities in the intelligent contract code based on the target information in the intelligent contract code to obtain a corresponding identification result.
[0119] Through the apparatus provided in the present embodiment, the intelligent contract code to be audited and the associated information of the intelligent contract code are acquired; the intelligent contract code and the associated information of the intelligent contract code are analyzed by using a large language model to obtain target information in the intelligent contract code; the target information includes a target method and a target variable; vulnerabilities in the intelligent contract code are identified based on the target information in the intelligent contract code to obtain a corresponding identification result, which solves the problem that efficient and accurate intelligent contract code auditing cannot be achieved, and improves the efficiency and accuracy of intelligent contract code auditing, while being directly adaptable to different intelligent contracts and improving the flexibility of processing.
[0120] In some embodiments, the analysis module 20 is further configured to analyze the intelligent contract code and the associated information of the intelligent contract code to obtain a plurality of key behaviors and a plurality of key variables corresponding to the intelligent contract code; determine whether each key behavior and each key variable has a security risk; determine a key behavior having a security risk as the target method, and a key variable having a security risk as the target variable.
[0121] In some embodiments, the identification module 30 is further configured to construct an abstract syntax tree database corresponding to the smart contract code; the abstract syntax tree database comprises a plurality of syntax nodes; perform enhanced processing on the abstract syntax tree database based on the target information in the smart contract code; and perform vulnerability identification on the smart contract code based on the abstract syntax tree database after the enhanced processing.
[0122] In some embodiments, the identification module 30 is further configured to parse the smart contract code to be audited to obtain a corresponding parsing result; and convert the smart contract code into a corresponding abstract syntax tree database based on the parsing result.
[0123] In some embodiments, the identification module 30 is further configured to determine a plurality of syntax nodes in the abstract syntax tree database corresponding to the target information; and add a label to each syntax node corresponding to the target information.
[0124] In some embodiments, the identification module 30 is further configured to determine that a target function corresponding to the smart contract code is a source point; determine that a target function corresponding to the syntax node with the label is a sink point; analyze the abstract syntax tree database after the enhanced processing based on the source point and the sink point through a code analysis algorithm; and determine whether the smart contract code has a code vulnerability according to the analysis result.
[0125] In some embodiments, the identification module 30 is further configured to determine that the smart contract code has a code vulnerability when the analysis result indicates that a call chain of the target function uses a parameter of the target function.
[0126] It should be noted that each of the above modules can be a functional module or a program module, and can be implemented by software or hardware. For the modules implemented by hardware, each of the above modules can be located in the same processor; or each of the above modules can be located in different processors in any combination.
[0127] In this embodiment, a computer device is also provided, which includes a memory and a processor, the memory stores a computer program, and the processor is configured to execute the computer program to perform the steps in any of the above method embodiments.
[0128] Optionally, the computer device can further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0129] Optionally, in this embodiment, the processor can be configured to perform the following steps through the computer program:
[0130] S1, obtaining the smart contract code to be audited and the associated information of the smart contract code;
[0131] S2, obtaining target information in the smart contract code by analyzing the smart contract code and the associated information of the smart contract code through a large language model; the target information includes a target method and a target variable;
[0132] S3, identifying a vulnerability in the smart contract code based on the target information in the smart contract code, and obtaining a corresponding identification result.
[0133] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation manners, which will not be described herein.
[0134] In addition, in combination with the smart contract code auditing method provided in the above embodiments, a storage medium can also be provided to implement the method in this embodiment. The storage medium has a computer program stored thereon; the computer program is executed by a processor to implement any one of the smart contract code auditing methods in the above embodiments.
[0135] It should be understood that the specific embodiments described herein are only used to explain this application, but not to limit it. According to the embodiments provided in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor are within the scope of protection of the present application.
[0136] Obviously, the drawings are only some examples or embodiments of the present application, and those of ordinary skill in the art can also apply the present application to other similar situations without creative labor. In addition, it can be understood that although the work done in the development process may be complex and long, for those of ordinary skill in the art, some design, manufacture or production changes according to the technical content disclosed in the present application are only routine technical means, and should not be regarded as insufficient disclosure of the present application.
[0137] The term "embodiment" in this application refers to the specific features, structures or characteristics described in combination with the embodiments, which can be included in at least one embodiment of the present application. The phrase appears in various places in the specification does not necessarily mean the same embodiment, nor does it mean independence or alternative to other embodiments. Those of ordinary skill in the art can clearly or implicitly understand that the embodiments described in the present application can be combined with other embodiments without conflict.
[0138] The above-described embodiments are merely illustrative of several embodiments of the present application, which are described in more detail and in a specific manner, but should not be construed as limiting the scope of patent protection. It should be noted that, for those skilled in the art, several modifications and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for smart contract code auditing, characterized in that, The method comprises the following steps: obtaining the smart contract code to be audited and the associated information of the smart contract code; analyzing the smart contract code and the associated information of the smart contract code by a large language model to obtain target information in the smart contract code; the target information includes a target method and a target variable; based on the target information in the smart contract code, the vulnerability of the smart contract code is identified to obtain the corresponding identification result. 2.The smart contract code auditing method of claim 1, wherein, The analysis process of the large language model comprises: analyzing the smart contract code and the associated information of the smart contract code to obtain a plurality of key behaviors and a plurality of key variables corresponding to the smart contract code; determine whether each key behavior and each key variable has a security risk; determine the key behavior with a security risk as the target method, and the key variable with a security risk as the target variable. 3.The smart contract code auditing method of claim 1, wherein, The vulnerability identification of the smart contract code based on the target information in the smart contract code comprises: constructing an abstract syntax tree database corresponding to the smart contract code; the abstract syntax tree database comprises a plurality of syntax nodes; based on the target information in the smart contract code, the abstract syntax tree database is enhanced; based on the abstract syntax tree database after enhancement, the vulnerability of the smart contract code is identified.
4. The smart contract code auditing method according to claim 3, characterized in that: The construction of the abstract syntax tree database corresponding to the smart contract code comprises: parsing the smart contract code to be audited to obtain a corresponding parsing result; based on the parsing result, the smart contract code is converted into a corresponding abstract syntax tree database. 5.The smart contract code auditing method of claim 3, wherein, The enhancement processing of the abstract syntax tree database based on the target information in the smart contract code comprises: determine a plurality of syntax nodes in the abstract syntax tree database corresponding to the target information; add a label to each syntax node corresponding to the target information. 6.The smart contract code auditing method of any one of claims 3 to 5, wherein, The vulnerability identification of the smart contract code based on the abstract syntax tree database after enhancement comprises: determine the external variable corresponding to the smart contract code as a source point; determine the target function corresponding to the syntax node with a label as a sink point; based on the source point and the sink point, the abstract syntax tree database after enhancement is analyzed by a code analysis algorithm; according to the analysis result, it is judged whether the smart contract code has a code vulnerability.
7. The smart contract code auditing method of claim 6, wherein, The method further comprises: when the analysis result represents that the calling chain of the target function uses the parameters of the target function, it is determined that the smart contract code has a code vulnerability.
8. An intelligent contract code auditing apparatus, characterized by comprising: The method comprises the following steps: an acquisition module for obtaining the smart contract code to be audited and the associated information of the smart contract code; an analysis module for analyzing the smart contract code and the associated information of the smart contract code by a large language model to obtain target information in the smart contract code; the target information includes a target method and a target variable; An identification module is configured to identify a vulnerability in the smart contract code based on the target information in the smart contract code, and obtain a corresponding identification result. 9.A computer device, comprising a memory and a processor, and characterized in that, The memory stores a computer program, and the processor is configured to run the computer program to execute the steps of the smart contract code auditing method in any one of claims 1 to 7.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the smart contract code auditing method in any one of claims 1 to 7.