Apparatus and method for analyzing vulnerability of smart contract code
The smart contract code vulnerability analysis apparatus and method address the challenge of analyzing vulnerabilities in smart contract infrastructure by converting input code into an intermediate representation language and detecting vulnerabilities, resulting in efficient and comprehensive vulnerability modeling.
Patent Information
- Application Number
- JP2023212174
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-15
- Publication Date
- 2025-06-26
AI Technical Summary
Existing vulnerability analysis technologies are unable to effectively analyze vulnerabilities in the software of smart contract infrastructure operating on a blockchain, posing a significant risk for security issues and economic damage.
A smart contract code vulnerability analysis apparatus and method that extracts meta information from input code, converts it into an intermediate representation language, and analyzes it using a code analysis unit to detect vulnerable codes and rule violations, generating a final vulnerability model.
Enables simple and efficient analysis of vulnerabilities in smart contract software, allowing for simultaneous analysis across multiple platforms and providing a comprehensive vulnerability model that prioritizes critical issues.
Smart Images

Figure 2025095846000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a smart contract code vulnerability analysis apparatus and method, and more particularly, to a smart contract code vulnerability analysis apparatus and method capable of simply and efficiently analyzing vulnerabilities that may occur in the software of a smart contract infrastructure operating on a blockchain.
Background Art
[0002] As is well known, a blockchain has the advantage of being able to prevent forgery and alteration of transaction details by sharing and storing a distributed ledger that stores transaction details in a plurality of nodes without the intervention of a central server.
[0003] Such a blockchain platform verifies blocks by a consensus algorithm and pays cryptocurrency as compensation to the generated nodes. For example, Bitcoin is well known.
[0004] Recent blockchain technology has evolved beyond the stage of exchanging value without an intermediary using a distributed ledger, to the stage where the execution results of a Turing complete programming language are recorded in the distributed ledger and a decentralized application (DApp; hereinafter also referred to as a "dapp") can be executed in a distributed manner. Such a decentralized application has the characteristic of being able to provide various services by the operation of the dapp incorporated in each user's computer without the intervention of a server via a peer-to-peer network directly connected between the users' computers.
[0005] For example, it can be said that a platform such as Ethereum is a typical example. In order to use this platform, users can trade the Ethereum, which is the token of the platform base, and the tokens issued by each DApp, pay the tokens to the DApp, and receive service provision.
[0006] To explain in more detail the implementation methods of blockchain in prior arts such as Bitcoin and Ethereum, each block constituting the blockchain stores transaction information, which is the breakdown information of transactions between users via the blockchain system. It is composed of a block header and a transaction, and these are generated by means such as proof of work by so-called miner nodes and are included in the blockchain.
[0007] On the other hand, in the Ethereum blockchain platform, compared with existing blockchain platforms such as Bitcoin that only store simple transaction breakdowns, it stores "smart contracts" composed of code through programming, and enables these to be executed by nodes constituting the blockchain system, so that the transaction breakdown based on the execution result of the smart contract can be reflected in the blockchain.
[0008] However, such smart contracts are created in a specific language through programming, but various vulnerabilities can occur due to errors in the source code or mistakes during creation. In particular, since the tokens on the Ethereum base use smart contracts, if there are vulnerabilities in the smart contracts, security problems such as hacking may occur, which may cause serious economic damage. Therefore, it is a very important issue to verify such vulnerabilities of smart contracts in advance.
[0009] However, existing vulnerability analysis technologies have limitations in that they cannot analyze vulnerabilities in the software of the smart contract infrastructure operating on the blockchain. Therefore, the development of a separate vulnerability analysis system for the smart contract environment is desired.
Summary of the Invention
Problems to be Solved by the Invention
[0010] The present invention is for solving the problems as described above, and an object thereof is to provide an apparatus and method capable of simply and efficiently analyzing vulnerabilities that may occur in the software of the smart contract infrastructure operating on the blockchain.
[0011] Another object of the present invention is to provide an apparatus and method capable of analyzing vulnerabilities on many platforms simultaneously based on an intermediate language that maintains the semantics of various smart contracts.
Means for Solving the Problems
[0012] To solve the problems as described above, the present invention provides a smart contract code vulnerability analysis apparatus, including: a meta information extraction unit that extracts meta information about input code that is the source code of a smart contract; an intermediate representation language conversion unit that converts the input code into an intermediate representation language based on the meta information extracted by the meta information extraction unit; a code analysis unit that analyzes the input code converted into the intermediate representation language by the intermediate representation language conversion unit to detect whether there are vulnerable codes and rule violation cases; and a vulnerability detection unit that detects vulnerabilities based on the vulnerable codes and rule violation cases detected by the code analysis unit and generates a final vulnerability model.
[0013] Here, the meta information can include at least one of blockchain platform information, programming language information, and version information.
[0014] The intermediate representation language conversion unit can include a convertible determination unit that determines whether the input code can be converted into an intermediate representation language based on the meta information extracted by the meta information extraction unit, and a conversion execution unit that converts the input code into an intermediate representation language when it is determined by the convertible determination unit that the input code can be converted into an intermediate representation language.
[0015] The conversion execution unit can include an abstract syntax tree generation unit that parses the input code to generate an abstract syntax tree, and an intermediate representation language generation unit that generates an intermediate representation language for the input code by traversing the abstract syntax tree generated by the abstract syntax tree generation unit via a visitor.
[0016] Also, the code analysis unit can be composed of a plurality corresponding to the meta information extracted by the meta information extraction unit.
[0017] The code analysis unit can include a code pattern information-based analysis unit that detects vulnerable codes and rule violation cases based on the code pattern information of the input code converted into an intermediate representation language, and a semantic information-based analysis unit that detects vulnerable codes and rule violation cases based on at least one of the variable tracking information, execution flow information, and conditional expression information of the input code converted into an intermediate representation language.
[0018] Also, the code pattern information-based analysis unit can include a code pattern information extraction unit that extracts the pattern information of the input code expressed in an intermediate representation language, and a vulnerable code detection unit that detects whether there are vulnerable codes and rule violation cases based on the code pattern information extracted by the code pattern information extraction unit.
[0019] In addition, the code pattern information extraction unit can extract code pattern information including syntax extracted in at least one unit of line unit, function unit, block unit, and token unit, the hash value of the extracted syntax, start line information, and end line information, for the input code expressed in the intermediate representation language.
[0020] In addition, the vulnerable code detection unit can detect whether there is the same data as the vulnerable code and rule data constructed in the vulnerability database for the code pattern information extracted by the code pattern information extraction unit.
[0021] In addition, the vulnerability database can be generated by extracting meta information with the vulnerable code and the line information of the vulnerable code as input, then converting the input vulnerable code into an intermediate representation language based on the extracted meta information, and then extracting code pattern information based on the line information of the vulnerable code.
[0022] In addition, the semantic information-based analysis unit can include a semantic information extraction unit that extracts semantic information including at least one of variable tracking information, execution flow information, and conditional expression information from the input code expressed in the intermediate representation language, and a vulnerable code detection unit that detects whether there are vulnerable codes and rule violation cases based on the semantic information generated by the semantic information extraction unit.
[0023] In addition, when each variable is declared in the input code converted into the intermediate representation language, the semantic information extraction unit can add each variable to the variable management table and save the range of values that each variable can represent in the variable value table to generate variable tracking information.
[0024] In addition, when the variable value information included in the variable tracking information is an integer overflow, an uninitialized variable, the represented value of the variable is the block.timestamp value, or the balance is 0 or less, the vulnerable code detection unit can detect vulnerable code and rule violation cases.
[0025] In addition, the semantic information extraction unit can generate and save a control flow graph indicating execution flow information.
[0026] In addition, when there are nodes that cannot be reached in the control flow graph, there are more nodes than a preset value, or an external smart contract is called even though it is not a leaf node, the vulnerable code detection unit can detect vulnerable code and rule violation cases.
[0027] In addition, the vulnerability detection unit can generate a vulnerability model for the vulnerabilities detected based on the code vulnerability points and rule violation cases detected by the code analysis unit, remove duplicates, sort them by priority, and generate a final vulnerability model.
[0028] In addition, the vulnerability detection unit generates a syntactic vulnerability model from the vulnerability information recorded in the code pattern vulnerability table generated by the code analysis unit, and generates a semantic vulnerability model from the vulnerability information recorded in the semantic vulnerability table generated by the code analysis unit. The vulnerability model can be represented by these two models, and the vulnerability model can be generated by adding additional information including severity information, reference information, and patch information.
[0029] In addition, when the vulnerability detection unit determines that the vulnerable points and the detected parts of the input code have the same type of vulnerability and one of them is included in the other, the detected part of the input code is determined to be a duplicate and removed. When there are parts of the input code with the same patch information, any one of them can be determined to be a duplicate and removed.
[0030] In addition, the vulnerability detection unit can rank the cases where patch information exists for vulnerabilities classified as "Critical", which is the most dangerous level of severity, as the highest priority, and rank the cases where no patch information exists as the next priority.
[0031] In addition, the vulnerability detection unit can rank the cases where patch information exists and the severity information is "High", "Medium", or "Low" as the next priority, and rank the cases where patch information exists and the severity information is "High", "Medium", or "Low" as the next priority, and rank the cases where no patch information exists and the severity information is "High", "Medium", or "Low" as the next priority to generate the final vulnerability model.
[0032] According to another aspect of the present invention, there is provided a smart contract code vulnerability analysis method executed by the smart contract code vulnerability analysis device as described above, including: a first step of extracting meta information about input code that is the source code of a smart contract; a second step of converting the input code into an intermediate representation language based on the meta information extracted in the first step; a third step of analyzing the input code converted into the intermediate representation language in the second step to detect whether there are vulnerable codes and rule violation cases; and a fourth step of detecting vulnerabilities based on the vulnerable codes and rule violation cases detected in the third step and generating a final vulnerability model.
Effects of the Invention
[0033] According to the present invention, it is possible to provide an apparatus and a method for simply and efficiently analyzing vulnerabilities that may occur in software of a smart contract infrastructure operating on a blockchain.
[0034] Further, the present invention can provide an apparatus and a method for analyzing vulnerabilities on many platforms simultaneously based on an intermediate language that maintains the semantics of various smart contracts.
[0035] Further, the present invention has the advantage of being able to easily add or remove an additional vulnerability analyzer.
Brief Description of the Drawings
[0036]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Embodiments for Carrying Out the Invention
[0037] Hereinafter, embodiments according to the present invention will be described in detail with reference to the accompanying drawings.
[0038] FIG. 1 is a diagram showing the overall configuration of a smart contract code vulnerability analysis apparatus 100 according to an embodiment of the present invention.
[0039] Referring to FIG. 1, a smart contract code vulnerability analysis apparatus 100 (hereinafter simply referred to as "analysis apparatus 100") according to the present embodiment includes a meta information extraction unit 10, an intermediate representation language conversion unit 20, a code analysis unit 30, and a vulnerability detection unit 40.
[0040] The meta information extraction unit 10 functions to extract meta information about the input code. Here, the input code means the source code of a smart contract.
[0041] Since there can be multiple blockchain platforms that support smart contracts, the meta information extraction unit 10 extracts meta information from the input code in order to detect which smart contract operates on which blockchain platform. The meta information to be extracted can include information such as, for example, blockchain platform information, programming language, version, and the like.
[0042] FIG. 2 is a diagram for explaining the operation of the meta information extraction unit 10.
[0043] As shown in FIG. 2, for example, when the input code is an Ethereum Solidity file (.sol), the meta information extraction unit 10 extracts language information through the file extension (.sol), and extracts version information while reading the file line by line. The meta information extraction unit 10 can estimate blockchain platform information, programming language information, and version information through such a process. For example, meta information such as "Ethereum" as the blockchain platform information, "Solidity" as the programming language information, and "0.5.0" as the version information can be extracted.
[0044] When the input code is a Go file (.go) based on the Hyperledger Fabric infrastructure, the meta information extraction unit 10 extracts programming language information through the extension, reads the file, and extracts meta information based on which packages were imported and which APIs were used. The blockchain platform can be estimated through such a process to extract meta information.
[0045] The intermediate representation language conversion unit 20 functions to convert the input code into an intermediate representation language based on the meta information extracted by the meta information extraction unit 10. The intermediate representation language serves as basic material for vulnerability analysis described later.
[0046] FIG. 3 is a diagram showing the configuration of the intermediate representation language conversion unit 20.
[0047] Referring to FIG. 3, the intermediate representation language conversion unit 20 includes a conversion possible determination unit 21 and a conversion execution unit 22.
[0048] The conversion possible determination unit 21 functions to determine whether the input code can be converted into an intermediate representation language based on the meta information extracted by the meta information extraction unit 10.
[0049] FIG. 4 is a diagram showing the operation of the conversion possible determination unit 21.
[0050] As shown in FIG. 4, the conversion possible determination unit 21 determines that the input code can be converted into an intermediate representation language when the input code is, for example, an Ethereum Solidity (solidity) file (.sol) or a Hyperledger Fabric-based Go file (.go). On the other hand, when an unknown blockchain Java file (.java (registered trademark)) that is not known by the meta information extracted by the meta information extraction unit 10 is the input code, it is determined that the conversion into an intermediate representation language is not possible.
[0051] The conversion possible determination unit 21 thus determines whether conversion into an intermediate representation language is possible based on the programming language information among the meta information. For this purpose, as shown in FIG. 4, the conversion possible determination unit 21 stores in advance a table indicating whether conversion is possible, and can determine whether the input code can be converted into an intermediate representation language based on the meta information of the input code.
[0052] When the conversion possible determination unit 21 determines that the conversion into an intermediate representation language is possible, the conversion execution unit 22 functions to convert the input code into an intermediate representation language.
[0053] The intermediate representation language means intermediate code used between the language used in the target software and the source code, is independent of the source code, and can be used by various compilers using this.
[0054] FIG. 5 is a diagram for explaining an intermediate representation language.
[0055] FIG. 5(a) is a diagram showing a compiler that does not use an intermediate language. As shown in the figure, it can be seen that source codes expressed in various programming languages such as Fortran, Scheme, Java, and Smalltalk are input through their respective compiler front-ends and are converted into the target machine language through their respective compiler back-ends. Therefore, N (= 4) × M (= 3) compilers are required.
[0056] On the other hand, FIG. 5(b) is a diagram showing a compiler that uses an intermediate representation language. As shown in the figure, it can be seen that source codes expressed in various programming languages such as Fortran, Scheme, Java, and Smalltalk are input through the compiler front-end and are converted into an intermediate representation language, and then are converted into the target machine language through their respective compiler back-ends. Therefore, N (= 4) + M (= 3) compilers are required.
[0057] FIG. 6 is a diagram showing an example of the configuration of the conversion execution unit 22.
[0058] Referring to FIG. 6, the conversion execution unit 22 includes an abstract syntax tree generation unit 221 and an intermediate representation language generation unit 222.
[0059] The abstract syntax tree generation unit 221 functions to parse the input code and generate an abstract syntax tree.
[0060] An abstract syntax tree means a tree-shaped data structure generated by a syntax analysis process in the stage of compiling a source code. The abstract syntax tree generation unit 221 parses the input code and generates the parsing result in a tree form.
[0061] FIG. 7 is a diagram showing an example of an abstract syntax tree.
[0062] As shown in FIG. 7, for example, when the input code is 1 + 2 * (3 + 4), the abstract syntax tree parses the input code into data form, operator type, symbol type, etc., and represents this in tree form.
[0063] The intermediate representation language generation unit 222 converts the input code into an intermediate representation language based on the abstract syntax tree generated by the abstract syntax tree generation unit 221.
[0064] Here, by traversing the abstract syntax tree via a visitor, the input code is converted into an intermediate representation language. Here, the visitor can traverse the abstract syntax tree in, for example, a depth first left-to-right manner, and when reaching each node of the abstract syntax tree, it can be converted into an intermediate representation language according to the given rules. The grammar determined for each decorator or binary operator and blockchain platform is desugared. Here, the intermediate representation language can follow the form of static single assignment where the assignment per variable occurs only once. When converting to the intermediate representation language, a Pass provided by the LLVM compiler and the like can also be utilized.
[0065] FIGS. 8 and 9 are diagrams showing an example in which the input code is converted into an intermediate representation language by the intermediate representation language generation unit 222.
[0066] As shown in FIGS. 8 and 9, it can be seen that various forms of input code are respectively converted to correspond to the intermediate representation language.
[0067] However, it goes without saying that the method for converting the intermediate representation language described with reference to FIGS. 7 to 9 is exemplary and not the direct object of the present invention, and other various conventionally known methods can also be used in addition to such a method.
[0068] When the input code is converted into an intermediate representation language through such a process, the intermediate representation language conversion unit 20 transmits the converted intermediate representation language to the code analysis unit 30.
[0069] The code analysis unit 30 is a means for analyzing the input code converted into an intermediate representation language by the intermediate representation language conversion unit 20 to detect whether there is vulnerable code and rule violation cases.
[0070] The code analysis unit 30 may be composed of a plurality corresponding to the meta information extracted by the meta information extraction unit 10. As described above, since the meta information includes at least one of blockchain platform information, programming language information, and version information, the intermediate representation language conversion unit 20 transmits the input code converted into the intermediate representation language to each code analysis unit 30 corresponding to the meta information of the input code converted into the intermediate representation language.
[0071] FIG. 10 is a diagram showing the configuration of the code analysis unit 30.
[0072] Referring to FIG. 10, the code analysis unit 30 includes a code pattern information base analysis unit 31 and a semantic information base analysis unit 32.
[0073] The code pattern information base analysis unit 31 is a means for detecting vulnerable code and rule violation cases based on the code pattern information of the input code converted into an intermediate representation language.
[0074] FIG. 11 is a diagram showing an example of the configuration of the code pattern information base analysis unit 31.
[0075] Referring to FIG. 11, the code pattern information base analysis unit 31 includes a code pattern information extraction unit 311 and a vulnerable code detection unit 312.
[0076] The code pattern information extraction unit 311 functions to extract the pattern information of the input code expressed by being converted into an intermediate representation language.
[0077] Here, the code pattern means dividing the statements of the input code expressed in the intermediate representation language into predetermined units according to the syntax.
[0078] FIG. 12 is a diagram showing an example of code pattern information.
[0079] As shown in FIG. 12, the code pattern information is composed of multiple types of code pattern information, and the code pattern information can be configured for each type.
[0080] In FIG. 12, the code pattern information is composed of four types. Each code pattern information can be generated according to the code pattern information ID composed of the ID of the input code (for example, smart contract name, file name, etc.), blockchain platform, programming language, version, and identifier (No).
[0081] In FIG. 12, the first code pattern information is the extraction of the line-unit statements of the input code in list form, and is composed of the input code ID, version, statement, statement hash value, start line, and end line, and is given the code pattern information ID composed of "SOOHO_ethereum_solidity_0.4.6_1".
[0082] The second code pattern information is the extraction of the function-unit statements of the input code in list form, and is composed of the input code ID, version, function name, function body, function hash value, start line, and end line, and is given the code pattern information ID composed of "SOOHO_ethereum_solidity_0.4.6_2".
[0083] The third code pattern information is the extraction of the syntax of the input code by block in list form, which consists of the input code ID, version, function name including the block, function reference block number, block body, block body hash value, start line, and end line, and is assigned a code pattern information ID composed of "SOOHO_ethereum_solidity_0.4.6_3".
[0084] The fourth code pattern information is the extraction of the syntax of the input code in token units, which consists of the input code ID, version, value of the reference token n, syntax, syntax hash value, start line, and end line, and is assigned a code pattern information ID composed of "SOOHO_ethereum_solidity_0.4.6_4". Here, a token means a group of words composed of n consecutive characters.
[0085] As mentioned above, the hash value of each code pattern information can be calculated by, for example, md5.
[0086] In this way, for the input code converted into the intermediate representation language, code pattern information can be extracted in units of lines, functions, blocks, and tokens according to the languages and versions of each blockchain platform.
[0087] However, the above code pattern information is exemplary, and it goes without saying that only some of them can be used, and other code pattern information can also be further used.
[0088] Also, referring to FIG. 11, the vulnerable code detection unit 312 is a means for detecting whether there are vulnerable codes and rule violation cases based on the code pattern information extracted by the code pattern information extraction unit 311 by the method as described above.
[0089] The vulnerability code detection unit 312 detects whether there is the same data as the vulnerability code and rule data constructed in the vulnerability database (DB) for the ID-specific code pattern information of the code pattern information extracted by the code pattern information extraction unit 311. When detecting, the conditional statement provided from the vulnerability database (for example, the where clause of mysql, etc.) can be used to detect whether there is a vulnerability code existing under the same condition. When a vulnerability code is detected, the vulnerability code detection unit 312 generates a code pattern vulnerability point table for each code pattern information ID.
[0090] The code pattern-based vulnerability point table can be generated in a one-to-many manner in the vulnerability database with the entire source code and line information (start line and end line) of the input code determined to be a vulnerability code as input and each code pattern information ID as an entity.
[0091] The vulnerability database is generated by the method described in the meta information extraction unit 10, the intermediate representation language conversion unit 20, and the code pattern information extraction unit 311 as described above. That is, after extracting meta information with the vulnerability code and the line information of the vulnerability code as input, converting the input vulnerability code into an intermediate representation language based on the extracted meta information, extracting code pattern information based on the line information of the vulnerability code, and then saving this in the vulnerability database.
[0092] When the vulnerability database is generated in this way, the vulnerability code detection unit 312 queries the vulnerability database using the code pattern information ID to detect whether there are vulnerability code and rule violation cases. Here, for fast search, for example, "code pattern information ID & md5" can be used as a pair to query with an index.
[0093] Also, the semantic information-based analysis unit 32 will be described with reference to FIG. 10.
[0094] The semantic information-based analysis unit 32 is a means for extracting the semantic information of the input code converted into the intermediate representation language and detecting vulnerable codes and rule violation cases based on the extracted semantic information.
[0095] FIG. 13 is a diagram showing an example of the configuration of the semantic information-based analysis unit 32.
[0096] Referring to FIG. 13, the semantic information-based analysis unit 32 includes a semantic information extraction unit 321 and a vulnerable code detection unit 322.
[0097] The semantic information extraction unit 321 functions to extract semantic information from the input code expressed in the intermediate representation language.
[0098] Here, the semantic information is information about the execution of the input code, which is a concept distinguished from syntactic information, and can include at least one of variable tracking information, execution flow information, and conditional expression information.
[0099] After reading the syntax of the input code converted into the intermediate representation language to extract semantic information, the semantic information extraction unit 321 can generate semantic information in a manner of storing data as a data structure in the form of a table and a graph.
[0100] FIG. 14 is a diagram for explaining the operation of the semantic information extraction unit 321 and is a diagram for explaining the process of extracting variable tracking information.
[0101] As shown in FIG. 14, the semantic information extraction unit 321 extracts and stores variable tracking information using a variable management table and a variable value table.
[0102] When each variable is declared in the input code converted into an intermediate representation language, these are added to the variable management table. However, since the input code of the present invention is a smart contract, for the vulnerability analysis of the smart contract, unlike a general variable management table, in the case of specific variables, they are managed via a separate flag. Also, the range of values that a variable can represent changes depending on conditional expressions etc., and information about this is also managed as a variable value table.
[0103] For example, when the variable x can take on any value, it is represented by TIFF2025095846000002.tif11170, and if it is 0 or more (0, ∞), or between -100 and 100 inclusive, it becomes (-100, 100), and such information is extracted and saved and managed in the variable value table.
[0104] FIG. 15 is a diagram for explaining the process in which the semantic information extraction unit 321 extracts execution flow information.
[0105] As shown in the figure, the semantic information extraction unit 321 generates and saves a control flow graph indicating the execution flow information, and when a branch occurs in the input code, nodes are generated and connected.
[0106] The vulnerable code detection unit 322 is a means for detecting whether there are vulnerable codes and rule violation cases based on the semantic information generated by the semantic information extraction unit 321 in the process as described above.
[0107] FIG. 16 is a diagram for explaining the operation of the vulnerable code detection unit 322.
[0108] The vulnerable code detection unit 322 can detect vulnerable codes and rule violation cases based on the variable tracking information and execution flow information generated by the semantic information extraction unit 321.
[0109] FIG. 16(a) is a diagram exemplarily showing a process of determining whether it corresponds to vulnerable code and a rule violation case preset by variable tracking information. For example, when the variable value information corresponds to an integer overflow or an uninitialized variable, it can be detected as vulnerable code. Since the input code is a smart contract, for example, it is possible to detect vulnerable code by determining whether the represented value of a variable is the block.timestamp value, whether the balance is 0 or less, and the like.
[0110] FIG. 16(b) is a diagram exemplarily showing a process of determining whether it corresponds to vulnerable code and a rule violation case using a control flow graph (CFG). For example, when there is an unreachable node in the control flow graph, it can be detected as vulnerable code. Also, since the input code is a smart contract, when there are more nodes than a preset value in the control flow graph, it can be determined as vulnerable code. This is because when there are too many nodes in a smart contract, gas consumption increases on the blockchain platform, and thus a situation where it does not operate properly like a denial of service may occur.
[0111] Also, when calling an external smart contract (for example,.call,.delegate,.send, etc.) even though it is not a leaf node, it corresponds to reentrancy, so it can be detected as vulnerable code.
[0112] Each time the vulnerable code detection unit 322 detects vulnerable code and a rule violation case in this way, it records them in the semantic vulnerability point table.
[0113] Also, the vulnerability detection unit 40 will be described with reference to FIG. 1.
[0114] The vulnerability detection unit 40 is a means for finally detecting vulnerabilities in the input code based on the vulnerable codes and rule violation cases detected by the code analysis unit 30 and generating a final vulnerability model.
[0115] As described above, the vulnerability detection unit 40 generates a vulnerability model by performing the following operations on the vulnerabilities detected by the code pattern information base analysis unit 31 and the semantic information base analysis unit 32 of the code analysis unit 30 and the vulnerabilities detected by rule violation cases: 1) correcting with a consistent vulnerability information schema to generate a vulnerability model, 2) removing duplicates, and 3) adjusting the priority order to generate a final vulnerability model.
[0116] FIG. 17 and FIG. 18 are diagrams for explaining the operation of the vulnerability detection unit 40.
[0117] The vulnerability detection unit 40 generates a syntactic vulnerability model while traversing each piece of vulnerability information in array form recorded in the code pattern vulnerability table generated by the vulnerable code detection unit 312 of the code pattern information base analysis unit 31 described above. Also, the vulnerability detection unit 40 generates a semantic vulnerability model while traversing each piece of vulnerability information in array form recorded in the semantic vulnerability table generated by the vulnerable code detection unit 322 of the semantic information base analysis unit 32, and merges these two models to generate a vulnerability model including all vulnerability results.
[0118] Then, the vulnerability detection unit 40 adds additional information to the vulnerability model, removes duplicates, and then generates a final vulnerability model by arranging them in priority order.
[0119] Here, the information to be added can include information such as severity information, reference information, patch information, and the like.
[0120] FIG. 18 is a diagram for explaining the process of generating the final vulnerability model.
[0121] As described above, the vulnerability detection unit 40 can add additional information as shown in FIG. 18 to the vulnerability model generated.
[0122] Referring to FIG. 18, the additional information can include severity information, reference information, and patch information.
[0123] The severity information is information indicating how serious the vulnerability is. Depending on the severity, it is classified into one of "Critical, High, Medium", and by default, it is recorded as "Note". The reference information is external vulnerability database reference information providing vulnerability information such as CVE (Common Vulnerabilities and Exposures), SWC, etc. Also, the patch information can include information for patching the vulnerability (such as patching methods, patch files, etc.).
[0124] In addition, as shown in FIG. 18, the vulnerability model is generated based on information such as the vulnerability name for distinguishing vulnerabilities, the CWE standard vulnerability classification ID, the SWC standard vulnerability classification ID, the start line and end line of the vulnerability-related code, etc.
[0125] Through such a process, the vulnerability detection unit 40 can generate a vulnerability model having a consistent vulnerability information schema.
[0126] Next, the vulnerability detection unit 40 performs duplicate removal on the vulnerability model. For this purpose, the following method can be used.
[0127] That is, when there are parts A and B of the result input code detected as vulnerabilities, in the following cases, it can be determined as a duplicate and removed.
[0128] 1) When A and B are vulnerabilities of the same type and A is included in B based on the input code TIFF2025095846000003.tif16170 In this case, part A of the input code can be removed.
[0129] 2) When the patch information of A and B is the same TIFF2025095846000004.tif11170 In this case, either part A or part B of the input code can be removed.
[0130] 3) When A and B differ only in patch information (in this case, append the patch information with the larger array index to the patch with the lower index).
[0131] Next, the vulnerability detection unit 40 performs priority sorting. The following rules can be used for this.
[0132] That is, when there is patch information for vulnerabilities classified as "Critical", which is the most dangerous level of severity information, it is sorted to the highest priority, and when there is no patch information, it is sorted to the next priority.
[0133] Next, when there is patch information and the severity information is "High", "Medium", or "Low", it is sorted to the next priority. This means that when there is patch information, it is sorted in the order of increasing danger of the severity information.
[0134] Then, when there is no patch information and the severity information is "High", "Medium", or "Low", it is sorted to the next priority. And when there is patch information but the severity information is "Note", and when there is no patch information and the severity information is "Note", they are sorted to the next priority.
[0135] Through such a process, the vulnerability detection unit 40 generates a vulnerability model indicating vulnerabilities in the input code based on the vulnerable codes and rule violation cases detected by the code pattern information base analysis unit 31 and the semantic information base analysis unit 32 of the code analysis unit 30. After further generating a final vulnerability model including patch information, severity information, and reference information as additional information related to the vulnerabilities, the final vulnerability result information can be provided through duplicate removal and priority ranking.
[0136] FIG. 19 is a flowchart showing an embodiment of a smart contract code vulnerability analysis method executed by the analysis apparatus 100 according to the present invention described with reference to FIGS. 1 to 18.
[0137] Referring to FIG. 19, as described above, the meta information extraction unit 10 extracts meta information about the input code (S100).
[0138] Then, the conversion possibility determination unit 21 of the intermediate representation language conversion unit 20 determines whether the input code can be converted into an intermediate representation language based on the meta information extracted by the meta information extraction unit 10 (S110).
[0139] If it is determined that the conversion is possible, the conversion execution unit 22 of the intermediate representation language conversion unit 20 converts the input code into an intermediate representation language by the method as described above (S120).
[0140] Next, the intermediate representation language conversion unit 20 transmits the input code converted into the intermediate representation language to the code pattern information base analysis unit 31 and the semantic information base analysis unit 32 of the code analysis unit 30 (S130).
[0141] As described above, the code pattern information-based analysis unit 31 extracts code pattern information and detects vulnerable codes and rule violation cases based on this information (S140, S150). Further, the semantic information-based analysis unit 32 detects vulnerable codes and rule violation cases based on semantic information, which is at least one of variable tracking information, execution flow information, and conditional expression information (S160, S170).
[0142] Then, as described above, the vulnerability detection unit 40 generates a final vulnerability model based on the code pattern vulnerability table and the semantic vulnerability table for the vulnerabilities detected by the code pattern information-based analysis unit 31 and the semantic information-based analysis unit 32 (S180).
[0143] The present invention has been described with reference to the preferred embodiments of the present invention. Needless to say, the present invention is not limited to the above embodiments, and various modifications and variations can be made.
Explanation of Reference Numerals
[0144] 10… Meta-information extraction unit, 20… Intermediate representation language conversion unit, 30… Code analysis unit 30, 40… Vulnerability detection unit, 100… Analysis device.
Claims
1. A smart contract code vulnerability analysis device, comprising: a meta information extraction unit that extracts meta information about input code which is the source code of a smart contract; an intermediate representation language conversion unit that converts the input code into an intermediate representation language based on the meta information extracted by the meta information extraction unit; a code analysis unit that analyzes the input code converted into the intermediate representation language by the intermediate representation language conversion unit to detect whether there is vulnerable code and rule violation cases; a vulnerability detection unit that detects vulnerabilities based on the vulnerable code and rule violation cases detected by the code analysis unit and generates a final vulnerability model; wherein, the intermediate representation language conversion unit comprises a convertible determination unit that determines whether the input code can be converted into an intermediate representation language based on the meta information extracted by the meta information extraction unit; and a conversion execution unit that converts the input code into an intermediate representation language when it is determined by the convertible determination unit that the input code can be converted into an intermediate representation language; wherein, the meta information includes at least one of blockchain platform information, programming language information, and version information; the vulnerability detection unit generates a vulnerability model for the vulnerabilities detected based on the code vulnerabilities and rule violation cases detected by the code analysis unit, removes duplicates, arranges them according to priority, and generates a final vulnerability model; the vulnerability detection unit generates a syntactic vulnerability model from the vulnerability information recorded in the code pattern vulnerability table generated by the code analysis unit, generates a semantic vulnerability model from the vulnerability information recorded in the semantic vulnerability table generated by the code analysis unit, represents the vulnerability model by these two models, and generates a vulnerability model by adding additional information including severity information, reference information, and patch information. A smart contract code vulnerability analysis device characterized by this.
2. The conversion execution unit comprises an abstract syntax tree generation unit that parses the input code to generate an abstract syntax tree; An intermediate representation language generation unit that generates an intermediate representation language for the input code by traversing the abstract syntax tree generated by the abstract syntax tree generation unit via a visitor; The smart contract code vulnerability analysis device according to claim 1, characterized by including
3. The code analysis unit A code pattern information-based analysis unit that detects vulnerable codes and rule violation cases based on the code pattern information of the input code converted into an intermediate representation language; A semantic information-based analysis unit that detects vulnerable codes and rule violation cases based on at least one of variable tracking information, execution flow information, and conditional expression information of the input code converted into an intermediate representation language; including The semantic information-based analysis unit A semantic information extraction unit that extracts semantic information including at least one of variable tracking information, execution flow information, and conditional expression information from the input code expressed in an intermediate representation language; A vulnerable code detection unit that detects whether there are vulnerable codes and rule violation cases based on the semantic information generated by the semantic information extraction unit; including The semantic information extraction unit generates and stores a control flow graph indicating execution flow information; The vulnerable code detection unit is characterized in that when there is a node that cannot be reached in the control flow graph, there are more nodes than a preset value, or an external smart contract is called although it is not a leaf node, it detects vulnerable codes and rule violation cases. The smart contract code vulnerability analysis device according to claim 1.
4. The code pattern information-based analysis unit A code pattern information extraction unit that extracts the pattern information of the input code expressed in an intermediate representation language; A vulnerable code detection unit that detects whether there are vulnerable codes and rule violation cases based on the code pattern information extracted by the code pattern information extraction unit; including The code pattern information extraction unit extracts code pattern information including syntax extracted in at least one unit of line unit, function unit, block unit, and token unit for the input code converted and expressed in an intermediate representation language, the hash value of the extracted syntax, start line information, and end line information. The vulnerability code detection unit detects whether there is the same data as the vulnerable codes and rule data constructed in the vulnerability database in the code pattern information extracted by the code pattern information extraction unit. The vulnerability database is generated by extracting meta-information with the vulnerable code and line information of the vulnerable code as inputs, then converting the input vulnerable code into an intermediate representation language based on the extracted meta-information, and then extracting code pattern information based on the line information of the vulnerable code. The smart contract code vulnerability analysis device according to claim 3 is characterized by this.
5. When each variable is declared in the input code converted into the intermediate representation language, the semantic information extraction unit adds each variable to the variable management table, saves the range of values that each variable can represent in the variable value table for each variable, and generates variable tracking information. The vulnerability code detection unit detects vulnerable codes and rule violation cases when the variable value information included in the variable tracking information is an integer overflow, an uninitialized variable, the represented value of the variable is the block.timestamp value, or the balance is 0 or less. The smart contract code vulnerability analysis device according to claim 3 is characterized by this.
6. The vulnerability detection unit When the parts of the input code detected as vulnerability points have the same type of vulnerability points and any one of them is included in the other, the part of the input code that is included is determined to be a duplicate and removed. When there are parts of the input code with the same patch information, any one of them is determined to be a duplicate and removed. When there is patch information for vulnerability points classified as "Critical", which is the most dangerous stage of severity information, it is sorted in the highest rank, and when there is no patch information, it is sorted in the next rank. The smart contract code vulnerability analysis device according to claim 1, characterized in that a final vulnerability model is generated by arranging, in the next rank, the cases where patch information exists and the severity information is "High", "Medium", "Low", arranging, in the next rank, the cases where patch information exists and the severity information is "High", "Medium", "Low", and arranging, in the next rank, the cases where patch information does not exist and the severity information is "High", "Medium", "Low".
7. A smart contract code vulnerability analysis method executed by the smart contract code vulnerability analysis device according to claim 1, comprising: a first step of extracting meta information about input code that is the source code of a smart contract; a second step of converting the input code into an intermediate representation language based on the meta information extracted in the first step; a third step of analyzing the input code converted into the intermediate representation language in the second step to detect whether there are vulnerable codes and rule violation cases; a fourth step of detecting vulnerabilities based on the vulnerable codes and rule violation cases detected in the third step and generating a final vulnerability model; including the fourth step is generating a vulnerability model for the vulnerabilities detected based on the code vulnerabilities and rule violation cases detected in the third step, removing duplicates, arranging them according to priority, and generating a final vulnerability model; generating a syntactic vulnerability model from the vulnerability information recorded in the code pattern vulnerability table generated in the third step, generating a semantic vulnerability model from the vulnerability information recorded in the semantic vulnerability table generated in the third step, representing the vulnerability model by these two models, and adding additional information including severity information, reference information, and patch information to generate a vulnerability model, characterized in that it is a smart contract code vulnerability analysis method.