Automated Smart Contract Attack Path Tracing on Blockchain

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for tracing hacker attacks on smart contracts on blockchain networks are inefficient, prone to errors, and lack accuracy due to reliance on manual queries.

Innovation Solution

An automated method for tracing the path of an attack on a smart contract, which involves determining the hacker's attack address, start and stop times, and automatically obtaining and parsing hash values of transactions to identify fungible and non-fungible tokens transferred.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual queries are used to trace hacker attacks on smart contracts, then the process can be performed with simple tools, but the efficiency and accuracy of tracing are poor and error-prone

Engineering Contradiction:
Improvetracing accuracyVSAvoidtracing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces manual mechanical querying operations with an automated computer-based system that uses algorithms to trace attack paths. The system automatically obtains transaction data, parses hash values, and identifies attack routes without human intervention, thereby improving both accuracy and efficiency simultaneously.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The tracing system performs self-service by automatically executing the entire attack path tracing process. It autonomously queries transaction data, parses cryptographic hash values, identifies hacker addresses, and generates tracing reports without requiring manual operation, thus resolving the contradiction between simplicity and effectiveness.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual queries are used to trace attack paths, then the system complexity remains low, but the tracing process is time-consuming and error-prone

Engineering Contradiction:
Improvetracing reliabilityVSAvoidtracing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces time-consuming manual tracing operations with automated computational processes. The system uses computer algorithms to rapidly query blockchain data, parse transaction hash values, and identify attack paths, reducing tracing time from hours or days to minutes while simultaneously improving reliability through consistent automated execution.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary actions by pre-establishing the automated tracing framework and algorithms before actual attack tracing is needed. This preparation enables rapid response to security incidents, reducing the time loss when actual tracing is required while ensuring reliable results through pre-tested automated processes.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automated methods are used to trace attack paths, then efficiency and accuracy improve, but the system complexity increases

Engineering Contradiction:
Improvetracing efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an automated tracing system as an intermediary between the blockchain network and security analysts. This intermediary automatically handles the complex tasks of data querying, hash parsing, and attack path identification, thereby improving tracing efficiency and accuracy while shielding users from the underlying system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates automated copies of manual tracing processes through algorithmic implementation. By replicating and automating the tracing logic in software, the system achieves high efficiency and accuracy while encapsulating the complexity within the automated system rather than requiring complex manual procedures.

Inventive Principle:
Principle #26Copying

4Loss of information

If manual queries are used, then the ease of operation is maintained, but the completeness of tracing results is poor with easy omission

Engineering Contradiction:
Improvetracing completenessVSAvoidoperation simplicity
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent replaces manual querying operations with automated systematic processes that comprehensively trace all attack-related transactions. The automated system methodically queries and analyzes every relevant transaction hash value, ensuring complete tracing results without omissions that are common in manual operations, while maintaining ease of use through automated execution.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The automated tracing system maintains continuous operation throughout the tracing process, systematically processing all transaction data without interruption or human error. This continuous automated action ensures complete tracing results by consistently applying the same rigorous methodology to every data point, eliminating the gaps and omissions inherent in manual operations.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20250080550A1Method for tracing path of attack on smart contract on blockchain
Publication Date: 2025.03.06 BEIJING LINGZONG SECURITY TECH CO LTD
  • US20250080550A1 patent drawing
  • US20250080550A1 patent drawing

AI summary

The present disclosure provides a method for tracing a path of an attack on a smart contract on a blockchain, belonging to the technical field of blockchains. The method specifically includes: determining a hacker's attack address, and determining an attack's start time and an attack's stop time according to a data record of the hacker's attack address; and determining hash values of all transactions from a hacker's attack destination address between the attack's start time and the attack's stop time automatically, and obtaining a fungible token and a non-fungible token by parsing the hash values automatically. The problems of large error and low efficiency during original manual extraction are solved, accuracy and efficiency are higher, and the overall security is improved.