Skip to main content

2022 | OriginalPaper | Buchkapitel

Ethereum Contract Honeypot Risk Analysis

verfasst von : Motoya Ishimaki, Kazumasa Omote

Erschienen in: Frontiers in Cyber Security

Verlag: Springer Nature Singapore

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

In recent years, smart contracts on the Ethereum platform have attracted considerable attention, and smart contracts have increasingly become targets of cyberattacks for the purpose of stealing cryptoassets. One of the emerging attack methods is to intentionally deploy contracts that appear to contain vulnerabilities but have backdoors, and that, lure attackers who are targeting vulnerable contracts to steal cryptoassets. These are called smart contract honeypots (henceforth referred to simply as “contract honeypots”). Torres et al. analyzed contract honeypots for the first time at USNIX Security 2019. In this study, we look at eight types of contract honeypots organized by Torres et al. and calculate the damages caused by each of them. We also analyze the code of contract honeypots by focusing on the arguments of the money transfer process, and we discovered a new type of contract honeypot. This analysis suggests that smart contracts with “this.balance” in the money transfer process may be contract honeypots. Furthermore, we discuss the impact of contract honeypots on general users.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Buterin, V.: A next-generation smart contract and decentralized application platform. White Paper (2014) Buterin, V.: A next-generation smart contract and decentralized application platform. White Paper (2014)
2.
Zurück zum Zitat Camino, R., Torres, C.F., Baden, M., State, R.: A data science approach for detecting honeypots in Ethereum. In: IEEE ICBC 2020, pp. 1–9. IEEE (2020) Camino, R., Torres, C.F., Baden, M., State, R.: A data science approach for detecting honeypots in Ethereum. In: IEEE ICBC 2020, pp. 1–9. IEEE (2020)
3.
Zurück zum Zitat Chen, W., et al.: Honeypot contract risk warning on Ethereum smart contracts. In: IEEE JCC (2020) Chen, W., et al.: Honeypot contract risk warning on Ethereum smart contracts. In: IEEE JCC (2020)
4.
Zurück zum Zitat Gogineni, A.K., et al.: Multi-class classification of vulnerabilities in smart contracts using AWD-LSTM, with pretrained encoder inspired from natural language processing. arXiv:2004.00362 (2020) Gogineni, A.K., et al.: Multi-class classification of vulnerabilities in smart contracts using AWD-LSTM, with pretrained encoder inspired from natural language processing. arXiv:​2004.​00362 (2020)
5.
Zurück zum Zitat Hara, K., Takahashi, T., Ishimaki, M., Omote, K.: Machine-learning approach using solidity bytecode for smart-contract honeypot detection in the Ethereum. In: IEEE QRS-C (2021) Hara, K., Takahashi, T., Ishimaki, M., Omote, K.: Machine-learning approach using solidity bytecode for smart-contract honeypot detection in the Ethereum. In: IEEE QRS-C (2021)
6.
Zurück zum Zitat Hu, T., et al.: Transaction-based classification and detection approach for Ethereum smart contract. Inf. Process. Manag. 58(2021), 102462 (2021)CrossRef Hu, T., et al.: Transaction-based classification and detection approach for Ethereum smart contract. Inf. Process. Manag. 58(2021), 102462 (2021)CrossRef
7.
Zurück zum Zitat Liao, W., Tsai, T.T., He, C.K., Tien, C.W.: SoliAudit: smart contract vulnerability assessment based on machine learning and fuzz testing. In: IOTSMS 2019, pp. 458–465. IEEE (2019) Liao, W., Tsai, T.T., He, C.K., Tien, C.W.: SoliAudit: smart contract vulnerability assessment based on machine learning and fuzz testing. In: IOTSMS 2019, pp. 458–465. IEEE (2019)
8.
Zurück zum Zitat Luu, L., et al.: Making smart contracts smarter. In: CCS 2016, pp. 254–269 (2016) Luu, L., et al.: Making smart contracts smarter. In: CCS 2016, pp. 254–269 (2016)
9.
Zurück zum Zitat Nakamoto, S.: Bitcoin: a peer-to-peer electronic cash system (2008) Nakamoto, S.: Bitcoin: a peer-to-peer electronic cash system (2008)
10.
Zurück zum Zitat Torres, C.F., et al.: The art of the scam: demystifying honeypots in Ethereum smart contracts. In: USENIX Security 2019, pp. 1591–1607 (2019) Torres, C.F., et al.: The art of the scam: demystifying honeypots in Ethereum smart contracts. In: USENIX Security 2019, pp. 1591–1607 (2019)
Metadaten
Titel
Ethereum Contract Honeypot Risk Analysis
verfasst von
Motoya Ishimaki
Kazumasa Omote
Copyright-Jahr
2022
Verlag
Springer Nature Singapore
DOI
https://doi.org/10.1007/978-981-19-8445-7_15