[論文レビュー] An Empirical Study on Ethereum Private Transactions and the Security Implications
本論文は、イーサリアムのプライベート取引に関する最初の大規模な実証的研究を提示する。取引の特性、経済的影響、セキュリティリスクを分析した。カスタムイーサリアムノードと公開データを用いて、プライベート取引は主にMEV抽出に使われており、ガスコストが低く、マイナーの利益が高いため、プライバシーとセキュリティの約束を損なう4.3%の漏洩率を示している。
Recently, Decentralized Finance (DeFi) platforms on Ethereum are booming, and numerous traders are trying to capitalize on the opportunity for maximizing their benefits by launching front-running attacks and extracting Miner Extractable Values (MEVs) based on information in the public mempool. To protect end users from being harmed and hide transactions from the mempool, private transactions, a special type of transactions that are sent directly to miners, were invented. Private transactions have a high probability of being packed to the front positions of a block and being added to the blockchain by the target miner, without going through the public mempool, thus reducing the risk of being attacked by malicious entities. Despite the good intention of inventing private transactions, due to their stealthy nature, private transactions have also been used by attackers to launch attacks, which has a negative impact on the Ethereum ecosystem. However, existing works only touch upon private transactions as by-products when studying MEV, while a systematic study on private transactions is still missing. To fill this gap and paint a complete picture of private transactions, we take the first step towards investigating the private transactions on Ethereum. In particular, we collect large-scale private transaction datasets and perform analysis on their characteristics, transaction costs and miner profits, as well as security impacts. This work provides deep insights on different aspects of private transactions.
研究の動機と目的
- プライベート取引がフロントランニングやMEV攻撃からユーザーを保護することを目的としているが、その実世界での使用状況と特性を理解すること。
- 取引コストとマイナー収益性を含む、プライベート取引の経済的影響を分析すること。
- 取引漏洩のリスクや新たな攻撃ベクトルの可能性を含む、セキュリティ上の影響を評価すること。
- MEVの役割を超えて、プライベート取引の包括的図像を提示し、重要な研究ギャップを埋めること。
提案手法
- カスタムイーサリアムノードとEtherscan、TradingViewからの公開データを用いて、大規模なプライベート取引データセットを収集した。
- 2021年5月から2022年4月までの取引データと、2022年5月のメモリーループ観測データ(9日間)を分析した。
- 使用状況のパターンを理解するために、取引をカテゴリ、DeFiトークン、プラットフォーム、関係者別に分類した。
- ガス使用量と収益の比較を通じて、プライベート取引とパブリック取引の両者における取引コストとマイナー利益を測定した。
- MEV関連のパターンを検出することで、プライベート取引がパブリックメモリーループに漏洩する可能性を評価した。
- 統計的およびグラフベースの分析を用いて、コンSENSUSセキュリティと実世界の攻撃表面を評価した。
実験結果
リサーチクエスチョン
- RQ1実際の運用において、プライベート取引はDeFiプラットフォーム、トークン、エントリティの間でどのように分布しているか?
- RQ2ガスコストとマイナー利益という観点から、プライベート取引の経済的影響は何か?
- RQ3プライベート取引はどの程度パブリックメモリーループに漏洩しており、そのセキュリティ上の影響は何か?
- RQ4プライベート取引はMEV抽出にどのように使われており、イーサリアムエコシステムにどのようなリスクをもたらしているか?
主な発見
- プライベート取引は主にMEV抽出に使われており、大多数がアービトラージやフロントランニングの機会を狙ったものである。
- プライベート取引は平均してパブリック取引よりも20〜30%少ないガスを使用しており、ユーザーのコストが削減されている。
- 戦略的な配置と競争の減少により、マイナーはプライベート取引から著しく高い利益を得ている。
- 約4.3%のプライベート取引がパブリックメモリーループに漏洩しており、フロントランニングやMEV攻撃の対象となっている。
- プライベート取引の高利益性は、アンダーバイアス攻撃のインセンティブを生み出し、コンセンサスセキュリティを脅かしている。
- プライバシーの意図にもかかわらず、プライベート取引は次第に攻撃者に悪用されており、ユーザー保護の根幹を揺るがしている。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。