Skip to main content
QUICK REVIEW

[논문 리뷰] A Survey on Ethereum Systems Security: Vulnerabilities, Attacks and Defenses

Huashan Chen, Marcus Pendleton|arXiv (Cornell University)|2019. 08. 13.
Blockchain Technology Applications and Security참고 문헌 96인용 수 115
한 줄 요약

시스템적으로 분류하는 연구로 이더리움의 보안을 44가지 취약점, 26가지 공격, 47가지 방어로 분류하고, 이더리움의 계층 아키텍처와 환경 전반에 걸친 근본 원인 분석과 향후 방향을 제시한다.

ABSTRACT

The blockchain technology is believed by many to be a game changer in many application domains, especially financial applications. While the first generation of blockchain technology (i.e., Blockchain 1.0) is almost exclusively used for cryptocurrency purposes, the second generation (i.e., Blockchain 2.0), as represented by Ethereum, is an open and decentralized platform enabling a new paradigm of computing --- Decentralized Applications (DApps) running on top of blockchains. The rich applications and semantics of DApps inevitably introduce many security vulnerabilities, which have no counterparts in pure cryptocurrency systems like Bitcoin. Since Ethereum is a new, yet complex, system, it is imperative to have a systematic and comprehensive understanding on its security from a holistic perspective, which is unavailable. To the best of our knowledge, the present survey, which can also be used as a tutorial, fills this void. In particular, we systematize three aspects of Ethereum systems security: vulnerabilities, attacks, and defenses. We draw insights into, among other things, vulnerability root causes, attack consequences, and defense capabilities, which shed light on future research directions.

연구 동기 및 목표

  • 시스템적으로 이더리움 아키텍처와 그 환경 전반에 걸쳐 이더리움 보안 이슈를 취약점, 공격, 방어로 분류한다.
  • 취약점의 근본 원인을 식별하고 공격이 이를 어떻게 악용하는지 매핑한다.
  • 기존 방어의 효과와 한계를 분석하고 향후 연구 방향을 제시한다.
  • 안전한 이더리움 기반 시스템을 위한 실용적인 모범 사례와 설계 고려사항를 요약한다.

제안 방법

  • 응용, 데이터, 합의, 네트워크, 환경의 계층적 이더리움 아키텍처를 사용하여 보안 주제를 구성한다.
  • 44가지 취약점 유형(V1–V44)을 열거하고 그 근본 원인과 현재 상태(제거됨, 모범 사례 회피 가능, 또는 열림)를 분석한다.
  • 26가지 공격(A1–A26)을 열거하고 관련 취약점 및 결과와 연결한다.
  • 47가지 방어(D1–D47)를 열거하고 이를 선제적 또는 반응적으로 분류하며, 그 역량과 필요한 투자에 대한 분석을 제공한다.
  • Solidity, Solidity 코드 관행, 및 클라이언트 구현(Geth, Parity) 등 보안 논의의 초점 기술로 사용한다.

실험 결과

연구 질문

  • RQ1이더리움의 주요 취약점 분류와 계층 아키텍처 전반의 근본 원인은 무엇인가?
  • RQ2이 취약점을 악용하는 공격 기술은 무엇이며 그 결과는 무엇인가?
  • RQ3방어 메커니즘은 무엇이 존재하며 그 효과는 얼마나 되며 이더리움 시스템을 보호하는 데 어떤 격차가 남아 있는가?
  • RQ4연구자와 실무자가 공격 예방 및 완화를 돕기 위해 이더리움 보안 관행을 어떻게 구조화할 수 있는가?

주요 결과

  • 스마트 계약과 이더리움 설계에 의해 전통적인 애플리케이션에서는 볼 수 없었던 새로운 취약점 유형이 도입된다.
  • 44가지 취약점, 26가지 공격, 47가지 방어가 식별되고 분석된다.
  • 이더리움 환경의 취약점은 주로 인간, 사용성, 네트워킹 요인에 의해 좌우된다.
  • 선제적 방어는 많은 취약점을 완화할 수 있지만 반응적 방어는 더 적고, 프런트엔드와 프런트엔드–백엔드 간 상호작용에 격차가 있다.
  • 산업 모범 사례가 적절히 적용되면 많은 취약점을 예방할 수 있다.
  • 애플리케이션 계층(DApps)에서의 공격은 상당한 재정적 손실을 초래했으며, 일부 DoS 스타일 및 중앙화된 프런트엔드 문제도 영향을 미친다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.