[论文解读] A Survey on the Security of Blockchain Systems
本论文系统性地综述了自 2009 年至 2017 年 5 月在主流区块链系统中的安全风险、真实攻击以及安全增强技术。
Since its inception, the blockchain technology has shown promising application prospects. From the initial cryptocurrency to the current smart contract, blockchain has been applied to many fields. Although there are some studies on the security and privacy issues of blockchain, there lacks a systematic examination on the security of blockchain systems. In this paper, we conduct a systematic study on the security threats to blockchain and survey the corresponding real attacks by examining popular blockchain systems. We also review the security enhancement solutions for blockchain, which could be used in the development of various blockchain systems, and suggest some future directions to stir research efforts into this area.
研究动机与目标
- 调查 blockchain 系统(1.0 与 2.0)面临的安全威胁。
- 调查在流行区块链平台上的真实世界攻击及被利用的漏洞。
- 评述实际的安全改进措施及未来研究方向。
提出的方法
- 将区块链安全风险分类为涵盖区块链运行与智能合约漏洞的九大类别。
- 分析真实攻击案例以将事件映射到具体漏洞。
- 总结学术文献中提出的安全改进措施和工具。
实验结果
研究问题
- RQ1区块链 1.0 与 2.0 系统面临的主要安全风险及其根本原因是什么?
- RQ2在流行区块链系统上发生了哪些真实世界的攻击,以及它们利用了哪些漏洞?
- RQ3为降低区块链风险提出了哪些安全增强措施,未来方向有哪些?
主要发现
- 确认九大风险类别,覆盖共识、私钥安全、犯罪活动、双花、隐私泄露、智能合约漏洞、未充分优化的合约,以及运行成本定价过低(低价运行)的问题。
- 记录的攻击和问题包括 51% 攻击漏洞、私钥恢复风险、双花,以及通过 gas mispricing 引发的 DoS/类似 DoS 问题。
- 智能合约的安全弱点证据,例如重入攻击和交易顺序依赖性,并且需要改进的验证工具(如 Oyente)和 gas 优化技术。
- 突出真实世界案例,如使用 Bitcoin 的勒索软件和地下市场,以及对自私矿工攻击作为攻击向量的分析。
- 讨论智能合约(区块链 2.0)特有的漏洞,如犯罪智能合约和不可变的 bug。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。