{"id":"https://openalex.org/W3128660473","doi":"https://doi.org/10.1109/tdsc.2020.3037332","title":"Oracle-Supported Dynamic Exploit Generation for Smart Contracts","display_name":"Oracle-Supported Dynamic Exploit Generation for Smart Contracts","publication_year":2020,"publication_date":"2020-11-11","ids":{"openalex":"https://openalex.org/W3128660473","doi":"https://doi.org/10.1109/tdsc.2020.3037332","mag":"3128660473"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2020.3037332","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"journal-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"http://arxiv.org/pdf/1909.06605","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100419375","display_name":"Haijun Wang","orcid":"https://orcid.org/0009-0001-3509-3919"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Haijun Wang","raw_affiliation_strings":["School of Computer Science and Engineering, Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100346528","display_name":"Ye Liu","orcid":"https://orcid.org/0000-0001-6709-3721"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Ye Liu","raw_affiliation_strings":["School of Computer Science and Engineering, Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100421812","display_name":"Yi Li","orcid":"https://orcid.org/0000-0003-4562-8208"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Yi Li","raw_affiliation_strings":["School of Computer Science and Engineering, Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072863865","display_name":"Shang\u2010Wei Lin","orcid":"https://orcid.org/0000-0002-9726-3434"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Shang-Wei Lin","raw_affiliation_strings":["School of Computer Science and Engineering, Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063347761","display_name":"Cyrille Artho","orcid":"https://orcid.org/0000-0002-3656-1614"},"institutions":[{"id":"https://openalex.org/I86987016","display_name":"KTH Royal Institute of Technology","ror":"https://ror.org/026vcq606","country_code":"SE","type":"education","lineage":["https://openalex.org/I86987016"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Cyrille Artho","raw_affiliation_strings":["School of Computer Science and Communication, KTH Royal Institute of Technology, Stockholm, Sweden"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Communication, KTH Royal Institute of Technology, Stockholm, Sweden","institution_ids":["https://openalex.org/I86987016"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101468661","display_name":"Lei Ma","orcid":"https://orcid.org/0000-0002-8621-2420"},"institutions":[{"id":"https://openalex.org/I135598925","display_name":"Kyushu University","ror":"https://ror.org/00p4k0j84","country_code":"JP","type":"education","lineage":["https://openalex.org/I135598925"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Lei Ma","raw_affiliation_strings":["Faculty of Information Science and Electrical Engineering, Kyushu University, Fukuoka, Japan"],"affiliations":[{"raw_affiliation_string":"Faculty of Information Science and Electrical Engineering, Kyushu University, Fukuoka, Japan","institution_ids":["https://openalex.org/I135598925"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100355692","display_name":"Yang Liu","orcid":"https://orcid.org/0000-0001-7300-9215"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Yang Liu","raw_affiliation_strings":["School of Computer Science and Engineering, Nanyang Technological University, Singapore"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Nanyang Technological University, Singapore","institution_ids":["https://openalex.org/I172675005"]}]}],"institution_assertions":[],"countries_distinct_count":3,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":7.191,"has_fulltext":false,"cited_by_count":44,"citation_normalized_percentile":{"value":0.999983,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":97},"biblio":{"volume":"19","issue":"3","first_page":"1795","last_page":"1809"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10270","display_name":"Blockchain Technology Applications and Security","score":0.999,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10270","display_name":"Blockchain Technology Applications and Security","score":0.999,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9925,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9904,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/smart-contract","display_name":"Smart contract","score":0.7396252},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability","score":0.5250754},{"id":"https://openalex.org/keywords/random-oracle","display_name":"Random oracle","score":0.48504394}],"concepts":[{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.92449236},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.843925},{"id":"https://openalex.org/C55166926","wikidata":"https://www.wikidata.org/wiki/Q2892946","display_name":"Oracle","level":2,"score":0.82290894},{"id":"https://openalex.org/C2779950589","wikidata":"https://www.wikidata.org/wiki/Q7544035","display_name":"Smart contract","level":3,"score":0.7396252},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.60441923},{"id":"https://openalex.org/C64869954","wikidata":"https://www.wikidata.org/wiki/Q1859747","display_name":"False positive paradox","level":2,"score":0.54004633},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5250754},{"id":"https://openalex.org/C75949130","wikidata":"https://www.wikidata.org/wiki/Q848010","display_name":"Database transaction","level":2,"score":0.49227872},{"id":"https://openalex.org/C94284585","wikidata":"https://www.wikidata.org/wiki/Q228184","display_name":"Random oracle","level":4,"score":0.48504394},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.25119093},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.20115745},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.122540295},{"id":"https://openalex.org/C203062551","wikidata":"https://www.wikidata.org/wiki/Q201339","display_name":"Public-key cryptography","level":3,"score":0.090782374},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2020.3037332","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/1909.06605","pdf_url":"http://arxiv.org/pdf/1909.06605","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/1909.06605","pdf_url":"http://arxiv.org/pdf/1909.06605","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[],"grants":[{"funder":"https://openalex.org/F4320320709","funder_display_name":"National Research Foundation Singapore","award_id":null},{"funder":"https://openalex.org/F4320320743","funder_display_name":"Energy Market Authority of Singapore","award_id":"NRF2017EWT-EP003-023"},{"funder":"https://openalex.org/F4320320751","funder_display_name":"Ministry of Education - Singapore","award_id":"MOE2018-T2-1-068"},{"funder":"https://openalex.org/F4320320766","funder_display_name":"Nanyang Technological University","award_id":"NWJ-2019-003"}],"datasets":[],"versions":[],"referenced_works_count":38,"referenced_works":["https://openalex.org/W185290757","https://openalex.org/W2007187080","https://openalex.org/W2041713059","https://openalex.org/W2052363833","https://openalex.org/W2068162212","https://openalex.org/W2144344516","https://openalex.org/W2176225732","https://openalex.org/W2183126124","https://openalex.org/W2471111208","https://openalex.org/W2538848838","https://openalex.org/W2539190473","https://openalex.org/W2578476968","https://openalex.org/W2604844934","https://openalex.org/W2613534458","https://openalex.org/W2621687283","https://openalex.org/W2741068848","https://openalex.org/W2769609281","https://openalex.org/W2790202156","https://openalex.org/W2805052744","https://openalex.org/W2846896781","https://openalex.org/W2884619780","https://openalex.org/W2885034081","https://openalex.org/W2892520266","https://openalex.org/W2898569715","https://openalex.org/W2902729902","https://openalex.org/W2906668391","https://openalex.org/W2955886508","https://openalex.org/W2963465913","https://openalex.org/W2963610883","https://openalex.org/W2963846926","https://openalex.org/W2964241064","https://openalex.org/W2964257386","https://openalex.org/W2982383932","https://openalex.org/W3015405072","https://openalex.org/W3016155638","https://openalex.org/W3023191323","https://openalex.org/W3101591015","https://openalex.org/W3121465398"],"related_works":["https://openalex.org/W4383898246","https://openalex.org/W4376606592","https://openalex.org/W4293653209","https://openalex.org/W4292566855","https://openalex.org/W4247269287","https://openalex.org/W4236848438","https://openalex.org/W3103506657","https://openalex.org/W3090326592","https://openalex.org/W2735770104","https://openalex.org/W2464784130"],"abstract_inverted_index":{"Despite":[0],"the":[1,17,51,59,70,78,103,111,160],"high":[2],"stakes":[3],"involved":[4],"in":[5,12],"smart":[6,38,148],"contracts,":[7],"they":[8],"are":[9],"often":[10],"developed":[11],"an":[13],"undisciplined":[14],"manner,":[15],"leaving":[16],"security":[18],"and":[19,58,76,106,130,157,163],"reliability":[20],"of":[21,72,102,137,169],"blockchain":[22],"transactions":[23],"at":[24],"risk.":[25],"In":[26,118],"this":[27,116],"article,":[28],"we":[29],"introduce":[30],"ContraMaster\u2014an":[31],"oracle-supported":[32],"dynamic":[33,60,91],"exploit":[34,115],"generation":[35],"framework":[36],"for":[37],"contracts.":[39,149],"Existing":[40],"approaches":[41],"mutate":[42],"only":[43],"single":[44],"transactions;":[45],"ContraMaster":[46,54,123,144],"exceeds":[47],"these":[48],"by":[49],"mutating":[50],"transaction":[52],"sequences.":[53],"uses":[55],"data-flow,":[56],"control-flow,":[57],"contract":[61,74],"state":[62],"to":[63,86,109,114,120,134],"guide":[64],"its":[65,154],"mutations.":[66],"It":[67],"then":[68],"monitors":[69],"executions":[71],"target":[73],"programs,":[75],"validates":[77],"results":[79,152],"against":[80],"a":[81,90,100],"general-purpose":[82],"semantic":[83],"test":[84,104],"oracle":[85,105],"discover":[87],"vulnerabilities.":[88],"Being":[89],"technique,":[92],"it":[93,131],"guarantees":[94],"that":[95],"each":[96],"discovered":[97],"vulnerability":[98],"is":[99,107],"violation":[101],"able":[108],"generate":[110],"attack":[112],"script":[113],"vulnerability.":[117],"contrast":[119],"rule-based":[121],"approaches,":[122],"has":[124],"not":[125],"shown":[126],"any":[127],"false":[128],"positives,":[129],"easily":[132],"generalizes":[133],"unknown":[135],"types":[136,168],"vulnerabilities":[138],"(e.g.,":[139],"logic":[140],"errors).":[141],"We":[142],"evaluate":[143],"on":[145],"218":[146],"vulnerable":[147],"The":[150],"experimental":[151],"confirm":[153],"practical":[155],"applicability":[156],"advantages":[158],"over":[159],"state-of-the-art":[161],"techniques,":[162],"also":[164],"reveal":[165],"three":[166],"new":[167],"attacks.":[170]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W3128660473","counts_by_year":[{"year":2024,"cited_by_count":13},{"year":2023,"cited_by_count":12},{"year":2022,"cited_by_count":4},{"year":2021,"cited_by_count":5}],"updated_date":"2024-12-13T12:34:00.313594","created_date":"2021-02-15"}