Requirements for the development of smart contracts and an overview of smart contract vulnerabilities at the Solidity code level on the Ethereum platform

N. Komleva, O. Tereshchenko
{"title":"Requirements for the development of smart contracts and an overview of smart contract vulnerabilities at the Solidity code level on the Ethereum platform","authors":"N. Komleva, O. Tereshchenko","doi":"10.15276/hait.06.2023.4","DOIUrl":null,"url":null,"abstract":"The article is devoted to the consideration of automated decentralized programs on the blockchain, which are a modern tool for processing transactions without the help of a trusted third party. The purpose of the study is to generalize and systematize information on the requirements for smart contracts, as well as review the vulnerabilities of smart contracts at the Solidity code level. The blockchain architecture was studied and the advantages of smart contracts compared to conventional contracts were determined, namely: risk reduction, reduction of administration and maintenance costs, and improvement of business process efficiency. A thorough analysis of current literature has been carried out and the current problems faced by users and developers of smart contracts have been identified. It is noted that the process of developing smart contracts is not sufficiently standardized and it is advisable to create a system of recommended requirements for smart contracts used in various subject areas. The requirements for smart contracts have been collected and analyzed for areas related to healthcare, education, business, project management, data analysis, software development, trading, logistics, and jurisprudence. It is determined that the mandatory requirements for all these subject areas are security, process transparency, determination of conditions and criteria for success, and automation of work. The rest of the requirements are analyzed and the concepts of the measure of coincidence and uniqueness of requirements for a particular subject area based on the corresponding functions are introduced. The coincidence and uniqueness measures were calculated for the considered subject areas. The proposed measures will allow in the future to obtain a quantitative assessment of templates for gathering requirements for programs, taking into account the used subject area. The article reviews and systematizes the types of vulnerabilities of smart contracts at the level of Solidity code on the Ethereum platform. The best practices to avoid such vulnerabilities and possible examples of their exploitation by attackers are identified. It has been shown that increasing the reliability of smart contracts will help increase trust in the blockchain among users.","PeriodicalId":375628,"journal":{"name":"Herald of Advanced Information Technology","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-04-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Herald of Advanced Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.15276/hait.06.2023.4","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

The article is devoted to the consideration of automated decentralized programs on the blockchain, which are a modern tool for processing transactions without the help of a trusted third party. The purpose of the study is to generalize and systematize information on the requirements for smart contracts, as well as review the vulnerabilities of smart contracts at the Solidity code level. The blockchain architecture was studied and the advantages of smart contracts compared to conventional contracts were determined, namely: risk reduction, reduction of administration and maintenance costs, and improvement of business process efficiency. A thorough analysis of current literature has been carried out and the current problems faced by users and developers of smart contracts have been identified. It is noted that the process of developing smart contracts is not sufficiently standardized and it is advisable to create a system of recommended requirements for smart contracts used in various subject areas. The requirements for smart contracts have been collected and analyzed for areas related to healthcare, education, business, project management, data analysis, software development, trading, logistics, and jurisprudence. It is determined that the mandatory requirements for all these subject areas are security, process transparency, determination of conditions and criteria for success, and automation of work. The rest of the requirements are analyzed and the concepts of the measure of coincidence and uniqueness of requirements for a particular subject area based on the corresponding functions are introduced. The coincidence and uniqueness measures were calculated for the considered subject areas. The proposed measures will allow in the future to obtain a quantitative assessment of templates for gathering requirements for programs, taking into account the used subject area. The article reviews and systematizes the types of vulnerabilities of smart contracts at the level of Solidity code on the Ethereum platform. The best practices to avoid such vulnerabilities and possible examples of their exploitation by attackers are identified. It has been shown that increasing the reliability of smart contracts will help increase trust in the blockchain among users.
智能合约开发的需求以及以太坊平台上Solidity代码级别的智能合约漏洞概述
本文致力于考虑区块链上的自动分散程序,这是一种无需可信第三方帮助即可处理事务的现代工具。该研究的目的是概括和系统化有关智能合约需求的信息,并在Solidity代码级别审查智能合约的漏洞。研究了区块链架构,确定了智能合约相对于传统合约的优势,即:降低风险、降低管理和维护成本、提高业务流程效率。对当前文献进行了彻底的分析,并确定了智能合约用户和开发人员当前面临的问题。值得注意的是,开发智能合约的过程还不够标准化,建议为各个主题领域使用的智能合约创建一个推荐需求系统。智能合约的需求已被收集和分析,涉及医疗保健、教育、商业、项目管理、数据分析、软件开发、贸易、物流和法学等领域。确定所有这些主题领域的强制性需求是安全性、过程透明性、成功的条件和标准的确定以及工作的自动化。对其余的需求进行了分析,并介绍了基于相应功能的特定主题领域需求的符合性和唯一性度量的概念。计算了所考虑的主题领域的一致性和唯一性度量。拟议的措施将允许在未来获得收集程序需求的模板的定量评估,考虑到使用的主题领域。本文回顾并系统化了以太坊平台上Solidity代码级别的智能合约漏洞类型。本文确定了避免此类漏洞的最佳实践以及攻击者利用这些漏洞的可能示例。事实证明,提高智能合约的可靠性将有助于增加用户对区块链的信任。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信