Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
The Art of The Scam: Demystifying Honeypots in Ethereum Smart Contracts
FERREIRA TORRES, Christof; STEICHEN, Mathis; STATE, Radu
2019In USENIX Security Symposium, Santa Clara, 14-16 August 2019
Peer reviewed
 

Documents


Texte intégral
HoneyBadger_USENIX_2019_Final.pdf
Preprint Auteur (545.7 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Symbolic execution; Smart contracts; Honeypots
Résumé :
[en] Modern blockchains, such as Ethereum, enable the execution of so-called smart contracts - programs that are executed across a decentralised network of nodes. As smart contracts become more popular and carry more value, they become more of an interesting target for attackers. In the past few years, several smart contracts have been exploited by attackers. However, a new trend towards a more proactive approach seems to be on the rise, where attackers do not search for vulnerable contracts anymore. Instead, they try to lure their victims into traps by deploying seemingly vulnerable contracts that contain hidden traps. This new type of contracts is commonly referred to as honeypots. In this paper, we present the first systematic analysis of honeypot smart contracts, by investigating their prevalence, behaviour and impact on the Ethereum blockchain. We develop a taxonomy of honeypot techniques and use this to build HoneyBadger - a tool that employs symbolic execution and well defined heuristics to expose honeypots. We perform a large-scale analysis on more than 2 million smart contracts and show that our tool not only achieves high precision, but is also highly efficient. We identify 690 honeypot smart contracts as well as 240 victims in the wild, with an accumulated profit of more than $90,000 for the honeypot creators. Our manual validation shows that 87% of the reported contracts are indeed honeypots.
Disciplines :
Sciences informatiques
Auteur, co-auteur :
FERREIRA TORRES, Christof ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
STEICHEN, Mathis ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
STATE, Radu  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Co-auteurs externes :
no
Langue du document :
Anglais
Titre :
The Art of The Scam: Demystifying Honeypots in Ethereum Smart Contracts
Date de publication/diffusion :
2019
Nom de la manifestation :
28th USENIX Security Symposium
Date de la manifestation :
from 14-08-2019 to 16-08-2019
Titre de l'ouvrage principal :
USENIX Security Symposium, Santa Clara, 14-16 August 2019
Peer reviewed :
Peer reviewed
Projet FnR :
FNR13192291 - Secure Blockchain Technologies For Finance, 2018 (01/10/2018-31/03/2022) - Christof Ferreira Torres
Disponible sur ORBilu :
depuis le 18 juin 2019

Statistiques


Nombre de vues
292 (dont 26 Unilu)
Nombre de téléchargements
641 (dont 20 Unilu)

Bibliographie


Publications similaires



Contacter ORBilu