Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Timely Identification of Victim Addresses in DeFi Attacks
PARHIZKARI, Bahareh; IANNILLO, Antonio Ken; FERREIRA TORRES, Christof et al.
2023In Timely Identification of Victim Addresses in DeFi Attacks
Peer reviewed
 

Files


Full Text
Identifying_Victims_in_DeFi_Attacks.pdf
Author postprint (412.64 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Ethereum; Smart Contracts; DeFi; Victims; Attacks
Abstract :
[en] Over the past years, Decentralized Finance (DeFi) protocols have suffered from several attacks. As a result, multiple solutions have been proposed to prevent such attacks. Most solutions rely on identifying malicious transactions before they are included in blocks. However, with the emergence of private pools, attackers can now conceal their exploit transactions from attack detection. This poses a significant challenge for existing security tools, which primarily rely on monitoring transactions in public mempools. To effectively address this challenge, it is crucial to develop proactive methods that predict malicious behavior before the actual attack transactions occur. In this work, we introduce a novel methodology to infer potential victims by analyzing the deployment bytecode of malicious smart contracts. Our idea leverages the fact that attackers typically split their attacks into two stages, a deployment stage, and an attack stage. This provides a small window to analyze the attacker's deployment code and identify victims in a timely manner before the actual attack occurs. By analyzing a set of past DeFi attacks, this work demonstrates that the victim of an attack transaction can be identified with an accuracy of almost 70%.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > SEDAN - Service and Data Management in Distributed Systems
Disciplines :
Computer science
Author, co-author :
PARHIZKARI, Bahareh  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SEDAN
IANNILLO, Antonio Ken  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SEDAN
FERREIRA TORRES, Christof ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust > SEDAN > Team Radu STATE ; ETH Zurich
Banescu, Sebastian;  Quantstamp, Inc
Xu, Joseph;  Quantstamp, Inc
STATE, Radu  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SEDAN
External co-authors :
yes
Language :
English
Title :
Timely Identification of Victim Addresses in DeFi Attacks
Publication date :
September 2023
Event name :
International Workshop on Cryptocurrencies and Blockchain Technology (CBT)
Event date :
2023
Main work title :
Timely Identification of Victim Addresses in DeFi Attacks
Publisher :
Springer
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Development Goals :
9. Industry, innovation and infrastructure
Available on ORBilu :
since 23 December 2023

Statistics


Number of views
229 (41 by Unilu)
Number of downloads
248 (13 by Unilu)

Scopus citations®
 
1
Scopus citations®
without self-citations
1
OpenAlex citations
 
5

Bibliography


Similar publications



Contact ORBilu