Skip to main navigation Skip to search Skip to main content

EVM-Shield: In-Contract State Access Control for Fast Vulnerability Detection and Prevention

  • Xiaoli Zhang
  • , Wenxiang Sun
  • , Zhicheng Xu
  • , Hongbing Cheng*
  • , Chengjun Cai
  • , Helei Cui
  • , Qi Li
  • *Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

Abstract

Recently, smart contracts have been widely applied in security-sensitive fields yet are fragile to various vulnerabilities and attacks. Regarding this, existing research efforts either statically scrutinize smart contracts code or detect suspicious transaction execution flows. However, they either fail to timely protect contracts or only handle a small subset of well-known vulnerabilities. In the paper, we propose EVMShield that secures vulnerable smart contracts in real-time via fine-grained access control over sensitive states. The behind rationale is most of attacks aim to manipulate money-related states (e.g., tokens) for profits. Specifically, transaction-level state access control policies are first defined by developers and then translated into EVM-level policies with contract-aware function-level state access permissions. In policy enforcement, EVM-Shield introduces a hybrid storage analyzer to accurately identify (dynamic-allocated) storage locations for policy-involved states and a multi-stage cache based filter to fast revert bad transactions with unexpected state access behaviors. Finally, we conduct thorough experiments using 12 types of real-world contract vulnerabilities and all open-source smart contracts on the first 8M blocks of Ethereum. The results demonstrate that EVM-Shield outperforms two state-of-the-art runtime analysis tools in terms of attack detection. Extensive performance evaluations with 185M real-world transactions show that EVMShield can block 100% unexpected state accesses at the cost of 8% throughput degradation (compared with the native EVM). © 2005-2012 IEEE.
Original languageEnglish
Pages (from-to)2517-2532
JournalIEEE Transactions on Information Forensics and Security
Volume19
DOIs
Publication statusPublished - 4 Jan 2024

Funding

This work was supported in part by the National Natural Science Foundation of China under Grant 62302452, Grant 62072407, Grant 62132011, Grant U22B2022, Grant 62002294, and Grant 62202398; in part by the Zhejiang Provincial Natural Science Foundation of China under Grant LQ23F020019 and Grant LZ24F020007; in part by the “Leading Goose Project Plan” of Zhejiang Province under Grant 2022C01086 and Grant 2022C03139; and in part by the National Key Research and Development Program of China under Grant 2022YFB2701400.

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 1 - No Poverty
    SDG 1 No Poverty

Research Keywords

  • access control policy
  • Smart contract vulnerability

Fingerprint

Dive into the research topics of 'EVM-Shield: In-Contract State Access Control for Fast Vulnerability Detection and Prevention'. Together they form a unique fingerprint.

Cite this