Skip to main navigation Skip to search Skip to main content

Increasing Fuzz Testing Coverage for Smart Contracts with Dynamic Taint Analysis

  • Songyan Ji
  • , Jian Dong
  • , Junfu Qiu
  • , Bowen Gu
  • , Ye Wang
  • , Tongqi Wang
  • Harbin Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Nowadays, smart contracts manage more and more digital assets and have become an attractive target for adversaries. To prevent smart contracts from malicious attacks, a thorough test is indispensable and must be finished before deployment because smart contracts cannot be modified after being deployed. Fuzzing is an important testing approach, but most existing smart contract fuzzers can hardly solve the constraints which involve deeply nested conditional statements, resulting in low coverage. To address this problem, we propose Targy, an efficient targeted mutation strategy based on dynamic taint analysis. We obtain the taint flow by dynamic taint propagation, and generate a more accurate mutation strategy for the input parameters of functions to simultaneously satisfy all conditional statements. We implemented Targy on sFuzz with 3.6 thousand smart contracts running on Ethereum. The numbers of covered branches and detected vulnerabilities increase by 6% and 7% respectively, and the average time required for covering a branch is reduced by 11 %.

Original languageEnglish
Title of host publicationProceedings - 2021 21st International Conference on Software Quality, Reliability and Security, QRS 2021
PublisherInstitute of Electrical and Electronics Engineers
Pages243-247
Number of pages5
ISBN (Electronic)9781665458139
DOIs
StatePublished - 2021
Event21st International Conference on Software Quality, Reliability and Security, QRS 2021 - Hainan, China
Duration: 6 Dec 202110 Dec 2021

Publication series

NameIEEE International Conference on Software Quality, Reliability and Security, QRS
Volume2021-December
ISSN (Print)2693-9177

Conference

Conference21st International Conference on Software Quality, Reliability and Security, QRS 2021
Country/TerritoryChina
CityHainan
Period6/12/2110/12/21

Keywords

  • Ethereum
  • dynamic taint analysis
  • fuzz testing
  • smart contracts

Fingerprint

Dive into the research topics of 'Increasing Fuzz Testing Coverage for Smart Contracts with Dynamic Taint Analysis'. Together they form a unique fingerprint.

Cite this