论文标题
一项有关EOSIO系统安全的调查:漏洞,攻击和缓解措施
A Survey on EOSIO Systems Security: Vulnerability, Attack, and Mitigation
论文作者
论文摘要
EOSIO作为最具代表性的区块链3.0平台之一,涉及许多新功能,例如,授权的股份证明共识算法和可更新的智能合约,每秒更高的交易和繁荣的分散应用应用程序(DAPP)生态系统。根据统计数据,它已达到近180亿美元,在比特币和以太坊之后,占据了整个加密货币市场的第三名。但是,漏洞隐藏在阴影中。著名的赌博DAPP EOSBET在一个月内遭受了两次袭击,损失了超过100万美元。从安全研究人员的角度来看,没有现有的工作对EOSIO进行了调查。为了填补这一空白,在本文中,我们收集了所有发生的对EOSIO的攻击事件,并系统地研究了它们的根本原因,即潜伏在所有依赖EOSIO的组件以及相应的攻击和缓解的脆弱性。我们还为DAPP开发人员,EOSIO官方团队和安全研究人员提供了一些最佳实践,以获取未来的方向。
EOSIO, as one of the most representative blockchain 3.0 platforms, involves lots of new features, e.g., delegated proof of stake consensus algorithm and updatable smart contracts, enabling a much higher transaction per second and the prosperous decentralized applications (DApps) ecosystem. According to the statistics, it has reached nearly 18 billion USD, taking the third place of the whole cryptocurrency market, following Bitcoin and Ethereum. Loopholes, however, are hiding in the shadows. EOSBet, a famous gambling DApp, was attacked twice within a month and lost more than 1 million USD. No existing work has surveyed the EOSIO from a security researcher perspective. To fill this gap, in this paper, we collected all occurred attack events against EOSIO, and systematically studied their root causes, i.e., vulnerabilities lurked in all relying components for EOSIO, as well as the corresponding attacks and mitigations. We also summarized some best practices for DApp developers, EOSIO official team, and security researchers for future directions.