1,720,962 research outputs found
Advancing smart contract security : vulnerability characterization, classification, and automated detection
Context: Smart contracts are computer programs deployed on the blockchain with significant value of cryptocurrency. They automate transactions and asset transfers, eliminating the need for intermediaries.
These contracts serve as the foundation of decentralized applications (DApps), driving blockchain growth. However, their value and role make them attractive targets for attackers, leading to financial losses estimated at around \$6.45 billion.
Objectives: This PhD dissertation aims to improve the security of smart contracts by systematically identifying, characterizing, and automatically detecting vulnerabilities in their code, hence advancing a more secure blockchain environment.
Method: We employ repository mining, qualitative analysis, and data science techniques. Specifically, we utilize repository mining to extract Ethereum smart contract vulnerabilities from public coding platforms and vulnerability databases. Moreover, qualitative methods such as open card sorting are employed to characterize the extracted vulnerabilities. Finally, data science techniques, including machine learning algorithms, are applied to automatically detect and prioritize vulnerabilities early in the smart contract lifecycle.
Results: Our research demonstrates the effectiveness of the mentioned methods in identifying, characterizing, and detecting vulnerabilities in smart contracts. Our findings reveal significant novel vulnerabilities in Ethereum smart contracts from the selected repositories. Through qualitative and quantitative analysis, we provide insights into the distribution of these vulnerabilities across several data sources, their characteristics, and dimensions, including error sources and impacts. Furthermore, this PhD dissertation provides a unified and comprehensive taxonomy of smart contract vulnerabilities. We offer a framework and a suite of tools for automated vulnerability mining, classification, prioritization, and detection using data science techniques to improve the overall security of smart contracts. Finally, several mitigation strategies, quantitatively extracted from real-world smart contract code changes, are presented, along with recommendations and implications for researchers and practitioners.
Conclusions: In conclusion, this PhD dissertation highlights the importance of securing Ethereum smart contracts by focusing on vulnerability key characteristics, automated prioritization, and detection to prevent cyberattacks. Despite encountering challenges, such as the need for unified data and extensive resources, this PhD dissertation offers valuable insights into smart contract security during the development process. Another key challenge was addressing logic vulnerabilities, which required a more advanced understanding of code semantics and proved particularly complex compared to syntactic vulnerabilities. Future work should focus on investing in advanced semantic analysis to effectively mitigate complex vulnerabilities. Our findings enable researchers, practitioners, and tool builders to better understand smart contract vulnerabilities and strengthen security policies and tools using our datasets, tools, and framework.Snjallsamningar eru forrit á bálkakeðjum sem varða mikil verðmæti af rafmynt.
Þau sjálfvirknivæða færslur og millifærslu á eignum, og afnema Þar með Þörfina
á milliliðum. Slíkir samningar Þjóna sem grunnur fyrir dreifð forrit (DApps),
og eru Þannig drifkraftur í vexi bálkakeðja. Hins vegar, gera verðmæti Þeirra
og hlutverk Þá að verðugu takmarki fyrir árásaraðila, sem leiðir til fjárhagslegs
taps sem metið er að 6,45 milljörðum dollara.
Þessi doktorsritgerð miðar að Því að auka öryggi snjallsamninga með Því að
greina, einkenna og greina kerfisbundið veikleika í kóða Þeirra og Þar með Þróa
öruggara bálkakeðjuumhverfi.
Við notum gagnanám, eigindlega greiningu og gagnavísindalegar aðferðir. Nánar
tiltekið notum við gagnanám til að finna veikleika í Ethereum snjallsamningum
úr opinberum kóðunarverkvöngum og veikleikagagnagrunnum. Auk Þess eru
eigindlegar aðferðir eins og opin kortaflokkun notaðar til að lýsa veikleikunum
sem finnast. Að lokum er gagnavísindalegum aðferðum, Þar með talið vélanámi,
beitt til að greina og forgangsraða veikleikum snemma í lífsferli snjallsamninga.
Rannsóknir okkar sýnir fram á árangur áðurnefndra aðferða við að greina,
einkenna og finna veikleika í snjallsamningum. Niðurstöður okkar leiða í ljós
umtalsverða nýbreytni í veikleikum í Ethereum snjallsamningum. Með eigindlegri
greiningu fáum við innsýn í dreifingu veikleikanna á milli nokkurra gagnasafna,
einkenni Þeirra og víddir, Þ.m.t. skekkjuvalda og áhrif. Auk Þess veitir
Þessi doktorsritgerð sameinaða og yfirgripsmikla flokkun á veikleikum í snjallsamningum.
Við bjóðum upp á umgjörð og tól til sjálfvirkrar vörpunar veikleika,
flokkunar, forgangsröðunar og greiningar með gagnavísindalegum aðferðum til
að bæta heildaröryggi snjallsamninga. Að lokum eru kynntar nokkrar aðferðir
til að draga úr veikleikum, byggðar á raunverulegum breytingum á kóða snjallsamninga,
ásamt tillögum og afleiðingum fyrir rannsakendur og fræðimenn.
Í Þessari doktorsritgerð er lögð áhersla á mikilvægi Þess að tryggja öryggi
Ethereum snjallsamninga með Því að beina sjónum að lykileiginleikum veikleika,
sjálfvirkri forgangsröðun og greiningu til að koma í veg fyrir netárásir. Þrátt fyrir
að viðfangsefnin séu mörg, svo sem Þörfin fyrir sameinuð gögn og umfangsmikilar
auðlind, Þá veitir doktorsverkefnið mikilvæga innsýn í snjallsamningavernd
í Þróunarferlinu. önnur lykilviðfangsefni voru röklegir veikleikar, sem kröfðust
dýpri skilnings á merkingarfræði og reyndust sérlega flókin í samanburði við
málskipanar veikleika. Næstu skref í Þessum rannsóknum er að leggja áherslu
á að fjárfesta í Þróaðri merkingarfræðilegri greiningu til að draga úr flóknum
veikleikum á skilvirkan hátt. Niðurstöður okkar gera rannsakendum, fagaðilum
og hugbúnaðarsérfræðingum kleift að skilja betur veikleika snjallsamninga og
styrkja öryggisstefnur og verkfæri með Því að nota gagnasöfnin okkar, verkfæri
og umgjörð.
PrAIoritize: Automated Early Prediction and Prioritization of Vulnerabilities in Smart Contracts
<p>PrAIoritize: Automated Early Prediction and Prioritization of Vulnerabilities in Smart Contracts</p>
PrAIoritize: Automated Early Prediction and Prioritization of Vulnerabilities in Smart Contracts
<p>PrAIoritize: Automated Early Prediction and Prioritization of Vulnerabilities in Smart Contracts</p>
Going Beyond Counting First Authors in Author Co-citation Analysis
The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation
counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings
are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that
only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into
account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed
Variations on the Author
“Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship
Appropriate Similarity Measures for Author Cocitation Analysis
We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis
Dispelling the Myths Behind First-author Citation Counts
We conducted a full-scale evaluative citation analysis study of scholars in the XML research field to explore just how different from each other author rankings resulting from different citation counting methods actually are, and to demonstrate the capability of emerging data and tools on the Web in supporting more realistic citation counting methods. Our results contest some common arguments for the continued
use of first-author citation counts in the evaluation of scholars, such as high correlations between author rankings by first-author citation counts and other citation
counting methods, and high costs of using more realistic citation counting methods that are not well-supported by the ISI databases. It is argued that increasingly available digital full text research papers make it possible for citation analysis studies to go beyond what the ISI databases have directly supported and to employ more
sophisticated methods
koamabayili/VECTRON-author-checklist: VECTRON author checklist
We have done our best to complete the author checklist relating to the use of animals in the hut study. Note that the objective for the hut study was to evaluate the IRS treatment applications for residual efficacy against Anopheles mosquitoes, including the local An. coluzzii mosquito population. Cows were only used to attract mosquitoes into the huts and no tests were carried out directly on the cows. The author checklist is intended for use with studies where experiments are carried out on animals, which is why we have had such difficulty in completing this for the hut study, as many of the questions do not relate to how the cows were used
- …
