Ruijie Luo

dblp:211/7621 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2024
0009-0009-9250-6095ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Blockchain and cryptocurrency security · 50% Network security · 50%
Software engineering, system software, and programming languages
2 papers
Program analysis · 100%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › attack strategy
denial-of-service attack
0.812024
Towards Automatic Discovery of Denial of Service Weaknesses in Blockchain Resource Models · CCS 2024
Blockchain and cryptocurrency security › smart contract security
vulnerability detection
0.812024
SCVHunter: Smart Contract Vulnerability Detection Based on Heterogeneous Graph Attention Network · ICSE 2024
Program analysis
graph-based analysis
0.812024
SCVHunter: Smart Contract Vulnerability Detection Based on Heterogeneous Graph Attention Network · ICSE 2024

Methods — techniques the papers use, named apart from their topics

intermediate representation · 1.5heterogeneous graph attention network · 1.5formal verification · 1.5attack synthesis · 1.5
YearPublicationVenuePosition
2024 Towards Automatic Discovery of Denial of Service Weaknesses in Blockchain Resource Models
abstract
nial-of-Service (DoS) attacks at the execution layer represent one of the most severe threats to blockchain systems, compromising availability by depleting the resources of victims. To counteract these attacks, many blockchains have implemented unique resource models that incorporate transaction fees. Nevertheless, historical incidents of DoS attacks demonstrate that these resource model designs remain inadequate. Although there are studies that manually craft DoS attacks on specific blockchains in isolation, none of them can discover DoS weaknesses in blockchains automatically. In this paper, we provide an insight into DoS weaknesses in blockchain resource models, and present a generic and systematic approach to uncover these weaknesses. In our approach, we first identify DoS weaknesses by DoSVER, a novel tool that reasons feasible DoS weaknesses against blockchain resource models by formal verification. The identified DoS weaknesses will be further validated by DoSDET, a new framework that automates the attack synthesis in exploiting the identified DoS weaknesses. We conduct a comprehensive and systematic evaluation by extensive experiments on nine diverse and widely-used blockchains, and discovered 12 DoS weaknesses with corresponding exploitation across the nine blockchains, 10 of which were unveiled for the first time.
Feng Luo 0009, Huangkun Lin, Zihao Li 0001, Xiapu Luo, Ruijie Luo, Zheyuan He, Shuwei Song, Ting Chen 0002, Wenxuan Luo
CCS5
2024 SCVHunter: Smart Contract Vulnerability Detection Based on Heterogeneous Graph Attention Network
abstract
Smart contracts are integral to blockchain's growth, but their vulnerabilities pose a significant threat. Traditional vulnerability detection methods rely heavily on expert-defined complex rules that are labor-intensive and dificult to adapt to the explosive expansion of smart contracts. Some recent studies of neural network-based vulnerability detection also have room for improvement. Therefore, we propose SCVHunter, an extensible framework for smart contract vulnerability detection. Specifically, SCVHunter designs a heterogeneous semantic graph construction phase based on intermediate representations and a vulnerability detection phase based on a heterogeneous graph attention network for smart contracts. In particular, SCVHunter allows users to freely point out more important nodes in the graph, leveraging expert knowledge in a simpler way to aid the automatic capture of more information related to vulnerabilities. We tested SCVHunter on reentrancy, block info dependency, nested call, and transaction state dependency vulnerabilities. Results show remarkable performance, with accuracies of 93.72%, 91.07%, 85.41%, and 87.37% for these vulnerabilities, surpassing previous methods.
Feng Luo 0009, Ruijie Luo, Ting Chen 0002, Ao Qiao, Zheyuan He, Shuwei Song, Yu Jiang 0001, Sixing Li
ICSE2