Jin-lei Sun

dblp:224/7166 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2022 Test Case Generation for Ethereum Smart Contract based on Data Dependency Analysis of State Variable
abstract
An Ethereum smart contract is an agreement reached by multiple parties, which is guaranteed by blockchain technology to be executed in accordance with the terms expressed in the form of code. Its security needs are particularly prominent due to a large number of digital assets under management. Testing is an effective way to find flaws that threaten the security of smart contracts. However, current smart contract test case generation methods do not regard the impact of other functions in the smart contract on state variables, resulting in the inaccessibility of the control statements related to state variables and low branch coverage of the function under test. To alleviate this problem, this paper proposes SV-Gen. SV-Gen generates test cases for smart contracts through two steps: static analysis and dynamic search. In the first step, SV-Gen considers the read-write relationship between functions and state variables in the smart contract to generate a function invocation sequence for the function to be tested through a backtracking algorithm on state variables. Then the arguments of transactions to invoke each function in the sequence are generated through regex matching to form the primitive test case. In the second step, the primitive test cases constitute an initial population, and a genetic algorithm undertakes the task of evolving them to high branch coverage. The experimental results on one of the VeriSmart datasets show that SV-Gen can effectively enter the control constraints related to state variables and improve the branch coverage of smart contracts.
Jinhu Du, Xingya Wang, Changyou Zheng, Jin-lei Sun
QRS5
2022 A Detection Method for Scarcity Defect of Blockchain Digital Asset based on Invariant Analysis
abstract
Blockchain Digital Assets (BDAs) are intangible assets issued based on blockchain, providing a new paradigm for managing digital assets. Smart contracts are programs running on the blockchain and enhance the flexibility of BDA in a programmable way. However, scarcity defects in smart contracts can lead to abnormal changes in the number of BDA and affect their worth. Software invariants are logical assertions that a program fragment needs to remain faithful during execution and work well in defect detection. This paper studies the scarcity defect detection method of smart contract digital assets based on invariant analysis for the first time. First, we point out eight scarcity defects in three categories and describe their examples. Next, we propose two invariants—transfer invariant and swap invariant—that should be maintained in digital assets’ management and transaction process. Then, we use the two invariants as test oracles and propose an oracle-based method to detect scarcity defects in smart contract. Finally, we evaluate the proposed method on a real-world smart contract dataset. The experimental results show that our method can effectively detect scarcity defects in smart contracts and improve the scarcity defect detection capability of existing smart contract testing tools.
Jin-lei Sun, Xingya Wang, Meijuan Wang, Jinhu Du
QRS1
2021 A Novel Method to Prevent Multiple Withdraw Attack on ERC20 Tokens
abstract
ERC20 is the first token standard on Ethereum and is widely used in ICOs, voting, and various asset representations. However, some methods defined in ERC20 imply potential vulnerabilities and Multiple Withdrawal Attack is one of them. Attackers can transfer more tokens than the actual allowance through this vulnerability. The current prevention methods for Multiple Withdrawal Attack include changing the transaction process, modifying the API of ERC20, and modifying the implementation of functions, etc. However, these methods have disadvantages such as poor compatibility, incomplete resolution, and high gas consumption. In this paper, we describe the process of Multiple Withdrawal Attack and analyze the shortcomings of the existing methods, and then propose a solution with lower gas consumption. In our method, a variable is added to record the allowance in the approval function to prevent tokens from being transferred repeatedly. Finally, the effectiveness and the performance of the proposed method is analyzed. The result shows that the method proposed in this paper is safe and has lower gas consumption than the existing methods.
Jin-lei Sun, Changyou Zheng, Meijuan Wang, Zhanwei Hui, Yixian Ding
QRS1