Songming Han

dblp:286/3841 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2021
—ORCID · unresolved

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Blockchain and cryptocurrency security · 100%
Software engineering, system software, and programming languages
1 paper
Program analysis · 100%

Topics — the 2 heaviest of 2, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Blockchain and cryptocurrency security › smart contract security
vulnerability detection
0.512021
Hunting Vulnerable Smart Contracts via Graph Embedding Based Bytecode Matching · IEEE Trans. Inf. Forensics Secur. 2021
Program analysis › binary analysis
bytecode analysis
0.512021
Hunting Vulnerable Smart Contracts via Graph Embedding Based Bytecode Matching · IEEE Trans. Inf. Forensics Secur. 2021

Methods — techniques the papers use, named apart from their topics

slicing · 1.0normalization · 1.0graph embedding · 1.0data flow tracking · 1.0control-flow tracking · 1.0
YearPublicationVenuePosition
2021 Hunting Vulnerable Smart Contracts via Graph Embedding Based Bytecode Matching
abstract
Smart contract vulnerabilities have attracted lots of concerns due to the resultant financial losses. Matching-based detection methods extrapolating known vulnerabilities to unknown have proven to be effective in other platforms. However, directly adopting the technique to smart contracts is obstructed by two issues, i.e., diversity of bytecode generation resulting from the rapid evolution of compilers and interference of noise code easily caused by the homogeneous business logics. To address the problems, we propose contract bytecode-oriented normalization and slicing techniques to augment bytecode matching. Specifically, we conduct data- and instruction-level normalizations to uniform the bytecode generated by different compilers, and enforce contract-specific slicing by tracking data- and control-flows with simulated bytecode executions to prune the noise code as far as possible. Based on the above techniques, we design an unsupervised graph embedding algorithm to encode the code graphs into quantitatively comparable vectors. The potentially vulnerable smart contracts can be identified by measuring the similarities between their vectors and known vulnerable ones. Our evaluations have shown the efficiency (0.47 seconds per contract on average), effectiveness (160 verified true positives) and high precision (91.95% for top-ranked). It is worth noting that, we also identify dozens of honeypot contracts, further demonstrating the capability of our method.
Jianjun Huang 0001, Songming Han, Wei You 0001, Wenchang Shi, Bin Liang 0002, JingZheng Wu
IEEE Trans. Inf. Forensics Secur.2