Towards Effective Guidance of Smart Contract Fuzz Testing Based on Static Analysis

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

In smart contract fuzz testing, it is crucial to consider the inter-dependencies between the contract functions. To effectively test the business logic of a contract, its functions must be invoked in a meaningful order. In this paper, we propose techniques that utilize static analysis on Ethereum bytecode to tackle this challenge. When compared with the current state-of-the-art, our approach takes Solidity compiler's variable packing optimization into account and allows more precise analysis of the data-flows between functions. In addition, we devise a novel test case initialization algorithm for fuzz testing, which minimizes the redundancy in the generated seed set. Our algorithm reduces test cases that share similar function call patterns and leads to more effective testing of the contract code during the fuzz testing. Experimental results show that the proposed techniques improve the effectiveness of smart contract fuzz testing for vulnerability detection. Specifically, our techniques enabled the fuzz testing tool to trigger the target bugs in the benchmark 3.0 times faster on average.

키워드

smart contractsoftware testingfuzz testingstatic analysis
제목
Towards Effective Guidance of Smart Contract Fuzz Testing Based on Static Analysis
저자
Park, JeongwonChoi, Jaeseung
DOI
10.3390/electronics14040806
발행일
2025-02
유형
Article
저널명
Electronics (Basel)
14
4