论文标题

估计跨(区块链)叉之间的补丁传播时间

Estimating Patch Propagation Times across (Blockchain) Forks

论文作者

Andreina, Sebastien, Alluminio, Lorenzo, Marson, Giorgia Azzurra, Karame, Ghassan

论文摘要

比特币的广泛成功导致了大量的替代加密货币(Altcoins)。大多数AltCoins本质上是针对比特币的代码进行了较小的修改,例如要铸造的硬币数,块大小和块生成时间。因此,在安全性,鲁棒性和成熟度方面,它们通常被认为与比特币相同。 在本文中,我们表明这种共同的概念具有误导性。通过从各种AltCoin项目的GitHub存储库中检索到的数据,我们估计将相关贴片从比特币传播到Altcoins所需的时间。我们发现,尽管比特币开发社区非常活跃地修复了比特币代码库的安全缺陷,但分叉的加密货币在修补相同的漏洞(从比特币中继承)时并不那么严格。在某些情况下,我们观察到,即使是在披露后数十个月的altcoins解决了在比特币社区中发现和固定的关键漏洞。除了提高对这个问题的认识之外,我们的工作还旨在激励在公开报告之前,需要适当的负责任地披露所有分叉链的脆弱性。

The wide success of Bitcoin has led to a huge surge of alternative cryptocurrencies (altcoins). Most altcoins essentially fork Bitcoin's code with minor modifications, such as the number of coins to be minted, the block size, and the block generation time. As such, they are often deemed identical to Bitcoin in terms of security, robustness, and maturity. In this paper, we show that this common conception is misleading. By mining data retrieved from the GitHub repositories of various altcoin projects, we estimate the time it took to propagate relevant patches from Bitcoin to the altcoins. We find that, while the Bitcoin development community is quite active in fixing security flaws of Bitcoin's code base, forked cryptocurrencies are not as rigorous in patching the same vulnerabilities (inherited from Bitcoin). In some cases, we observe that even critical vulnerabilities, discovered and fixed within the Bitcoin community, have been addressed by the altcoins tens of months after disclosure. Besides raising awareness of this problem, our work aims to motivate the need for a proper responsible disclosure of vulnerabilities to all forked chains prior to reporting them publicly.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源