论文标题

XSCOPE:狩猎跨链桥梁攻击

Xscope: Hunting for Cross-Chain Bridge Attacks

论文作者

Zhang, Jiashuo, Gao, Jianbo, Li, Yue, Chen, Ziming, Guan, Zhi, Chen, Zhong

论文摘要

跨链桥已成为支持异构区块链之间资产互操作性的最流行解决方案。但是,在提供高效且灵活的跨链资产转移的同时,涉及链接智能合约和链链计划的复杂工作流程会导致新兴的安全问题。在过去的一年中,针对跨链桥梁发生了十多次攻击,造成了数十亿美元的损失。很少有研究重点关注跨链桥的安全性,社区仍然缺乏减轻这种重大威胁的知识和工具。为了弥合差距,我们对跨链桥的安全性进行了首次研究。我们记录了三个新的安全错误类,并提出了一组安全属性和模式来表征它们。根据这些模式,我们设计XScope,这是一种自动工具,可以在跨链桥梁中找到安全性违规并检测现实世界攻击。我们在四个流行的跨链桥上评估了Xscope。它成功地发现了所有已知的攻击,并发现以前未报告的可疑攻击。 Xscope的视频可从https://youtu.be/vmro_qoqtxy获得。

Cross-Chain bridges have become the most popular solution to support asset interoperability between heterogeneous blockchains. However, while providing efficient and flexible cross-chain asset transfer, the complex workflow involving both on-chain smart contracts and off-chain programs causes emerging security issues. In the past year, there have been more than ten severe attacks against cross-chain bridges, causing billions of loss. With few studies focusing on the security of cross-chain bridges, the community still lacks the knowledge and tools to mitigate this significant threat. To bridge the gap, we conduct the first study on the security of cross-chain bridges. We document three new classes of security bugs and propose a set of security properties and patterns to characterize them. Based on those patterns, we design Xscope, an automatic tool to find security violations in cross-chain bridges and detect real-world attacks. We evaluate Xscope on four popular cross-chain bridges. It successfully detects all known attacks and finds suspicious attacks unreported before. A video of Xscope is available at https://youtu.be/vMRO_qOqtXY.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源