VDABSys: A Novel Security-Testing Framework for Blockchain Systems Based on Vulnerability detection

Jinfu Chen, Qiaowei Feng, Saihua Cai, Dengzhou Shi, Dave Towey, Yuhao Chen, Dongjie Wang

Research output: Chapter in Book/Conference proceedingConference contributionpeer-review

Abstract

Blockchain technology is a popular solution for secure transactions in untrusted networks. However, with the growing number of blockchain applications, how to ensure the security of the blockchain system itself has become an urgent problem. In this paper, we propose a novel security-testing framework for blockchain systems based on a vulnerability-detection model. Our study involves an analysis and comparison with existing software-vulnerability analysis methods. Our framework first addresses each factor that impacts the security of the blockchain system, with a vulnerability attack graph being constructed using model-checking to describe the complete exploitation process of system vulnerabilities. Reliability Theory is used to quantitatively assess the vulnerability attack graph of the blockchain system, thereby providing a theoretical basis for evaluating its security. Finally, we verify the effectiveness and feasibility of the proposed security-testing framework for blockchain systems on an e-voting election blockchain system. The results from our extensive experiments show that our proposed method outperforms other formal-verification-based methods for detecting blockchain vulnerabilities, and also provides a scientific and reliable assessment of blockchain system security.

Original languageEnglish
Title of host publicationSecurity and Privacy in Communication Networks - 19th EAI International Conference, SecureComm 2023, Proceedings
EditorsHaixin Duan, Mourad Debbabi, Xavier de Carné de Carnavalet, Xiapu Luo, Man Ho Allen Au, Xiaojiang Du
PublisherSpringer Science and Business Media Deutschland GmbH
Pages287-305
Number of pages19
ISBN (Print)9783031649479
DOIs
Publication statusPublished - 2025
Event19th EAI International Conference on Security and Privacy in Communication Networks, SecureComm 2023 - Hong Kong, China
Duration: 19 Oct 202321 Oct 2023

Publication series

NameLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
Volume567 LNICST
ISSN (Print)1867-8211
ISSN (Electronic)1867-822X

Conference

Conference19th EAI International Conference on Security and Privacy in Communication Networks, SecureComm 2023
Country/TerritoryChina
CityHong Kong
Period19/10/2321/10/23

Keywords

  • Blockchain system
  • Formal theory
  • Reliability theory
  • Vulnerability attack graph
  • Vulnerability detection model

ASJC Scopus subject areas

  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'VDABSys: A Novel Security-Testing Framework for Blockchain Systems Based on Vulnerability detection'. Together they form a unique fingerprint.

Cite this