Smart Contracts vulnerabilities: a call for Blockchain Software Engineering?

Michele Marchesi;Marco Ortu;Roberto Tonelli;
2018-01-01

Abstract

Smart Contracts have gained tremendous popularity in the past few years, to the point that billions of US Dollars are currently exchanged every day through such technology. However, since the release of the Frontier network of Ethereum in 2015, there have been many cases in which the execution of Smart Contracts managing Ether coins has led to problems or conflicts. Compared to traditional Software Engineering, a discipline of Smart Contract and Blockchain programming, with standardized best practices that can help solve the mentioned problems and conflicts, is not yet sufficiently developed. Furthermore, Smart Contracts rely on a non-standard software life-cycle, according to which, for instance, delivered applications can hardly be updated or bugs resolved by releasing a new version of the software. In this paper we advocate the need for a discipline of Blockchain Software Engineering, addressing the issues posed by smart contract programming and other applications running on blockchains.We analyse a case of study where a bug discovered in a Smart Contract library, and perhaps "unsafe" programming, allowed an attack on Parity, a wallet application, causing the freezing of about 500K Ethers (about 150M USD, in November 2017). In this study we analyze the source code of Parity and the library, and discuss how recognised best practices could mitigate, if adopted and adapted, such detrimental software misbehavior. We also reflect on the specificity of Smart Contract software development, which makes some of the existing approaches insufficient, and call for the definition of a specific Blockchain Software Engineering.
2018
Inglese
2018 International Workshop on Blockchain Oriented Software Engineering (IWBOSE)
19
25
7
2018 International Workshop on Blockchain Oriented Software Engineering (IWBOSE)
Esperti anonimi
20 marzo 2018
Campobasso, Italia
internazionale
scientifica
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
Marchesi, Michele; Ortu, Marco; Tonelli, Roberto; Destefanis, Giuseppe; Bracciali, Andrea; Hierons, Robert
273
6
4.1 Contributo in Atti di convegno
reserved
info:eu-repo/semantics/conferencePaper
Files in This Item:
File Size Format  
ParityIEEE.pdf

Solo gestori archivio

Type: versione editoriale
Size 316.56 kB
Format Adobe PDF
316.56 kB Adobe PDF & nbsp; View / Open   Request a copy

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Questionnaire and social

Share on:
Impostazioni cookie