BiAn: Smart Contract Source Code Obfuscation

Pengcheng Zhang,Qifan Yu,Yan Xiao,Hai Dong,Xiapu Luo,Xiao Wang,Meng Zhang
DOI: https://doi.org/10.1109/tse.2023.3298609
IF: 7.4
2023-01-01
IEEE Transactions on Software Engineering
Abstract:With the rising prominence of smart contracts, security attacks targeting them have increased, posing severe threats to their security and intellectual property rights. Existing simplistic datasets hinder effective vulnerability detection, raising security concerns. To address these challenges, we propose BiAn, a source code level smart contract obfuscation method that generates complex vulnerability test datasets. BiAn protects contracts by obfuscating data flows, control flows, and code layouts, increasing complexity and making it harder for attackers to discover vulnerabilities. Our experiments with buggy contracts showed an average complexity enhancement of approximately 174% after obfuscation. Decompilers Vandal and Gigahorse had total failure rate increments of 38.8% and 40.5% respectively. Obfuscated contracts also decreased vulnerability detection rates in more than 50% of cases for ten widely-used static analysis detection tools.
engineering, electrical & electronic,computer science, software engineering
What problem does this paper attempt to address?