Ethereum Name Service: the Good, the Bad, and the Ugly

04/12/2021
by   Pengcheng Xia, et al.
0

DNS has always been criticized for its inherent design flaws, making the system vulnerable to kinds of attacks. Besides, DNS domain names are not fully controlled by the users, which can be easily taken down by the authorities and registrars. Since blockchain has its unique properties like immutability and decentralization, it seems to be promising to build a decentralized name service on blockchain. Ethereum Name Service (ENS), as a novel name service built atop Etheruem, has received great attention from the community. Yet, no existing work has systematically studied this emerging system, especially the security issues and misbehaviors in ENS. To fill the void, we present the first large-scale study of ENS by collecting and analyzing millions of event logs related to ENS. We characterize the ENS system from a number of perspectives. Our findings suggest that ENS is showing gradually popularity during its four years' evolution, mainly due to its distributed and open nature that ENS domain names can be set to any kinds of records, even censored and malicious contents. We have identified several security issues and misbehaviors including traditional DNS security issues and new issues introduced by ENS smart contracts. Attackers are abusing the system with thousands of squatting ENS names, a number of scam blockchain addresses and malicious websites, etc. Our exploration suggests that our community should invest more effort into the detection and mitigation of issues in Blockchain-based Name Services towards building an open and trustworthy name service.

READ FULL TEXT

page 16

page 27

research
07/02/2023

Abusing the Ethereum Smart Contract Verification Services for Fun and Profit

Smart contracts play a vital role in the Ethereum ecosystem. Due to the ...
research
03/28/2023

Does Money Laundering on Ethereum Have Traditional Traits?

As the largest blockchain platform that supports smart contracts, Ethere...
research
01/14/2021

The Good, the Bad and the Ugly: Pitfalls and Best Practices in Automated Sound Static Analysis of Ethereum Smart Contracts

Ethereum smart contracts are distributed programs running on top of the ...
research
03/04/2021

BLOCKEYE: Hunting For DeFi Attacks on Blockchain

Decentralized finance, i.e., DeFi, has become the most popular type of a...
research
11/27/2018

SOC: hunting the underground inside story of the ethereum Social-network Opinion and Comment

The cryptocurrency is attracting more and more attention because of the ...
research
01/12/2023

Sharpening Ponzi Schemes Detection on Ethereum with Machine Learning

Blockchain technology has been successfully exploited for deploying new ...
research
08/14/2020

Privacy Preserving Passive DNS

The Domain Name System (DNS) was created to resolve the IP addresses of ...

Please sign up or login with your details

Forgot password? Click here to reset