Towards the Comprehensive Understanding of Mempool DoS Security in Ethereum (Work in Progress)

09/21/2023
by   Yibo Wang, et al.
0

While awareness has been recently raised on Ethereum mempool security, the current state of the art lacks a comprehensive understanding of the subject: The only known attack, DETER (CCS'21), is manually discovered, and it remains an open problem whether attacks other than DETER exist that disable the mempool at an asymmetrically low cost. In this paper, we propose automatic exploit generation techniques to discover new mempool-DoS attack. By employing model checking, we discover a new attack pattern beyond DETER. By further leveraging attack synthesis techniques, we generate exploits from the patterns to adaptively bypass defenses adopted in real Ethereum clients. Our evaluation result shows that while the recent Ethereum clients (e.g., Geth V1.10.14 and OpenEthereum V3.3.5) have mitigated the existing DETER attacks, they are vulnerable to the newly discovered attacks that achieve high success rates (88 Gas/Ether).

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/02/2022

Two Attacks On Proof-of-Stake GHOST/Ethereum

We present two attacks targeting the Proof-of-Stake (PoS) Ethereum conse...
research
08/13/2019

A Survey on Ethereum Systems Security: Vulnerabilities, Attacks and Defenses

The blockchain technology is believed by many to be a game changer in ma...
research
03/04/2021

BLOCKEYE: Hunting For DeFi Attacks on Blockchain

Decentralized finance, i.e., DeFi, has become the most popular type of a...
research
08/27/2019

Eclipsing Ethereum Peers with False Friends

Ethereum is a decentralized Blockchain system that supports the executio...
research
12/18/2017

An Adaptive Gas Cost Mechanism for Ethereum to Defend Against Under-Priced DoS Attacks

The gas mechanism in Ethereum charges the execution of every operation t...
research
12/29/2020

Resource Analysis of Ethereum 2.0 Clients

Scalability is a common issue among the most used permissionless blockch...

Please sign up or login with your details

Forgot password? Click here to reset