Skip to main content

Showing 1–5 of 5 results for author: Schneidewind, C

.
  1. arXiv:2301.13769  [pdf, other

    cs.CR

    HoRStify: Sound Security Analysis of Smart Contracts

    Authors: Sebastian Holler, Sebastian Biewer, Clara Schneidewind

    Abstract: The cryptocurrency Ethereum is the most widely used execution platform for smart contracts. Smart contracts are distributed applications, which govern financial assets and, hence, can implement advanced financial instruments, such as decentralized exchanges or autonomous organizations (DAOs). Their financial nature makes smart contracts an attractive attack target, as demonstrated by numerous expl… ▽ More

    Submitted 31 January, 2023; originally announced January 2023.

    Comments: Accepted for CSF 2023

  2. The Good, the Bad and the Ugly: Pitfalls and Best Practices in Automated Sound Static Analysis of Ethereum Smart Contracts

    Authors: Clara Schneidewind, Markus Scherer, Matteo Maffei

    Abstract: Ethereum smart contracts are distributed programs running on top of the Ethereum blockchain. Since program flaws can cause significant monetary losses and can hardly be fixed due to the immutable nature of the blockchain, there is a strong need of automated analysis tools which provide formal security guarantees. Designing such analyzers, however, proved to be challenging and error-prone. We revie… ▽ More

    Submitted 14 January, 2021; originally announced January 2021.

  3. arXiv:2005.06227  [pdf, other

    cs.PL cs.CR

    eThor: Practical and Provably Sound Static Analysis of Ethereum Smart Contracts

    Authors: Clara Schneidewind, Ilya Grishchenko, Markus Scherer, Matteo Maffei

    Abstract: Ethereum has emerged as the most popular smart contract development platform, with hundreds of thousands of contracts stored on the blockchain and covering a variety of application scenarios, such as auctions, trading platforms, and so on. Given their financial nature, security vulnerabilities may lead to catastrophic consequences and, even worse, they can be hardly fixed as data stored on the blo… ▽ More

    Submitted 13 May, 2020; originally announced May 2020.

    Comments: Accepted for CCS 2020

  4. arXiv:1806.09111  [pdf, other

    cs.CR

    WPSE: Fortifying Web Protocols via Browser-Side Security Monitoring

    Authors: Stefano Calzavara, Riccardo Focardi, Matteo Maffei, Clara Schneidewind, Marco Squarcina, Mauro Tempesta

    Abstract: We present WPSE, a browser-side security monitor for web protocols designed to ensure compliance with the intended protocol flow, as well as confidentiality and integrity properties of messages. We formally prove that WPSE is expressive enough to protect web applications from a wide range of protocol implementation bugs and web attacks. We discuss concrete examples of attacks which can be prevente… ▽ More

    Submitted 24 June, 2018; originally announced June 2018.

  5. A Semantic Framework for the Security Analysis of Ethereum smart contracts

    Authors: Ilya Grishchenko, Matteo Maffei, Clara Schneidewind

    Abstract: Smart contracts are programs running on cryptocurrency (e.g., Ethereum) blockchains, whose popularity stem from the possibility to perform financial transactions, such as payments and auctions, in a distributed environment without need for any trusted third party. Given their financial nature, bugs or vulnerabilities in these programs may lead to catastrophic consequences, as witnessed by recent a… ▽ More

    Submitted 23 April, 2018; v1 submitted 23 February, 2018; originally announced February 2018.

    Comments: The EAPLS Best Paper Award at ETAPS

    Journal ref: POST 2018: 243-269