Repository files navigation

TxSpector

TxSpector is the first generic logic-driven framework for uncovering attacks on Ethereum Blockchain from transactions.

Revised Go-Ethereum

Generate transaction trace by replaying transactions in the Ethereum Blockchain

To collect transaction trace, we revised the offcial Go-Ethereum EVM to record transaction info, such as its date, sender, reciver, and so on. To obtain all the transaction traces in Ethereum Blockchain, you can just replay all the transactions by syncing. For only one transaction, you can simulate the interaction with the geth client. The traces will be recorded in the MongoDB dataset named "geth" automatically.

Revised files

*go-ethereum/mongo/mongodb.go initializes the mongodb and creates some global data, such as transaction related metadata.
*go-ethereum/mongo/bashdb.go creates the struct Transac that is used to store the transaction related info, including the transaction trace.
*go-ethereum/core/state_processor.go and core/state_transition.go deal with the logic that execute transactions.
*go-ethereum/core/state_prefetcher.go and core/vm/evm.go are changed to remove the redundency casued by prefetching.
*go-ethereum/core/vm/interpreter.go, in Run function, every opcode is executed and its related trace is recored into the dataset.
*go-ethereum/core/vm/instructions.go, every opcode related function is changed to return the results that we need for the furture anlysis, which are the arguments of the opcode.
*go-ethereum/core/vm/tx_pool.go stores the left transaction traces into the "geth" mongodb dataset.

Detector

Requirements

Modules needed from python are put in the detector/requirements.txt. In addition, we need souffle. Other versions may also work.

souffle==1.5.1

Analyze the transaction trace and detect attacks

With the traces being collected, TxSpector can parse the trace into the EFG (execution flow graph). Then the trace opcode based EFG is converted into the IR based EFG and the logic relations are exported afterwards. Specifically, logic relations represent the data and control dependencies of the transactions. An example is a transaction trace example stored in the directory example 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt, to generate facts/logic relations, the command should be as the following:

./bin/analyze_geth.sh trace_file facts_dir
./detector/bin/analyze_geth.sh 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt facts

Before detecting the attacks, we need to generate a facts "sc_addr.facts" by ourself, in which we only need to fill the receiver smart contract address. This facts file will be used to detect reentrancy attack. You can use the browser Etherscan 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b to obtain the info or use the go-ethereum to get the related info.

After the facts are generated, users can customize their detection rules to detect related attacks. We define some rules in the directory rules. An example is that with the generated facts, we can use the following command:

souffle -F facts_dir detection_rule_file
souffle -F facts ./detector/rules/1Reentrancy.dl (detect reentrancy attack)

Now we have the final results in file ReenResult.csv that have some metadata for forensic analysis.

Files

  • directory bin storess the files that are used to analyze.
  • directory rules stores the rules to detect the attacks, including reentrancy attack, unchecked call attack, failed send attack, timestamp dependence attack and other similar opcodes dependency attack, unsecured balance attack, misuse of origin attack, sucidal attack, and securify based reentrancy attack.
  • directory src stores the code
    src/opcode.py stores the opcodes of EVM
    src/evm_efg.py parses the transaction trace and builds a trace-based EFG (Execution Flow Graph)
    src/tac_efg.py generates a IR (Intermediate Representation) based EFG
    src/exporter.py exports the needed facts
    other files are helpers to analyze

About

No description, website, or topics provided.

Resources

Stars

65 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

TxSpector

TxSpector is the first generic logic-driven framework for uncovering attacks on Ethereum Blockchain from transactions.

Revised Go-Ethereum

Generate transaction trace by replaying transactions in the Ethereum Blockchain

To collect transaction trace, we revised the offcial Go-Ethereum EVM to record transaction info, such as its date, sender, reciver, and so on. To obtain all the transaction traces in Ethereum Blockchain, you can just replay all the transactions by syncing. For only one transaction, you can simulate the interaction with the geth client. The traces will be recorded in the MongoDB dataset named "geth" automatically.

Revised files

*go-ethereum/mongo/mongodb.go initializes the mongodb and creates some global data, such as transaction related metadata.
*go-ethereum/mongo/bashdb.go creates the struct Transac that is used to store the transaction related info, including the transaction trace.
*go-ethereum/core/state_processor.go and core/state_transition.go deal with the logic that execute transactions.
*go-ethereum/core/state_prefetcher.go and core/vm/evm.go are changed to remove the redundency casued by prefetching.
*go-ethereum/core/vm/interpreter.go, in Run function, every opcode is executed and its related trace is recored into the dataset.
*go-ethereum/core/vm/instructions.go, every opcode related function is changed to return the results that we need for the furture anlysis, which are the arguments of the opcode.
*go-ethereum/core/vm/tx_pool.go stores the left transaction traces into the "geth" mongodb dataset.

Detector

Requirements

Modules needed from python are put in the detector/requirements.txt. In addition, we need souffle. Other versions may also work.

souffle==1.5.1

Analyze the transaction trace and detect attacks

With the traces being collected, TxSpector can parse the trace into the EFG (execution flow graph). Then the trace opcode based EFG is converted into the IR based EFG and the logic relations are exported afterwards. Specifically, logic relations represent the data and control dependencies of the transactions. An example is a transaction trace example stored in the directory example 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt, to generate facts/logic relations, the command should be as the following:

./bin/analyze_geth.sh trace_file facts_dir
./detector/bin/analyze_geth.sh 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt facts

Before detecting the attacks, we need to generate a facts "sc_addr.facts" by ourself, in which we only need to fill the receiver smart contract address. This facts file will be used to detect reentrancy attack. You can use the browser Etherscan 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b to obtain the info or use the go-ethereum to get the related info.

After the facts are generated, users can customize their detection rules to detect related attacks. We define some rules in the directory rules. An example is that with the generated facts, we can use the following command:

souffle -F facts_dir detection_rule_file
souffle -F facts ./detector/rules/1Reentrancy.dl (detect reentrancy attack)

Now we have the final results in file ReenResult.csv that have some metadata for forensic analysis.

Files

  • directory bin storess the files that are used to analyze.
  • directory rules stores the rules to detect the attacks, including reentrancy attack, unchecked call attack, failed send attack, timestamp dependence attack and other similar opcodes dependency attack, unsecured balance attack, misuse of origin attack, sucidal attack, and securify based reentrancy attack.
  • directory src stores the code
    src/opcode.py stores the opcodes of EVM
    src/evm_efg.py parses the transaction trace and builds a trace-based EFG (Execution Flow Graph)
    src/tac_efg.py generates a IR (Intermediate Representation) based EFG
    src/exporter.py exports the needed facts
    other files are helpers to analyze

About

No description, website, or topics provided.

Resources

Stars

65 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

TxSpector

TxSpector is the first generic logic-driven framework for uncovering attacks on Ethereum Blockchain from transactions.

Revised Go-Ethereum

Generate transaction trace by replaying transactions in the Ethereum Blockchain

To collect transaction trace, we revised the offcial Go-Ethereum EVM to record transaction info, such as its date, sender, reciver, and so on. To obtain all the transaction traces in Ethereum Blockchain, you can just replay all the transactions by syncing. For only one transaction, you can simulate the interaction with the geth client. The traces will be recorded in the MongoDB dataset named "geth" automatically.

Revised files

*go-ethereum/mongo/mongodb.go initializes the mongodb and creates some global data, such as transaction related metadata.
*go-ethereum/mongo/bashdb.go creates the struct Transac that is used to store the transaction related info, including the transaction trace.
*go-ethereum/core/state_processor.go and core/state_transition.go deal with the logic that execute transactions.
*go-ethereum/core/state_prefetcher.go and core/vm/evm.go are changed to remove the redundency casued by prefetching.
*go-ethereum/core/vm/interpreter.go, in Run function, every opcode is executed and its related trace is recored into the dataset.
*go-ethereum/core/vm/instructions.go, every opcode related function is changed to return the results that we need for the furture anlysis, which are the arguments of the opcode.
*go-ethereum/core/vm/tx_pool.go stores the left transaction traces into the "geth" mongodb dataset.

Detector

Requirements

Modules needed from python are put in the detector/requirements.txt. In addition, we need souffle. Other versions may also work.

souffle==1.5.1

Analyze the transaction trace and detect attacks

With the traces being collected, TxSpector can parse the trace into the EFG (execution flow graph). Then the trace opcode based EFG is converted into the IR based EFG and the logic relations are exported afterwards. Specifically, logic relations represent the data and control dependencies of the transactions. An example is a transaction trace example stored in the directory example 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt, to generate facts/logic relations, the command should be as the following:

./bin/analyze_geth.sh trace_file facts_dir
./detector/bin/analyze_geth.sh 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt facts

Before detecting the attacks, we need to generate a facts "sc_addr.facts" by ourself, in which we only need to fill the receiver smart contract address. This facts file will be used to detect reentrancy attack. You can use the browser Etherscan 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b to obtain the info or use the go-ethereum to get the related info.

After the facts are generated, users can customize their detection rules to detect related attacks. We define some rules in the directory rules. An example is that with the generated facts, we can use the following command:

souffle -F facts_dir detection_rule_file
souffle -F facts ./detector/rules/1Reentrancy.dl (detect reentrancy attack)

Now we have the final results in file ReenResult.csv that have some metadata for forensic analysis.

Files

  • directory bin storess the files that are used to analyze.
  • directory rules stores the rules to detect the attacks, including reentrancy attack, unchecked call attack, failed send attack, timestamp dependence attack and other similar opcodes dependency attack, unsecured balance attack, misuse of origin attack, sucidal attack, and securify based reentrancy attack.
  • directory src stores the code
    src/opcode.py stores the opcodes of EVM
    src/evm_efg.py parses the transaction trace and builds a trace-based EFG (Execution Flow Graph)
    src/tac_efg.py generates a IR (Intermediate Representation) based EFG
    src/exporter.py exports the needed facts
    other files are helpers to analyze

About

No description, website, or topics provided.

Resources

Stars

65 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

TxSpector

TxSpector is the first generic logic-driven framework for uncovering attacks on Ethereum Blockchain from transactions.

Revised Go-Ethereum

Generate transaction trace by replaying transactions in the Ethereum Blockchain

To collect transaction trace, we revised the offcial Go-Ethereum EVM to record transaction info, such as its date, sender, reciver, and so on. To obtain all the transaction traces in Ethereum Blockchain, you can just replay all the transactions by syncing. For only one transaction, you can simulate the interaction with the geth client. The traces will be recorded in the MongoDB dataset named "geth" automatically.

Revised files

*go-ethereum/mongo/mongodb.go initializes the mongodb and creates some global data, such as transaction related metadata.
*go-ethereum/mongo/bashdb.go creates the struct Transac that is used to store the transaction related info, including the transaction trace.
*go-ethereum/core/state_processor.go and core/state_transition.go deal with the logic that execute transactions.
*go-ethereum/core/state_prefetcher.go and core/vm/evm.go are changed to remove the redundency casued by prefetching.
*go-ethereum/core/vm/interpreter.go, in Run function, every opcode is executed and its related trace is recored into the dataset.
*go-ethereum/core/vm/instructions.go, every opcode related function is changed to return the results that we need for the furture anlysis, which are the arguments of the opcode.
*go-ethereum/core/vm/tx_pool.go stores the left transaction traces into the "geth" mongodb dataset.

Detector

Requirements

Modules needed from python are put in the detector/requirements.txt. In addition, we need souffle. Other versions may also work.

souffle==1.5.1

Analyze the transaction trace and detect attacks

With the traces being collected, TxSpector can parse the trace into the EFG (execution flow graph). Then the trace opcode based EFG is converted into the IR based EFG and the logic relations are exported afterwards. Specifically, logic relations represent the data and control dependencies of the transactions. An example is a transaction trace example stored in the directory example 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt, to generate facts/logic relations, the command should be as the following:

./bin/analyze_geth.sh trace_file facts_dir
./detector/bin/analyze_geth.sh 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt facts

Before detecting the attacks, we need to generate a facts "sc_addr.facts" by ourself, in which we only need to fill the receiver smart contract address. This facts file will be used to detect reentrancy attack. You can use the browser Etherscan 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b to obtain the info or use the go-ethereum to get the related info.

After the facts are generated, users can customize their detection rules to detect related attacks. We define some rules in the directory rules. An example is that with the generated facts, we can use the following command:

souffle -F facts_dir detection_rule_file
souffle -F facts ./detector/rules/1Reentrancy.dl (detect reentrancy attack)

Now we have the final results in file ReenResult.csv that have some metadata for forensic analysis.

Files

  • directory bin storess the files that are used to analyze.
  • directory rules stores the rules to detect the attacks, including reentrancy attack, unchecked call attack, failed send attack, timestamp dependence attack and other similar opcodes dependency attack, unsecured balance attack, misuse of origin attack, sucidal attack, and securify based reentrancy attack.
  • directory src stores the code
    src/opcode.py stores the opcodes of EVM
    src/evm_efg.py parses the transaction trace and builds a trace-based EFG (Execution Flow Graph)
    src/tac_efg.py generates a IR (Intermediate Representation) based EFG
    src/exporter.py exports the needed facts
    other files are helpers to analyze

About

No description, website, or topics provided.

Resources

Stars

65 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

TxSpector

TxSpector is the first generic logic-driven framework for uncovering attacks on Ethereum Blockchain from transactions.

Revised Go-Ethereum

Generate transaction trace by replaying transactions in the Ethereum Blockchain

To collect transaction trace, we revised the offcial Go-Ethereum EVM to record transaction info, such as its date, sender, reciver, and so on. To obtain all the transaction traces in Ethereum Blockchain, you can just replay all the transactions by syncing. For only one transaction, you can simulate the interaction with the geth client. The traces will be recorded in the MongoDB dataset named "geth" automatically.

Revised files

*go-ethereum/mongo/mongodb.go initializes the mongodb and creates some global data, such as transaction related metadata.
*go-ethereum/mongo/bashdb.go creates the struct Transac that is used to store the transaction related info, including the transaction trace.
*go-ethereum/core/state_processor.go and core/state_transition.go deal with the logic that execute transactions.
*go-ethereum/core/state_prefetcher.go and core/vm/evm.go are changed to remove the redundency casued by prefetching.
*go-ethereum/core/vm/interpreter.go, in Run function, every opcode is executed and its related trace is recored into the dataset.
*go-ethereum/core/vm/instructions.go, every opcode related function is changed to return the results that we need for the furture anlysis, which are the arguments of the opcode.
*go-ethereum/core/vm/tx_pool.go stores the left transaction traces into the "geth" mongodb dataset.

Detector

Requirements

Modules needed from python are put in the detector/requirements.txt. In addition, we need souffle. Other versions may also work.

souffle==1.5.1

Analyze the transaction trace and detect attacks

With the traces being collected, TxSpector can parse the trace into the EFG (execution flow graph). Then the trace opcode based EFG is converted into the IR based EFG and the logic relations are exported afterwards. Specifically, logic relations represent the data and control dependencies of the transactions. An example is a transaction trace example stored in the directory example 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt, to generate facts/logic relations, the command should be as the following:

./bin/analyze_geth.sh trace_file facts_dir
./detector/bin/analyze_geth.sh 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt facts

Before detecting the attacks, we need to generate a facts "sc_addr.facts" by ourself, in which we only need to fill the receiver smart contract address. This facts file will be used to detect reentrancy attack. You can use the browser Etherscan 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b to obtain the info or use the go-ethereum to get the related info.

After the facts are generated, users can customize their detection rules to detect related attacks. We define some rules in the directory rules. An example is that with the generated facts, we can use the following command:

souffle -F facts_dir detection_rule_file
souffle -F facts ./detector/rules/1Reentrancy.dl (detect reentrancy attack)

Now we have the final results in file ReenResult.csv that have some metadata for forensic analysis.

Files

  • directory bin storess the files that are used to analyze.
  • directory rules stores the rules to detect the attacks, including reentrancy attack, unchecked call attack, failed send attack, timestamp dependence attack and other similar opcodes dependency attack, unsecured balance attack, misuse of origin attack, sucidal attack, and securify based reentrancy attack.
  • directory src stores the code
    src/opcode.py stores the opcodes of EVM
    src/evm_efg.py parses the transaction trace and builds a trace-based EFG (Execution Flow Graph)
    src/tac_efg.py generates a IR (Intermediate Representation) based EFG
    src/exporter.py exports the needed facts
    other files are helpers to analyze

About

No description, website, or topics provided.

Resources

Stars

65 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

TxSpector

TxSpector is the first generic logic-driven framework for uncovering attacks on Ethereum Blockchain from transactions.

Revised Go-Ethereum

Generate transaction trace by replaying transactions in the Ethereum Blockchain

To collect transaction trace, we revised the offcial Go-Ethereum EVM to record transaction info, such as its date, sender, reciver, and so on. To obtain all the transaction traces in Ethereum Blockchain, you can just replay all the transactions by syncing. For only one transaction, you can simulate the interaction with the geth client. The traces will be recorded in the MongoDB dataset named "geth" automatically.

Revised files

*go-ethereum/mongo/mongodb.go initializes the mongodb and creates some global data, such as transaction related metadata.
*go-ethereum/mongo/bashdb.go creates the struct Transac that is used to store the transaction related info, including the transaction trace.
*go-ethereum/core/state_processor.go and core/state_transition.go deal with the logic that execute transactions.
*go-ethereum/core/state_prefetcher.go and core/vm/evm.go are changed to remove the redundency casued by prefetching.
*go-ethereum/core/vm/interpreter.go, in Run function, every opcode is executed and its related trace is recored into the dataset.
*go-ethereum/core/vm/instructions.go, every opcode related function is changed to return the results that we need for the furture anlysis, which are the arguments of the opcode.
*go-ethereum/core/vm/tx_pool.go stores the left transaction traces into the "geth" mongodb dataset.

Detector

Requirements

Modules needed from python are put in the detector/requirements.txt. In addition, we need souffle. Other versions may also work.

souffle==1.5.1

Analyze the transaction trace and detect attacks

With the traces being collected, TxSpector can parse the trace into the EFG (execution flow graph). Then the trace opcode based EFG is converted into the IR based EFG and the logic relations are exported afterwards. Specifically, logic relations represent the data and control dependencies of the transactions. An example is a transaction trace example stored in the directory example 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt, to generate facts/logic relations, the command should be as the following:

./bin/analyze_geth.sh trace_file facts_dir
./detector/bin/analyze_geth.sh 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt facts

Before detecting the attacks, we need to generate a facts "sc_addr.facts" by ourself, in which we only need to fill the receiver smart contract address. This facts file will be used to detect reentrancy attack. You can use the browser Etherscan 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b to obtain the info or use the go-ethereum to get the related info.

After the facts are generated, users can customize their detection rules to detect related attacks. We define some rules in the directory rules. An example is that with the generated facts, we can use the following command:

souffle -F facts_dir detection_rule_file
souffle -F facts ./detector/rules/1Reentrancy.dl (detect reentrancy attack)

Now we have the final results in file ReenResult.csv that have some metadata for forensic analysis.

Files

  • directory bin storess the files that are used to analyze.
  • directory rules stores the rules to detect the attacks, including reentrancy attack, unchecked call attack, failed send attack, timestamp dependence attack and other similar opcodes dependency attack, unsecured balance attack, misuse of origin attack, sucidal attack, and securify based reentrancy attack.
  • directory src stores the code
    src/opcode.py stores the opcodes of EVM
    src/evm_efg.py parses the transaction trace and builds a trace-based EFG (Execution Flow Graph)
    src/tac_efg.py generates a IR (Intermediate Representation) based EFG
    src/exporter.py exports the needed facts
    other files are helpers to analyze

About

No description, website, or topics provided.

Resources

Stars

65 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

TxSpector

TxSpector is the first generic logic-driven framework for uncovering attacks on Ethereum Blockchain from transactions.

Revised Go-Ethereum

Generate transaction trace by replaying transactions in the Ethereum Blockchain

To collect transaction trace, we revised the offcial Go-Ethereum EVM to record transaction info, such as its date, sender, reciver, and so on. To obtain all the transaction traces in Ethereum Blockchain, you can just replay all the transactions by syncing. For only one transaction, you can simulate the interaction with the geth client. The traces will be recorded in the MongoDB dataset named "geth" automatically.

Revised files

*go-ethereum/mongo/mongodb.go initializes the mongodb and creates some global data, such as transaction related metadata.
*go-ethereum/mongo/bashdb.go creates the struct Transac that is used to store the transaction related info, including the transaction trace.
*go-ethereum/core/state_processor.go and core/state_transition.go deal with the logic that execute transactions.
*go-ethereum/core/state_prefetcher.go and core/vm/evm.go are changed to remove the redundency casued by prefetching.
*go-ethereum/core/vm/interpreter.go, in Run function, every opcode is executed and its related trace is recored into the dataset.
*go-ethereum/core/vm/instructions.go, every opcode related function is changed to return the results that we need for the furture anlysis, which are the arguments of the opcode.
*go-ethereum/core/vm/tx_pool.go stores the left transaction traces into the "geth" mongodb dataset.

Detector

Requirements

Modules needed from python are put in the detector/requirements.txt. In addition, we need souffle. Other versions may also work.

souffle==1.5.1

Analyze the transaction trace and detect attacks

With the traces being collected, TxSpector can parse the trace into the EFG (execution flow graph). Then the trace opcode based EFG is converted into the IR based EFG and the logic relations are exported afterwards. Specifically, logic relations represent the data and control dependencies of the transactions. An example is a transaction trace example stored in the directory example 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt, to generate facts/logic relations, the command should be as the following:

./bin/analyze_geth.sh trace_file facts_dir
./detector/bin/analyze_geth.sh 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt facts

Before detecting the attacks, we need to generate a facts "sc_addr.facts" by ourself, in which we only need to fill the receiver smart contract address. This facts file will be used to detect reentrancy attack. You can use the browser Etherscan 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b to obtain the info or use the go-ethereum to get the related info.

After the facts are generated, users can customize their detection rules to detect related attacks. We define some rules in the directory rules. An example is that with the generated facts, we can use the following command:

souffle -F facts_dir detection_rule_file
souffle -F facts ./detector/rules/1Reentrancy.dl (detect reentrancy attack)

Now we have the final results in file ReenResult.csv that have some metadata for forensic analysis.

Files

  • directory bin storess the files that are used to analyze.
  • directory rules stores the rules to detect the attacks, including reentrancy attack, unchecked call attack, failed send attack, timestamp dependence attack and other similar opcodes dependency attack, unsecured balance attack, misuse of origin attack, sucidal attack, and securify based reentrancy attack.
  • directory src stores the code
    src/opcode.py stores the opcodes of EVM
    src/evm_efg.py parses the transaction trace and builds a trace-based EFG (Execution Flow Graph)
    src/tac_efg.py generates a IR (Intermediate Representation) based EFG
    src/exporter.py exports the needed facts
    other files are helpers to analyze

About

No description, website, or topics provided.

Resources

Stars

65 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

TxSpector

TxSpector is the first generic logic-driven framework for uncovering attacks on Ethereum Blockchain from transactions.

Revised Go-Ethereum

Generate transaction trace by replaying transactions in the Ethereum Blockchain

To collect transaction trace, we revised the offcial Go-Ethereum EVM to record transaction info, such as its date, sender, reciver, and so on. To obtain all the transaction traces in Ethereum Blockchain, you can just replay all the transactions by syncing. For only one transaction, you can simulate the interaction with the geth client. The traces will be recorded in the MongoDB dataset named "geth" automatically.

Revised files

*go-ethereum/mongo/mongodb.go initializes the mongodb and creates some global data, such as transaction related metadata.
*go-ethereum/mongo/bashdb.go creates the struct Transac that is used to store the transaction related info, including the transaction trace.
*go-ethereum/core/state_processor.go and core/state_transition.go deal with the logic that execute transactions.
*go-ethereum/core/state_prefetcher.go and core/vm/evm.go are changed to remove the redundency casued by prefetching.
*go-ethereum/core/vm/interpreter.go, in Run function, every opcode is executed and its related trace is recored into the dataset.
*go-ethereum/core/vm/instructions.go, every opcode related function is changed to return the results that we need for the furture anlysis, which are the arguments of the opcode.
*go-ethereum/core/vm/tx_pool.go stores the left transaction traces into the "geth" mongodb dataset.

Detector

Requirements

Modules needed from python are put in the detector/requirements.txt. In addition, we need souffle. Other versions may also work.

souffle==1.5.1

Analyze the transaction trace and detect attacks

With the traces being collected, TxSpector can parse the trace into the EFG (execution flow graph). Then the trace opcode based EFG is converted into the IR based EFG and the logic relations are exported afterwards. Specifically, logic relations represent the data and control dependencies of the transactions. An example is a transaction trace example stored in the directory example 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt, to generate facts/logic relations, the command should be as the following:

./bin/analyze_geth.sh trace_file facts_dir
./detector/bin/analyze_geth.sh 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b.txt facts

Before detecting the attacks, we need to generate a facts "sc_addr.facts" by ourself, in which we only need to fill the receiver smart contract address. This facts file will be used to detect reentrancy attack. You can use the browser Etherscan 0x37085f336b5d3e588e37674544678f8cb0fc092a6de5d83bd647e20e5232897b to obtain the info or use the go-ethereum to get the related info.

After the facts are generated, users can customize their detection rules to detect related attacks. We define some rules in the directory rules. An example is that with the generated facts, we can use the following command:

souffle -F facts_dir detection_rule_file
souffle -F facts ./detector/rules/1Reentrancy.dl (detect reentrancy attack)

Now we have the final results in file ReenResult.csv that have some metadata for forensic analysis.

Files

  • directory bin storess the files that are used to analyze.
  • directory rules stores the rules to detect the attacks, including reentrancy attack, unchecked call attack, failed send attack, timestamp dependence attack and other similar opcodes dependency attack, unsecured balance attack, misuse of origin attack, sucidal attack, and securify based reentrancy attack.
  • directory src stores the code
    src/opcode.py stores the opcodes of EVM
    src/evm_efg.py parses the transaction trace and builds a trace-based EFG (Execution Flow Graph)
    src/tac_efg.py generates a IR (Intermediate Representation) based EFG
    src/exporter.py exports the needed facts
    other files are helpers to analyze

About

No description, website, or topics provided.

Resources

Stars

65 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages