Assessing Smart Contracts Security Technical Debts
Sabreen Ahmadjee, Carlos Mera-G\'omez, Rami Bahsoon

TL;DR
This paper introduces a debt-aware assessment approach for identifying and understanding security vulnerabilities in smart contracts, helping developers prioritize fixes and improve contract security.
Contribution
It presents a novel method combining security analysis with technical debt concepts to evaluate the impact of vulnerabilities in smart contracts.
Findings
Increases visibility of security design issues.
Enables prioritization of vulnerabilities based on technical debt impact.
Demonstrates applicability with examples of vulnerable contracts.
Abstract
Smart contracts are self-enforcing agreements that are employed to exchange assets without the approval of trusted third parties. This feature has encouraged various sectors to make use of smart contracts when transacting. Experience shows that many deployed contracts are vulnerable to exploitation due to their poor design, which allows attackers to steal valuable assets from the involved parties. Therefore, an assessment approach that allows developers to recognise the consequences of deploying vulnerable contracts is needed. In this paper, we propose a debt-aware approach for assessing security design vulnerabilities in smart contracts. Our assessment approach involves two main steps: (i) identification of design vulnerabilities using security analysis techniques and (ii) an estimation of the ramifications of the identified vulnerabilities leveraging the technical debt metaphor, its…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
