РЕАЛІЗАЦІЯ ТА ЕКСПЕРИМЕНТАЛЬНА ПЕРЕВІРКА БІБЛІОТЕКИ ТЕМПЛЕЙТІВ ЗАХИСТУ СМАРТ-КОНТРАКТІВ
Topicality. The development of decentralized applications based on blockchain technology is accompanied by an increase in the number and variety of vulnerabilities of smart contracts. The creation of a specialized security template library for Solidity, which combines mechanisms for protecting against typical attacks, automated testing, and tools for integrating with developer projects, is relevant. The subject of the study is methods and software tools for implementing and integrating smart contract security templates in the Solidity language, as well as approaches to testing them, estimating gas costs, and checking compatibility when used in software projects. The purpose of the article is to highlight the results of the implementation and experimental verification of a security template library for Solidity, designed to counter typical attacks on smart contracts, as well as to develop a CLI tool for automated addition of templates, control of their compatibility, and integration into projects based on Foundry and Hardhat. Results have been obtained. A full cycle of development of a security template library was implemented, covering the implementation of software components, the formation of positive and negative test scenarios, static analysis, invariant verification, and code coverage assessment. The implementation was performed in the Foundry environment using Solidity 0.8.24 and Cancun EVM. To verify the functionality of the library, 88 test cases were generated in 17 test suites, which were completed successfully, and invariant verification was performed using Echidna without detecting counterexamples within the specified testing profile. For key templates, protection mechanisms against re-login, access control errors, signature reuse, oracle manipulation, payment blocking, front-running, and emergency scenarios were investigated. Additionally, the ts-templates CLI tool was implemented, which provides project type determination, template and dependency loading, compatibility checking, initialization order control, configuration file updates, and integration recommendations. Conclusion. The results obtained confirm the feasibility of the proposed approach to building a reusable security template library for Solidity. Experimental data show that the use of modern EVM mechanisms, in particular transient storage, allows to increase the gas efficiency of individual security tools without degrading their functional purpose. The combination of security templates, automated testing and CLI-tools for compatibility control creates a basis for simplifying the integration of security mechanisms and increasing the reliability of smart contract development.
Authors
- Rashid Mamedov
- Арзу Ібрагімова
- Анаханим Муталлімова
- Ельвіра Бунятова
- Гюнай Гасанова
Institutions
- Azerbaijan State Oil and Industry University (AZ)
Publication Details
- Journal
- Scientific periodicals of Ukraine
- Published
- 2026-09-20
- Primary Topic
- Cybersecurity and Information Systems
- Type
- article
- Field-Weighted Citation Impact
- 0.00