Researcher profile

Markus Scherer

Markus Scherer contributes to research discovery and scholarly infrastructure.

ResearcherAffiliation not importedOpen to collaborate

Trust snapshot

Quick read

Trust 15 - UnverifiedVerification L1Unclaimed author
3works
0followers
4topics
4close collaborators

Actions

Decide how to stay connected

Follow researcher0

Identity and collaboration

How to connect with this researcher

Claiming links this public author record to a researcher profile and unlocks direct collaboration workflows.

Log in to claim

Direct collaboration

Open a focused conversation when the fit is right

Claim this author entity first to unlock direct invitations.

Research graph

See the researcher in context

Open full explorer

Inspect adjacent work, topics, institutions and collaborators without jumping out to a separate graph page.

Building this graph slice

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

3 published item(s)

preprint2021arXiv

The Good, the Bad and the Ugly: Pitfalls and Best Practices in Automated Sound Static Analysis of Ethereum Smart Contracts

Ethereum smart contracts are distributed programs running on top of the Ethereum blockchain. Since program flaws can cause significant monetary losses and can hardly be fixed due to the immutable nature of the blockchain, there is a strong need of automated analysis tools which provide formal security guarantees. Designing such analyzers, however, proved to be challenging and error-prone. We review the existing approaches to automated, sound, static analysis of Ethereum smart contracts and highlight prevalent issues in the state of the art. Finally, we overview eThor, a recent static analysis tool that we developed following a principled design and implementation approach based on rigorous semantic foundations to overcome the problems of past works.

preprint2020arXiv

eThor: Practical and Provably Sound Static Analysis of Ethereum Smart Contracts

Ethereum has emerged as the most popular smart contract development platform, with hundreds of thousands of contracts stored on the blockchain and covering a variety of application scenarios, such as auctions, trading platforms, and so on. Given their financial nature, security vulnerabilities may lead to catastrophic consequences and, even worse, they can be hardly fixed as data stored on the blockchain, including the smart contract code itself, are immutable. An automated security analysis of these contracts is thus of utmost interest, but at the same time technically challenging for a variety of reasons, such as the specific transaction-oriented programming mechanisms, which feature a subtle semantics, and the fact that the blockchain data which the contract under analysis interacts with, including the code of callers and callees, are not statically known. In this work, we present eThor, the first sound and automated static analyzer for EVM bytecode, which is based on an abstraction of the EVM bytecode semantics based on Horn clauses. In particular, our static analysis supports reachability properties, which we show to be sufficient for capturing interesting security properties for smart contracts (e.g., single-entrancy) as well as contract-specific functional properties. Our analysis is proven sound against a complete semantics of EVM bytecode and an experimental large-scale evaluation on real-world contracts demonstrates that eThor is practical and outperforms the state-of-the-art static analyzers: specifically, eThor is the only one to provide soundness guarantees, terminates on 95% of a representative set of real-world contracts, and achieves an F-measure (which combines sensitivity and specificity) of 89%.

preprint2020arXiv

On the scaling of the instability of a flat sediment bed with respect to ripple-like patterns

We investigate the formation of subaqueous transverse bedforms in turbulent open channel flow by means of direct numerical simulations with fully-resolved particles. The main goal of the present analysis is to address the question whether the initial pattern wavelength scales with the particle diameter or with the mean fluid height. A previous study (Kidanemariam and Uhlmann, J. Fluid Mech., vol. 818, 2017, pp. 716-743) has observed a lower bound for the most unstable pattern wavelength in the range 75-100 times the particle diameter, which was equivalent to 3-4 times the mean fluid height. In the current paper, we vary the streamwise box length in terms of the particle diameter and of the mean fluid height independently in order to distinguish between the two possible scaling relations. For the chosen parameter range, the obtained results clearly exhibit a scaling of the initial pattern wavelength with the particle diameter, with a lower bound around a streamwise extent of approximately 80 particle diameters. In longer domains, on the other hand, patterns are observed at initial wavelengths in the range 150-180 times the particle diameter, which is in good agreement with experimental measurements. Variations of the mean fluid height, on the other hand, seem to have no significant influence on the most unstable initial pattern wavelength. Furthermore, for the cases with the largest relative submergence, we observe spanwise and streamwise sediment waves of similar amplitude to evolve and superimpose, leading to three-dimensional sediment patterns.