论文标题
在NFT平台中确定安全风险
Identifying Security Risks in NFT Platforms
论文作者
论文摘要
本文探讨了固有风险在不可杀菌令牌的新兴技术中的影响,并为本生态系统和观察者中的利益相关者提出了一套可行的解决方案。 Web3和NFTS是一个快速增长的3000亿美元经济,最近出现了一些清晰,高度宣传的危害。我们着手探索了解其性质和范围的风险,以及是否可以找到减轻它们的方法。在适当的调查中,我们回顾了Web从客户端服务器模型的演变到2000年代初期Web2.0技术巨头的兴起的背景。我们将Web3运动试图重新建立早期网络的独立风格进行对比。在我们的研究中,我们发现了与生态系统相关的主要风险和危害,并将其分类为简单的分类法,同时通过解决方案来解决他们的缓解。我们提出了一系列解决方案,这些解决方案是要采用的过程的组合,以及将要纳入生态系统的技术变化或改进,以实施风险缓解。通过将缓解措施与个体风险联系起来,我们相信我们的建议将改善不断增长的Web3生态系统的安全成熟度。我们不认可或建议在我们的解决方案集中特别建议任何特定的产品或服务。这些公司也没有以任何方式进行补偿或影响,以在我们的研究中列出这些产品。我们研究中对产品的评估必须简单地看作是建议的改进。
This paper examines the effects of inherent risks in the emerging technology of non-fungible tokens and proposes an actionable set of solutions for stakeholders in this ecosystem and observers. Web3 and NFTs are a fast-growing 300 billion dollar economy with some clear, highly publicized harms that came to light recently. We set out to explore the risks to understand their nature and scope, and if we could find ways to mitigate them. In due course of investigation, we recap the background of the evolution of the web from a client-server model to the rise of Web2.0 tech giants in the early 2000s. We contrast how the Web3 movement is trying to re-establish the independent style of the early web. In our research we discover a primary set of risks and harms relevant to the ecosystem, and classify them into a simple taxonomy while addressing their mitigations with solutions. We arrive at a set of solutions that are a combination of processes to be adopted, and technological changes or improvements to be incorporated into the ecosystem, to implement risk mitigations. By linking mitigations to individual risks, we are confident our recommendations will improve the security maturity of the growing Web3 ecosystem. We are not endorsing, or recommending specifically any particular product or service in our solution set. Nor are we compensated or influenced in any way by these companies to list these products in our research. The evaluations of products in our research have to simply be viewed as suggested improvements.