Certora: Keeping your code secure forever: Move Fast and Break Nothing by Mooly Sagiv
Fri, Oct 2, 2020, 12:00 AM
We will describe a platform for formally verifying smart contract correctness that can be integrated in CI/CD. Smart contracts and their invariants are converted into SMT formulas and the SMT solvers automatically identify vulnerabilities or generate mathematical proofs of correctness. We describe our experience applying this technology in the development phase and present bugs found and smart contracts verified. Our hope is that this SaaS technology can speed up the development process. The secret sauce for integrating in the CI/CD is that the invariants are reusable across different versions of the code, and targeting the low level EVM bytecode. This raises various technical challenges both at the conceptual level of the specification and at the technical level.
Speakers
Shmuel_Sagiv is a professor and chair of Computer Sciences at Tel-Aviv University and a CEO and co-founder of Certora. He is a leading researcher in large-scale (inter-procedural) program analysis and one of the key contributors to shape analysis. His fields of interest include programming languages, compilers, abstract interpretation, profiling, pointer analysis, shape analysis, interprocedural dataflow analysis, program slicing, and language-based programming.