# Adoption of Slither for enhancing smart contracts security - Nikita Kirillov | Pessimistic Security

- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2023-10-07
- Duration: 14:25
- Watch: https://streameth.org/watch/yt-CU9JAqGY5h8
- YouTube: https://www.youtube.com/watch?v=CU9JAqGY5h8

## Transcript

as I've got already presented I think I can start her right away with the speech which is on our custom Slither detectors which we called slithering if you are not familiar with the original tools leader or you've never heard of our library no need to worry I'll get a brief introduction before diving into details uh feel free to scan the QR and go back and forth the slides click all the links and Etc but let's start so I think it's quite obvious from the second words in our company's name security what we are doing but still our main activity is security audits which we are doing since 2017. and in order to help that activity we recently started doing blockchain research and write articles on how to integrate with different large projects or how to deploy projects onto different blockchains you can always check our blog and like give us feedback also uh in the late 2022 we started two development projects one of them is spotter a proactive on chain monitoring system and actually uh one of my colleagues evgeny had a talk an hour and a half ago basically this project is how we can prevent hacks before they even happen so if you got interested you can always check its website and finally Slytherin our custom Slither detectors about which I'm going to tell you today so here's a picture of Jana beautiful me um my occupation is mainly research related so for example at spotter my main responsibilities are analyzing its results suggesting features and sometimes implementing them also I'm one of one of the people who started Slytherin in autumn in 2022 and currently I'm the one who is responsible for it so what is slither shortly it is by far the most popular static analyzer of smart contracts codes developed by trail of bits it looks for vulnerabilities and weaknesses in smart contracts and give some recommendations on how to fix them for your better understanding I created the sort of of a roadmap with three levels each level requires certain skills to get on and at the same time it gives you certain benefits let's start with the basic so in my opinion it is a must level for everyone especially for smart contract developers because I know that they don't really like to focus on security and they prefer just to give their projects for an audit but actually running Slither is the easiest way to make sure that your code by that foolish mistakes are not presented in your code base so at this level you should know how to run basic Slither functionality moreover as you would get some results and there are around 60 detectors in the original Slither you should understand what the results mean and how you can fix them also you can install Slytherin as it's extremely easy it is done with two commands you just need to clone the repository install and then use leader as usual um when you've mastered the basics you can move on to the second level at this point you should learn the plugins which covered the five percent of vulnerabilities that are not covered by the original slither at the same time uh you should not run these plugins on every code on every project for example there is a plugin which checks the which which is called the ERC complements and which checks how you implemented the standard so you should use this plugin on certain standards and for example there is an upgradability check plugin which you use on upgradable contracts and when you've learned all the features you're probably a great security Enthusiast or you're working on a security related position and at this point you probably follow the web3 security ecosystem and you can expand Slither functionality by introducing your own detectors and covering what you need that's actually what we are doing and you are if you're at the same secure security Enthusiast with us feel free to create pull requests to our library about which I'm going to tell you right now uh currently there are 19 detectors in our plugin which we use on a daily basis in our audits for example one of them is the mainstream vulnerability read-only re-entrancy which is not covered by the original Slither but which is presented in our library also there is one large detector which is called uniswap V2 which checks the integration of your code with the unit swap it consists of six checks and provides you all the needed data all the needed information for the secure integration and again it's extremely easy to install and use just two commands and I think next month will drop a python package so it would be installed with just one command um one is tested the presentation with my team they told me that this light is pretty bad so I'll try to dive into more details so you would understand everything uh it all started with a checklist so our Auditors have their checklist uh for the better Audits and of course the best way to not to miss the check is to automate it and we did some sort of research of tools with which we can create well at that point we knew that we want to create detectors but how we can automate the checklist for example we have a tool Smart check which was developed by our team but it has a lot of disadvantages and it is pretty out of date so Slither became the best engine for automating the checklist the process starts with a research when I just read the checklist see which checks could be automated then I perform calls with Auditors because primarily the Slither and our library is to help Auditors and I should know what they need what checks do they want to automate themselves how they want the results to look like and etc etc etc then I add the detector into a backlog and move on to the second Point detectors assessment um this process is quite complex but the result of it are two values one of which is how much funds can potentially the detector save the protocol and the second value is how much does it cost for us to implement the detector when the backlog is arranged it's time to create a detector the structure of our code base is pretty simple so there is a separate documentation file where we give a brief explanation what we are looking for and give some recommendations how to how not to make a mistake and how to make your code secure of course there is detectors code which is written in Python and there is there are two test cases on which we are destined primarily a sort of a bad contract bad function and good contract good function and finally we have a database of contracts both off chain and non-chain where we test our detectors to check the false positive rate um this Tool uh this slide with the graph is also pretty controversial uh because I got some feedback that you're showing the graph where Slither is our performance slithering but I could easily comment it we are making a tool which is not going to compete with slither but which is going to add functionality to it and from the slide which shows how many issues were found just by tools and which were included into the reports that we gave to our clients and actually the graph shows the spread across 12 projects that we audited recently and I think it's quite obvious that automated tools must be used both in the development and in audits because they find a lot of bugs of all the severities as soon as we understood that our library our plugin gives value well it was a sort of a crime not to open source it so that's what you did again feel free to scan the QR or click the link to see the repo um the structure again is extremely simple documentations readme also there are benchmarks which you can check and we try to keep it up to date which and they provide information on our auditing process and how automated tools are doing them after open source open source in the project uh we were fascinated with the feedback we've got were included into newsletters like we can ethereum block thread we got a lot of positive feedback from Developers security researchers Auditors people start to joining our chat discussing new ideas for new detectors just automated tools and we even received several pull requests with new detectors and we have already merged them again a sort of a crime not to continue working on on the plugin and the future plans are pretty simple so of course we're going to create new detectors as new vulnerabilities occur every day every month every week um also we are going to optimize our all detectors so they produce less false positives moreover we are interested in the idea of creating more integration detectors as we've done with the unit Swap and we actually created a demo of such detector for one of the big projects which will maybe uncover anytime soon and with two simple points we are looking to form a community of people who are also enjoying the automated tools and who also think that automation is also a great way to make our ecosystem secure um here are a couple of my links feel free to contact me anytime and also there is a bunch of links of pessimistic again join our chat and at this point I think we can move on to questions if you've got any yeah thank you [Applause] foreign thanks for the presentation uh one question for my side on the graph that you showed the comparison between Slither and Slytherin uh do you do the Delta between the two of them or is it the Benchmark that's performed directly on the code base that you tasted tested uh no it is just a benchmark which shows uh the number of issues found in our recent Audits and it is not a comparison graph I would say I thought that it would be just another argument to show that automated tools should be used in audits because they find bugs like as you could see like there were around 10 critical bugs that were found just by tools and a lot of bugs of medium and low severity and I think that currently comparing Slither and Slytherin is not the the right thing to do because they for example Slither they have around 80 detectors and we are currently implemented 19 of them and the number of projects that we checked is also pretty low as we open sourced the tool I think one month ago so I think it's just a matter of time and of course we'll continue working on it so we could like next time when I'll show this graph it would be like at least equal any more questions seems like no thank you yeah thank you [Applause]
