New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Systematic security approach for blockchain-based software - Yehor Balytskyi | pessimistic.io

ETH Belgrade CommunityMon, Oct 7, 2024, 12:00 AM

Transcript

[Applause] uh hi everyone today we'll speak about systematic approach for web3 security it's uh like a topic that I was exploring a lot with my team before pessimistic and rof and right now I try to push the this vision and this concept into uh in the pessimistic um so yeah so a bit about pessimistic who we are um we have six years experience in evm security so we providing Audits and we have a bunch of big lines that you can see on the screen um we did more than 400 Security reviews uh like half of them did by the team itself and plus our Engineers do the solo Audits and Etc and we contributed the blockchain space a lot uh we tried to engage with the slithering this is like a static uh analy detectors based on Slither and we built a spotter this is op Source monitoring solution that you can check check right now you can just go to the telegram and uh put smart contract and you can like uh put a protection for your smart contracts um a bit about me I'm I'm doing security relation pessimistic and pushing uh alternative to evm uh research so this is rust and we are also research in the ZK I I really uh L in Rust uh language I really enjoying it a lot um I was in the ziki hack so we kind of you know doing R&D inside of pessimistic and trying to build some stuff and understand how the security can be helpful in in in this case um I also love uh ZK and FH are based in Paris so they're like FH kind of Monopoly there with the Z and um I tried to research also this and I love the cows uh cows Theory and this is one of my uh uh favorite topic to talk about so the question is like what it does all about what does it mean the systematic approach to AB security what the system is and how we can kind of protect ourself against all this uh Malian activities on chain and increase the protection itself and decrease the amount of uh uh hacks happening amount of stalling money Etc so on the screen you can see just some uh copy pasted uh kind of materials from the wrecked uh News website where you see the biggest hack in the industry which happen not like most of them happen uh not because of the smart contract vulnerabilities but because of like uh um some web 2 security uh vulnerabilities uh that I will show next so yeah uh a bit about like what what the system is and how we kind of see and how we Define in the pessimistic what system is so in the market you have different kind of tools Solutions Services platform Etc that kind of trying to improve your security as much as as it possible and for for for the last two years I see the kind of a demand on the on the kind of U explanation to the developer teams why uh what what we should choose as what what Engineers what teams we should choose what uh oh sorry uh what solution we should choose and how we can Define the best kind of services for uh for ourselves um so yeah in the screen you see just like a different bunch of uh Security reviews formal verification security tooling and other kind of security services that exist on the market and it's all like a system so we try to create something like uh we kind of um we kind of try to create um a structure that can be understandable for everybody and and build this um inside of the teams so they can you know optimize their cost uh improve their security and like you know be as productive as they can so uh a b about the industry as itself like all this system is is again just split it uh kind of of uh Services tooling Etc and we really uh like in web through security we don't have the standards so we don't have a minimal uh requirements for the project as from the developer side also for security side so we really don't know what is like what is the uh like a standard uh to be uh the Professional Security um researcher or the right kind of framework to build your blockchain protocol Etc and uh in security we have a lot we have like different bunch of Standards we have for example for software we have sck 2 we have n standards and many others we also have like for individuals they can like uh they really this is like a goal for them just to achieve this kind of certification and be this professional and it's opens you a lot of doors into the market because the market we security is big and as I see my as I see it myself is just uh we also moving into the standards so all this system that we trying to build to protect our projects in the industry we still want to create from this kind of a standard that everyone can be like compliant uh using as a compliance for big Enterprises and then new uh traditional liquidity will come to our blockchain Market um yeah so this is how we kind of Define uh like a like a system in the pessimistic and you see the idea and uh uh maturity kind of um Lifetime right and you can see what is the best um uh solution that can be integrated on each stages of the prodal development post deployment predeployment uh yeah predeployment po sorry [Music] um yeah and also we have web security so this is like kind of Hot Topic right now because many as I said before hacks happen in the web to and it's kind of uh like fishing uh Keys leakage Etc so how we can like protect also ourselves from this traditional uh vulnerabilities so yeah this is like just a picture so um we Define by ourself it's not it's not a new thing but uh I try to uh try to focus on this kind of uh structure that we have basically three stages of the development life cycle we have a development uh and design of the protocol so where you spec specify all the you know architectures and kind of create innovate on that then I have predeployment chain and like you have like rushing with this all these services and then you have post deploy when you done a lot of work you like kind of uh built your kind of system and you trying to uh add additional kind of um important things to your security as a monitoring as a insul response plan for example if if your blockchain protocol is hacked how we can like f in in in a very productive way to protect it and like Fast respond to the to the thread so yeah we have design stage we have couple of recommendations so on the design stage I think the testing is the one of the most important thing and when you test your when you test your smart contract or you test your code you should have like really um really uh Focus time on that and you have yeah here you can see the three kind of different testing that is the most famous one so in the unit testing I mean the The Foundry for c for example an a static analyzer like slythering or sther or what to do slytherine then you have Dynamic analysis the fuzzing stuff I think uh today you will have some big debate on the uh on the fuzzing and formal verification uh in the next uh speeches so um and the third one is formal verification that right now kind of trying to uh you know uh innovate and uh because the formal verification itself the mass behind it is so complex and right now the teams like ctor or R time verification trying to do something in this kind of Direction and provide the their tools for security researchers so they can test and they can improve uh their um efficiency with the mass behind it so yeah this is uh just uh pictures and one other uh second very very important topic for my opinion is that we should have like documentation so we need to specify everything for example uh I think here someone is from you just like a security researcher and you know what somehow when the project comes to you there is a problem that like the code base is like a cow so you have different kind of code it's not specified not documented at all and it's hard to kind of engage so you you you spend a lot of time to like to to try to understand what Cod is does and and then yeah you spend a lot of time so unproductively and that we really recommend our teams every time that we talk with them is that yeah you need to specify you need a technical specification you need to high level doc so you can understand the kind of antology model of the of the protocol on a full scale uh and yeah the coding policy so this is like a devops or the new word def SEC Ops for that so you kind of Define the the stage in the C and like how it should work how it should work productively um yeah so best practic is also in the in the design and architecture so you should like uh we see this a lot that people try to do the first their audit so they trying to on board on the first Audits and like try to uh start their journey in the security from the like uh an audit from the company and then try to work with them and architecture advisor this is our one of the our services we provided this like we advise uh companies or what we can do how we can like um help them build the right kind of stuff um yeah on the predeployment practices we start to think okay what that what what the next step and uh the next step would be more Security reviews of course so you do a bunch of depends on your budgets and depend depends on your expectations but um yeah and the also writing that we really kind of uh um focus on is that we we we helping uh we advise projects to to to build this incitive response plan so you not focus on the iner response plan after when you deploy you're focusing on the predeployment uh after you deploy a contract you don't have a time to to think right you just you you're thinking in in in each kind of a direction you can be hacked or something like that so it it should be prepared so really security should be like more uh tackled more seriously and and we need to focus on the on the those both sides from the documentation perspective from the technical perspective a lot and so when a pass deploy this is like a everything so you are just um yeah you choosing the monitor tool monitor tool is really interesting topic uh I would not dive in into different monitoring solution how they work but basically what we have for example in pessimistic we have spotter spotter is a easy uh easy use uh tooling that you can just connect your smart contract to the um to the telegram bot just an address and it's starting to detecting some kind of Malian activities in the M poool um yeah so it is free it's easy you can try to test it without any unboarding big other projects that take your money on that you can try spot right now and of course bu Bounty bu Bounty is like uh endless kind of stuff you put your code basis on The Bu Bounty and people try to you know uh find the vulnerabilities there in the not uh specified time yeah so um have you ever heard about viso can you raise a hand uh maybe someone you heard about rual yeah cool uh it's not a lot of people but okay um so So In traditional kind of In traditional uh security there is a uh kind of solution called virtual CA so the C ciso is Chief informational security officer uh whose duties is to uh build kind of a framework uh which would be um which would be improving your um Security Services on like as as as much as as as it can um yeah so what's the differ between the the person and the virtual basically it is hard to find the the this kind of guy in our Market um and it's hard to integrate himself into the in the into the process and like you know understand if if he the right person to to protect your blockchain protocol and to build this team and to build this requirements the minimal requirements what I say what I said before uh for the security services yeah so how it works in p istic that we were trying to research right now uh is that basically First Step uh is just a thesis don't like we don't dive into a lot um so first we're analyzing the complete like organizational and Technical situation of the your protocol where we kind of not only looking at the Smart contract and some specific we're also looking for the whole requirements for for example for you want to hired someone like someone developer right there are many hacks that some malicious developer that didn't uh go through the qic or something just H just you know change something in the smart contract and yeah it's HCK and uh there are many situation like that so um we trying to analyze on a full scale what what's going on in your business and in your kind of technical part so uh after that the second step is that after we Define we start to work on that so we connecting you with the appropriate partners that um we establish with the with them like a ways in productive ways rather than you will go to uh some you know for example back bounties and start to talk we already have like um optimized kind of a connect connection uh groups that you can just dive in you know unboard on the back boundary platform as fast as you can so this is like uh optimizing your uh time and cost and whatever um yeah and so we advise you through the whole kind of a process what is the best uh what's the solution is the right one of course we have a Partners we don't have all capabilities in the market so we have Partners uh that will support you so for example like contests uh for example like um some Advanced tooling like M Lai fuzzing formal verification soon we will talk with our team so we have bunch of different kind of uh um partners that can provide you the the the best security for for from their technical stack um yeah so one of the M main uh think in that is that for example as I said in documentation we should develop kind of these policies requirements guidelines uh uh consistent uh weekly monthly checks of what's going on in your protocol so I think in in the in the big uh like Enterprise cyber security companies it's it's well defined already and as uh as as we and as how many our partners on the market like compe but Partners we are moving into the field where like not only uh will be just uh cool nerdy technical guys who will you know check your code base and then we will find everything and uh uh we try to build like really um efficient organizational framework where uh you will not spend your time you will not spend your like consideration uh and time on the on the um on the on the what what is the best what is wrong and Etc you will like uh you have really big uh chance to do something wrong because you do it by yourself and the funny thing is that uh as we talk many with many teams uh we understand that like even the best engineers in the in the in the industry they still don't know what is security and so some simple advises even to build some kind of a road map or strategy it is really useful for them and it is kind of fun because when when you like uh when you see someone from the big project that is kind of senior engineer and come to him and and kind of like just point it out you should do this and he like oh my God you're right I I didn't I didn't think about that and uh this is how how our industry right now working even even after so like 10 years or something uh this is how it works so even the best teams don't know what they want and like what what to choose so um so yeah that's kind of what we trying to solve and in the end we kind of wanted to to provide for the companies uh with who we work on this kind of uh service what what we done so right if you for example uh we connect all the partners so we Define all our kpis what we do um so yeah our the main goals in that so um it's the cost efficiency like in the web security you spend a huge amount of money on the Audits and it's really like sometimes it's it's honestly it's stupid because because you spend a lot of money on just whole best uh security providers and think like your SEC your codebase would be secure but it's not it's how it works and we've seen so much like cases when it when it was like um yeah you you done some audits from spear bit TR bits or something like that I I'm not uh trying to you know say that this is like this is really good teams but like sometimes it's just you cannot fully secure your system and it happens some hacks and you're like okay what's what I WR what I did wrong or something and uh in the end you're just okay and we understand that like this is not a problem in the skills of these teams this is problems in the in the from the starts the problem started from the starts like for example um if you're not specify and you not Define everything in documentation you not do everything that we what we recommend to you we think it like um this is not uh the problem of the security firm again this is problem of the developer it's not wellestablished it uh developer operations uh um and like many other stuff that developers are kind of um uh focus should focus on and yeah of course we increase the level of protection so in any industry there is no like kind of solution for absolute security so uh we try to kind of in in systematic approach to structure security advice on on that topics to connect with our partners uh to to to track everything and like to to give you some numbers on how your security already improved um yeah so that's basically it um but you can connect to telegram asking the questions I think this is a um interesting topic that we can talk about you can talk about other different things so uh if you're a prodical blockchain or you're a developer or you're security engineer let's talk let's debate I would love to do it um we have like our CD here so we can like create some kind of debate yeah and so that's it maybe you have some questions yes I can answer let's open up a Q&A session so raise your hand if there's any questions in the audience feel free to raise your hand yes hear me yep uh thank you for your presentation uh my question is related to uh when should teams approach you uh is it early stage do you have some recommendation about that uh like it's really hard to say when when when the there is no like a framework where the teams should approach security providers but as we provide such a support I think even from the start when you for example raise some money and you have some Investments you're not starting to just on board for the audits right you do it you're just like okayy cool Engineers you you go to the some kind of support system that shows you what's the best in the market so you spend some time on the you know after the okay fundraiser you have some money on the security okay okay I decided to to spend like uh couple of uh 10 of thousands on the security what should I do rather than go to the audit from the start you go to The Experts who will advise you like okay here's the market here's what we have here's what our team have and you can decide so you're not spending a lot of time on the on the you know on our interactions you just spend the time intelligently you know so you can like kind of understand the whole Market what's going on there and then doing your uh choosing what is the best for you and we are not want to you know sell our uh Services we want to provide as many support as we can and we want to uh point you to the best Partners uh uh from our perspective okay but do you have some kind of queue or I mean uh what do you mean by that well are you if I approach you today are you ready to work with my team or should yeah of course so you just should scan QR code chat to me and we can make a call to to to start the discussion so as as I said the first step is just to to meet each other understand what's going on into the in in your blockchain protocol on a full scale so you know you provide us kind of uh for example sign NDA you provide us gab you provide all information about your organization and we make couple of calls and just advise you what is the best what is wrong and then we kind of uh speaks about start from there okay thanks we have one more question we have time for one more yes uh what is your experience with the customers do they Implement all the things that you tell them or just some of them or half of them or something uh depends on the case like many people just don't do anything cuz they have uh just I don't know they they decide by themselves so we're not trying to be your uh uh we not try to you know take your decisions and like to take n you don't do this you don't you you do this because we advise you no it's not how it works we just we provide our kind of perspective and you decide uh answering to your question uh um can you repeat again uh so I can like yeah what's your experience do your customers Implement all your recommendations or just some of them yeah many people just doing audits for real because it's like other other services is just hard like all this tooling stuff it just hurt right now CU it's not optimized enough and not optimized in the in the in the developer flow so it's hard to kind of just come and like okay use this so we working on that we want to optimize it as as as as much as we can and um yeah that's how it works thanks good questionss guys just so you know like I I love when you engage like good job good job I would love I would love I know uh are you from Trail bits maybe you can say something I would love to because you're the you're working with the big Enterprises I would love to hear your opinion on that so maybe I can learn from okay we have we have time for one more I just want to make from this can you okay on the question if customer implement the recommendation y um I think most of the time they're going to implement the most critical recommendation but they don't always follow like the more long-term recommendation because sometimes we are going to tell them look here there is like you know an immediate bug you need to fix it because if you don't fix it it's game over but sometimes we're also going to provide recommendation like okay maybe your design here is not the best fit for the long term you know of your project consider refactoring this function consider adding like this additional layer of protection and depending on the maturity of the team and depending on their deadline and you know like what what kind of limitation they have and resource they are going or not to implement what we recommend um we also work a lot with customer on a regular basis so for example we see the same customer every six months or every year whatever uh and for this type of customer they do Implement a recommendation and we see the improvement over time that answer the question yeah yeah that's cool yeah so you see security is never like uh like as it was before just not it you move to the deploy stage right now everyone says everyone says on the market we should do the different so companies like trailer bits or companies like spe bit they try to they they understood it well and they try to implement it you see on their website they already have their services and you can check them out so this is not a new thing this is not something uh really Innovative from technological perspective but it just how it should work and how it should work not from from only our opinion but from opinion of the whole security market so that's it how much time we have yeah we have we have like two minutes more okay okay if no question it's no problem yes like I was sced that I do it so so fast so it's good yeah if there's no more questions okay yeah heard thank you so much for sharing this with the community appreciate it good job

Automatic transcript — names and jargon may be misspelled.