Security Auditing on Canton
One of the security auditors asked me about the scope of auditing within the Canton Network. Could you guys provide more information about the auditing process? Is auditing performed by domain-specific or party-specific auditors who are hired for that purpose ? Also, if someone wants to get started with independent auditing in a local to mainnet environment, how can they begin? What would be the recommended approach, tools, or learning path?
Looping in @nycnewman who might be able to advice.
Is there a specific auditor you are referring to? We are working with the Canton Foundation to build out a set of security auditors across the Canton Network ecosystem. This includes (apologies if I missed any) some of the well known Web3 auditors: Quantstamp, Halborn, Certik, Cure53, Sherlock, OpenZeppelin, Zellic, Hacken and others.
We are also aware of several AI companies who are building AI solution in this space from smart contract / application auditing, through vulnerability checks, to code generation and AI continuous penetration testing. Many of these have support for Daml auditing.
We are also seeing increasing interest from independent security researchers who are looking at the Canton Network.
Yes, correct me if I’m wrong, but auditing is primarily done on the business logic. We may also discover some bugs during code generation or while running the DPM TypeScript/Java codegen.
Auditing is done on many aspects of the applications including the business logic and enforcement of conditions, authorization model and permissions, core language concerns, error and unhappy path handling, input validation, and many other aspects. There are many resources available online that talk to the standard concerns for security verification of systems.
Many teams are building out “Top X” lists of security weaknesses.
I’m one of those independent security researchers with experience auditing Solidity,Rust based protocols. I’ve been learning DAML and the Canton Network and I’m interested in specializing in application security within this ecosystem.
If you have any recommendations on where I should focus or which open-source projects, reference applications are worth studying, I’d really appreciate your advice.
Also, if there’s a community channel (Discord, Slack, etc.) where security researchers discuss Canton security, I’d love to join.
Thanks for sharing these insights!
You should start with Splice as this defines the base models for Amulet and Canton Coin:
github.comGitHub - canton-network/splice: Splice repository
Splice repository
For reference, there is a public audit of this here: Quantstamp
You may also want to look at:
github.comGitHub - digital-asset/canton: Global Workflow Composition that is Scalable,...
Global Workflow Composition that is Scalable, Secure, and GDPR-compliant
and
github.comGitHub - digital-asset/daml: The Daml smart contract language
The Daml smart contract language
There is no Security SIG as yet but we are looking to set one up soon.
Thank you for the quick response and for sharing these resources.
I’ll start with Splice.
I appreciate the guidance.
Hello everyone, Veselin from Valves Security here.
You can check out the comment I left on the forum here:
Hello everyone, Veselin from Valves Security here. We’ve been building a security tool for CantonNetwork / DAML, and the results are looking very promising. Yesterday, I had a great chat with a member of the community who shared an audit report from a well-known security firm for a Canton/DAML project. Afterward, I found another public DAML audit from the same firm and used the scope of both audits to evaluate our tool. Here are the results: • It identified 10 of the 12 validated findings r…
We’re still building and working hard to deliver something valuable for the Canton/DAML community. Things are progressing well - we just need a little more time before it’s ready.