Since the 2020 Defi summer, on-chain TVL has reached hundreds of billions of dollars in size, while at the same time billion dollar capital loss on-chain security incidents are commonplace.
The industry is evolving and the complexity of security incidents is growing rapidly. From the initial simple vulnerabilities in the ERC20 Token contract to more complex vulnerabilities such as bridges, lending protocols and oracle manipulation, this has made analysis more difficult. The source and flow of fees has evolved from the initial direct association with centralized exchanges to the inclusion of coin mixers, which further increases the difficulty of tracking.
The entire lifecycle of an on-chain application includes: design, development, testing, auditing, deployment, and operation, with upgrade iterations overlaid on top of this. Auditing by a reputable auditing firm is an important part but not the whole picture, as more problems occur during subsequent usage and iterations.
In view of this, we(@stars_labs) propose the concept of "full lifecycle&all weather on-chain security" with the intention of building from two major directions, static auditing and dynamic protection, and eventually realizing an on-chain security simulation platform by combining an expert system and an automated system, as a way to establish an on-chain security system.
I look forward to discussing, learning and building with all experts in the industry in the process of establishing this system.
For friends interested in this topic and work, dm me Twitter @changbinhe
====================Chinese version
关于全天候链上安全的思考
2020 defi summer以来,链上TVL到达数千亿规模,与此同时亿级美金资损的链上安全事件屡见不鲜。
行业在发展,安全事件复杂度也在快速增长。从最初的 ERC20 Token合约简单漏洞到跨连桥、借贷协议、预言机操纵等复杂度更高的漏洞,这加大了分析难度。手续费来源和资金流向从最初的直接与中心化交易所关联发展到加入混币器,这进一步加大了追踪难度。
链上应用整个生命周期包括:设计、开发、测试、审计、部署、运行,在此基础上叠加升级迭代。知名审计公司审计是重要的一环_但不是全部,因为更多的问题是发生在后续使用和迭代过程中。
鉴于此,我们(@stars_labs)提出「全天候链上安全」的概念,意图从静态审计和动态预警两个大方向进行建设,以专家系统和自动化系统结合的方式,最终实现链上安全仿真平台,以此来建立链上安全体系。
期望在建立这个体系的过程中,与业界各位同行进行探讨、学习、共建。
对这个话题和工作感兴趣的同志,dm我微信@freeface
