Blockchains in the Age of Softwarization – Hands-on Experiences with Programming Smart Contracts and Their Security Pitfalls
Bruno Rodrigues, Eder J. Scheid, Burkhard Stiller · Zenodo (CERN European Organization for Nuclear Research) · 2020
The age of Softwarization is characterized as an era in which telecommunication providers, hardware vendors, and software companies seek for an increasing product functionality while coping with the optimization of related hardware-software interactions. Thus, the decentralization of certain information elements, as well as an integration of potentially non-trusted stakeholders provides a dedicated path to follow, while exploiting the characteristics of decentralized Blockchains (BC). Thus, BCs themselves and Smart Contracts (SC) – the central element of BC-based applications, here for implementing information management logics within an (a) application domain, (b) a network management domain, or (c) a system’s security domain – offer a transparent and immutable platform within a fully softwarized setting. However, since a variety of different notions of a BC exist, the real and public BC vs. the private BC – better termed to be a Distributed Ledger (DL) – all these are based on very different trust assumptions. Thus, application-specific requirements will lead to preferring one technical solution over the other. Nevertheless of this BC type to be differentiated, the language and compilers – on which SCs rely on – are still in their infancy compared to highly consolidated programming languages, such as C or Java. Thus, the SC security becomes a vital element for all actors interacting with BC-based applications, both (a) from the viewpoint of platform-relevant blockchain vulnerabilities and (b) the application logic itself, which that can be exploited by malicious users. Thus, this tutorial is based specifically on the Ethereum platform and Solidity contracts, to demonstrate theoretically and practically main common vulnerabilities and SC development mistakes. In this regard, the course provides a theoretical basis at first in which key BC and SC elements are introduced, as well as key vulnerabilities are explained. Following, the course provides – based on a cluster of 20 Raspberry Pi devices – the experimental environment so the attendees can practically analyze a selection of these vulnerabilities in a permissioned blockchain with nodes accessible from a browser. Thus, the practical part only requires the audience to work on its own laptop with a standard browser to connect to the cluster and execute the respective tutorial commands and perform the guided exercises. Subsequently to completing those, the tutorial concludes by highlighting the development principles for SCs in order to avoid common mistakes and unacceptable trends in SC development.