Introduction
We express our gratitude to the DENT Wireless Limited team for the collaborative engagement that enabled the execution of this Security Assessment.
DENTNet represents a revolutionary approach, designed to enhance the management of telecommunication assets through seamless integration with existing telco systems, leveraging blockchain technology. This innovative solution is tailored for use by mobile operators and their ecosystem of partners, including enterprises, resellers, and service providers. DENTNet aims to deliver services to users in a manner that is both secure and decentralized, setting a new standard for transparency and efficiency in the telecommunications industry.
| title | content |
|---|---|
| Platform | DENTNet |
| Language | Rust |
| Tags | Substrate, Bridge |
| Timeline | 24/01/2024 - 01/03/2024 |
| Methodology | Blockchain Protocol and Security Analysis Methodology→ |
Review Scope | |
|---|---|
| Repository | https://github.com/dentnet/dentnet-node→ |
| Commit | 24454d3af428f92ebe42341403e0aa551ac6e1d6 |
Review Scope
- Repository
- https://github.com/dentnet/dentnet-node→
- Commit
- 24454d3af428f92ebe42341403e0aa551ac6e1d6
Audit Summary
10/10
10/10
9/10
10/10
The system users should acknowledge all the risks summed up in the risks section of the report
Document Information
This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.
The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.
Document | |
|---|---|
| Name | Blockchain Protocol Code Review and Security Analysis Report for DENT Wireless Limited |
| Audited By | Nataliia Balashova |
| Approved By | Sofiane Akermoun |
| Website | https://www.dentwireless.com/→ |
| Changelog | 01/03/2024 - Preliminary Report |
| ChangeLog | 08/03/2024 - Final report |
Document
- Name
- Blockchain Protocol Code Review and Security Analysis Report for DENT Wireless Limited
- Audited By
- Nataliia Balashova
- Approved By
- Sofiane Akermoun
- Changelog
- 01/03/2024 - Preliminary Report
- ChangeLog
- 08/03/2024 - Final report
System Overview
DENTNet nodes employ the Substrate framework, including multiple pallets and a specifically configured Runtime. DENTNet nodes utilize the Aura block authoring mechanism and the GRANDPA finality gadget for consensus.
Executive Summary
Documentation quality
The total Documentation Quality score is 10 out of 10.
The code adheres to Rust and Substrate documentation standards with complete doc strings.
Code quality
The total Code Quality score is 9 out of 10.
Good usage of the Substrate Framework
Very good code coverage
The project applies Polkadot linter rules for code quality assurance.
Two minor mitigated quality issues will be addressed in upcoming releases.
Architecture quality
The total Architecture Quality score is 10 out of 10.
Based on the Substrate framework, which enhances security and maintainability
Good integration of ChainBridge pallet
Functionalities are well scoped within specific pallets
No tight coupling in pallets design
Security score
Upon auditing, the code was found to contain 0 critical, 0 high, 1 medium, and 1 low severity issues. The two security issues were quickly resolved, resulting in a perfect security score of 10 out of 10.
All identified issues are detailed in the “Findings” section of this report.
Summary
The comprehensive audit of the customer's blockchain protocol yields an overall score of 9.9. This score reflects the combined evaluation of documentation, code quality, architecture quality, and security aspects of the project.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2024-1062 | Missing exchange rate protection parameter | fixed | Medium | |
| F-2024-1164 | Sponsorees can't remove their sponsorship relationship | fixed | Low | |
| F-2024-1181 | Missing event for set_account extrinsic | mitigated | Observation | |
| F-2024-1178 | Overuse of Generic InvalidPackage Error in Pallet-Vending | mitigated | Observation | |
| F-2024-1177 | Missing event for add_vendor extrinsic | fixed | Observation | |
| F-2024-1151 | Potential Improvements in Documentation | fixed | Observation | |
| F-2024-1055 | Linter Warnings | fixed | Observation | |
| F-2024-0952 | Missing event for setallowedsponsors | fixed | Observation | |
| F-2024-0948 | Inaccurate weight attribute in add_vendor | fixed | Observation | |
| F-2024-0781 | Test coverage | fixed | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required. |
High | High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category. |
Medium | Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively. |
Low | Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system. |
Severity
- Critical
Description
- Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.
Severity
- High
Description
- High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.
Severity
- Medium
Description
- Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.
Severity
- Low
Description
- Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.
Appendix 2. Scope
The scope of the project includes the following components from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/dentnet/dentnet-node→ |
| Commit | 24454d3af428f92ebe42341403e0aa551ac6e1d6 |
| Whitepaper | DENT Whitepaper→ |
Scope Details
- Repository
- https://github.com/dentnet/dentnet-node→
- Commit
- 24454d3af428f92ebe42341403e0aa551ac6e1d6
- Whitepaper
- DENT Whitepaper→
Components in Scope
Cryptography and Keys
Cryptography Libraries
Keys Generation
Keystore storage
Asymmetric Signing and Verification)
XCM
XCM Implementation
Protocol-level vulnerabilities
Interoperability vulnerabilities
Integration vulnerabilities
Runtime & Pallets
Runtime implementation review
Pallets review
Attack scenarios analysis Weight, race,stack,DoS, state implosion, access control bypass...)
RPC
RPC implementation review
Attack scenarios analysis (defaults,DoS, overflows, ..)
Substrate client configuration review
Genesis review
Consensus
Substrate FRAME pallets usage review
Standard attacks review (replay, malleability,...)
Substrate fork review
Review of all code changes and missing updates since Substrate clone date
Weights & Benchmarks
Weight values & benchmarks review
Node Tests
Environment Setup
E2E sync tests
Consensus tests
E2E transaction tests