arrow
返回

Wasmati: An efficient static vulnerability scanner for WebAssembly

delete2022-07-01
delete11
delete
OA
AI
T
Tiago Brito *
P
Pedro Lopes
N
Nuno M. Santos
J
José Fragoso Santos
DOI:10.1016/j.cose.2022.102745delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
WebAssembly is a new binary instruction format that allows targeted compiled code written in high-level languages to be executed with near-native speed by the browser's JavaScript engine. However, given that WebAssembly binaries can be compiled from unsafe languages like C/C++, classical code vulnerabilities such as buffer overflows or format strings can be transferred over from the original programs down to the cross-compiled binaries. As a result, this possibility of incorporating vulnerabilities in WebAssembly modules has widened the attack surface of modern web applications. This paper presents Wasmati, a static analysis tool for finding security vulnerabilities in WebAssembly binaries. It is based on the generation of a code property graph (CPG), a program representation previously adopted for detecting vulnerabilities in various languages but hitherto unapplied to WebAssembly. We formalize the definition of CPG for WebAssembly, introduce techniques to generate CPG for complex WebAssembly, and present four different query specification languages for finding vulnerabilities by traversing a program's CPG. We implemented ten queries capturing different vulnerability types and extensively tested Wasmati on four heterogeneous datasets. We show that Wasmati can scale the generation of CPGs for large real-world applications and can efficiently find vulnerabilities for all our query types. We have also tested our tool on WebAssembly binaries collected in the wild and identified several potential vulnerabilities, some of which we have manually confirmed to exist unless the enclosing application properly sanitizes the interaction with such affected binaries. (C) 2022 Elsevier Ltd. All rights reserved.
Keyword:
WebAssembly
Vulnerability
Static analysis
CPG
Security
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

I
inesc-id
学者数:
636
论文数: 504
被引数: 0
引用论文

引用论文

The effect of pomegranate on bone in ovariectomized rats
errBone
IF0
err2010-06-01
err0
PREAI
errT. Kim; K.H. Ahn; K.W. Lee; B.S. Lee; H.M. Park
err分享
err收藏
Non-enzymatic cleavage and ligation of RNAs complementary to a plant virus satellite RNA
err1986-09-01
err0
PREAI
errJamal M. Buzayan; Wayne L. Gerlach; George Bruening
err分享
err收藏