arrow
返回

WASP: Stack protection for WebAssembly

delete2026-01-21
delete0
delete
OA
AI
E
Ewan Massey
P
Pierre Olivier *
DOI:10.1016/j.sysarc.2025.103666delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
WebAssembly is a binary executable format designed as a compilation target enabling high-level language code to be run natively in web browsers, JavaScript runtimes, and standalone interpreters. Previous work has highlighted WebAssembly's vulnerability to traditional memory exploits, such as stack smashing (stackbased buffer overflows), when compiled from memory-unsafe languages. Such vulnerabilities are used as a component in impactful end-to-end exploits, hence the design and implementation in WebAssembly of mitigations against memory exploits, such as stack canaries, is needed. We present WASP, an implementation of stack-based buffer overflow protection using stack canaries within Emscripten, the leading C and C++ to WebAssembly compiler. Further, we provide an extension to the standard stack smashing protection design, offering extra security against canary leak attacks by randomizing the canary on a per-function call basis. We verify WASP's effectiveness against proof-of-concept exploits. Evaluation results show that the overheads brought by WASP on execution time, executable binary size, and compilation workflow are negligible to low in all platforms considered: the Chromium web browser, the Node.js JavaScript runtime, as well as the standalone WebAssembly runtimes Wasmer and WAVM.
Keyword:
WebAssembly
Stack protector
Memory safety
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Systems Architecture 封面图
Journal of Systems Architecture
IF:
4.1
论文数:
3.0K
被引数:
4.2K

机构

U
university of manchester
学者数:
1.2K
论文数: 552
被引数: 0
引用论文

引用论文

GuaNary: Efficient Buffer Overflow Detection In Virtualized Clouds Using Intel EPT-based Sub-Page Write Protection Support
err2024-06-11
err0
PREAI
errBitchebe,Stella; Kone,Yves; Olivier,Pierre; Boukhobza,Jalil; Bromberg,Yérom-David; Hagimont,Daniel; Tchana,Alain
err分享
err收藏
Digging into Browser-based Crypto Mining
err2018-10-31
err0
errOAAI
errJan Rüth; Torsten Zimmermann; Konrad Wolsing; Oliver Hohlfeld
err分享
err收藏
FreeGuard
err2017-10-30
err0
errOAAI
errSam Silvestro; Hongyu Liu; Corey Crosser; Zhiqiang Lin; Tongping Liu
err分享
err收藏
err分享
err收藏
err分享
err收藏
DynaGuard
err2015-12-07
err0
PREAI
errTheofilos Petsios; Vasileios P. Kemerlis; Michalis Polychronakis; Angelos D. Keromytis
err分享
err收藏
CCured
err2002-01-01
err0
PREAI
errGeorge C. Necula; Scott McPeak; Westley Weimer
err分享
err收藏
Protecting the stack with PACed canaries
err2019-10-27
err0
errOAAI
errHans Liljestrand; Zaheer Gauhar; Thomas Nyman; Jan-Erik Ekberg; N. Asokan
err分享
err收藏
Breaking the memory secrecy assumption
err2009-03-31
err0
errOAAI
errRaoul Strackx; Yves Younan; Pieter Philippaerts; Frank Piessens; Sven Lachmund; Thomas Walter
err分享
err收藏
err分享
err收藏
学者 查看更多内容