Abstract
WebAssembly (Wasm) has emerged as a pivotal technology for web applications, offering near-native execution speeds and bolstered security through sandboxed execution. Despite its widespread adoption in major browsers, the rapid evolution of Wasm introduces novel attack surfaces, particularly in Wasm compilers. The challenge of Wasm compiler testing lies in producing semi-valid Wasm samples that are structurally sound enough to bypass initial checks yet sufficiently unique to probe for vulnerabilities. In response, we introduce WasmCFuzz, an innovative fuzzing approach that utilizes AFL-generated random bytes to create semi-valid Wasm formats. This method effectively balances structural validity with the potential to uncover compiler corner cases. Our comprehensive evaluation demonstrates that WasmCFuzz not only outperforms existing methods like Wasm-smith and WAfuzzer but also uncovers 13 previously unidentified bugs in mainstream browsers within just a week. These findings highlight WasmCFuzz's capability in enhancing the security of Wasm compilers, marking a significant step forward in Wasm compiler testing.
| Original language | English |
|---|---|
| Title of host publication | Proceedings - 2024 IEEE/ACM 4th International Workshop on Engineering and Cybersecurity of Critical Systems and 2024 IEEE/ACM Second International Workshop on Software Vulnerability, EnCyCriS/SVM 2024 |
| Editors | Coralie Esnoul, Eunkyoung Jee, Triet Huynh Minh Le, Ali Babar, Ricardo Colomo-Palacios, Awais Rashid |
| Place of Publication | New York NY USA |
| Publisher | Association for Computing Machinery (ACM) |
| Pages | 1-5 |
| Number of pages | 5 |
| ISBN (Electronic) | 9798400705656 |
| DOIs | |
| Publication status | Published - 2024 |
| Event | 4th International Workshop on Engineering and Cybersecurity of Critical Systems and 2024 IEEE/ACM 2nd International Workshop on Software Vulnerability 2024: held in conjunction with the 46th IEEE/ACM International Conference on Software Engineering, ICSE 2024 - Lisbon, Portugal Duration: 15 Apr 2024 → 15 Apr 2024 https://dl.acm.org/doi/proceedings/10.1145/3643662 (Proceedings) https://conf.researchr.org/home/icse-2024/encycris-svm-2024 (Website) |
Conference
| Conference | 4th International Workshop on Engineering and Cybersecurity of Critical Systems and 2024 IEEE/ACM 2nd International Workshop on Software Vulnerability 2024 |
|---|---|
| Abbreviated title | EnCyCriS/SVM 2024 |
| Country/Territory | Portugal |
| City | Lisbon |
| Period | 15/04/24 → 15/04/24 |
| Internet address |
Keywords
- browser
- fuzzing
- WebAssembly
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver