WaSCR: A WebAssembly Instruction-Timing Side Channel Repairer
Liyan Huang, Junzhou He, Chao Wang, Weihang Wang
Abstract
WebAssembly (Wasm) is a platform-independent, low-level binary language that enables near-native performance in web applications. Given its growing importance in the web ecosystem, securing We-bAssembly programs becomes increasingly important. A key security concern with WebAssembly is the threat of instruction-timing side-channel attacks, which exploit timing variations in branch instructions dependent on sensitive data, allowing attackers to infer sensitive information through timing measurement. In this paper, we introduce WaSCR, an automated WebAssembly instruction-timing Side-Channel Repairer. WaSCR uses control and data dependencies to trace the flow of sensitive data and prevent its leakage. It employs rule-based code transformations to linearize the program, eliminating branches dependent on sensitive data and substituting them with constant-time selectors. Our evaluation demonstrates that WaSCR effectively eliminates instruction-timing side channels while maintaining program correctness, with efficient repairs and moderate performance overhead. CCS Concepts • Security and privacy → Side-channel analysis and countermeasures; Software security engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7d8af499-0427-4e46-8a5d-5139902fb3f5Cited by top-tier papers1
Ask how each one uses itBuilds on12
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 282 citations
- Verifying Constant-Time ImplementationsJosé Bacelar Almeida, Manuel Barbosa, Gilles Barthe, François Dupressoir et al.USENIX Security 2016 · 274 citations
- An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use CasesAaron Hilbig, Daniel Lehmann, Michael PradelWWW 2021 · 114 citations
- Swivel: Hardening WebAssembly against SpectreShravan Narayan, Craig Disselkoen, Daniel Moghimi, Sunjay Cauligi et al.USENIX Security 2021 · 74 citations
- Automatically eliminating speculative leaks from cryptographic code with bladeMarco Vassena, Craig Disselkoen, Klaus von Gleissenthall, Sunjay Cauligi et al.POPL 2021 · 53 citations
Related papers
- Everything Old is New Again: Binary Security of WebAssemblyDaniel Lehmann, Johannes Kinder, Michael PradelUSENIX Security 2020
- E2WR: An Effective and Efficient Reduction Framework for WebAssembly BinariesShiyao Zhou, Ningyu He, David Lo, Xiapu LuoISSTA 2026
- On (the Lack of) Code Confidentiality in Trusted Execution EnvironmentsIvan Puddu, Moritz Schneider, Daniele Lain, Stefano Boschetto et al.S&P 2024 · 14 citations
- DeJITLeak: eliminating JIT-induced timing side-channel leaksQi Qin, JulianAndres JiYang, Fu Song, Taolue Chen et al.FSE 2022 · 18 citations
- JVM fuzzing for JIT-induced side-channel detectionTegan Brennan, Seemanta Saha, Tevfik BultanICSE 2020 · 26 citations
