SymWeb: Feedback-Driven Context Exploration and Context-Aware Symbolic Execution for Browser-Embedded WebAssembly Vulnerability Detection
Yuanpeng Wang, Yeqi Fu, Zhineng Zhong, Zhenkai Liang, Ding Li, Yao Guo, Xiangqun Chen
摘要
Browser-deployed WebAssembly (Wasm) modules often inherit memory-safety bugs from C and C++-style code, yet exploiting, and even reaching, these bugs in the Web threat model is fundamentally context-dependent. JavaScript (JS) controls the exported-call schedule and constructs the Wasm entry state, including arguments, globals, and linear-memory layouts, from attacker-influenced web inputs. This makes both Wasm-only analysis, which assumes static initial states, and prior browser-based testing such as Wemby ineffective. Wemby generates a fixed, Wasm-agnostic context pool and then only mutates Wasm parameters, which limits its ability to systematically reach deeper, Wasm-relevant contexts and gated behaviors. We present SymWeb, a feedback-driven closed-loop system that links external inputs to browser-reachable JS-induced Wasm contexts and then to context-aware Wasm symbolic execution. SymWeb couples an Feedback-driven Context Generator with an Context-Aware Wasm Symbolic Executor. The Feedback-driven Context Generator performs binary rewriting for ASan-like checks and observability, collects contexts in the browser, and uses Influence-guided Mutation to steer web inputs. The symbolic executor clusters and symbolizes contexts, performs coverage-guided symbolic execution under reachable entry states, and returns actionable constraints to steer the next online round. We evaluate SymWeb on 30 real-world Wasm-enabled websites. Under our Web threat model, SymWeb verifies 17 exploitable vulnerabilities and achieves 72.8% average Wasm basic-block coverage. Compared to the browser-based baseline Wemby, SymWeb finds 8 more verified vulnerabilities and improves coverage by 19.9 percentage points. Compared to the Wasm-only baseline WASEM, SymWeb finds 14 more verified vulnerabilities and improves coverage by 40.4 percentage points. Overall, these results show that closing the loop between browser-reachable context generation and context-aware Wasm analysis substantially improves both vulnerability-finding effectiveness and exploration depth in real Web environments.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Wemby's Web: Hunting for Memory Corruption in WebAssemblyOussama Draissi, Tobias Cloosters, David Klein, Michael Rodler 等ISSTA 2025 · 被引用 1 次
- LWDIFF: an LLM-Assisted Differential Testing Framework for Webassembly RuntimesShiyao Zhou, Jincheng Wang, He Ye, Hao Zhou 等ICSE 2025 · 被引用 2 次
- Everything Old is New Again: Binary Security of WebAssemblyDaniel Lehmann, Johannes Kinder, Michael PradelUSENIX Security 2020
- Waltzz: WebAssembly Runtime Fuzzing with Stack-Invariant TransformationLingming Zhang, Binbin Zhao, Jiacheng Xu, Peiyu Liu 等USENIX Security 2025
- EOSAFE: Security Analysis of EOSIO Smart ContractsNingyu He, Ruiyi Zhang, Haoyu Wang, Lei Wu 等USENIX Security 2021 · 被引用 69 次
