WBSan: WebAssembly Bug Detection for Sanitization and Binary-Only Fuzzing
Xiao Wu, Junzhou He, Liyan Huang, Cai Fu, Weihang Wang
摘要
With the advancement of WebAssembly, abbreviated as Wasm, various memory bugs and undefined behaviors have emerged, leading to security issues that affect usability and portability. Existing methods struggle to detect these problems in Wasm binaries due to challenges associated with binary instrumentation and the difficulty of defining legal memory bounds. While sanitizers combined with fuzzing are recognized as effective means for identifying bugs, current Wasm sanitizers necessitate compile-time instrumentation, rendering them unsuitable for practical scenarios where only binaries are accessible. In this paper, we propose WBSan, the first Wasm binary sanitizer employing static analysis and Wasm binary instrumentation to detect memory bugs and undefined behaviors. We develop distinct instrumentation patterns tailored for each type of bug and introduce Wasm shadow memory to address complex memory bugs. Our results reveal that WBSan achieves a 16.8% false detection rate, outperforming current Wasm binary checkers and native sanitizers in detecting memory bugs and undefined behaviors. Furthermore, when compared with the binary-only fuzzer, WBSan uncovers more crashes and achieves greater code coverage. CCS Concepts • Security and privacy → Vulnerability scanners.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper13
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 被引用 187 次
- An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use CasesAaron Hilbig, Daniel Lehmann, Michael PradelWWW 2021 · 被引用 114 次
- Breaking Through Binaries: Compiler-quality Instrumentation for Better Binary-only FuzzingStefan Nagy, Anh Nguyen-Tuong, Jason D. Hiser, Jack W. Davidson 等USENIX Security 2021 · 被引用 65 次
- An Empirical Study of Bugs in WebAssembly CompilersAlan Romano, Xinyue Liu, Yonghwi Kwon, Weihang WangASE 2021 · 被引用 43 次
- WASAI: uncovering vulnerabilities in Wasm smart contractsWeimin Chen, Zihan Sun, Haoyu Wang, Xiapu Luo 等ISSTA 2022 · 被引用 43 次
相关 Paper
- Wemby's Web: Hunting for Memory Corruption in WebAssemblyOussama Draissi, Tobias Cloosters, David Klein, Michael Rodler 等ISSTA 2025 · 被引用 1 次
- CombiSan: Unifying Software Sanitizers for Comprehensive FuzzingMatteo Marini, Floris Gorter, Daniele Cono D'Elia, Cristiano GiuffridaUSENIX Security 2026
- QMSan: Efficiently Detecting Uninitialized Memory Errors During FuzzingMatteo Marini, Daniele Cono D'Elia, Mathias Payer, Leonardo QuerzoniNDSS 2025
- Waltzz: WebAssembly Runtime Fuzzing with Stack-Invariant TransformationLingming Zhang, Binbin Zhao, Jiacheng Xu, Peiyu Liu 等USENIX Security 2025
- SymWeb: Feedback-Driven Context Exploration and Context-Aware Symbolic Execution for Browser-Embedded WebAssembly Vulnerability DetectionYuanpeng Wang, Yeqi Fu, Zhineng Zhong, Zhenkai Liang 等ISSTA 2026
