An Empirical Study of WebAssembly Usage in Node.js
Michelle Thalakottur, Maxwell Bernstein, Daniel Lehmann, Michael Pradel, Frank Tip
摘要
WebAssembly code executes within a host environment, such as JavaScript running on Node.js. Despite the increasing popularity of mixed JavaScript-WebAssembly applications, the interactions between these two languages and the effect of WebAssembly usage on the NPM ecosystem, are currently not well understood. As a result, developers of program analyses, runtime engines, and ecosystem tooling are forced to make assumptions that may not hold in practice. Moreover, there currently is no executable dataset of WebAssembly modules that allows for studying how WebAssembly is used at runtime within Node.js packages. This paper presents the first comprehensive study of WebAssembly usage in Node.js code. The study is enabled by a novel dataset that we collect comprising 510 executable Node.js packages that exercise 217 unique WebAssembly modules. We study dependencies among packages that use WebAssembly, how JavaScript and WebAssembly interoperate, and the implications for security, efficiency and reliability in the WebAssembly-JavaScript ecosystem. The study provides several insights and future research opportunities, including: (i) a lack of maintenance of WebAssembly binaries that are ports of C/C++/Rust libraries, which motivates future work on cross-language package maintenance, (ii) a lack of testing of WebAssembly usage from JavaScript, which motivates work on targeted testing techniques; (iii) relatively little dynamism in WebAssembly usage, allowing for pragmatic assumptions in program analyses; and (iv) untapped optimization opportunities in engine caching and client-specific debloating. Beyond these insights, we envision our dataset to provide a basis for future studies, program analyses, and work on WebAssembly engine design.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use CasesAaron Hilbig, Daniel Lehmann, Michael PradelWWW 2021 · 被引用 114 次
- How do programmers use unsafe rust?Vytautas Astrauskas, Christoph Matheja, Federico Poli, Peter Müller 等OOPSLA 2020 · 被引用 78 次
- A study of inline assembly in solidity smart contractsStefanos Chaliasos, Arthur Gervais, Benjamin LivshitsOOPSLA 2022 · 被引用 22 次
- That's a Tough Call: Studying the Challenges of Call Graph Construction for WebAssemblyDaniel Lehmann, Michelle Thalakottur, Frank Tip, Michael PradelISSTA 2023 · 被引用 11 次
相关 Paper
- Wobfuscator: Obfuscating JavaScript Malware via Opportunistic Translation to WebAssemblyAlan Romano, Daniel Lehmann, Michael Pradel, Weihang WangS&P 2022 · 被引用 40 次
- An Empirical Study of Bugs in WebAssembly CompilersAlan Romano, Xinyue Liu, Yonghwi Kwon, Weihang WangASE 2021 · 被引用 43 次
- Best of Both Worlds: Effective Foreign Bridge Identification in V8 Embedders for Security AnalysisGeorgios Alexopoulos, Thodoris Sotiropoulos, Zhendong Su, Dimitris MitropoulosS&P 2026 · 被引用 1 次
- Flexible Non-intrusive Dynamic Instrumentation for WebAssemblyBen L. Titzer, Elizabeth Gilbert, Bradley Wei Jie Teo, Yash Anand 等ASPLOS 2024 · 被引用 7 次
- Everything Old is New Again: Binary Security of WebAssemblyDaniel Lehmann, Johannes Kinder, Michael PradelUSENIX Security 2020
