TY - GEN
T1 - Robust Stack Smashing Protection for WebAssembly
AU - Michaud, Quentin
AU - Pipereau, Yohan
AU - Levillain, Olivier
AU - Ayed, Dhouha
N1 - Publisher Copyright:
© 2024 IEEE.
PY - 2024/1/1
Y1 - 2024/1/1
N2 - WebAssembly is an instruction set architecture and binary format standard, designed for secure execution by an interpreter. This technology is identified as an alternative for current containerization technologies that is suitable for secure and lightweight orchestration for 5G/6G environments. Previous work has shown that WebAssembly is vulnerable to buffer overflow due to the lack of effective protection mechanisms.In this paper, we evaluate the implementation of Stack Smashing Protection (SSP) in WebAssembly standalone runtimes, and uncover two weaknesses in their current implementation. The first one is the possibility to overwrite the SSP reference value because of the contiguous memory zones inside a WebAssembly process. The second comes from the reliance of WebAssembly on the runtime to provide randomness in order to initialize the SSP reference value, which impacts the robustness of the solution.We address these two flaws by hardening the SSP implementation in terms of storage and random generator failure, in a way that is generalizable to all of WebAssembly.
AB - WebAssembly is an instruction set architecture and binary format standard, designed for secure execution by an interpreter. This technology is identified as an alternative for current containerization technologies that is suitable for secure and lightweight orchestration for 5G/6G environments. Previous work has shown that WebAssembly is vulnerable to buffer overflow due to the lack of effective protection mechanisms.In this paper, we evaluate the implementation of Stack Smashing Protection (SSP) in WebAssembly standalone runtimes, and uncover two weaknesses in their current implementation. The first one is the possibility to overwrite the SSP reference value because of the contiguous memory zones inside a WebAssembly process. The second comes from the reliance of WebAssembly on the runtime to provide randomness in order to initialize the SSP reference value, which impacts the robustness of the solution.We address these two flaws by hardening the SSP implementation in terms of storage and random generator failure, in a way that is generalizable to all of WebAssembly.
KW - Memory bugs
KW - Stack Smashing Protection
KW - WebAssembly
UR - https://www.scopus.com/pages/publications/105009034772
U2 - 10.1109/FNWF63303.2024.11028722
DO - 10.1109/FNWF63303.2024.11028722
M3 - Conference contribution
AN - SCOPUS:105009034772
T3 - 2024 IEEE Future Networks World Forum, FNWF 2024
SP - 861
EP - 866
BT - 2024 IEEE Future Networks World Forum, FNWF 2024
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2024 IEEE Future Networks World Forum, FNWF 2024
Y2 - 15 October 2024 through 17 October 2024
ER -