WaShadow: Effectively Protecting WebAssembly Memory Through Virtual Machine-Aware Shadow Memory

Zhuochen Jiang, Baojian Hua · 2024

WebAssembly (Wasm) is an emerging binary instruction set architecture designed for secure binary program execution and is rapidly being deployed across various security-critical domains, such as edge computing and smart contracts. However, despite its security-oriented design, Wasm remains susceptible to vulnerabilities, including integer overflows and memory corruption, due to the lack of effective protection mechanisms, which undermines its security guarantees.In this paper, we present WaShadow, the first approach for effective Wasm protection using virtual machine-aware shadow memory. Our key insight is that, since Wasm is a virtual instruction set, we can leverage memory layout information in the underlying Wasm VMs to enforce the protection. Specifically, we first extend the Wasm VMs with shadow memory to record memory information and track the status of linear memory, by introducing two new pseudo Wasm instructions for inserting and performing sanity checks on canaries in the linear memory. We then design a static binary instrumentation method to instrument Wasm binaries with canary instructions. Finally, we implement these canary pseudo-instructions through virtual machine extensions as well as a set of vulnerability detection algorithms as security plugins. We implemented a software prototype for WaShadow and conducted extensive experiments to evaluate its effectiveness, usability, and overhead on micro and real-world benchmarks. Experimental results demonstrated that WaShadow is effective in protecting Wasm linear memory against various memory vulnerabilities, with an average code size increase of 26.5% and an execution time penalty of 108.5%.

Read the paper · More papers on PaperTik