PROCEEDINGS OF THE 2025 CLOUD COMPUTING SECURITY WORKSHOP, CCSW 2025(2025)
SUNY Binghamton
被引用0|浏览0
摘要
WebAssembly has become increasingly popular in web development, offering a versatile and efficient platform for executing code in languages beyond JavaScript, such as C and C++. However, WebAssembly's flat memory model exposes memory-safety vulnerabilities. While C and C++ code are primarily susceptible to memory safety issues, Rust, though improved, still presents vulnerabilities[44]. Inspired by the ARM Memory Tagging Extension, this paper proposes a memory tagging solution for WebAssembly. Our evaluation indicates that the proposed memory tagging mechanism introduces average time overheads of 48.91% for Wasm64 and 72.38% for Wasm32 in pure software implementations. On ARM Memory Tagging Extension-supported CPUs, the time overheads decrease to 5.71% for Wasm64 and 18.05% for Wasm32. Additionally, we compare our WebAssembly memory tagging to the host Address Sanitizer to demonstrate the efficacy of our approach. Finally, we conduct a case study on real-world CVEs to demonstrate the impact of our work.