Discovering Vulnerabilities in WebAssembly with Code Property Graphs

Discovering Vulnerabilities in WebAssembly with Code Property Graphs
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Pedro Daniel;Rogeiro Lopes;Nuno Santos;Jos´e Fragoso Santos
Pedro Daniel;Rogeiro Lopes;Nuno Santos;Jos´e Fragoso Santos
中科院分区:
其他
文献类型:
--
作者:
Pedro Daniel;Rogeiro Lopes;Nuno Santos;Jos´e Fragoso Santos

文献摘要

被引文献

相似文献

WebAssembly是一项新技术,允许Web开发人员在网页上运行本地性能,因此比典型的JavaScript应用程序更快。使更复杂的客户端应用程序可以在浏览器上运行。在服务器端运行时间,物联网平台和边缘计算的情况下,平台采用了该平台。可以导入W​​ebAssembly方法是使用代码属性图(CPG),该程序表示已成功地应用于高级语言中漏洞的检测。
. WebAssembly is a new technology that allows web developers to run native C/C++ on a webpage with near-native performance and therefore much faster than typical JavaScript applications. Currently supported by the most popular browsers, WebAssembly brings implications for the web platform since it enables more complex client apps to run on the browser. The compact binary format, performance, and safety mechanisms present in the language led it to be used beyond the browser platform, being employed in the context of server-side run-times, IoT platforms and edge computing. However, in spite of its be-nefits, WebAssembly technology brings some security concerns attached. In particular, vulnerabilities from C and C++ such buffer overflows can be imported to WebAssembly. The goal of this project is to design and implement a new tool that can statically find vulnerabilities in Web-Assembly code. Our approach is to use code property graphs (CPGs), a program representation that has been successfully applied to the detection of vulnerabilities in high-level languages. We propose to adopt this representation into the realm of WebAssembly programs.