Characterizing and Detecting WebAssembly Runtime Bugs

Author:

Zhang Yixuan1ORCID,Cao Shangtong2ORCID,Wang Haoyu3ORCID,Chen Zhenpeng4ORCID,Luo Xiapu5ORCID,Mu Dongliang3ORCID,Ma Yun6ORCID,Huang Gang7ORCID,Liu Xuanzhe1ORCID

Affiliation:

1. Key Laboratory of High Confidence Software Technologies (Peking University), Ministry of Education; School of Computer Science, Peking University, China

2. Beijing University of Posts and Telecommunications, China

3. Huazhong University of Science and Technology, China

4. University College London, UK

5. The Hong Kong Polytechnic University, China

6. Key Laboratory of High Confidence Software Technologies (Peking University), Ministry of Education; Institute for Artificial Intelligence, Peking University, China

7. School of Computer Science, Peking University; National Key Laboratory of Data Space Technology and System, China

Abstract

WebAssembly (abbreviated WASM) has emerged as a promising language of the Web and also been used for a wide spectrum of software applications such as mobile applications and desktop applications. These applications, named WASM applications, commonly run in WASM runtimes. Bugs in WASM runtimes are frequently reported by developers and cause the crash of WASM applications. However, these bugs have not been well studied. To fill in the knowledge gap, we present a systematic study to characterize and detect bugs in WASM runtimes. We first harvest a dataset of 311 real-world bugs from hundreds of related posts on GitHub. Based on the collected high-quality bug reports, we distill 31 bug categories of WASM runtimes and summarize their common fix strategies. Furthermore, we develop a pattern-based bug detection framework to automatically detect bugs in WASM runtimes. We apply the detection framework to seven popular WASM runtimes and successfully uncover 60 bugs that have never been reported previously, among which 13 have been confirmed and 9 have been fixed by runtime developers.

Funder

National Key R&D Program of China

National Natural Science Foundation of China

Beijing Outstanding Young Scientist Program

Center for Data Space Technology and System, Peking University

ERC Advanced Grant

Hong Kong RGC Project

Publisher

Association for Computing Machinery (ACM)

Subject

Software

Reference79 articles.

1. Nicolas Falliere. 2018. Reverse Engineering WebAssembly. https://www.pnfsoftware.com/reversing-wasm.pdf

2. Wasmer. 2019. wasmer issue 830. https://github.com/wasmerio/wasmer/issues/830

3. Bytecode Alliance. 2020. WAMR issue 1144. https://github.com/bytecodealliance/wasm-micro-runtime/issues/1144

4. Wasmer. 2020. wasmer issue 1263. https://github.com/wasmerio/wasmer/issues/1263

5. Bytecode Alliance. 2020. wasmtime issue 2347. https://github.com/bytecodealliance/wasmtime/issues/2347

Cited by 7 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Wapplique: Testing WebAssembly Runtime via Execution Context-Aware Bytecode Mutation;Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis;2024-09-11

2. Characterizing and Detecting WebAssembly Runtime Bugs;ACM Transactions on Software Engineering and Methodology;2023-12-21

3. A Comprehensive Study of Bugs in Embedded WebAssembly Virtual Machines;2023 3rd International Conference on Computer Science, Electronic Information Engineering and Intelligent Control Technology (CEI);2023-12-15

4. Enabling Trusted TEE-as-a-Service Models with Privacy Preserving Automatons;2023 IEEE International Conference on Cloud Computing Technology and Science (CloudCom);2023-12-04

5. WADIFF: A Differential Testing Framework for WebAssembly Runtimes;2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE);2023-09-11

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3