WASMOD: Detecting vulnerabilities in Wasm smart contracts

8Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.

Abstract

Over the past few years, blockchain platforms supporting WebAssembly (Wasm) smart contracts are gaining popularity. However, Wasm smart contracts are often compiled from memory-unsafe languages (e.g. C and C++). And there is a lack of effective defense against integer overflow and stack overflow at the compiler and virtual machine (VM) layers, making Wasm smart contracts even more exploitable than native C and C++ programs. In this paper, the authors propose wasm overflow detector (WASMOD) to address the integer overflow and stack overflow vulnerabilities. The authors’ approach combines bytecode instrumentation, run-time validation, and grey-box fuzzing to detect these vulnerabilities. The authors applied their approach to the popular EOSIO blockchain and evaluated it on 4616 deployed Wasm smart contracts. The authors’ approach detected 13 real-world vulnerable smart contracts.

Cite

CITATION STYLE

APA

Zhou, J., & Chen, T. (2023). WASMOD: Detecting vulnerabilities in Wasm smart contracts. IET Blockchain, 3(4), 172–181. https://doi.org/10.1049/blc2.12029

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free