Abstract
Over the past few years, blockchain platforms supporting WebAssembly (Wasm) smart contracts are gaining popularity. However, Wasm smart contracts are often compiled from memory-unsafe languages (e.g. C and C++). And there is a lack of effective defense against integer overflow and stack overflow at the compiler and virtual machine (VM) layers, making Wasm smart contracts even more exploitable than native C and C++ programs. In this paper, the authors propose wasm overflow detector (WASMOD) to address the integer overflow and stack overflow vulnerabilities. The authors’ approach combines bytecode instrumentation, run-time validation, and grey-box fuzzing to detect these vulnerabilities. The authors applied their approach to the popular EOSIO blockchain and evaluated it on 4616 deployed Wasm smart contracts. The authors’ approach detected 13 real-world vulnerable smart contracts.
Author supplied keywords
Cite
CITATION STYLE
Zhou, J., & Chen, T. (2023). WASMOD: Detecting vulnerabilities in Wasm smart contracts. IET Blockchain, 3(4), 172–181. https://doi.org/10.1049/blc2.12029
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.