Lost in the Pages: WebAssembly Code Recovery through SEV-SNP's Exposed Address Space

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Berthilsson, Markus, Gehrmann, Christian
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909965374980096
author Berthilsson, Markus
Gehrmann, Christian
author_facet Berthilsson, Markus
Gehrmann, Christian
contents WebAssembly (Wasm) has risen as a widely used technology to distribute computing workloads on different platforms. The platform independence offered through Wasm makes it an attractive solution for many different applications that can run on disparate infrastructures. In addition, Trusted Execution Environments (TEEs) are offered in many computing infrastructures, which allows also running security sensitive Wasm workloads independent of the specific platforms offered. However, recent work has shown that Wasm binaries are more sensitive to code confidentiality attacks than native binaries. The previous result was obtained for Intel SGX only. In this paper, we take this one step further, introducing a new Wasm code-confidentiality attack that exploits exposed address-space information in TEEs. Our attack enables the extraction of crucial execution features which, when combined with additional side channels, allows us to with high reliability obtain more than 70% of the code in most cases. This is a considerably larger amount than was previously obtained by single stepping Intel SGX where only upwards to 50% of the code could be obtained.
format Preprint
id arxiv_https___arxiv_org_abs_2512_14376
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Lost in the Pages: WebAssembly Code Recovery through SEV-SNP's Exposed Address Space
Berthilsson, Markus
Gehrmann, Christian
Cryptography and Security
WebAssembly (Wasm) has risen as a widely used technology to distribute computing workloads on different platforms. The platform independence offered through Wasm makes it an attractive solution for many different applications that can run on disparate infrastructures. In addition, Trusted Execution Environments (TEEs) are offered in many computing infrastructures, which allows also running security sensitive Wasm workloads independent of the specific platforms offered. However, recent work has shown that Wasm binaries are more sensitive to code confidentiality attacks than native binaries. The previous result was obtained for Intel SGX only. In this paper, we take this one step further, introducing a new Wasm code-confidentiality attack that exploits exposed address-space information in TEEs. Our attack enables the extraction of crucial execution features which, when combined with additional side channels, allows us to with high reliability obtain more than 70% of the code in most cases. This is a considerably larger amount than was previously obtained by single stepping Intel SGX where only upwards to 50% of the code could be obtained.
title Lost in the Pages: WebAssembly Code Recovery through SEV-SNP's Exposed Address Space
topic Cryptography and Security
url https://arxiv.org/abs/2512.14376