Federal grant · project grant (b)
Satc: Core: Medium: Securing Webassembly Using Static Analysis and Binary Instrumentation -webassembly Is a Web Technology That Has Rapidly Been Gaining in Popularity. It Is a Low-level Bytecode Format That Was Introduced in 2017, and Was Originally Designed for Computationally-intensive Tasks in the Browser Such as Cryptography and Games. Today, as Envisioned, Webassembly Is Supported by All Modern Browsers, and Heavily Used by Applications. Recently, a Number of Critical Security Concerns in Webassembly Binaries Have Been Identified for Which No Adequate Solutions Exist. This Project Is Concerned With the Development of Wassy, a Novel System and a Comprehensive Suite of Tools for Detecting and Mitigating Security Vulnerabilities in Applications That Rely on Webassembly. Wassy Will Rely on a Combination of Static Analysis Techniques, Which Analyze Webassembly Binaries Without Executing Them, to Detect Likely Vulnerabilities, and Binary Instrumentation Techniques That Rewrite a Webassembly Binary to Mitigate Potential Vulnerabilities. the Developed Techniques Will Be Evaluated on a Suite of Applications That Rely on Webassembly Binaries and That Contain Vulnerabilities. the Research Will Benefit Users of Web Applications by Reducing the Number of Vulnerabilities That Can Be Exploited, Thereby Reducing the Potential for Loss of Data, and Associated Financial and Legal Exposure. Results of the Project Will Be Disseminated via Publications in Scientific Venues and Through Release of Open-source Software and Data Sets. Societal Benefits Will Follow From Improvements in Web Software Security That Is Enabled by the Adoption of the Developed Techniques. the Developed Static Analysis Techniques Will Be Designed to Accommodate Several Characteristics That Are Specific to Webassembly Such as Its Stack-based Representation, Lack of Names and Structure, Lack of Type Information, and Index-based Access to Linear Memory and Function Tables. a Family of Flow-insensitive, Flow-sensitive, and Context-sensitive Algorithms Will Be Developed Accordingly, Using Abstractions Suitable to the Domain, and Designed to Account for Interaction With Javascript Code That Executes in the Host Environment. the Developed Binary Instrumentation Techniques Will Be Designed to Counteract Vulnerabilities That May Arise in Web Applications That Rely on Webassembly Binaries, Such as Injection Vulnerabilities and Cross-site Scripting Vulnerabilities. to This End, Binary Instrumentation Will Be Used to Implement Suitable Variations on Classic Security Concepts Such as Stack Canaries, Memory Segmentation, and Address Space Randomization. This Award Reflects NSF'S Statutory Mission and Has Been Deemed Worthy of Support Through Evaluation Using the Foundation's Intellectual Merit and Broader Impacts Review Criteria.
Committed
$1.2 Million
Paid out
$950.1K
79%
Committed, not yet paid
$259.9K
21%
Loading…
Everything here is this single award's whole record — signed, amended, paid — not a fiscal-year slice. The by-year charts elsewhere split an award across the years it was committed; this page keeps it whole.
Committed is what the government has legally promised on this award so far. Contracts can also carry a ceiling — the maximum if every option is exercised. Unspent ceiling is headroom, not money owed.
The cash actually disbursed against this award. The gap from committed is the disbursement pipeline: promised, not yet cashed.
Each transaction is a signing event — an action that created or changed the award, dated the day it was signed — not a payment. Negative amounts are real: money de-committed at closeout or renegotiation.
One bar, the award’s whole arithmetic: paid out, then committed, not yet paid, then unspent ceiling.