{"id":"https://openalex.org/W4226053725","doi":"https://doi.org/10.1145/3477314.3507308","title":"Security risks of porting C programs to webassembly","display_name":"Security risks of porting C programs to webassembly","publication_year":2022,"publication_date":"2022-04-25","ids":{"openalex":"https://openalex.org/W4226053725","doi":"https://doi.org/10.1145/3477314.3507308"},"language":"en","primary_location":{"id":"doi:10.1145/3477314.3507308","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3477314.3507308","pdf_url":null,"source":{"id":"https://openalex.org/S4363608665","display_name":"Proceedings of the 37th ACM/SIGAPP Symposium on Applied Computing","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 37th ACM/SIGAPP Symposium on Applied Computing","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2112.11745","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5061688363","display_name":"Quentin Sti\u00e9venart","orcid":"https://orcid.org/0000-0001-9985-9808"},"institutions":[{"id":"https://openalex.org/I13469542","display_name":"Vrije Universiteit Brussel","ror":"https://ror.org/006e5kg04","country_code":"BE","type":"education","lineage":["https://openalex.org/I13469542"]}],"countries":["BE"],"is_corresponding":true,"raw_author_name":"Quentin Sti\u00e9venart","raw_affiliation_strings":["Vrije Universiteit Brussel, Belgium"],"affiliations":[{"raw_affiliation_string":"Vrije Universiteit Brussel, Belgium","institution_ids":["https://openalex.org/I13469542"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5042827940","display_name":"Coen De Roover","orcid":"https://orcid.org/0000-0002-1710-1268"},"institutions":[{"id":"https://openalex.org/I13469542","display_name":"Vrije Universiteit Brussel","ror":"https://ror.org/006e5kg04","country_code":"BE","type":"education","lineage":["https://openalex.org/I13469542"]}],"countries":["BE"],"is_corresponding":false,"raw_author_name":"Coen De Roover","raw_affiliation_strings":["Vrije Universiteit Brussel, Belgium"],"affiliations":[{"raw_affiliation_string":"Vrije Universiteit Brussel, Belgium","institution_ids":["https://openalex.org/I13469542"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5024783227","display_name":"Mohammad Ghafari","orcid":"https://orcid.org/0000-0002-1986-9668"},"institutions":[{"id":"https://openalex.org/I154130895","display_name":"University of Auckland","ror":"https://ror.org/03b94tp07","country_code":"NZ","type":"education","lineage":["https://openalex.org/I154130895"]}],"countries":["NZ"],"is_corresponding":false,"raw_author_name":"Mohammad Ghafari","raw_affiliation_strings":["University of Auckland, New Zealand"],"affiliations":[{"raw_affiliation_string":"University of Auckland, New Zealand","institution_ids":["https://openalex.org/I154130895"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5061688363"],"corresponding_institution_ids":["https://openalex.org/I13469542"],"apc_list":null,"apc_paid":null,"fwci":1.9832,"has_fulltext":false,"cited_by_count":20,"citation_normalized_percentile":{"value":0.88318228,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1713","last_page":"1722"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9952999949455261,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9793999791145325,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/porting","display_name":"Porting","score":0.9051423668861389},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7817193269729614},{"id":"https://openalex.org/keywords/compiler","display_name":"Compiler","score":0.7764828205108643},{"id":"https://openalex.org/keywords/x86","display_name":"x86","score":0.6243478655815125},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.452564537525177},{"id":"https://openalex.org/keywords/point","display_name":"Point (geometry)","score":0.4318724274635315},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.41392430663108826},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.41068243980407715},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3647170066833496},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.18402013182640076}],"concepts":[{"id":"https://openalex.org/C106251023","wikidata":"https://www.wikidata.org/wiki/Q851989","display_name":"Porting","level":3,"score":0.9051423668861389},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7817193269729614},{"id":"https://openalex.org/C169590947","wikidata":"https://www.wikidata.org/wiki/Q47506","display_name":"Compiler","level":2,"score":0.7764828205108643},{"id":"https://openalex.org/C170723468","wikidata":"https://www.wikidata.org/wiki/Q182933","display_name":"x86","level":3,"score":0.6243478655815125},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.452564537525177},{"id":"https://openalex.org/C28719098","wikidata":"https://www.wikidata.org/wiki/Q44946","display_name":"Point (geometry)","level":2,"score":0.4318724274635315},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.41392430663108826},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.41068243980407715},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3647170066833496},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.18402013182640076},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1145/3477314.3507308","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3477314.3507308","pdf_url":null,"source":{"id":"https://openalex.org/S4363608665","display_name":"Proceedings of the 37th ACM/SIGAPP Symposium on Applied Computing","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 37th ACM/SIGAPP Symposium on Applied Computing","raw_type":"proceedings-article"},{"id":"pmh:oai:vubissmart:VUBISSMART:2000:161892","is_oa":false,"landing_page_url":"https://biblio.vub.ac.be/vubir/security-risks-of-porting-c-programs-to-webassembly(ca107517-88d1-4007-b8fb-77d53be62c50).html","pdf_url":null,"source":{"id":"https://openalex.org/S4306402573","display_name":"VUBIR (Vrije Universiteit Brussel)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I13469542","host_organization_name":"Vrije Universiteit Brussel","host_organization_lineage":["https://openalex.org/I13469542"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":null,"raw_type":"publishedVersion"},{"id":"pmh:oai:arXiv.org:2112.11745","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2112.11745","pdf_url":"https://arxiv.org/pdf/2112.11745","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:oai:vubissmart:VUBISSMART:2000:191024","is_oa":false,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4306402573","display_name":"VUBIR (Vrije Universiteit Brussel)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I13469542","host_organization_name":"Vrije Universiteit Brussel","host_organization_lineage":["https://openalex.org/I13469542"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2112.11745","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2112.11745","pdf_url":"https://arxiv.org/pdf/2112.11745","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.6800000071525574}],"awards":[],"funders":[{"id":"https://openalex.org/F4320321730","display_name":"Fonds Wetenschappelijk Onderzoek","ror":"https://ror.org/03qtxy027"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":30,"referenced_works":["https://openalex.org/W2025411198","https://openalex.org/W2170737051","https://openalex.org/W2753617992","https://openalex.org/W2765648970","https://openalex.org/W2903428887","https://openalex.org/W2932657656","https://openalex.org/W2954419750","https://openalex.org/W3014583938","https://openalex.org/W3034145953","https://openalex.org/W3048513423","https://openalex.org/W3094062523","https://openalex.org/W3099668644","https://openalex.org/W3101399476","https://openalex.org/W3104442698","https://openalex.org/W3107571154","https://openalex.org/W3108990740","https://openalex.org/W3119305140","https://openalex.org/W3131541588","https://openalex.org/W3149775480","https://openalex.org/W3153291015","https://openalex.org/W3155529437","https://openalex.org/W3155555003","https://openalex.org/W3173940409","https://openalex.org/W3194856199","https://openalex.org/W3208781723","https://openalex.org/W3213344964","https://openalex.org/W4206578767","https://openalex.org/W4226258240","https://openalex.org/W4232865065","https://openalex.org/W4238083723"],"related_works":["https://openalex.org/W2386329253","https://openalex.org/W2387474457","https://openalex.org/W2384479030","https://openalex.org/W3195889798","https://openalex.org/W2376033584","https://openalex.org/W2973892509","https://openalex.org/W2352844827","https://openalex.org/W1987014004","https://openalex.org/W2368028869","https://openalex.org/W2389790172"],"abstract_inverted_index":{"WebAssembly":[0,52,138,152],"is":[1,9],"a":[2,86,118],"compilation":[3],"target":[4],"for":[5,80,139],"cross-platform":[6,140],"applications":[7],"that":[8,43,57,114,131],"increasingly":[10],"being":[11],"used.":[12],"In":[13],"this":[14],"paper,":[15],"we":[16,55,73],"investigate":[17],"whether":[18],"one":[19],"can":[20,33],"transparently":[21],"cross-compile":[22],"C":[23,135],"programs":[24,42],"to":[25,47,51,137],"WebAssembly,":[26,97],"and":[27,50,54,98,110,123],"if":[28],"not,":[29],"what":[30],"impact":[31],"porting":[32],"have":[34],"on":[35],"their":[36],"security.":[37],"We":[38,106,129],"compile":[39],"17":[40],"802":[41],"exhibit":[44],"common":[45],"vulnerabilities":[46],"64-bit":[48],"x86":[49],"binaries,":[53],"observe":[56],"the":[58,83,91,99,103,112,148,151],"execution":[59,104],"of":[60,77,85,93,102,121,150],"4":[61],"911":[62],"binaries":[63],"produces":[64],"different":[65,87,100],"results":[66],"across":[67],"these":[68],"platforms.":[69],"Through":[70],"manual":[71],"inspection,":[72],"identify":[74],"three":[75],"classes":[76],"root":[78],"causes":[79],"such":[81],"differences:":[82],"use":[84],"standard":[88],"library":[89],"implementation,":[90],"lack":[92],"security":[94,119,149],"measures":[95],"in":[96],"semantics":[101],"environments.":[105],"describe":[107],"our":[108],"observations":[109],"discuss":[111],"ones":[113],"are":[115],"critical":[116],"from":[117,127],"point":[120],"view":[122],"need":[124],"most":[125],"attention":[126],"developers.":[128],"conclude":[130],"compiling":[132],"an":[133],"existing":[134],"program":[136],"distribution":[141],"may":[142,154],"require":[143],"source":[144],"code":[145],"adaptations;":[146],"otherwise,":[147],"application":[153],"be":[155],"at":[156],"risk.":[157]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":8},{"year":2022,"cited_by_count":1}],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2025-10-10T00:00:00"}
