Analyzing the Unanalyzable: Multi-Layer Detection and Runtime Analysis for WebAssembly Malware

Dr. Sapna V M&Prof. Prasad B Honnavalli&Dhruthan M N

Associate Professor @ PES University

LinkedInView Profile
Dr. Sapna V M

Arsenal Overview

WebAssembly (WASM) has emerged as a universal execution substrate deployed across browsers, cloud functions, edge runtimes, and IoT devices. Its platform-independent bytecode format and sandboxed execution model, while designed for safety, have created a significant blind spot in modern security tooling existing malware analyzers are built for PE, ELF binaries and have no capability to parse, disassemble, or analyze WASM binaries.

Malware authors have begun exploiting this gap, embedding cryptominers, ransomware, droppers, and credential stealers in WASM modules that pass undetected through conventional security pipelines.

This analyzer has three independent and complementary analysis layers.

The static analysis engine implements a full WASM binary parser, disassembler, control flow graph builder with correct structured control flow resolution, intra-procedural taint analysis, entropy and cryptographic constant detection, and a rule engine with YARA like detection signatures covering 12 threat categories.

The dynamic analysis layer integrates Wasabi to perform instruction-level execution tracing, runtime call graph reconstruction, state machine extraction, and static-to-dynamic CFG divergence analysis.

The runtime monitoring layer uses bpftrace eBPF tracepoints to observe kernel-level behavior of WASM runtimes, detecting W+X memory mappings, credential exposure, and anomalous network connections without requiring modification of the runtime itself.

About the Speakers

Dr. Sapna V M

Dr. Sapna V M

Associate Professor @ PES University

Dr. Sapna V M is an Associate Professor in Computer Science and Engineering with 14+ years of academic and research experience. She has published several research papers in reputed journals and conferences and actively participates in cybersecurity and digital forensics initiatives including Black Hat.
LinkedInView Profile
Prof. Prasad B Honnavalli

Prof. Prasad B Honnavalli

Professor @ PES University

Prof. Prasad B Honnavalli is a Professor in Computer Science and Engineering with expertise in Information Security, Networks, and Internet of Things. He is the Director of the PESU Centre for Information Security, Forensics and Cyber Resilience (C-ISFCR) and the PESU Centre for Internet of Things with a focus on Security (C-IoT).
LinkedInView Profile
Dhruthan M N

Dhruthan M N

Student @ PES University

Dhruthan M N is a final year undergraduate student in Computer Science and Engineering. Has interests in Networks, Systems.
LinkedInView Profile