About
I am a doctoral researcher in the Systems Security group at the University of Duisburg‑Essen, advised by Prof. Lucas Davi.
I work on memory corruption in sandboxed bytecode such as WebAssembly: finding it automatically with fuzzing and program analysis, and containing it with practical, low-overhead defenses. The same problems carry over to blockchains, trusted execution environments, and RISC-V.
Published at ACM CCS · ACM ISSTA · RAID · The Web Conference · IEEE CNS · ACNS
News
- HammerWatch: Standing Watch Against Rowhammer accepted at IEEE CNS 2026 in Newark, Delaware.
- Waslr: Fine-Grained Memory Randomization for WebAssembly accepted at RAID 2026 in Lancaster, UK.
- Presented Bento at The Web Conference (WWW 2026) in Dubai.
Research
Wemby’s Web: Hunting for Memory Corruption in WebAssembly
ACM ISSTA 2025
The first holistic fuzzer for WebAssembly on the live web: 232× faster and +46% coverage over prior Wasm fuzzers, with real bugs found, including one on the Zoom platform. Across 37,797 domains, 77.81% pass unchecked Wasm memory into XSS-prone sinks.
Websites trust the data coming out of Wasm memory and pass it into sinks such as
eval or innerHTML, so corrupting that memory becomes
cross-site scripting. Wemby’s
binary-only instrumentation adds memory-corruption oracles and taint tracking on top
of SAP’s Foxhound browser. Joint work
with TU Braunschweig and
AWS.
Rust · Python · JavaScript · Foxhound (Firefox) · Taint tracking
Bento: Fine-Grained Memory Isolation for COTS WebAssembly Binaries
The Web Conference (WWW) 2026
The first static binary rewriter that hardens off-the-shelf WebAssembly modules: a software MMU built on Wasm multi-memory, with no new instructions and no runtime checks, stopping real exploits at 3% runtime / 1% startup overhead.
A whole-program pointer analysis splits a module’s single linear memory into stack, heap, and globals, each placed in its own isolated memory. Bento stops real exploits in libpng and pdfalto, and differential testing confirms the rewritten binaries behave the same. A compiler-pass version is in progress and will be open-sourced.
Rust · Binary rewriting · Whole-program pointer analysis · Wasm multi-memory
Waslr: Fine-Grained Memory Randomization for WebAssembly
RAID 2026
ASLR for WebAssembly: every module load gets a fresh, unpredictable memory layout, cutting the odds of a correct address guess to as low as 1 in 6.4M at 3–8% overhead, an order of magnitude below WBSan (34%) and ASan (123%).
Wasm has no virtual memory, page permissions, or kernel entropy, so exploits work the same on every machine. Waslr adds randomization inside the sandbox: a compiler pass randomizes every stack frame and a linker pass relocates static data at load time. The binary uses only standard Wasm features, so it runs unchanged in browsers and in runtimes such as Wasmtime. Against CVEs in libpng, pdfalto, and OpenSSL (Heartbleed), all 10,000 randomized exploit attempts failed.
LLVM compiler & linker passes · C++ · Wasmtime
FuzzDelSol: Fuzzing Solana Smart Contracts
ACM CCS 2023
The first binary-only, coverage-guided fuzzer for Solana smart contracts, and the largest security study of the Solana mainnet to date (6,049 contracts), finding impactful vulnerabilities with high precision and recall.
Most Solana contracts ship without source code, and their stateless execution model creates bugs that Ethereum tools miss. FuzzDelSol models the runtime faithfully and has bug oracles for every major Solana bug class.
Rust · Coverage-guided fuzzing · Solana eBPF binaries · Bug oracles
Attestation of Attacks and Complex Software
DFG CROSSING · Area S2
Taking remote attestation beyond embedded devices to microarchitectural attacks such as Rowhammer and to complex software such as WebAssembly applications and cross-chain bridges.
Includes HammerWatch (IEEE CNS 2026), which reports Rowhammer to a remote verifier; Walma, which learns to recognize memory corruption in WebAssembly; and Brigade (ACNS 2026), a Tamarin-verified defense against token losses in cross-chain bridges, evaluated on twelve real-world attacks.
Remote attestation · Rowhammer · TEEs · CNN classifiers · Tamarin proofs
Publications
My name is in bold. Full list on Google Scholar.
-
HammerWatch: Standing Watch Against Rowhammer. M. Herrmann, O. Draissi, C. Niesler, A.-R. Sadeghi, L. Davi. IEEE Conference on Communications and Network Security (CNS), 2026. · arXiv
-
Waslr: Fine-Grained Memory Randomization for WebAssembly. N. Kappert, O. Draissi, L. Davi. RAID, 2026. · Code
-
Bento: Fine-Grained Memory Isolation for COTS WebAssembly Binaries. O. Draissi, L. Davi. The Web Conference (WWW), 2026. · DOI
-
$2B Lessons: Brigade as a Defense Against Real-World DeFi Bridge Exploits. P. Winkler, J.-R. Giesen, O. Draissi, F. Badaloni, S. Holler, C. Schneidewind, L. Davi. ACNS, 2026.
-
Walma: Learning to See Memory Corruption in WebAssembly. O. Draissi, M. Günzel, A.-R. Sadeghi, L. Davi. Preprint, 2026. · arXiv
-
Wemby’s Web: Hunting for Memory Corruption in WebAssembly. O. Draissi, T. Cloosters, D. Klein, M. Rodler, M. Musch, M. Johns, L. Davi. ACM ISSTA, 2025. · DOI · Code
-
Memory Corruption at the Border of Trusted Execution. T. Cloosters, O. Draissi, J. Willbold, T. Holz, L. Davi. IEEE Security & Privacy Magazine, 22(4), 2024. · DOI
-
Fuzz on the Beach: Fuzzing Solana Smart Contracts. S. Smolka, J.-R. Giesen, P. Winkler, O. Draissi, L. Davi, G. Karame, K. Pohl. ACM CCS, 2023. · DOI
-
RiscyROP: Automated Return-Oriented Programming Attacks on RISC-V and ARM64. T. Cloosters, D. Paaßen, J. Wang, O. Draissi, P. Jauernig, E. Stapf, L. Davi, et al. RAID, 2022. · DOI
Talks
-
Bento: Fine-Grained Memory Isolation for COTS WebAssembly Binaries Slides (PDF) pptx
-
Attestation of Attacks and Complex Software Slides (PDF) pptx
-
Hunting for Memory Corruption in WebAssembly Slides (PDF) pptx
-
Introduction to IT Security (outreach lecture for teachers) Slides (PDF) pptx
CV
Experience
Research Scientist & Doctoral Candidate · Systems Security, UDE 2022–now
Memory-safety analysis and defenses for WebAssembly, trusted execution, and emerging instruction sets (see Research). Mentoring student project groups and theses.
Research Assistant · Systems Security, UDE 2019–2022
RISC-V and TEE security; wrote exploits by hand and then automatically in RiscyROP, with Ahmad-Reza Sadeghi’s group at TU Darmstadt. Co-designed the mini-CTF exploitation lab for Secure Software Systems (M.Sc.).
Student Research Assistant · Systems Security, UDE 2017–2019
One of the group’s first hires. Wrote data-only exploits with pwntools for teaching and reproduced artifacts of academic security papers.
Education
Dr.-Ing. Computer Science · University of Duisburg‑Essen 2022–2027 (expected)
M.Sc. Software and Network Engineering · University of Duisburg‑Essen 2019–2022
Master’s thesis: WaWebFuzz, a WebAssembly Fuzzer for the Web
Fuzzed WebAssembly at web scale by compiling modules to native code with wasm2c. Of 2,844,980 websites crawled, 9,526 used WebAssembly, and 34% of the analyzed modules had memory errors. The bugs were hard to exploit without the surrounding page, which led to Wemby.
WAT: WebAssembly Analysis Toolkit
To our knowledge the first binary-only Wasm fuzzer. It builds on Wasabi to generate fuzzing harnesses and crash oracles automatically, and drives them with AFL++.
DataMed: Anomaly Detection in Medical Insurance Data
A graph-analysis prototype, built with the Barmenia insurance group, that flags patterns of organized insurance fraud, a problem estimated at €4–5 billion a year in Germany.
CompatAI: Comparative Training of AI Agents
Multi-agent reinforcement learning in Pommerman and Food Collector: a hierarchical communication scheme improved performance, and cooperation correlated with winning.
B.Sc. Applied Computer Science (Systems Engineering) · University of Duisburg‑Essen 2015–2019
Bachelor’s thesis: FAILT, Automated Information-Leak Exploitation
Combined JIT-ROP and Pathfinder ideas to leak memory at runtime, recovering most of a binary’s segments under modern randomization and telling code pointers from data pointers with >90% accuracy. Key finding: extra defenses often add pointers that make leaks easier. Supervised by Michael Rodler.
Contact
Email me at oussama.draissi@protonmail.com. I’m based in Essen, Germany, and happy to talk about memory safety, fuzzing, and research or industry roles.