Introduces WaSC to enhance isolation in serverless applications, suggesting improved security and performance.
WebAssembly (WASM) is emerging as an alternative to containers in serverless computing due to its lightweight memory isolation and secure language semantics. However, the WASM System Interface (WASI) does not guarantee isolation from the host kernel. Secure containers reduce exposure to the host kernel API, but they do not match WASM’s memory efficiency or startup latency. In this paper, we introduce WaSC/, a secure container runtime that hardens WASM system isolation by decoupling the system interface used by sandbox functions into a virtualization-based daemon. WASM functions connect to this daemon transparently; the daemon protects the system interface with machine-level isolation while preserving function-level startup times and memory footprints. Our evaluation shows that WaSC/ achieves a 99th-percentile startup latency of 15ms and maintains a memory footprint of ∼ 10MB. Compared to Firecracker, a state-of-the-art secure container runtime, WaSC/ achieves 3 × memory density on a single physical machine. We present microbenchmarks and application benchmarks that characterize WaSC/’s performance and inform performance tuning for serverless applications ported to WaSC/. WaSC/ incurs a 3.2 × slowdown for WASI calls along the virtualization-based daemon path, and SQLite speedtest1 indicates an average 80% increase in runtime.
No takes yet. Share an insight, caveat, or question.
Yu et al. (2026) studied this question.
Synapse has enriched 4 closely related papers on similar clinical questions. Consider them for comparative context: