BlankIt library debloating: getting what you want instead of cutting what you don't
Chris Porter, Girish Mururu, Prithayan Barua, Santosh Pande
Abstract
Modern software systems make extensive use of libraries derived from C and C++. Because of the lack of memory safety in these languages, however, the libraries may suffer from vulnerabilities, which can expose the applications to potential attacks. For example, a very large number of return-oriented programming gadgets exist in glibc that allow stitching together semantically valid but malicious Turing-complete and -incomplete programs. While CVEs get discovered and often patched and remedied, such gadgets serve as building blocks of future undiscovered attacks, opening an ever-growing set of possibilities for generating malicious programs. Thus, significant reduction in the quantity and expressiveness (utility) of such gadgets for libraries is an important problem.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 76d350da-b0b0-4384-a03e-f94606eda9cdCited by top-tier papers15
- Slimium: Debloating the Chromium Browser with Feature SubsettingChenxiong Qian, Hyungjoon Koo, ChangSeok Oh, Taesoo Kim et al.CCS 2020 · 35 citations
- C2C: Fine-grained Configuration-driven System Call FilteringSeyedhamed Ghavamnia, Tapti Palit, Michalis PolychronakisCCS 2022 · 22 citations
- Logical bytecode reductionChristian Gram Kalhauge, Jens PalsbergPLDI 2021 · 16 citations
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood et al.USENIX Security 2024 · 16 citations
- Studying and Understanding the Tradeoffs Between Generality and Reduction in Software DebloatingQi Xin, Qirun Zhang, Alessandro OrsoASE 2022 · 15 citations
Related papers
- Decker: Attack Surface Reduction via On-Demand Code MappingChris Porter, Sharjeel Khan, Santosh PandeASPLOS 2023 · 3 citations
- Not so fast: understanding and mitigating negative impacts of compiler optimizations on code reuse gadget setsMichael D. Brown, Matthew Pruett, Robert Bigelow, Girish Mururu et al.OOPSLA 2021 · 11 citations
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- ropbot: Reimaging Code Reuse Attack SynthesisKyle Zeng, Moritz Schloegel, Christopher Salls, Adam Doupé et al.NDSS 2026 · 1 citation
- Robust Constant-Time CryptographyMatthew Kolosick, Basavesh Ammanaghatta Shivakumar, Sunjay Cauligi, Marco Patrignani et al.PLDI 2025 · 1 citation
