One size does not fit all: security hardening of MIPS embedded systems via static binary debloating for shared libraries
Haotian Zhang, Mengfei Ren, Yu Lei, Jiang Ming
Abstract
Embedded systems have become prominent targets for cyberattacks. To exploit firmware’s memory corruption vulnerabilities, cybercriminals harvest reusable code gadgets from the large shared library codebase (e.g., uClibc). Unfortunately, unlike their desktop counterparts, embedded systems lack essential computing resources to enforce security hardening techniques. Recently, we have witnessed a surge of software debloating as a new defense mechanism against code-reuse attacks; it erases unused code to significantly diminish the possibilities of constructing reusable gadgets. Because of the single firmware image update style, static library debloating shows promise to fortify embedded systems without compromising performance and forward compatibility. However, static library debloating on stripped binaries (e.g., firmware’s shared libraries) is still an enormous challenge. In this paper, we show that this challenge is not insurmountable for MIPS firmware. We develop a novel system, named uTrimmer, to identify and wipe out unused basic blocks from shared libraries’ binary code, without causing additional runtime overhead or memory consumption. We propose a new method to identify address-taken blocks/functions, which further help us maintain an inter-procedural control flow graph to conservatively include library code that could be potentially used by firmware. By capturing address access patterns for position-independent code, we circumvent the challenge of determining code-pointer targets and safely eliminate unused code. We run uTrimmer to debloat shared libraries for SPEC CPU2017 benchmarks, popular firmware applications (e.g., Apache, BusyBox, and OpenSSL), and a real-world wireless router firmware image. Our experiments show that not only does uTrimmer deliver functional programs, but also it can cut the exposed code surface and eliminate various reusable code gadgets remarkably. uTrimmer’s debloating capability can compete with the static linking results.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 980371c6-3a7f-4331-9f43-407456bba38aCited by top-tier papers7
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood et al.USENIX Security 2024 · 16 citations
- Input-Driven Dynamic Program Debloating for Code-Reuse Attack MitigationXiaoke Wang, Tao Hui, Lei Zhao, Yueqiang ChengFSE 2023 · 3 citations
- LeanBin: Harnessing Lifting and Recompilation to Debloat BinariesIgor Wodiany, Antoniu Pop, Mikel LujánASE 2024 · 1 citation
- Bond: Constraint-Directed Fuzzing for Automated Validation of Taint Analysis Results in Linux-based IoT FirmwareJiaqian Peng, Puzhuo Liu, Kai Cheng, Zhaoteng Yan et al.USENIX Security 2026
- MemoryTrap: Booby Trapping Memory to Counter Memory Disclosure Attacks with Hardware SupportChenke Luo, Jiang Ming, Dongpeng Xu, Guojun Peng et al.USENIX ATC 2025
Related papers
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 153 citations
- Decker: Attack Surface Reduction via On-Demand Code MappingChris Porter, Sharjeel Khan, Santosh PandeASPLOS 2023 · 3 citations
- IRQDebloat: Reducing Driver Attack Surface in Embedded DevicesZhenghao Hu, Brendan Dolan-GavittS&P 2022 · 7 citations
- DECAF: Automatic, Adaptive De-bloating and Hardening of COTS FirmwareJake Christensen, Ionut Mugurel Anghel, Rob Taglang, Mihai Chiroiu et al.USENIX Security 2020
- Building Embedded Systems Like It's 1996Ruotong Yu, Francesca Del Nin, Yuchen Zhang, Shan Huang et al.NDSS 2022
