Subdomain-Based Generality-Aware Debloating
Qi Xin, Myeongsoo Kim, Qirun Zhang, Alessandro Orso
Abstract
Programs are becoming increasingly complex and typically contain an abundance of unneeded features, which can degrade the performance and security of the software. Recently, we have witnessed a surge of debloating techniques that aim to create a reduced version of a program by eliminating the unneeded features therein. To debloat a program, most existing techniques require a usage profile of the program, typically provided as a set of inputs 𝐼 . Unfortunately, these techniques tend to generate a reduced program that is overfitted to 𝐼 and thus fails to behave correctly for other inputs. To address this limitation, we propose DomGad, which has two main advantages over existing debloating approaches. First, it produces a reduced program that is guaranteed to work for subdomains, rather than for specific inputs. Second, it uses stochastic optimization to generate reduced programs that achieve a close-to-optimal tradeoff between reduction and generality (i.e., the extent to which the reduced program is able to correctly handle inputs in its whole domain). To assess the effectiveness of DomGad, we applied our approach to a benchmark of ten Unix utility programs. Our results are promising, as they show that DomGad could produce debloated programs that achieve, on average, 50% code reduction and 95% generality. Our results also show that DomGad performs well when compared with two state-of-the-art debloating approaches. CCS CONCEPTS • Software and its engineering → Software maintenance tools.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a7609214-0da0-43de-8b85-e44a7da0befdCited by top-tier papers4
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood et al.USENIX Security 2024 · 16 citations
- Studying and Understanding the Tradeoffs Between Generality and Reduction in Software DebloatingQi Xin, Qirun Zhang, Alessandro OrsoASE 2022 · 15 citations
- FreePart: Hardening Data Processing Software via Framework-based Partitioning and IsolationAli Ahad, Gang Wang, Chung Hwan Kim, Suman Jana et al.ASPLOS 2023 · 1 citation
- LeanBin: Harnessing Lifting and Recompilation to Debloat BinariesIgor Wodiany, Antoniu Pop, Mikel LujánASE 2024 · 1 citation
Builds on4
- Effective Program Debloating via Reinforcement LearningKihong Heo, Woosuk Lee, Pardis Pashakhanloo, Mayur NaikCCS 2018 · 175 citations
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 153 citations
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung et al.USENIX Security 2019 · 132 citations
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 100 citations
Related papers
- JShrink: in-depth investigation into debloating modern Java applicationsBobby R. Bruce, Tianyi Zhang, Jaspreet Arora, Guoqing Harry Xu et al.FSE 2020 · 46 citations
- Toward a Better Understanding of Probabilistic Delta DebuggingMengxiao Zhang, Zhenyang Xu, Yongqiang Tian, Xinru Cheng et al.ICSE 2025 · 4 citations
- Decker: Attack Surface Reduction via On-Demand Code MappingChris Porter, Sharjeel Khan, Santosh PandeASPLOS 2023 · 3 citations
- MiniMon: Minimizing Android Applications with Intelligent Monitoring-Based DebloatingJiakun Liu, Zicheng Zhang, Xing Hu, Ferdian Thung et al.ICSE 2024 · 2 citations
- Input-Driven Dynamic Program Debloating for Code-Reuse Attack MitigationXiaoke Wang, Tao Hui, Lei Zhao, Yueqiang ChengFSE 2023 · 3 citations
