USENIX Security2018Top-tier venue
Debloating Software through Piece-Wise Compilation and Loading
Anh Quach, Aravind Prakash, Lok-Kwong Yan
Abstract
Programs are bloated. Our study shows that only 5% of libc is used on average across Ubuntu Desktop environment (>2200 programs); the heaviest user, vlc media player, only used 18%. This is striking because bloating presents a vulnerable attack surface for software exploitation and imposes undue burden on defenses (e.g., CFI defenses). In this paper: (1) We present a debloating framework built on a compiler toolchain that can successfully debloat software (shared/static libraries and executables). Our solution can successfully compile and load most libraries on Ubuntu Desktop 16.04. (2) We demonstrate an elimination of over 84% code from coreutils and 85% code from SPEC CPU 2006 benchmark programs without affecting functionality. We show that even complex COTS programs (e.g., FireFox, Curl) can be debloated without a need to recompile. (3) We demonstrate the security impact of our system by eliminating over 70% of reusable code gadgets from coreutils suite, and show that unused code that contain real-world vulnerabilities can be successfully eliminated without adverse effects on the program. (4) Our solution imposes a low load time overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d6f58e20-65be-476a-aa20-50ba6f41c049Cited by top-tier papers36
- Effective Program Debloating via Reinforcement LearningKihong Heo, Woosuk Lee, Pardis Pashakhanloo, Mayur NaikCCS 2018 · 175 citations
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung et al.USENIX Security 2019 · 132 citations
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 100 citations
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 97 citations
- A Linux in unikernel clothingHsuan-Chi Kuo, Dan Williams, Ricardo Koller, Sibin MohanEuroSys 2020 · 57 citations
Builds on1
Related papers
- One size does not fit all: security hardening of MIPS embedded systems via static binary debloating for shared librariesHaotian Zhang, Mengfei Ren, Yu Lei, Jiang MingASPLOS 2022 · 18 citations
- Minimalist: Semi-automated Debloating of PHP Web Applications through Static AnalysisRasoul Jahanshahi, Babak Amin Azad, Nick Nikiforakis, Manuel EgeleUSENIX Security 2023
- LeanBin: Harnessing Lifting and Recompilation to Debloat BinariesIgor Wodiany, Antoniu Pop, Mikel LujánASE 2024 · 1 citation
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood et al.USENIX Security 2024 · 16 citations
- Subdomain-Based Generality-Aware DebloatingQi Xin, Myeongsoo Kim, Qirun Zhang, Alessandro OrsoASE 2020 · 8 citations
