USENIX Security2020Top-tier venue
DECAF: Automatic, Adaptive De-bloating and Hardening of COTS Firmware
Jake Christensen, Ionut Mugurel Anghel, Rob Taglang, Mihai Chiroiu, Radu Sion
Abstract
Once compromised, server firmware can surreptitiously and permanently take over a machine and any stack running thereon, with no hope for recovery, short of hardware-level intervention. To make things worse, modern firmware contains millions of lines of unnecessary code and hundreds of unnecessary modules as a result of a long firmware supply chain designed to optimize time-to-market and cost, but not security. As a result, off-the-shelf motherboards contain large, unnecessarily complex, closed-source vulnerability surfaces that can completely and irreversibly compromise systems. In this work, we address this problem by dramatically and automatically reducing the vulnerability surface. DECAF is an extensible platform for automatically pruning a wide class of commercial UEFI firmware. DECAF intelligently runs dynamic iterative surgery on UEFI firmware to remove a maximal amount of code with no regressive effects on the functionality and performance of higher layers in the stack (OS, applications). DECAF has successfully pruned over 70% of unnecessary, redundant, reachable firmware in leading server-grade motherboards with no effect on the upper layers, and increased resulting system performance and boot times.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e4288ba1-78ce-49ea-81a6-797e1d8fef9dCited by top-tier papers4
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood et al.USENIX Security 2024 · 16 citations
- Achieving Zen: Combining Mathematical and Programmatic Deep Learning Model Representations for Attribution and ReuseDavid Oygenblik, Dinko Dermendzhiev, Filippos Sofias, Mingxuan Yao et al.NDSS 2026 · 1 citation
- μEFI: A Microkernel-Style UEFI with Isolation and TransparencyLe Chen, Yiyang Wu, Jinyu Gu, Yubin Xia et al.USENIX ATC 2025
- SoK: All You Ever Wanted to Know About Bootloader Security but Were Afraid to AskConnor Glosner, Aravind MachiryS&P 2026
Builds on2
Related papers
- One size does not fit all: security hardening of MIPS embedded systems via static binary debloating for shared librariesHaotian Zhang, Mengfei Ren, Yu Lei, Jiang MingASPLOS 2022 · 18 citations
- UEFI Firmware Fuzzing with Simics Virtual PlatformZhenkun Yang, Yuriy Viktorov, Jin Yang, Jiewen Yao et al.DAC 2020 · 8 citations
- The Design and Implementation of a Virtual Firmware MonitorCharly Castes, François Costa, Neelu S. Kalani, Timothy Roscoe et al.SOSP 2025 · 1 citation
- Finding SMM Privilege-Escalation Vulnerabilities in UEFI Firmware with Protocol-Centric Static AnalysisJiawei Yin, Menghao Li, Wei Wu, Dandan Sun et al.S&P 2022 · 15 citations
- IRQDebloat: Reducing Driver Attack Surface in Embedded DevicesZhenghao Hu, Brendan Dolan-GavittS&P 2022 · 7 citations
