USENIX Security2023Top-tier venue
Minimalist: Semi-automated Debloating of PHP Web Applications through Static Analysis
Rasoul Jahanshahi, Babak Amin Azad, Nick Nikiforakis, Manuel Egele
Abstract
As web applications grow more complicated and rely on third-party libraries to deliver new features to their users, they become bloated with unnecessary code. This unnecessary code increases a web application's attack surface, which can be exploited to steal user data and compromise the underlying web server. One approach to deal with bloated code is the process of selectively removing features that users do not require -debloating. In this paper, we identify the current challenges with debloating web applications and propose a semi-automated static debloating scheme. We implement a prototype of our proposed method, called Minimalist that generates a call-graph for a given PHP web application. Minimalist performs a reachability analysis for the features users require and removes unreachable functions in the analyzed web application. Compared to prior work, Minimalist debloats web applications without relying on heavy runtime instrumentation. Furthermore, the call-graph generated by Minimalist can be reused (in combination with web server logs) to debloat different installations of the same web application. Due to the inherent complexity and highly dynamic nature of the PHP language, Minimalist cannot guarantee the soundness of its call-graph analysis. However, Minimalist follows a best-effort approach to model the majority of PHP features used by popular web applications, such as WordPress, phpMyAdmin, and others. We evaluated Minimalist on 12 versions of four popular PHP web applications with 45 recent security vulnerabilities. We show that Minimalist reduces the size of web applications in our dataset on average by 18% and removes 38% of known vulnerabilities. Our results demonstrate that the principled debloating of web applications can lead to significant security gains without relying on instrumentation mechanisms that degrade the performance of the server.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f26e20d4-dcc5-4d32-8a92-80ace39bd494Cited by top-tier papers5
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood et al.USENIX Security 2024 · 16 citations
- CoinDef: A Comprehensive Code Injection Defense for the Electron FrameworkZheng Yang, Simon P. Chung, Jizhou Chen, Runze Zhang et al.S&P 2025
- QUACK: Hindering Deserialization Attacks via Static Duck TypingYaniv David, Neophytos Christou, Andreas D. Kellas, Vasileios P. Kemerlis et al.NDSS 2024
- Fuzzing the PHP Interpreter via Dataflow FusionYuancheng Jiang, Chuqi Zhang, Bonan Ruan, Jiahao Liu et al.USENIX Security 2025
- PyXray: Practical Cross-Language Call Graph Construction through Object Layout AnalysisGeorgios Alexopoulos, Thodoris Sotiropoulos, Georgios Gousios, Zhendong Su et al.ICSE 2026
Builds on8
- Effective Program Debloating via Reinforcement LearningKihong Heo, Woosuk Lee, Pardis Pashakhanloo, Mayur NaikCCS 2018 · 175 citations
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 153 citations
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 100 citations
- Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser SecurityPeter Snyder, Cynthia Bagier Taylor, Chris KanichCCS 2017 · 75 citations
- SHARD: Fine-Grained Kernel Specialization with Context-Aware HardeningMuhammad Abubakar, Adil Ahmad, Pedro Fonseca, Dongyan XuUSENIX Security 2021 · 47 citations
Related papers
- AnimateDead: Debloating Web Applications Using Concolic ExecutionBabak Amin Azad, Rasoul Jahanshahi, Chris Tsoukaladelis, Manuel Egele et al.USENIX Security 2023
- Slimium: Debloating the Chromium Browser with Feature SubsettingChenxiong Qian, Hyungjoon Koo, ChangSeok Oh, Taesoo Kim et al.CCS 2020 · 35 citations
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung et al.USENIX Security 2019 · 132 citations
- MiniMon: Minimizing Android Applications with Intelligent Monitoring-Based DebloatingJiakun Liu, Zicheng Zhang, Xing Hu, Ferdian Thung et al.ICSE 2024 · 2 citations
- JShrink: in-depth investigation into debloating modern Java applicationsBobby R. Bruce, Tianyi Zhang, Jaspreet Arora, Guoqing Harry Xu et al.FSE 2020 · 46 citations
