Slimium: Debloating the Chromium Browser with Feature Subsetting
Chenxiong Qian, Hyungjoon Koo, ChangSeok Oh, Taesoo Kim, Wenke Lee
摘要
Today, a web browser plays a crucial role in offering a broad spectrum of web experiences. The most popular browser, Chromium, has become an extremely complex application to meet ever-increasing user demands, exposing unavoidably large attack vectors due to its large code base. Code debloating attracts attention as a means of reducing such a potential attack surface by eliminating unused code. However, it is very challenging to perform sophisticated code removal without breaking needed functionalities because Chromium operates on a large number of closely connected and complex components, such as a renderer and JavaScript engine. In this paper, we present Slimium, a debloating framework for a browser (i.e., Chromium) that harnesses a hybrid approach for a fast and reliable binary instrumentation. The main idea behind Slimium is to determine a set of features as a debloating unit on top of a hybrid (i.e., static, dynamic, heuristic) analysis, and then leverage feature subsetting to code debloating. It aids in i) focusing on security-oriented features, ii) discarding unneeded code simply without complications, and iii) reasonably addressing a non-deterministic path problem raised from code complexity. To this end, we generate a feature-code map with a relation vector technique and prompt webpage profiling results. Our experimental results demonstrate the practicality and feasibility of Slimium for 40 popular websites, as on average it removes 94 CVEs (61.4%) by cutting down 23.85 MB code (53.1%) from defined features (21.7% of the whole) in Chromium.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- A longitudinal analysis of bloated Java dependenciesCésar Soto-Valero, Thomas Durieux, Benoit BaudryFSE 2021 · 被引用 47 次
- C2C: Fine-grained Configuration-driven System Call FilteringSeyedhamed Ghavamnia, Tapti Palit, Michalis PolychronakisCCS 2022 · 被引用 22 次
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood 等USENIX Security 2024 · 被引用 16 次
- Studying and Understanding the Tradeoffs Between Generality and Reduction in Software DebloatingQi Xin, Qirun Zhang, Alessandro OrsoASE 2022 · 被引用 15 次
- Input-Driven Dynamic Program Debloating for Code-Reuse Attack MitigationXiaoke Wang, Tao Hui, Lei Zhao, Yueqiang ChengFSE 2023 · 被引用 3 次
它引用的顶会 Paper9
- Effective Program Debloating via Reinforcement LearningKihong Heo, Woosuk Lee, Pardis Pashakhanloo, Mayur NaikCCS 2018 · 被引用 175 次
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 被引用 153 次
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung 等USENIX Security 2019 · 被引用 132 次
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 被引用 100 次
- Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser SecurityPeter Snyder, Cynthia Bagier Taylor, Chris KanichCCS 2017 · 被引用 75 次
相关 Paper
- Minimalist: Semi-automated Debloating of PHP Web Applications through Static AnalysisRasoul Jahanshahi, Babak Amin Azad, Nick Nikiforakis, Manuel EgeleUSENIX Security 2023
- AnimateDead: Debloating Web Applications Using Concolic ExecutionBabak Amin Azad, Rasoul Jahanshahi, Chris Tsoukaladelis, Manuel Egele 等USENIX Security 2023
- JShrink: in-depth investigation into debloating modern Java applicationsBobby R. Bruce, Tianyi Zhang, Jaspreet Arora, Guoqing Harry Xu 等FSE 2020 · 被引用 46 次
- Mystique: Uncovering Information Leakage from Browser ExtensionsQuan Chen, Alexandros KapravelosCCS 2018 · 被引用 88 次
- LIGHTBLUE: Automatic Profile-Aware Debloating of Bluetooth StacksJianliang Wu, Ruoyu Wu, Daniele Antonioli, Mathias Payer 等USENIX Security 2021 · 被引用 38 次
