Decker: Attack Surface Reduction via On-Demand Code Mapping
Chris Porter, Sharjeel Khan, Santosh Pande
摘要
Modern code reuse attacks take full advantage of bloated software. Attackers piece together short sequences of instructions in otherwise benign code to carry out malicious actions. Mitigating these reusable code snippets, known as gadgets, has become one of the prime focuses of attack surface reduction research. While some debloating techniques remove parts of software that contain such gadgets, other methods focus on making them unusable by breaking up chains of them, thereby substantially diminishing the possibility of code reuse attacks. Third-party libraries are another main focus, because they exhibit a high number of vulnerabilities, but recently, techniques have emerged that deal with whole applications. Attack surface reduction efforts have typically tried to eliminate such attacks by subsetting (debloating) the application, e.g. via user-specified inputs, configurations, or features to achieve high gadget reductions. However, such techniques suffer from the limitations of soundness, i.e. the software might crash during no-attack executions on regular inputs, or they may be conservative and leave a large amount of attack surface untackled.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- One size does not fit all: security hardening of MIPS embedded systems via static binary debloating for shared librariesHaotian Zhang, Mengfei Ren, Yu Lei, Jiang MingASPLOS 2022 · 被引用 18 次
- BlankIt library debloating: getting what you want instead of cutting what you don'tChris Porter, Girish Mururu, Prithayan Barua, Santosh PandePLDI 2020 · 被引用 31 次
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 被引用 100 次
- Input-Driven Dynamic Program Debloating for Code-Reuse Attack MitigationXiaoke Wang, Tao Hui, Lei Zhao, Yueqiang ChengFSE 2023 · 被引用 3 次
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 被引用 153 次
