Kondo: Efficient Provenance-Driven Data Debloating
Aniket Modi, Rohan Tikmany, Tanu Malik, Raghavan Komondoor, Ashish Gehani, Deepak D'Souza
摘要
Isolation increases upfront costs of provisioning containers. This is due to unnecessary software and data in container images. While several static and dynamic analysis methods for pruning unnecessary software are known, less attention has been paid to pruning unnecessary data. In this paper, we address the problem of determining and reducing unused data within a containerized application. Current data lineage methods can be used to detect data files that are never accessed in any of the observed runs, but this leads to a pessimistic amount of debloating. It is our observation that while an application may access a data file, it often accesses only a small portion of it over all its runs. Based on this observation, we present an approach and a tool Kondo, which aims to identify the set of all possible offsets that could be accessed within the data files over all executions of the application. Kondo works by fuzzing the parameter inputs to the application, and running it on the fuzzed inputs, with vastly fewer runs than brute force execution over all possible parameter valuations. Our evaluation on realistic benchmarks shows that Kondo is able to achieve 63% reduction in data file sizes and 98% recall against the set of all required offsets, on average.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper2
相关 Paper
- A Container-Usage-Pattern-Based Context Debloating Approach for Object-Sensitive Pointer AnalysisDongjie He, Yujiang Gui, Wei Li, Yonggang Tao 等OOPSLA 2023 · 被引用 9 次
- FlacIO: Flat and Collective I/O for Container Image ServiceYubo Liu, Hongbo Li, Mingrui Liu, Rui Jing 等FAST 2025 · 被引用 7 次
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood 等USENIX Security 2024 · 被引用 16 次
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 被引用 153 次
- Modus: a Datalog dialect for building container imagesChris Tomy, Tingmao Wang, Earl T. Barr, Sergey MechtaevFSE 2022 · 被引用 3 次
