DECAF: Automatic, Adaptive De-bloating and Hardening of COTS Firmware
Jake Christensen, Ionut Mugurel Anghel, Rob Taglang, Mihai Chiroiu, Radu Sion
摘要
Once compromised, server firmware can surreptitiously and permanently take over a machine and any stack running thereon, with no hope for recovery, short of hardware-level intervention. To make things worse, modern firmware contains millions of lines of unnecessary code and hundreds of unnecessary modules as a result of a long firmware supply chain designed to optimize time-to-market and cost, but not security. As a result, off-the-shelf motherboards contain large, unnecessarily complex, closed-source vulnerability surfaces that can completely and irreversibly compromise systems. In this work, we address this problem by dramatically and automatically reducing the vulnerability surface. DECAF is an extensible platform for automatically pruning a wide class of commercial UEFI firmware. DECAF intelligently runs dynamic iterative surgery on UEFI firmware to remove a maximal amount of code with no regressive effects on the functionality and performance of higher layers in the stack (OS, applications). DECAF has successfully pruned over 70% of unnecessary, redundant, reachable firmware in leading server-grade motherboards with no effect on the upper layers, and increased resulting system performance and boot times.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- A Broad Comparative Evaluation of Software Debloating ToolsMichael D. Brown, Adam Meily, Brian Fairservice, Akshay Sood 等USENIX Security 2024 · 被引用 16 次
- Achieving Zen: Combining Mathematical and Programmatic Deep Learning Model Representations for Attribution and ReuseDavid Oygenblik, Dinko Dermendzhiev, Filippos Sofias, Mingxuan Yao 等NDSS 2026 · 被引用 1 次
- μEFI: A Microkernel-Style UEFI with Isolation and TransparencyLe Chen, Yiyang Wu, Jinyu Gu, Yubin Xia 等USENIX ATC 2025
- SoK: All You Ever Wanted to Know About Bootloader Security but Were Afraid to AskConnor Glosner, Aravind MachiryS&P 2026
它引用的顶会 Paper2
相关 Paper
- One size does not fit all: security hardening of MIPS embedded systems via static binary debloating for shared librariesHaotian Zhang, Mengfei Ren, Yu Lei, Jiang MingASPLOS 2022 · 被引用 18 次
- UEFI Firmware Fuzzing with Simics Virtual PlatformZhenkun Yang, Yuriy Viktorov, Jin Yang, Jiewen Yao 等DAC 2020 · 被引用 8 次
- The Design and Implementation of a Virtual Firmware MonitorCharly Castes, François Costa, Neelu S. Kalani, Timothy Roscoe 等SOSP 2025 · 被引用 1 次
- Finding SMM Privilege-Escalation Vulnerabilities in UEFI Firmware with Protocol-Centric Static AnalysisJiawei Yin, Menghao Li, Wei Wu, Dandan Sun 等S&P 2022 · 被引用 15 次
- IRQDebloat: Reducing Driver Attack Surface in Embedded DevicesZhenghao Hu, Brendan Dolan-GavittS&P 2022 · 被引用 7 次
