Less is More: Quantifying the Security Benefits of Debloating Web Applications

Less is More: Quantifying the Security Benefits of Debloating Web Applications
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Babak Amin Azad;Pierre Laperdrix;Nick Nikiforakis
Babak Amin Azad;Pierre Laperdrix;Nick Nikiforakis
中科院分区:
其他
文献类型:
--
作者:
Babak Amin Azad;Pierre Laperdrix;Nick Nikiforakis

文献摘要

被引文献

相似文献

随着软件变得越来越复杂,其攻击面不断扩大,从而可以利用各种漏洞。 Web 应用程序也不例外,因为现代 HTML5 标准和 JavaScript 不断增强的功能被用来构建丰富的 Web 应用程序,通常包含对传统桌面应用程序的需求。处理这种增加的复杂性的一种可能方法是通过软件去膨胀过程,即不仅删除死代码,而且删除与一组特定用户不需要的功能相对应的代码。尽管 debloating 已成功应用于操作系统、库和编译程序,但其在 Web 应用程序上的适用性尚未得到研究。在本文中,我们首次分析了 debloating Web 应用程序的安全优势。我们重点关注四个流行的 PHP 应用程序,并动态地运用它们来获取有关由于客户端请求而执行的服务器端代码的信息。我们评估了两种不同的 debloating 策略(文件级 debloating 和函数级 debloating),并且证明我们可以生成比原始版本小 46% 的功能性 Web 应用程序,并且表现出原始圈复杂度的一半。此外,我们的结果表明,膨胀过程删除了与数十个历史漏洞相关的代码,并通过删除不必要的外部包和可滥用的 PHP 小工具进一步缩小了 Web 应用程序的攻击面。
As software becomes increasingly complex, its attack surface expands enabling the exploitation of a wide range of vulnerabilities. Web applications are no exception since modern HTML5 standards and the ever-increasing capabilities of JavaScript are utilized to build rich web applications, often subsuming the need for traditional desktop applications. One possible way of handling this increased complexity is through the process of software debloating, i.e., the removal not only of dead code but also of code corresponding to features that a specific set of users do not require. Even though debloating has been successfully applied on operating systems, libraries, and compiled programs, its applicability on web applications has not yet been investigated. In this paper, we present the first analysis of the security benefits of debloating web applications. We focus on four popular PHP applications and we dynamically exercise them to obtain information about the server-side code that executes as a result of client-side requests. We evaluate two different debloating strategies (file-level debloating and function-level debloating) and we show that we can produce functional web applications that are 46% smaller than their original versions and exhibit half their original cyclomatic complexity. Moreover, our results show that the process of debloating removes code associated with tens of historical vulnerabilities and further shrinks a web application’s attack surface by removing unnecessary external packages and abusable PHP gadgets.