Program debloating via stochastic optimization

Program debloating via stochastic optimization
复制标题

通过随机优化进行程序膨胀

DOI:
10.1145/3377816.3381739
复制
发表时间:
2020
期刊:
Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering: New Ideas and Emerging Results
影响因子:
--
通讯作者:
Orso, Alessandro
Orso, Alessandro
中科院分区:
--
文献类型:
--
作者:
Xin, Qi;Kim, Myeongsoo;Zhang, Qirun;Orso, Alessandro

文献摘要

相似文献

程序通常提供广泛的功能。由于不同类型的用户倾向于仅使用这些功能的子集,并且不必要的功能可能会损害性能和安全性,因此程序缩减技术(可以通过消除(可能)不需要的功能来减小程序的大小)变得越来越流行。大多数现有的去膨胀技术往往只关注程序大小的减小,尽管有效,但忽略了去膨胀的其他重要方面。我们认为,程序膨胀是一个多方面的问题,必须以更普遍的方式解决。本着这种精神,我们提出了一种通用方法,允许将程序去膨胀制定为多目标优化问题。给定一个要去膨胀的程序,我们的方法允许用户指定(1)程序的使用概况(即一组具有相关使用概率的输入),(2)去膨胀感兴趣的因素,以及(3)这些因素的相对重要性。基于此信息,该方法定义了一个合适的目标函数,用于将分数与每个可能的简化程序相关联,并旨在生成最大化目标函数的最佳解决方案。我们还介绍并评估了 Debop,这是我们方法的一个具体实例,它考虑了三个目标:减小规模、减小攻击面和通用性(即,简化的程序处理所提供的使用配置文件中的输入的程度)。我们的结果虽然仍处于初步阶段,但很有希望,并表明我们的方法可以有效地生成去膨胀程序,从而在所考虑的不同去膨胀目标之间实现良好的权衡。与专门的单目标技术相比,我们的结果还提供了对我们的通用方法的性能的见解。
Programs typically provide a broad range of features. Because different typologies of users tend to use only a subset of these features, and unnecessary features can harm performance and security, program debloating techniques, which can reduce the size of a program by eliminating (possibly) unneeded features, are becoming increasingly popular. Most existing debloating techniques tend to focus on program-size reduction alone and, although effective, ignore other important aspects of debloating. We believe that program debloating is a multifaceted problem that must be addressed in a more general way. In this spirit,we propose a general approach that allows for formulating program debloating as a multi-objective optimization problem.Given a program to be debloated, our approach lets users specify (1) a usage profile for the program (i.e., a set of inputs with associated usage probabilities), (2) the factors of interest for debloating, and (3) the relative importance of these factors. Based on this information, the approach defines a suitable objective function for associating a score to every possible reduced program and aims to generate an optimal solution that maximizes the objective function. We also present and evaluate Debop, a specific instance of our approach that considers three objectives: size reduction, attack-surface reduction, and generality (i.e., the extent to which the reduced program handles inputs in the usage profile provided). Our results, albeit still preliminary, are promising and show that our approach can be effective at generating debloated programs that achieve a good trade-off between the different de-bloating objectives considered. Our results also provide insights on the performance of our general approach when compared to a specialized single-goal technique.