Nibbler: debloating binary shared libraries

Nibbler: debloating binary shared libraries
复制标题

DOI:
10.1145/3359789.3359823
复制
发表时间:
2019-12
期刊:
Proceedings of the 35th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Ioannis Agadakos;Di Jin;David Williams-King;V. Kemerlis;G. Portokalidis
Ioannis Agadakos;Di Jin;David Williams-King;V. Kemerlis;G. Portokalidis
中科院分区:
其他
文献类型:
--
作者:
Ioannis Agadakos;Di Jin;David Williams-King;V. Kemerlis;G. Portokalidis

文献摘要

被引文献

相似文献

当今,开发人员可以使用工具包和库的武器库来快速应用程序。但是,当应用程序加载库时,即使实际上只需要一个函数,该库代码的整个代码都会映射到地址空间中。未使用的部分是膨胀的,可能会通过不必要地夸大其开销或增加攻击表面而对软件防御产生负面影响。最近的工作探索了源代码,以减轻上述问题的一种方式。在本文中,我们研究了在二进制层面上是否有可能且实用的。为此,我们提出了nibbler:标识和删除共享库中未使用的功能的系统。 Nibbler与连续代码重新随机化和控制流的完整性等防御措施同时起作用,从而增强它们而不会产生额外的运行时间开销。我们在X86-64 Linux上开发并测试了Nibbler的原型。 Nibbler将共享库的大小和可用功能的数量减少,对于现实世界中的二进制文件和Spec Cint2006 Suite,分别降低了高达56%和82%。我们还证明了nibbler通过证明:(i)提高二进制文件的连续重新随机化系统的可部署性,即Shuffler,将其效率提高20%,并且(ii)它可以快速提高,但它很快,但很粗糙通过减少可通过回报和间接呼叫的呼叫来降低75%和49%的小工具的数量来减少上下文不敏感的控制流的完整性方案。
Developers today have access to an arsenal of toolkits and libraries for rapid application prototyping. However, when an application loads a library, the entirety of that library's code is mapped into the address space, even if only a single function is actually needed. The unused portion is bloat that can negatively impact software defenses by unnecessarily inflating their overhead or increasing their attack surface. Recent work has explored debloating as a way of alleviating the above problems, when source code is available. In this paper, we investigate whether debloating is possible and practical at the binary level. To this end, we present Nibbler: a system that identifies and erases unused functions within shared libraries. Nibbler works in tandem with defenses like continuous code re-randomization and control-flow integrity, enhancing them without incurring additional run-time overhead. We developed and tested a prototype of Nibbler on x86-64 Linux; Nibbler reduces the size of shared libraries and the number of available functions, for real-world binaries and the SPEC CINT2006 suite, by up to 56% and 82%, respectively. We also demonstrate that Nibbler benefits defenses by showing that: (i) it improves the deployability of a continuous re-randomization system for binaries, namely Shuffler, by increasing its efficiency by 20%, and (ii) it improves certain fast, but coarse and context-insensitive control-flow integrity schemes by reducing the number of gadgets reachable through returns and indirect calls by 75% and 49% on average.