Configuration-Driven Software Debloating

Configuration-Driven Software Debloating
复制标题

配置驱动的软件膨胀

DOI:
10.1145/3301417.3312501
复制
发表时间:
2019
期刊:
Proceedings of the 12th European Workshop on System Security (EuroSec
影响因子:
--
通讯作者:
Polychronakis, Michalis
Polychronakis, Michalis
中科院分区:
--
文献类型:
--
作者:
Koo, Hyungjoon;Ghavamnia, Seyedhamed;Polychronakis, Michalis

文献摘要

参考文献

被引文献

相似文献

由于代码重用攻击的激增,合法代码成为攻击面,软件膨胀是一种有效的缓解措施,除了消除已删除代码中潜在的可利用错误之外,还可以减少可能对攻击者有用的指令序列的数量。现有的反膨胀方法要么静态地删除保证不会运行的代码(例如,来自共享库的非导入函数),要么依赖于实际工作负载的分析来查明并仅保留已执行的代码子集。在这项工作中,我们探索了另一种配置驱动的软件反膨胀方法,该方法删除仅在指定某些配置指令时才需要的特定于功能的代码——这通常是 默认禁用。使用半自动化方法,我们的技术识别仅用于实现特定功能所需的库,并将它们映射到某些配置指令。根据此映射,如果禁用了相应的指令,则根本不会加载特定于功能的库。我们对 Nginx、VSFTPD 和 OpenSSH 的实验评估结果表明,在每种情况下使用默认配置,配置驱动的 debloating 可以删除 Nginx 77% 的代码、VSFTPD 53% 和 OpenSSH 20% 的代码,这意味着攻击面显着减少。
With legitimate code becoming an attack surface due to the proliferation of code reuse attacks, software debloating is an effective mitigation that reduces the amount of instruction sequences that may be useful for an attacker, in addition to eliminating potentially exploitable bugs in the removed code. Existing debloating approaches either statically remove code that is guaranteed to not run (e.g., non-imported functions from shared libraries), or rely on profiling with realistic workloads to pinpoint and keep only the subset of code that was executed.In this work, we explore an alternative configuration-driven software debloating approach that removes feature-specific code that is exclusively needed only when certain configuration directives are specified---which are often disabled by default. Using a semi-automated approach, our technique identifies libraries solely needed for the implementation of a particular functionality and maps them to certain configuration directives. Based on this mapping, feature-specific libraries are not loaded at all if their corresponding directives are disabled. The results of our experimental evaluation with Nginx, VSFTPD, and OpenSSH show that using the default configuration in each case, configuration-driven debloating can remove 77% of the code for Nginx, 53% for VSFTPD, and 20% for OpenSSH, which represent a significant attack surface reduction.
DamGate:程序二进制文件中的动态自适应多功能门控
DOI: 10.1145/3141235.3141243
发表时间: 2017
期刊: Proceedings of the 2017 Workshop on Forming an Ecosystem Around Software Transformation
影响因子: --
作者:
Yurong Chen;Tian Lan;Guru Venkataramani
通讯作者: Guru Venkataramani
DOI: 10.1145/3106237.3106271
发表时间: 2017-08
期刊: Proceedings of the 2017 11th Joint Meeting on Foundations of Software Engineering
影响因子: --
作者:
Vaibhav Rastogi;Drew Davidson;Lorenzo De Carli;S. Jha;P. Mcdaniel
通讯作者: Vaibhav Rastogi;Drew Davidson;Lorenzo De Carli;S. Jha;P. Mcdaniel
DOI: 10.1145/1315245.1315313
发表时间: 2007-10
期刊: --
影响因子: --
作者:
H. Shacham
通讯作者: H. Shacham
TOSS:通过二进制特征定制来定制在线服务器系统
DOI: 10.1145/3273045.3273048
发表时间: 2018
期刊: Proceedings of the 2018 Workshop on Forming an Ecosystem Around Software Transformation
影响因子: --
作者:
Yurong Chen;Shaowen Sun;Tian Lan;Guru Venkataramani
通讯作者: Guru Venkataramani
基于特征的软件定制:初步分析、形式化和方法
DOI: 10.1109/hase.2016.27
发表时间: 2016
期刊: 2016 IEEE 17th International Symposium on High Assurance Systems Engineering (HASE)
影响因子: --
作者:
Yufei Jiang;Can Zhang;Dinghao Wu;Peng Liu
通讯作者: Peng Liu