JS']JShrink: In-Depth Investigation into Debloating Modern Java']Java Applications

被引:28
|
作者
Bruce, Bobby R. [1 ]
Zhang, Tianyi [2 ]
Arora, Jaspreet [3 ]
Xu, Guoqing Harry [3 ]
Kim, Miryung [3 ]
机构
[1] Univ Calif Davis, Davis, CA 95616 USA
[2] Harvard Univ, Cambridge, MA 02138 USA
[3] Univ Calif Los Angeles, Los Angeles, CA 90024 USA
来源
PROCEEDINGS OF THE 28TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING (ESEC/FSE '20) | 2020年
关键词
!text type='Java']Java[!/text] bytecode; size reduction; reachability analysis; debloating;
D O I
10.1145/3368089.3409738
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Modern software is bloated. Demand for new functionality has led developers to include more and more features, many of which become unneeded or unused as software evolves. This phenomenon, known as software bloat, results in software consuming more resources than it otherwise needs to. How to effectively and automatically debloat software is a long-standing problem in software engineering. Various debloating techniques have been proposed since the late 1990s. However, many of these techniques are built upon pure static analysis and have yet to be extended and evaluated in the context of modern Java applications where dynamic language features are prevalent. To this end, we develop an end-to-end bytecode debloating framework called JSHRINK. It augments traditional static reachability analysis with dynamic profiling and type dependency analysis and renovates existing bytecode transformations to account for new language features in modern Java. We highlight several nuanced technical challenges that must be handled properly and examine behavior preservation of debloated software via regression testing. We find that (1) JSHRINK is able to debloat our real-world Java benchmark suite by up to 47% (14% on average); (2) accounting for dynamic language features is indeed crucial to ensure behavior preservation-reducing 98% of test failures incurred by a purely static equivalent, Jax, and 84% for ProGuard; and (3) compared with purely dynamic approaches, integrating static analysis with dynamic profiling makes the debloated software more robust to unseen test executions-in 22 out of 26 projects, the debloated software ran successfully under new tests.
引用
收藏
页码:135 / 146
页数:12
相关论文
共 32 条
  • [1] WebJS']JShrink: A Web Service for Debloating Java']Java Bytecode
    Macias, Konner
    Mathur, Mihir
    Bruce, Bobby R.
    Zhang, Tianyi
    Kim, Miryung
    PROCEEDINGS OF THE 28TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING (ESEC/FSE '20), 2020, : 1665 - 1669
  • [2] An in-depth JAVA']JAVA Teaching Exploration into the Software Engineering Curriculum
    Xu, Qing-Wei
    PROCEEDINGS OF THE 2015 3D INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION AND COMMUNICATION TECHNOLOGY FOR EDUCATION, 2015, 11 : 204 - 206
  • [3] EJS']JS: An authoring tool to develop Java']Java applications
    Esquembre, F
    Zamarro, JM
    COMPUTERS AND EDUCATION: TOWARDS AN INTERCONNECTED SOCIETY, 2001, : 143 - 148
  • [4] An In-Depth Study of More Than Ten Years of Java']Java Exploitation
    Holzinger, Philipp
    Triller, Stefan
    Bartel, Alexandre
    Bodden, Eric
    CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, : 779 - 790
  • [5] Stubbifier: debloating dynamic server-side Java']JavaScript applications
    Turcotte, Alexi
    Arteca, Ellen
    Mishra, Ashish
    Alimadadi, Saba
    Tip, Frank
    EMPIRICAL SOFTWARE ENGINEERING, 2022, 27 (07)
  • [6] An In-depth Study of Java']Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
    Sayar, Imen
    Bartel, Alexandre
    Bodden, Eric
    Le Traon, Yves
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2023, 32 (01)
  • [7] Performance Analysis and Comparison of Node.Js']Js and Java']Java Spring Boot in Implementation of Restful Applications
    Mohan, J. S. Shyam
    Goswami, Krishanu
    SOFTWARE-PRACTICE & EXPERIENCE, 2025,
  • [8] An In-Depth Analysis of Android's Java']Java Class Library: its Evolution and Security Impact
    Riom, Timothee
    Bartel, Alexandre
    2023 IEEE SECURE DEVELOPMENT CONFERENCE, SECDEV, 2023, : 133 - 144
  • [9] JS']JST: An Automatic Test Generation Tool for Industrial Java']Java Applications with Strings
    Ghosh, Indradeep
    Shafiei, Nastaran
    Li, Guodong
    Chiang, Wei-Fan
    PROCEEDINGS OF THE 35TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE 2013), 2013, : 992 - 1001
  • [10] Integrating Spatial Information into JS']JSF Java']Java EE Web Applications with GeoJS']JSF
    Kisner, Thorsten
    Hemmer, Helge
    Jacobi, Klaus
    PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON ADVANCED GEOGRAPHIC INFORMATION SYSTEMS, APPLICATIONS, AND SERVICES (GEOPROCESSING 2011), 2011, : 1 - 6