BlankIt Library Debloating Getting What You Want Instead of Cutting What You Don't

被引:25
|
作者
Porter, Chris [1 ]
Mururu, Girish [1 ]
Barua, Prithayan [1 ]
Pande, Santosh [1 ]
机构
[1] Georgia Inst Technol, Atlanta, GA 30332 USA
关键词
software debloating; program security;
D O I
10.1145/3385412.3386017
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Modern software systems make extensive use of libraries derived from C and C++. Because of the lack of memory safety in these languages, however, the libraries may suffer from vulnerabilities, which can expose the applications to potential attacks. For example, a very large number of return-oriented programming gadgets exist in glibc that allow stitching together semantically valid but malicious Turing-complete and -incomplete programs. While CVEs get discovered and often patched and remedied, such gadgets serve as building blocks of future undiscovered attacks, opening an ever-growing set of possibilities for generating malicious programs. Thus, significant reduction in the quantity and expressiveness (utility) of such gadgets for libraries is an important problem. In this work, we propose a new approach for handling an application's library functions that focuses on the principle of lgetting only what you want.z This is a significant departure from the current approaches that focus on lcutting what is unwanted.z Our approach focuses on activating/deactivating library functions on demand in order to reduce the dynamically linked code surface, so that the possibilities of constructing malicious programs diminishes substantially. The key idea is to load only the set of library functions that will be used at each library call site within the application at runtime. This approach of demand-driven loading relies on an input-aware oracle that predicts a near-exact set of library functions needed at a given call site during the execution. The predicted functions are loaded just in time and unloaded on return. We present a decision-tree based predictor, which acts as an oracle, and an optimized runtime system, which works directly with library binaries like GNU libc and libstdc++. We show that on average, the proposed scheme cuts the exposed code surface of libraries by 97.2%, reduces ROP gadgets present in linked libraries by 97.9%, achieves a prediction accuracy in most cases of at least 97%, and adds a runtime overhead of 18% on all libraries (16% for glibc, 2% for others) across all benchmarks of SPEC 2006. Further, we demonstrate BlankIt on two real-world applications, sshd and nginx, with a high amount of debloating and low overheads.
引用
收藏
页码:164 / 180
页数:17
相关论文
共 50 条
  • [1] You Don't Always Get What You Want!
    Morgan, Philip G.
    Sedensky, Margaret M.
    ANESTHESIOLOGY, 2024, 141 (04) : 745 - 749
  • [2] Getting what you want
    Lyndal Grant
    Milo Phillips-Brown
    Philosophical Studies, 2020, 177 : 1791 - 1810
  • [3] Getting what you want
    Grant, Lyndal
    Phillips-Brown, Milo
    PHILOSOPHICAL STUDIES, 2020, 177 (07) : 1791 - 1810
  • [4] GETTING WHAT YOU WANT
    BERGSTROM, RP
    MANUFACTURING ENGINEERING, 1989, 103 (02): : 61 - 63
  • [5] Getting what you want
    Smith, S
    SOUND AND VIBRATION, 1999, 33 (03): : 5 - 6
  • [6] Getting What You Don’t Deserve
    Philip Perlmutter
    Society, 2012, 49 : 76 - 83
  • [7] Getting What You Don't Deserve
    Perlmutter, Philip
    SOCIETY, 2012, 49 (01) : 76 - 83
  • [8] GETTING WHAT YOU WANT BY REVISING WHAT YOU HAD
    CONWAY, M
    ROSS, M
    JOURNAL OF PERSONALITY AND SOCIAL PSYCHOLOGY, 1984, 47 (04) : 738 - 748
  • [9] THE ART OF GETTING WHAT YOU WANT
    DAVIDHIZAR, R
    NURSING CONNECTIONS, 1994, 7 (04) : 45 - 49
  • [10] NEGOTIATIONS - GETTING WHAT YOU WANT
    KIRK, R
    JOURNAL OF NURSING ADMINISTRATION, 1986, 16 (12): : 6 - 9