kirancodes.me
To Proof Maintenance & Beyond!

Input-Driven Dynamic Program Debloating for Code-Reuse Attack Mitigation

Xiaoke Wang, Tao Hui, Lei Zhao, Yueqiang Cheng

Abstract

Modern software is bloated, especially for libraries. The unnecessary code not only brings severe vulnerabilities, but also assists attackers to construct exploits. To mitigate the damage of bloated libraries, researchers have proposed several debloating techniques to remove or restrict the invocation of unused code in a library. However, existing approaches either statically keep code for all expected inputs, which leave unused code for each concrete input, or rely on runtime context to dynamically determine the necessary code, which could be manipulated by attackers.

BibTeX
@inproceedings{Wang-al:FSE23,
  author    = {Xiaoke Wang and
               Tao Hui and
               Lei Zhao and
               Yueqiang Cheng},
  title     = {{Input-Driven} Dynamic Program Debloating for {Code-Reuse} Attack Mitigation},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {934--946},
  publisher = {{ACM}},
  year      = {2023},
}

Related papers