{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,27]],"date-time":"2026-07-27T22:56:03Z","timestamp":1785192963804,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":77,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,6,11]],"date-time":"2020-06-11T00:00:00Z","timestamp":1591833600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100015089","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-17-1-2895"],"award-info":[{"award-number":["N00014-17-1-2895"]}],"id":[{"id":"10.13039\/100015089","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,6,11]]},"DOI":"10.1145\/3385412.3386017","type":"proceedings-article","created":{"date-parts":[[2020,6,7]],"date-time":"2020-06-07T01:40:10Z","timestamp":1591494010000},"page":"164-180","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["BlankIt library debloating: getting what you want instead of cutting what you don\u2019t"],"prefix":"10.1145","author":[{"given":"Chris","family":"Porter","sequence":"first","affiliation":[{"name":"Georgia Institute of Technology, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Girish","family":"Mururu","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Prithayan","family":"Barua","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Santosh","family":"Pande","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,6,11]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102165"},{"key":"e_1_3_2_1_2_1","unstructured":"S. Andersen and V. Abella. 2004. Data Execution Prevention: Changes to Functionality in Microsoft Windows XP Service Pack 2 Part 3: Memory Protection Technologies. http:\/\/technet.microsoft.com\/enus\/library\/bb457155.aspx. Accessed: 2018 May 7."},{"key":"e_1_3_2_1_3_1","unstructured":"ANDK 2017. Android NDK. https:\/\/developer.android.com\/ndk\/ guides\/cpp-support.html. Accessed: 2017 Feb 5."},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the 29th Annual ACM\/IEEE International Symposium on Microarchitecture (MICRO 29)","author":"Ball Thomas","unstructured":"Thomas Ball and James R. Larus. 1996. Efficient Path Profiling. In Proceedings of the 29th Annual ACM\/IEEE International Symposium on Microarchitecture (MICRO 29). IEEE Computer Society, USA, 46\u201357."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/937503.937504"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076783"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1966913.1966919"},{"key":"e_1_3_2_1_8_1","volume-title":"Towards Better Metrics for Measuring Security Improvements Realized Through Software Debloating. In 12th USENIX Workshop on Cyber Security Experimentation and Test, CSET 2019","author":"Michael","year":"2019","unstructured":"Michael D. Brown and Santosh Pande. 2019. Is Less Really More? Towards Better Metrics for Measuring Security Improvements Realized Through Software Debloating. In 12th USENIX Workshop on Cyber Security Experimentation and Test, CSET 2019, Santa Clara, CA, USA, August 12, 2019., Rob Jansen and Peter A. H. Peterson (Eds.). USENIX Association. https:\/\/www.usenix.org\/conference\/cset19\/presentation\/ brown"},{"key":"e_1_3_2_1_9_1","unstructured":"Caffe 2017. Caffe. http:\/\/caffe.berkeleyvision.org\/. Accessed: 2017 Feb 5."},{"key":"e_1_3_2_1_10_1","volume-title":"Proceedings of the 24th USENIX Conference on Security Symposium (SEC\u201915)","author":"Carlini Nicolas","unstructured":"Nicolas Carlini, Antonio Barresi, Mathias Payer, David Wagner, and Thomas R. Gross. 2015. Control-flow Bending: On the Effectiveness of Control-flow Integrity. In Proceedings of the 24th USENIX Conference on Security Symposium (SEC\u201915). USENIX Association, Berkeley, CA, USA, 161\u2013176. http:\/\/dl.acm.org\/citation.cfm?id=2831143.2831154"},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of the 14th USENIX Security Symposium","author":"Chen Shuo","year":"2005","unstructured":"Shuo Chen, Jun Xu, and Emre Can Sezer. 2005. Non-Control-Data Attacks Are Realistic Threats. In Proceedings of the 14th USENIX Security Symposium, Baltimore, MD, USA, July 31 - August 5, 2005, Patrick D. McDaniel (Ed.). USENIX Association. https:\/\/www.usenix.org\/conference\/14th-usenix-securitysymposium\/non-control-data-attacks-are-realistic-threats"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.26"},{"key":"e_1_3_2_1_13_1","unstructured":"CVE 2017. CVE Details. https:\/\/www.cvedetails.com\/vulnerabilitylist\/vendor_id-72\/product_id-767\/GNU-Glibc.html. Accessed: 2017 Feb 5."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/512529.512542"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/349214"},{"key":"e_1_3_2_1_16_1","unstructured":"349233"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3296979"},{"key":"e_1_3_2_1_18_1","unstructured":"3192388"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.53"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813646"},{"key":"e_1_3_2_1_21_1","unstructured":"Flask 2018. Flask. http:\/\/flask.pocoo.org\/. Accessed: 2018 Apr 24."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-30806-7_10"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/265563.265576"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3037697.3037716"},{"key":"e_1_3_2_1_25_1","unstructured":"glibc 2017. glibc. https:\/\/www.gnu.org\/software\/libc\/. Accessed: 2017 Feb 5."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243838"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243838"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243797"},{"key":"e_1_3_2_1_29_1","volume-title":"Code-pointer Integrity. In Proceedings of the 11th USENIX Conference on Operating Systems Design and Implementation (OSDI\u201914)","author":"Kuznetsov Volodymyr","year":"2014","unstructured":"Volodymyr Kuznetsov, L\u00e1szl\u00f3 Szekeres, Mathias Payer, George Candea, R. Sekar, and Dawn Song. 2014. Code-pointer Integrity. In Proceedings of the 11th USENIX Conference on Operating Systems Design and Implementation (OSDI\u201914). USENIX Association, Berkeley, CA, USA, 147\u2013163. http:\/\/dl.acm.org\/citation.cfm?id=2685048.2685061"},{"key":"e_1_3_2_1_30_1","unstructured":"Volodymyr Kuznetsov Laszlo Szekeres Mathias Payer George Candea and Dawn Song. 2015. Poster : Getting The Point(er): On the Feasibility of Attacks on Code-Pointer Integrity."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2771783.2771785"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2017.18"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.60"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03013-0_5"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","unstructured":"Springer 77\u201397. 10.1007\/978-3-642-03013-0_5","DOI":"10.1007\/978-3-642-03013-0_5"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2010.7"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1297027.1297046"},{"key":"e_1_3_2_1_38_1","volume-title":"Opaque Control-Flow Integrity. In 22nd Annual Network and Distributed System Security Symposium, NDSS 2015","author":"Mohan Vishwath","year":"2015","unstructured":"Vishwath Mohan, Per Larsen, Stefan Brunthaler, Kevin W. Hamlen, and Michael Franz. 2015. Opaque Control-Flow Integrity. In 22nd Annual Network and Distributed System Security Symposium, NDSS 2015, San Diego, California, USA, February 8-11, 2015. The Internet Society."},{"key":"e_1_3_2_1_39_1","unstructured":"https:\/\/www.ndss-symposium.org\/ndss2015\/opaque-controlflow-integrity"},{"key":"e_1_3_2_1_40_1","unstructured":"musl 2019. musl. https:\/\/www.musl-libc.org\/. Accessed: 2019 June 15."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1002\/1097-024X(200101)31:1%26#38;lt;67::AID-SPE357%26#38;gt;3.0.CO;2-A"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806651.1806657"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250746"},{"key":"e_1_3_2_1_44_1","unstructured":"nginx 2019. nginx. https:\/\/nginx.org\/. Accessed: 2019 June 10."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594295"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813644"},{"key":"e_1_3_2_1_47_1","unstructured":"Node.js 2018. Node.js. https:\/\/nodejs.org\/en\/. Accessed: 2018 Apr 24."},{"key":"e_1_3_2_1_48_1","unstructured":"norvig 2019. norvig. https:\/\/norvig.com\/big.txt. Accessed: 2019 June 12."},{"key":"e_1_3_2_1_49_1","unstructured":"openssh 2019. openssh. https:\/\/www.openssh.com\/. Accessed: 2019 June 11."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.28"},{"key":"e_1_3_2_1_51_1","volume-title":"ASLR 2003","author":"PAX","year":"2018","unstructured":"PAX ASLR 2003. PaX Address Space Layout Randomization. https: \/\/pax.grsecurity.net\/docs\/aslr.txt. Accessed: 2018 May 7."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.5555\/1953048.2078195"},{"key":"e_1_3_2_1_53_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Quach Anh","year":"2018","unstructured":"Anh Quach, Aravind Prakash, and Lok Yan. 2018. Debloating Software through Piece-Wise Compilation and Loading. In 27th USENIX Security Symposium (USENIX Security 18). USENIX Association, Baltimore, MD, 869\u2013886. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/ presentation\/quach"},{"key":"e_1_3_2_1_54_1","volume-title":"A Framework for Post-deployment Software Debloating","author":"RAZOR","year":"2019","unstructured":"RAZOR: A Framework for Post-deployment Software Debloating 2019. RAZOR: A Framework for Post-deployment Software Debloating. https:\/\/www.cc.gatech.edu\/~hhu86\/papers\/razor.pdf."},{"key":"e_1_3_2_1_55_1","unstructured":"ROPgadget 2018. ROPgadget v5.4. https:\/\/github.com\/ JonathanSalwan\/ROPgadget. Accessed: 2018 May 7."},{"key":"e_1_3_2_1_56_1","unstructured":"Konstantin Serebryany Derek Bruening Alexander Potapenko and Dmitriy Vyukov. 2012."},{"key":"e_1_3_2_1_57_1","volume-title":"Presented as part of the 2012 USENIX Annual Technical Conference (USENIX ATC 12)","unstructured":"AddressSanitizer: A Fast Address Sanity Checker. In Presented as part of the 2012 USENIX Annual Technical Conference (USENIX ATC 12). USENIX, Boston, MA, 309\u2013 318. https:\/\/www.usenix.org\/conference\/atc12\/technical-sessions\/ presentation\/serebryany"},{"key":"e_1_3_2_1_58_1","volume-title":"Proceedings of the 2005 USENIX Annual Technical Conference","author":"Seward Julian","year":"2005","unstructured":"Julian Seward and Nicholas Nethercote. 2005. Using Valgrind to Detect Undefined Value Errors with Bit-Precision. In Proceedings of the 2005 USENIX Annual Technical Conference, April 10-15, 2005, Anaheim, CA, USA. USENIX, 17\u201330. http:\/\/www.usenix.org\/events\/usenix05\/tech\/ general\/seward.html"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315313"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238160"},{"key":"e_1_3_2_1_61_1","unstructured":"sshdCve 2019. sshdCve. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015- 7547. Accessed: 2019 June 12."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/1086642.1086645"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/1210268.1210273"},{"key":"e_1_3_2_1_64_1","unstructured":"TensorC 2017. Tensorflow for C. https:\/\/www.tensorflow.org\/install\/ install_c. Accessed: 2017 Feb 5."},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.09.001"},{"key":"e_1_3_2_1_66_1","volume-title":"Recent Advances in Intrusion Detection","author":"Tran Minh","unstructured":"Minh Tran, Mark Etheridge, Tyler Bletsch, Xuxian Jiang, Vincent Freeh, and Peng Ning. 2011. On the Expressiveness of Return-intolibc Attacks. In Recent Advances in Intrusion Detection, Robin Sommer, Davide Balzarotti, and Gregor Maier (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 121\u2013141."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.60"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","unstructured":"IEEE Computer Society 934\u2013953. 10.1109\/SP.2016.60","DOI":"10.1109\/SP.2016.60"},{"key":"e_1_3_2_1_69_1","unstructured":"wikipedia 2019. wikipedia. https:\/\/en.wikipedia.org\/wiki\/Main_Page. Accessed: 2019 June 10."},{"key":"e_1_3_2_1_70_1","volume-title":"June 15\u201320","year":"2020","unstructured":"wrk 2019. wrk. https:\/\/github.com\/wg\/wrk. Accessed: 2019 June 10. BlankIt PLDI \u201920, June 15\u201320, 2020, London, UK"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806596.1806616"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/2384616.2384690"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806596.1806617"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978340"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.44"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.5555\/2535461.2535463"},{"key":"e_1_3_2_1_77_1","volume-title":"Proceedings of the 22Nd USENIX Conference on Security (SEC\u201913)","author":"Zhang Mingwei","unstructured":"Mingwei Zhang and R. Sekar. 2013. Control Flow Integrity for COTS Binaries. In Proceedings of the 22Nd USENIX Conference on Security (SEC\u201913). USENIX Association, Berkeley, CA, USA, 337\u2013352. http: \/\/dl.acm.org\/citation.cfm?id=2534766.2534796"}],"event":{"name":"PLDI '20: 41st ACM SIGPLAN International Conference on Programming Language Design and Implementation","location":"London UK","acronym":"PLDI '20","sponsor":["SIGPLAN ACM Special Interest Group on Programming Languages"]},"container-title":["Proceedings of the 41st ACM SIGPLAN Conference on Programming Language Design and Implementation"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3385412.3386017","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3385412.3386017","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3385412.3386017","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:38:49Z","timestamp":1750199929000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3385412.3386017"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,11]]},"references-count":77,"alternative-id":["10.1145\/3385412.3386017","10.1145\/3385412"],"URL":"https:\/\/doi.org\/10.1145\/3385412.3386017","relation":{},"subject":[],"published":{"date-parts":[[2020,6,11]]},"assertion":[{"value":"2020-06-11","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}