kirancodes.me
To Proof Maintenance & Beyond!

Extracting taint specifications for JavaScript libraries

Cristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller, Michael Pradel

Abstract

Modern JavaScript applications extensively depend on third-party libraries. Especially for the Node.js platform, vulnerabilities can have severe consequences to the security of applications, resulting in, e.g., cross-site scripting and command injection attacks. Existing static analysis tools that have been developed to automatically detect such issues are either too coarse-grained, looking only at package dependency structure while ignoring dataflow, or rely on manually written taint specifications for the most popular libraries to ensure analysis scalability.

BibTeX
@inproceedings{Staicu-al:ICSE20,
  author    = {Cristian{-}Alexandru Staicu and
               Martin Toldam Torp and
               Max Sch{\"{a}}fer and
               Anders M{\o}ller and
               Michael Pradel},
  title     = {Extracting taint specifications for {JavaScript} libraries},
  booktitle = {ICSE},
  pages     = {198--209},
  publisher = {{ACM}},
  year      = {2020},
}

Related papers