Extracting taint specifications for JavaScript libraries
Abstract
Modern JavaScript applications extensively depend on third-party libraries. Especially for the Node.js platform, vulnerabilities can have severe consequences to the security of applications, resulting in, e.g., cross-site scripting and command injection attacks. Existing static analysis tools that have been developed to automatically detect such issues are either too coarse-grained, looking only at package dependency structure while ignoring dataflow, or rely on manually written taint specifications for the most popular libraries to ensure analysis scalability.
BibTeX
@inproceedings{Staicu-al:ICSE20,
author = {Cristian{-}Alexandru Staicu and
Martin Toldam Torp and
Max Sch{\"{a}}fer and
Anders M{\o}ller and
Michael Pradel},
title = {Extracting taint specifications for {JavaScript} libraries},
booktitle = {ICSE},
pages = {198--209},
publisher = {{ACM}},
year = {2020},
}