Jasmine: A Static Analysis Framework for Spring Core Technologies
Miao Chen, Tengfei Tu, Hua Zhang, Qiaoyan Wen, Weihang Wang
Abstract
The Spring framework is widely used in developing enterprise web applications. Spring core technologies, such as Dependency Injection and Aspect-Oriented Programming, make development faster and easier. However, the implementation of Spring core technologies uses a lot of dynamic features. Those features impose significant challenges when using static analysis to reason about the behavior of Spring-based applications. In this paper, we propose Jasmine, a static analysis framework for Spring core technologies extends from Soot to enhance the call graph’s completeness while not greatly affecting its performance. We evaluate Jasmine’s completeness, precision, and performance using Spring micro-benchmarks and a suite of 18 real-world Spring programs. Our experiments show that Jasmine effectively enhances the state-of-the-art tools based on Soot and Doop to better support Spring core technologies. We also add Jasmine support to FlowDroid and discovered twelve sensitive information leakage paths in our benchmarks. Jasmine is expected to provide significant benefits for many program analyses scenes of Spring applications where more complete call graphs are required.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0c3ca5df-671a-49bc-b2da-e30f2fc09424Cited by top-tier papers6
- Pointer Analysis for Database-Backed ApplicationsYufei Liang, Teng Zhang, Ganlin Li, Tian Tan et al.PLDI 2025 · 5 citations
- Bridge the Islands: Pointer Analysis for Microservice SystemsTeng Zhang, Yufei Liang, Ganlin Li, Tian Tan et al.ISSTA 2025 · 2 citations
- Effective Directed Fuzzing with Hierarchical Scheduling for Web Vulnerability DetectionZihan Lin, Yuan Zhang, Jiarun Dai, Xinyou Huang et al.USENIX Security 2025
- MOCGuard: Automatically Detecting Missing-Owner-Check Vulnerabilities in Java Web ApplicationsFengyu Liu, Youkun Shi, Yuan Zhang, Guangliang Yang et al.S&P 2025
- BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web ApplicationsFengyu Liu, Yuan Zhang, Enhao Li, Wei Meng et al.CCS 2025
Builds on5
- Static analysis of Java enterprise applications: frameworks and caches, the elephants in the roomAnastasios Antoniadis, Nikos Filippakis, Paddy Krishnan, Raghavendra Ramesh et al.PLDI 2020 · 41 citations
- BlankIt library debloating: getting what you want instead of cutting what you don'tChris Porter, Girish Mururu, Prithayan Barua, Santosh PandePLDI 2020 · 31 citations
- Chianina: an evolving graph system for flow- and context-sensitive analyses of million lines of C codeZhiqiang Zuo, Yiyu Zhang, Qiuhong Pan, Shenming Lu et al.PLDI 2021 · 18 citations
- Dynamic dispatch of context-sensitive optimizationsGabriel Poesia, Fernando Magno Quintão PereiraOOPSLA 2020 · 7 citations
- Temporal System Call Specialization for Attack Surface ReductionSeyedhamed Ghavamnia, Tapti Palit, Shachee Mishra, Michalis PolychronakisUSENIX Security 2020
Related papers
- GlassWing: A Tailored Static Analysis Approach for Flutter Android AppsXiangyu Zhang, Yucheng Su, Lingling Fan, Miaoying Cai et al.ASE 2025
- ECSTATIC: An Extensible Framework for Testing and Debugging Configurable Static AnalysisAustin Mordahl, Zenong Zhang, Dakota Soles, Shiyi WeiICSE 2023 · 7 citations
- JuCify: A Step Towards Android Code Unification for Enhanced Static AnalysisJordan Samhi, Jun Gao, Nadia Daoudi, Pierre Graux et al.ICSE 2022 · 43 citations
- The ART of Sharing Points-to Analysis: Reusing Points-to Analysis Results Safely and EfficientlyShashin Halalingaiah, Vijay Sundaresan, Daryl Maier, V. Krishna NandivadaOOPSLA 2024 · 2 citations
- Tai-e: A Developer-Friendly Static Analysis Framework for Java by Harnessing the Good Designs of ClassicsTian Tan, Yue LiISSTA 2023 · 26 citations
