Lune

CCS2025Top-tier venue

NodeShield: Runtime Enforcement of Security-Enhanced SBOMs for Node.js

Eric Cornelissen, Musard Balliu

2025Year

Abstract

The software supply chain is an increasingly common attack vector for malicious actors. The Node.js ecosystem has been subject to a wide array of attacks, likely due to its size and prevalence. To counter such attacks, the research community and practitioners have proposed a range of static and dynamic mechanisms, including process- and language-level sandboxing, permission systems, and taint tracking. Drawing on valuable insight from these works, this paper studies a runtime protection mechanism for (the supply chain of) Node.js applications with the ambitious goals of compatibility, automation, minimal overhead, and policy conciseness.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext bdb230f8-ceae-41a3-a210-4d4ac7321954

Builds on17

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines