NodeShield: Runtime Enforcement of Security-Enhanced SBOMs for Node.js
Eric Cornelissen, Musard Balliu
Abstract
The software supply chain is an increasingly common attack vector for malicious actors. The Node.js ecosystem has been subject to a wide array of attacks, likely due to its size and prevalence. To counter such attacks, the research community and practitioners have proposed a range of static and dynamic mechanisms, including process- and language-level sandboxing, permission systems, and taint tracking. Drawing on valuable insight from these works, this paper studies a runtime protection mechanism for (the supply chain of) Node.js applications with the ambitious goals of compatibility, automation, minimal overhead, and policy conciseness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bdb230f8-ceae-41a3-a210-4d4ac7321954Builds on17
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn et al.NDSS 2018 · 66 citations
- Practical Automated Detection of Malicious npm PackagesAdriana Sejfia, Max SchäferICSE 2022 · 65 citations
- DONAPI: Malicious NPM Packages Detector using Behavior Sequence Knowledge MappingCheng Huang, Nannan Wang, Ziyan Wang, Siqi Sun et al.USENIX Security 2024 · 38 citations
- SandTrap: Securing JavaScript-driven Trigger-Action PlatformsMohammad M. Ahmadpanah, Daniel Hedin, Musard Balliu, Lars Eric Olsson et al.USENIX Security 2021 · 31 citations
Related papers
- HODOR: Shrinking Attack Surface on Node.js via System Call LimitationWenya Wang, Xingwei Lin, Jingyi Wang, Wang Gao et al.CCS 2023 · 3 citations
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 91 citations
- Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its EcosystemAbdullah AlHamdan, Cristian-Alexandru StaicuNDSS 2025
- Containing Malicious Package Updates in npm with a Lightweight Permission SystemGabriel Ferreira, Limin Jia, Joshua Sunshine, Christian KästnerICSE 2021 · 3 citations
- Finding and Preventing Bugs in JavaScript BindingsFraser Brown, Shravan Narayan, Riad S. Wahby, Dawson R. Engler et al.S&P 2017 · 63 citations
