Reducing Static Analysis Unsoundness with Approximate Interpretation
Mathias Rud Laursen, Wenyuan Xu, Anders Møller
Abstract
Static program analysis for JavaScript is more difficult than for many other programming languages. One of the main reasons is the presence of dynamic property accesses that read and write object properties via dynamically computed property names. To ensure scalability and precision, existing state-of-the-art analyses for JavaScript mostly ignore these operations although it results in missed call edges and aliasing relations. We present a novel dynamic analysis technique named approximate interpretation that is designed to efficiently and fully automatically infer likely determinate facts about dynamic property accesses, in particular those that occur in complex library API initialization code, and how to use the produced information in static analysis to recover much of the abstract information that is otherwise missed. Our implementation of the technique and experiments on 141 real-world Node.js-based JavaScript applications and libraries show that the approach leads to significant improvements in call graph construction. On average the use of approximate interpretation leads to 55.1 % more call edges, 21.8 % more reachable functions, 17.7 % more resolved call sites, and only 1.5 % fewer monomorphic call sites. For 36 JavaScript projects where dynamic call graphs are available, average analysis recall is improved from 75.9 % to 88.1 % with a negligible reduction in precision.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d9230e98-e8df-4ad4-bd14-dd1b49dbdbd8Cited by top-tier papers4
- More Effective JavaScript Breaking Change Detection via Dynamic Object Relation GraphDezhen Kong, Jiakun Liu, Chao Ni, David Lo et al.ISSTA 2025
- IRIDIUM: A Framework for Statically Optimizing JavaScript ProgramsMeetesh Kalpesh Mehta, Anirudh Garg, Aneeket Yadav, Manas ThakurOOPSLA 2026
- JavaScript Pointer Analysis with Adaptive Heap AbstractionWenyuan Xu, Anders MøllerFSE 2026
- When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-gamesPei Chen, Geng Hong, Yicheng Qin, Huazhe Wang et al.USENIX Security 2026
Builds on4
- Modular call graph construction for security scanning of Node.js applicationsBenjamin Barslev Nielsen, Martin Toldam Torp, Anders MøllerISSTA 2021 · 47 citations
- Accelerating JavaScript static analysis via dynamic shortcutsJoonyoung Park, Jihyeok Park, Dongjun Youn, Sukyoung RyuFSE 2021 · 15 citations
- Mining Node.js Vulnerabilities via Object Dependence Graph and QuerySong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoUSENIX Security 2022
- Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style VulnerabilityMingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo et al.S&P 2023
Related papers
- ABSINT-AI: Agentic Heap Abstractions for Abstract InterpretationMichael Wang, Kexin Pei, Armando Solar-LezamaICML 2026
- Extracting taint specifications for JavaScript librariesCristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller et al.ICSE 2020 · 34 citations
- On the recall of static call graph construction in practiceLi Sui, Jens Dietrich, Amjed Tahir, George FourtounisICSE 2020 · 34 citations
- Automatically deriving JavaScript static analyzers from specifications using Meta-level static analysisJihyeok Park, Seungmin An, Sukyoung RyuFSE 2022 · 10 citations
- Preventing Dynamic Library Compromise on Node.js via RWX-Based Privilege ReductionNikos Vasilakis, Cristian-Alexandru Staicu, Grigoris Ntousakis, Konstantinos Kallas et al.CCS 2021 · 27 citations
