Dynamic Security Analysis of JavaScript: Are We There Yet?
Stefano Calzavara, Samuele Casarin, Riccardo Focardi
Abstract
In this paper, we systematically evaluate the effectiveness of existing tools for the dynamic security analysis of client-side JavaScript, focusing in particular on information flow control. Each tool is evaluated in terms of: (𝑖) compatibility, i.e., the ability to process and analyze existing scripts without breaking; (𝑖𝑖) transparency, i.e., the ability to preserve the original script semantics when security enforcement is not necessary; (𝑖𝑖𝑖) coverage, i.e., the effectiveness in terms of number of detected information flows; (𝑖𝑣) performance, i.e., the computational overhead introduced by the analysis. Our investigation shows that most of the existing analysis tools are incompatible with the modern Web and the compatibility issues affecting them are not easily fixed. Moreover, transparency issues abound and make us question analysis correctness. This is also confirmed by our coverage evaluation, showing that some tools are unable to detect any information flow on real-world websites, while the remaining tools report significantly different outputs. Finally, we observe that the computational overhead of analysis tools may be significant and can exceed 30x. In the end, out of all the evaluated tools, just one of them (Project Foxhound) is effective enough for practical adoption at scale. CCS Concepts • Security and privacy → Web application security; Software security engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e82970cf-ee25-47eb-b218-0f4307d324c3Builds on6
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Reproducibility and Replicability of Web Measurement StudiesNurullah Demir, Matteo Große-Kampmann, Tobias Urban, Christian Wressnegger et al.WWW 2022 · 47 citations
- U Can't Debug This: Detecting JavaScript Anti-Debugging Techniques in the WildMarius Musch, Martin JohnsUSENIX Security 2021 · 8 citations
- PanoptiChrome: A Modern In-browser Taint Analysis FrameworkRahul Kanyal, Smruti R. SarangiWWW 2024 · 5 citations
Related papers
- Finding client-side business flow tampering vulnerabilitiesI Luk Kim, Yunhui Zheng, Hogun Park, Weihang Wang et al.ICSE 2020 · 14 citations
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer et al.NDSS 2018 · 84 citations
- Extracting taint specifications for JavaScript librariesCristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller et al.ICSE 2020 · 34 citations
- Jasmine: Scale up JavaScript Static Security Analysis with Computation-based Semantic ExplanationFeng Xiao, Zhongfu Su, Guangliang Yang, Wenke LeeS&P 2024
- Testability Tarpits: the Impact of Code Patterns on the Security Testing of Web ApplicationsFeras Al Kassar, Giulia Clerici, Luca Compagna, Davide Balzarotti et al.NDSS 2022
