Lune

WWW2025Top-tier venue

Dynamic Security Analysis of JavaScript: Are We There Yet?

Stefano Calzavara, Samuele Casarin, Riccardo Focardi

2025Year
3Citations

Abstract

In this paper, we systematically evaluate the effectiveness of existing tools for the dynamic security analysis of client-side JavaScript, focusing in particular on information flow control. Each tool is evaluated in terms of: (𝑖) compatibility, i.e., the ability to process and analyze existing scripts without breaking; (𝑖𝑖) transparency, i.e., the ability to preserve the original script semantics when security enforcement is not necessary; (𝑖𝑖𝑖) coverage, i.e., the effectiveness in terms of number of detected information flows; (𝑖𝑣) performance, i.e., the computational overhead introduced by the analysis. Our investigation shows that most of the existing analysis tools are incompatible with the modern Web and the compatibility issues affecting them are not easily fixed. Moreover, transparency issues abound and make us question analysis correctness. This is also confirmed by our coverage evaluation, showing that some tools are unable to detect any information flow on real-world websites, while the remaining tools report significantly different outputs. Finally, we observe that the computational overhead of analysis tools may be significant and can exceed 30x. In the end, out of all the evaluated tools, just one of them (Project Foxhound) is effective enough for practical adoption at scale. CCS Concepts • Security and privacy → Web application security; Software security engineering.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext e82970cf-ee25-47eb-b218-0f4307d324c3

Builds on6

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines