Modular call graph construction for security scanning of Node.js applications
Benjamin Barslev Nielsen, Martin Toldam Torp, Anders Møller
Abstract
Most of the code in typical Node.js applications comes from thirdparty libraries that consist of a large number of interdependent modules. Because of the dynamic features of JavaScript, it is difficult to obtain detailed information about the module dependencies, which is vital for reasoning about the potential consequences of security vulnerabilities in libraries, and for many other software development tasks. The underlying challenge is how to construct precise call graphs that capture the connectivity between functions in the modules. In this work we present a novel approach to call graph construction for Node.js applications that is modular, taking into account the modular structure of Node.js applications, and sufficiently accurate and efficient to be practically useful. We demonstrate experimentally that the constructed call graphs are useful for security scanning, reducing the number of false positives by 81% compared to npm audit and with zero false negatives. Compared to js-callgraph, the call graph construction is significantly more accurate and efficient. The experiments also show that the analysis time is reduced substantially when reusing modular call graphs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fc810f09-93d3-47a3-913b-76329276690eCited by top-tier papers22
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen et al.ICSE 2022 · 94 citations
- Practical Automated Detection of Malicious npm PackagesAdriana Sejfia, Max SchäferICSE 2022 · 65 citations
- Tai-e: A Developer-Friendly Static Analysis Framework for Java by Harnessing the Good Designs of ClassicsTian Tan, Yue LiISSTA 2023 · 26 citations
- AutoPruner: transformer-based call graph pruningThanh Le-Cong, Hong Jin Kang, Truong Giang Nguyen, Stefanus Agus Haryono et al.FSE 2022 · 21 citations
- SecBench.js: An Executable Security Benchmark Suite for Server-Side JavaScriptMasudul Hasan Masud Bhuiyan, Adithya Srinivas Parthasarathy, Nikos Vasilakis, Michael Pradel et al.ICSE 2023 · 20 citations
Builds on5
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson et al.NDSS 2017 · 183 citations
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 91 citations
- Extracting taint specifications for JavaScript librariesCristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller et al.ICSE 2020 · 34 citations
- Detecting locations in JavaScript programs affected by breaking library changesAnders Møller, Benjamin Barslev Nielsen, Martin Toldam TorpOOPSLA 2020 · 32 citations
Related papers
- Reducing Static Analysis Unsoundness with Approximate InterpretationMathias Rud Laursen, Wenyuan Xu, Anders MøllerPLDI 2024 · 5 citations
- From Noise to Signal: Precisely Identify Affected Packages of Known Vulnerabilities in npm EcosystemYingyuan Pu, Lingyun Ying, Yacong GuNDSS 2026 · 4 citations
- Efficient Static Vulnerability Analysis for JavaScript with Multiversion Dependency GraphsMafalda Ferreira, Miguel Monteiro, Tiago Brito, Miguel E. Coimbra et al.PLDI 2024 · 13 citations
- ProfMal: Detecting Malicious NPM Packages by the Synergy between Static and Dynamic AnalysisYiheng Huang, Wen Zheng, Susheng Wu, Bihuan Chen et al.ASE 2025 · 2 citations
- Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style VulnerabilityMingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo et al.S&P 2023
