Jasmine: A Static Analysis Framework for Spring Core Technologies
Miao Chen, Tengfei Tu, Hua Zhang, Qiaoyan Wen, Weihang Wang
摘要
The Spring framework is widely used in developing enterprise web applications. Spring core technologies, such as Dependency Injection and Aspect-Oriented Programming, make development faster and easier. However, the implementation of Spring core technologies uses a lot of dynamic features. Those features impose significant challenges when using static analysis to reason about the behavior of Spring-based applications. In this paper, we propose Jasmine, a static analysis framework for Spring core technologies extends from Soot to enhance the call graph’s completeness while not greatly affecting its performance. We evaluate Jasmine’s completeness, precision, and performance using Spring micro-benchmarks and a suite of 18 real-world Spring programs. Our experiments show that Jasmine effectively enhances the state-of-the-art tools based on Soot and Doop to better support Spring core technologies. We also add Jasmine support to FlowDroid and discovered twelve sensitive information leakage paths in our benchmarks. Jasmine is expected to provide significant benefits for many program analyses scenes of Spring applications where more complete call graphs are required.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Pointer Analysis for Database-Backed ApplicationsYufei Liang, Teng Zhang, Ganlin Li, Tian Tan 等PLDI 2025 · 被引用 5 次
- Bridge the Islands: Pointer Analysis for Microservice SystemsTeng Zhang, Yufei Liang, Ganlin Li, Tian Tan 等ISSTA 2025 · 被引用 2 次
- Effective Directed Fuzzing with Hierarchical Scheduling for Web Vulnerability DetectionZihan Lin, Yuan Zhang, Jiarun Dai, Xinyou Huang 等USENIX Security 2025
- MOCGuard: Automatically Detecting Missing-Owner-Check Vulnerabilities in Java Web ApplicationsFengyu Liu, Youkun Shi, Yuan Zhang, Guangliang Yang 等S&P 2025
- BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web ApplicationsFengyu Liu, Yuan Zhang, Enhao Li, Wei Meng 等CCS 2025
它引用的顶会 Paper5
- Static analysis of Java enterprise applications: frameworks and caches, the elephants in the roomAnastasios Antoniadis, Nikos Filippakis, Paddy Krishnan, Raghavendra Ramesh 等PLDI 2020 · 被引用 41 次
- BlankIt library debloating: getting what you want instead of cutting what you don'tChris Porter, Girish Mururu, Prithayan Barua, Santosh PandePLDI 2020 · 被引用 31 次
- Chianina: an evolving graph system for flow- and context-sensitive analyses of million lines of C codeZhiqiang Zuo, Yiyu Zhang, Qiuhong Pan, Shenming Lu 等PLDI 2021 · 被引用 18 次
- Dynamic dispatch of context-sensitive optimizationsGabriel Poesia, Fernando Magno Quintão PereiraOOPSLA 2020 · 被引用 7 次
- Temporal System Call Specialization for Attack Surface ReductionSeyedhamed Ghavamnia, Tapti Palit, Shachee Mishra, Michalis PolychronakisUSENIX Security 2020
相关 Paper
- GlassWing: A Tailored Static Analysis Approach for Flutter Android AppsXiangyu Zhang, Yucheng Su, Lingling Fan, Miaoying Cai 等ASE 2025
- ECSTATIC: An Extensible Framework for Testing and Debugging Configurable Static AnalysisAustin Mordahl, Zenong Zhang, Dakota Soles, Shiyi WeiICSE 2023 · 被引用 7 次
- JuCify: A Step Towards Android Code Unification for Enhanced Static AnalysisJordan Samhi, Jun Gao, Nadia Daoudi, Pierre Graux 等ICSE 2022 · 被引用 43 次
- The ART of Sharing Points-to Analysis: Reusing Points-to Analysis Results Safely and EfficientlyShashin Halalingaiah, Vijay Sundaresan, Daryl Maier, V. Krishna NandivadaOOPSLA 2024 · 被引用 2 次
- Tai-e: A Developer-Friendly Static Analysis Framework for Java by Harnessing the Good Designs of ClassicsTian Tan, Yue LiISSTA 2023 · 被引用 26 次
