Mining Node.js Vulnerabilities via Object Dependence Graph and Query
Song Li, Mingqing Kang, Jianwei Hou, Yinzhi Cao
摘要
Node.js is a popular non-browser JavaScript platform that provides useful but sometimes also vulnerable packages. On one hand, prior works have proposed many program analysisbased approaches to detect Node.js vulnerabilities, such as command injection and prototype pollution, but they are specific to individual vulnerability and do not generalize to a wide range of vulnerabilities on Node.js. On the other hand, prior works on C/C++ and PHP have proposed graph querybased approaches, such as Code Property Graph (CPG), to efficiently mine vulnerabilities, but they are not directly applicable to JavaScript due to the language's extensive use of dynamic features. In the paper, we propose flow-and context-sensitive static analysis with hybrid branch-sensitivity and points-to information to generate a novel graph structure, called Object Dependence Graph (ODG), using abstract interpretation. ODG represents JavaScript objects as nodes and their relations with Abstract Syntax Tree (AST) as edges, and accepts graph queries-especially on object lookups and definitions-for detecting Node.js vulnerabilities. We implemented an open-source prototype system, called ODGEN, to generate ODG for Node.js programs via abstract interpretation and detect vulnerabilities. Our evaluation of recent Node.js vulnerabilities shows that ODG together with AST and Control Flow Graph (CFG) is capable of modeling 13 out of 16 vulnerability types. We applied ODGEN to detect six types of vulnerabilities using graph queries: ODGEN correctly reported 180 zero-day vulnerabilities, among which we have received 70 Common Vulnerabilities and Exposures (CVE) identifiers so far. * The author contributes to the paper when she is visiting JHU.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper46
- HiddenCPG: Large-Scale Vulnerable Clone Detection Using Subgraph Isomorphism of Code Property GraphsSeongil Wi, Sijae Woo, Joyce Jiyoung Whang, Sooel SonWWW 2022 · 被引用 27 次
- SecBench.js: An Executable Security Benchmark Suite for Server-Side JavaScriptMasudul Hasan Masud Bhuiyan, Adithya Srinivas Parthasarathy, Nikos Vasilakis, Michael Pradel 等ICSE 2023 · 被引用 20 次
- Undefined-oriented Programming: Detecting and Chaining Prototype Pollution Gadgets in Node.js Template Engines for Malicious ConsequencesZhengyu Liu, Kecheng An, Yinzhi CaoS&P 2024 · 被引用 17 次
- Efficient Static Vulnerability Analysis for JavaScript with Multiversion Dependency GraphsMafalda Ferreira, Miguel Monteiro, Tiago Brito, Miguel E. Coimbra 等PLDI 2024 · 被引用 13 次
- Cerberus: Query-driven Scalable Vulnerability Detection in OAuth Service Provider ImplementationsTamjid Al Rahat, Yu Feng, Yuan TianCCS 2022 · 被引用 12 次
它引用的顶会 Paper16
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 被引用 125 次
- AdGraph: A Graph-Based Approach to Ad and Tracker BlockingUmar Iqbal, Peter Snyder, Shitong Zhu, Benjamin Livshits 等S&P 2020 · 被引用 112 次
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 被引用 91 次
- HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTsAurore Fass, Michael Backes, Ben StockCCS 2019 · 被引用 78 次
相关 Paper
- Automated Exploit Generation for Node.js PackagesFilipe Marques, Mafalda Ferreira, André Nascimento, Miguel E. Coimbra 等PLDI 2025 · 被引用 5 次
- Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style VulnerabilityMingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo 等S&P 2023
- Bullseye: Detecting Prototype Pollution in NPM Packages with Proof of Concept ExploitsTariq Houis, Shaoqi Jiang, Mohammad Mannan, Amr YoussefNDSS 2026 · 被引用 2 次
- Abusing Hidden Properties to Attack the Node.js EcosystemFeng Xiao, Jianwei Huang, Yichang Xiong, Guangliang Yang 等USENIX Security 2021 · 被引用 35 次
- Modular call graph construction for security scanning of Node.js applicationsBenjamin Barslev Nielsen, Martin Toldam Torp, Anders MøllerISSTA 2021 · 被引用 47 次
