Reducing Static Analysis Unsoundness with Approximate Interpretation
Mathias Rud Laursen, Wenyuan Xu, Anders Møller
摘要
Static program analysis for JavaScript is more difficult than for many other programming languages. One of the main reasons is the presence of dynamic property accesses that read and write object properties via dynamically computed property names. To ensure scalability and precision, existing state-of-the-art analyses for JavaScript mostly ignore these operations although it results in missed call edges and aliasing relations. We present a novel dynamic analysis technique named approximate interpretation that is designed to efficiently and fully automatically infer likely determinate facts about dynamic property accesses, in particular those that occur in complex library API initialization code, and how to use the produced information in static analysis to recover much of the abstract information that is otherwise missed. Our implementation of the technique and experiments on 141 real-world Node.js-based JavaScript applications and libraries show that the approach leads to significant improvements in call graph construction. On average the use of approximate interpretation leads to 55.1 % more call edges, 21.8 % more reachable functions, 17.7 % more resolved call sites, and only 1.5 % fewer monomorphic call sites. For 36 JavaScript projects where dynamic call graphs are available, average analysis recall is improved from 75.9 % to 88.1 % with a negligible reduction in precision.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- More Effective JavaScript Breaking Change Detection via Dynamic Object Relation GraphDezhen Kong, Jiakun Liu, Chao Ni, David Lo 等ISSTA 2025
- IRIDIUM: A Framework for Statically Optimizing JavaScript ProgramsMeetesh Kalpesh Mehta, Anirudh Garg, Aneeket Yadav, Manas ThakurOOPSLA 2026
- JavaScript Pointer Analysis with Adaptive Heap AbstractionWenyuan Xu, Anders MøllerFSE 2026
- When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-gamesPei Chen, Geng Hong, Yicheng Qin, Huazhe Wang 等USENIX Security 2026
它引用的顶会 Paper4
- Modular call graph construction for security scanning of Node.js applicationsBenjamin Barslev Nielsen, Martin Toldam Torp, Anders MøllerISSTA 2021 · 被引用 47 次
- Accelerating JavaScript static analysis via dynamic shortcutsJoonyoung Park, Jihyeok Park, Dongjun Youn, Sukyoung RyuFSE 2021 · 被引用 15 次
- Mining Node.js Vulnerabilities via Object Dependence Graph and QuerySong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoUSENIX Security 2022
- Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style VulnerabilityMingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo 等S&P 2023
相关 Paper
- ABSINT-AI: Agentic Heap Abstractions for Abstract InterpretationMichael Wang, Kexin Pei, Armando Solar-LezamaICML 2026
- Extracting taint specifications for JavaScript librariesCristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller 等ICSE 2020 · 被引用 34 次
- On the recall of static call graph construction in practiceLi Sui, Jens Dietrich, Amjed Tahir, George FourtounisICSE 2020 · 被引用 34 次
- Automatically deriving JavaScript static analyzers from specifications using Meta-level static analysisJihyeok Park, Seungmin An, Sukyoung RyuFSE 2022 · 被引用 10 次
- Preventing Dynamic Library Compromise on Node.js via RWX-Based Privilege ReductionNikos Vasilakis, Cristian-Alexandru Staicu, Grigoris Ntousakis, Konstantinos Kallas 等CCS 2021 · 被引用 27 次
