Dynamic Security Analysis of JavaScript: Are We There Yet?
Stefano Calzavara, Samuele Casarin, Riccardo Focardi
摘要
In this paper, we systematically evaluate the effectiveness of existing tools for the dynamic security analysis of client-side JavaScript, focusing in particular on information flow control. Each tool is evaluated in terms of: (𝑖) compatibility, i.e., the ability to process and analyze existing scripts without breaking; (𝑖𝑖) transparency, i.e., the ability to preserve the original script semantics when security enforcement is not necessary; (𝑖𝑖𝑖) coverage, i.e., the effectiveness in terms of number of detected information flows; (𝑖𝑣) performance, i.e., the computational overhead introduced by the analysis. Our investigation shows that most of the existing analysis tools are incompatible with the modern Web and the compatibility issues affecting them are not easily fixed. Moreover, transparency issues abound and make us question analysis correctness. This is also confirmed by our coverage evaluation, showing that some tools are unable to detect any information flow on real-world websites, while the remaining tools report significantly different outputs. Finally, we observe that the computational overhead of analysis tools may be significant and can exceed 30x. In the end, out of all the evaluated tools, just one of them (Project Foxhound) is effective enough for practical adoption at scale. CCS Concepts • Security and privacy → Web application security; Software security engineering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper6
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- Reproducibility and Replicability of Web Measurement StudiesNurullah Demir, Matteo Große-Kampmann, Tobias Urban, Christian Wressnegger 等WWW 2022 · 被引用 47 次
- U Can't Debug This: Detecting JavaScript Anti-Debugging Techniques in the WildMarius Musch, Martin JohnsUSENIX Security 2021 · 被引用 8 次
- PanoptiChrome: A Modern In-browser Taint Analysis FrameworkRahul Kanyal, Smruti R. SarangiWWW 2024 · 被引用 5 次
相关 Paper
- Finding client-side business flow tampering vulnerabilitiesI Luk Kim, Yunhui Zheng, Hogun Park, Weihang Wang 等ICSE 2020 · 被引用 14 次
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer 等NDSS 2018 · 被引用 84 次
- Extracting taint specifications for JavaScript librariesCristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller 等ICSE 2020 · 被引用 34 次
- Jasmine: Scale up JavaScript Static Security Analysis with Computation-based Semantic ExplanationFeng Xiao, Zhongfu Su, Guangliang Yang, Wenke LeeS&P 2024
- Testability Tarpits: the Impact of Code Patterns on the Security Testing of Web ApplicationsFeras Al Kassar, Giulia Clerici, Luca Compagna, Davide Balzarotti 等NDSS 2022
