D-BUNDLR: Destructing JavaScript Bundles for Effective Static Analysis
Wenyuan Xu, Alexi Turcotte, Cristian-Alexandru Staicu
摘要
Static analysis for vulnerability detection in JavaScript is an extensively studied research area. However, state-of-the-art approaches ignore bundling, an emerging development practice, akin to compilation, which allows developers to merge code from different providers, while also applying optimizations to reduce code size. A typical bundle heavily reuses single-letter identifiers and extensively relies on dynamic JavaScript features to emulate code dependencies, thus, hindering static analysis. In this work, we propose a reverse engineering approach that relies on domain-specific code transformations to unpack bundles and replace reidentified libraries with their source code. Our technique applies lightweight static analysis to dissect bundles into individual components, machine learning to identify libraries, and dynamic analysis to verify that libraries were correctly identified. We implement this approach in a tool called D-Bundlr, and evaluate it by comparing the output of CodeQL (a popular static analysis tool) before and after debundling.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Jack-in-the-box: An Empirical Study of JavaScript Bundling on the Web and its Security ImplicationsJeremy Rack, Cristian-Alexandru StaicuCCS 2023 · 被引用 11 次
- Debun: Detecting Bundled JavaScript Libraries on Web using Property-Order GraphsSeojin Kim, Sungmin Park, Jihyeok ParkASE 2025
- PTDETECTOR: An Automated JavaScript Front-end Library DetectorXinyue Liu, Lukasz ZiarekASE 2023 · 被引用 2 次
- Beware of the Unexpected: Bimodal Taint AnalysisYiu Wai Chow, Max Schäfer, Michael PradelISSTA 2023 · 被引用 13 次
- Best of Both Worlds: Effective Foreign Bridge Identification in V8 Embedders for Security AnalysisGeorgios Alexopoulos, Thodoris Sotiropoulos, Zhendong Su, Dimitris MitropoulosS&P 2026 · 被引用 1 次
