Efficient Static Vulnerability Analysis for JavaScript with Multiversion Dependency Graphs
Mafalda Ferreira, Miguel Monteiro, Tiago Brito, Miguel E. Coimbra, Nuno Santos, Limin Jia, José Fragoso Santos
摘要
While static analysis tools that rely on Code Property Graphs (CPGs) to detect security vulnerabilities have proven effective, deciding how much information to include in the graphs remains a challenge. Including less information can lead to a more scalable analysis but at the cost of reduced effectiveness in identifying vulnerability patterns, potentially resulting in classification errors. Conversely, more information in the graph allows for a more effective analysis but may affect scalability. For example, scalability issues have been recently highlighted in ODGen, the state-of-the-art CPG-based tool for detecting Node.js vulnerabilities.
This paper examines a new point in the design space of CPGs for JavaScript vulnerability detection. We introduce the Multiversion Dependency Graph (MDG), a novel graph-based data structure that captures the state evolution of objects and their properties during program execution. Compared to the graphs used by ODGen, MDGs are significantly simpler without losing key information needed for vulnerability detection. We implemented Graph.js, a new MDG-based static vulnerability scanner specialized in analyzing npm packages and detecting taint-style and prototype pollution vulnerabilities. Our evaluation shows that Graph.js outperforms ODGen by significantly reducing both the false negatives and the analysis time. Additionally, we have identified 49 previously undiscovered vulnerabilities in npm packages. CCS Concepts: • Software and its engineering → Software verification and validation; Automated static analysis; • Security and privacy → Software and application security; • Theory of computation → Program analysis.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Automated Exploit Generation for Node.js PackagesFilipe Marques, Mafalda Ferreira, André Nascimento, Miguel E. Coimbra 等PLDI 2025 · 被引用 5 次
- CoSSJIT: Combining Static Analysis and Speculation in JIT CompilersAditya Anand, Vijay Sundaresan, Daryl Maier, Manas ThakurOOPSLA 2025 · 被引用 4 次
- Skyler: Static Analysis for Predicting API-Driven Costs in Serverless ApplicationsBernardo Ribeiro, Mafalda Ferreira, José Fragoso Santos, Rodrigo Bruno 等ASPLOS 2026
- JavaScript Pointer Analysis with Adaptive Heap AbstractionWenyuan Xu, Anders MøllerFSE 2026
它引用的顶会 Paper18
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 被引用 125 次
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 被引用 91 次
- HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTsAurore Fass, Michael Backes, Ben StockCCS 2019 · 被引用 78 次
- Deemon: Detecting CSRF with Dynamic Analysis and Property GraphsGiancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes 等CCS 2017 · 被引用 74 次
相关 Paper
- Mining Node.js Vulnerabilities via Object Dependence Graph and QuerySong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoUSENIX Security 2022
- Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style VulnerabilityMingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo 等S&P 2023
- Modular call graph construction for security scanning of Node.js applicationsBenjamin Barslev Nielsen, Martin Toldam Torp, Anders MøllerISSTA 2021 · 被引用 47 次
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen 等ICSE 2022 · 被引用 94 次
- Extracting taint specifications for JavaScript librariesCristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller 等ICSE 2020 · 被引用 34 次
