arrow
Return

Study of JavaScript Static Analysis Tools for Vulnerability Detection in Node.js Packages

delete2023-12-01
delete5
delete
OA
AI
T
Tiago Brito *
M
Mafalda Ferreira
M
Miguel Monteiro
P
Pedro Lopes
M
Miguel Barros
J
José Fragoso Santos
N
Nuno Santos
DOI:10.1109/TR.2023.3286301delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
With the emergence of the Node.js ecosystem, JavaScript has become a widely used programming language for implementing server-side web applications. In this article, we present the first empirical study of static code analysis tools for detecting vulnerabilities in Node.js code. To conduct a comprehensive tool evaluation, we created the largest known curated dataset of Node.js code vulnerabilities. We characterized and annotated a set of 957 vulnerabilities by analyzing information contained in npm advisory reports. We tested nine different tools and found that many important vulnerabilities appearing in the OWASP top-10 are not detected by any tool. The three best performing tools combined only detect up to 57.6% of all vulnerabilities in the dataset, but at a very low precision of 0.11%. Our curated dataset offers a new benchmark to help characterize existing Node.js code vulnerabilities and foster the development of better vulnerability detection tools for Node.js code.
Keywords:
Automatic testing
computer security
static analysis

Journal

IEEE Transactions on Reliability cover
IEEE Transactions on Reliability
IF:
5.7
Papers:
2.7K
Citations:
8.5K

Organization

U
universidade de lisboa
Scholars:
3.4W
Papers: 3.1W
Citations: 29