Title
Journey to find bugs in JavaScript web applications in the wild.
Abstract
Analyzing real-world JavaScript web applications is a challenging task. On top of understanding the semantics of JavaScript, it requires modeling of web documents, platform objects, and interactions between them. Not only the JavaScript language itself but also its usage patterns are extremely dynamic. JavaScript can generate code and run it during evaluation, and most web applications load JavaScript code dynamically. Such dynamic characteristics of JavaScript web applications make pure static analysis approaches inapplicable. In this talk, we present our attempts to analyze JavaScript web applications in the wild mostly statically using various approaches. From pure JavaScript programs to JavaScript web applications using platform-specific libraries and dynamic code loading, we explain technical challenges in analyzing each of them and how we built an open-source analysis framework for JavaScript, SAFE, that addresses the challenges incrementally. In spite of active research accomplishments in analysis of JavaScript web applications, many issues still remain to be resolved such as events, callback functions, and hybrid web applications. We discuss possible future research directions and open challenges.
Year
DOI
Venue
2016
10.1145/2951913.2976747
ICFP
Field
DocType
Citations 
World Wide Web,Programming language,Dynamic HTML,Computer science,Unobtrusive JavaScript,Ajax,Web application,Dynamic web page,Rich Internet application,JavaScript,Content Security Policy
Conference
0
PageRank 
References 
Authors
0.34
0
1
Name
Order
Citations
PageRank
Sukyoung Ryu118525.77