PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 21, 2022104 citationsOpen Access

Demystifying the vulnerability propagation and its evolution via dependency trees in the NPM ecosystem

CLChengwei LiuSCSen ChenLFLingling Fan

Key Points

Key points are not available for this paper at this time.

Abstract

Third-party libraries with rich functionalities facilitate the fast development of JavaScript software, leading to the explosive growth of the NPM ecosystem. However, it also brings new security threats that vulnerabilities could be introduced through dependencies from third-party libraries. In particular, the threats could be excessively amplified by transitive dependencies. Existing research only considers direct dependencies or reasoning transitive dependencies based on reachability analysis, which neglects the NPM-specific dependency resolution rules as adapted during real installation, resulting in wrongly resolved dependencies. Consequently, further fine-grained analysis, such as precise vulnerability propagation and their evolution over time in dependencies, cannot be carried out precisely at a large scale, as well as deriving ecosystem-wide solutions for vulnerabilities in dependencies.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Liu et al. (2022) studied this question.

synapsesocial.com/papers/6a1f1e2d0a1e4e63fe914f34https://doi.org/10.1145/3510003.3510142
Ask AI
Helpful
Bookmark
Share
View Full Paper