skip to main content
10.1145/2584469.2584472acmotherconferencesArticle/Chapter ViewAbstractPublication PagesmodularityConference Proceedingsconference-collections
abstract

JavaScript API misuse detection by using typescript

Published:22 April 2014Publication History

ABSTRACT

Static analysis of JavaScript programs to detect errors in them is a challenging task. Especially when the program imports massive JavaScript libraries such as jQuery and MooTools, analyzing the whole program and the libraries is expensive and extremely declines the analysis efficiency. In this paper, we introduce a novel approach to solve the problem by modularizing the analysis. We separate the analysis of JavaScript libraries by using types extracted from their corresponding specifications in TypeScript and the analysis of JavaScript applications by a static analysis framework. We use DefinitelyTyped, an open-source repository that provides TypeScript declaration files of over 300 popular JavaScript libraries, and we extend SAFE, an open-source analysis framework for JavaScript.

References

  1. ECMAScript Language Specification. Edition 5.1. http://www.ecma-international.org/publications/standards/Ecma-262.htm.Google ScholarGoogle Scholar
  2. Christopher Anderson, Paola Giannini, and Sophia Drossopoulou. Towards type inference for JavaScript. In ECOOP 2005. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. Ravi Chugh, Jeffrey A. Meister, Ranjit Jhala, and Sorin Lerner. Staged information flow for JavaScript. In PLDI 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. Douglas Crockford. JSLint. http://www.jslint.com.Google ScholarGoogle Scholar
  5. Salvatore Guarnieri, Marco Pistoia, Omer Tripp, Julian Dolbyand Stephen Teilhet, and Ryan Berg. Saving the world wide web from vulnerable JavaScript. In ISSTA 2011. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. Arjun Guha, Shriram Krishnamurthi, and Trevor Jim. Using static analysis for Ajax intrusion detection. In WWW 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. Phillip Heidegger and Peter Thiemann. Recency types for analyzing scripting languages. In ECOOP 2010. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. Simon Holm Jensen, Anders Møller, and Peter Thiemann. Type analysis for JavaScript. In SAS 2009.Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. PLRG @ KAIST. SAFE: Scalable Analysis Framework for ECMAScript. http://safe.kaist.ac.kr.Google ScholarGoogle Scholar
  10. Hongki Lee, Sooncheol Won, Joonho Jin, Junhee Cho, and Sukyoung Ryu. SAFE: Formal specification and implementation of a scalable analysis framework for ECMAScript. In FOOL 2012.Google ScholarGoogle Scholar
  11. Sergio Maffeis, John C. Mitchell, and Ankur Taly. Isolating JavaScript with filters, rewriting, and wrappers. In ESORICS 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. Microsoft. TypeScript. http://www.typescriptlang.org.Google ScholarGoogle Scholar

Index Terms

  1. JavaScript API misuse detection by using typescript

      Recommendations

      Comments

      Login options

      Check if you have access through your login credentials or your institution to get full access on this article.

      Sign in
      • Published in

        cover image ACM Other conferences
        MODULARITY '14: Proceedings of the companion publication of the 13th international conference on Modularity
        April 2014
        44 pages
        ISBN:9781450327732
        DOI:10.1145/2584469

        Copyright © 2014 Owner/Author

        Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

        Publisher

        Association for Computing Machinery

        New York, NY, United States

        Publication History

        • Published: 22 April 2014

        Check for updates

        Qualifiers

        • abstract

        Acceptance Rates

        Overall Acceptance Rate41of139submissions,29%

      PDF Format

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader