2021
DOI: 10.1007/s10207-020-00537-0
|View full text |Cite
|
Sign up to set email alerts
|

DAPP: automatic detection and analysis of prototype pollution vulnerability in Node.js modules

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
5
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
5
2
1
1

Relationship

1
8

Authors

Journals

citations
Cited by 25 publications
(9 citation statements)
references
References 22 publications
0
5
0
Order By: Relevance
“…The authors of [93] also apply dynamic analysis and symbolic execution to detect attacks that leverage hidden properties in client-and server-side JavaScript. There are also academic works that employ static analysis techniques for detecting vulnerabilities in Node.js, but most focus on detecting prototype pollution vulnerabilities [94,95]. ODGen [15] is the only purely static code analysis tool developed by the academia that aims to detect several types of vulnerabilities in Node.js.…”
Section: Related Workmentioning
confidence: 99%
“…The authors of [93] also apply dynamic analysis and symbolic execution to detect attacks that leverage hidden properties in client-and server-side JavaScript. There are also academic works that employ static analysis techniques for detecting vulnerabilities in Node.js, but most focus on detecting prototype pollution vulnerabilities [94,95]. ODGen [15] is the only purely static code analysis tool developed by the academia that aims to detect several types of vulnerabilities in Node.js.…”
Section: Related Workmentioning
confidence: 99%
“…Docker has seized 83 percent of the containerization industry, which is expected to generate $2.7 billion in sales by 2020. In 2018, the Data log estimated that around a quarter of their clients had already used Docker [41].…”
Section: G Dockermentioning
confidence: 99%
“…Due to the prevalence of online services offered by various organizations, websites have become a significant target for cyber-attacks [1]. As a result, extensive research has been conducted on attack methods and defenses against websites [2][3][4][5]. Attacks on websites can be classified into two categories: those targeting web server applications and those targeting website users.…”
Section: Introductionmentioning
confidence: 99%