Characterizing JavaScript Security Code Smells

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Kambhampati, Vikas, Mohammed, Nehaz Hussain, Fard, Amin Milani
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866929608555757568
author Kambhampati, Vikas
Mohammed, Nehaz Hussain
Fard, Amin Milani
author_facet Kambhampati, Vikas
Mohammed, Nehaz Hussain
Fard, Amin Milani
contents JavaScript has been consistently among the most popular programming languages in the past decade. However, its dynamic, weakly-typed, and asynchronous nature can make it challenging to write maintainable code for developers without in-depth knowledge of the language. Consequently, many JavaScript applications tend to contain code smells that adversely influence program comprehension, maintenance, and debugging. Due to the widespread usage of JavaScript, code security is an important matter. While JavaScript code smells and detection techniques have been studied in the past, current work on security smells for JavaScript is scarce. Security code smells are coding patterns indicative of potential vulnerabilities or security weaknesses. Identifying security code smells can help developers to focus on areas where additional security measures may be needed. We present a set of 24 JavaScript security code smells, map them to a possible security awareness defined by Common Weakness Enumeration (CWE), explain possible refactoring, and explain our detection mechanism. We implement our security code smell detection on top of an existing open source tool that was proposed to detect general code smells in JavaScript.
format Preprint
id arxiv_https___arxiv_org_abs_2411_19358
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Characterizing JavaScript Security Code Smells
Kambhampati, Vikas
Mohammed, Nehaz Hussain
Fard, Amin Milani
Cryptography and Security
Software Engineering
D.2.3; D.2.3; D.2.3
JavaScript has been consistently among the most popular programming languages in the past decade. However, its dynamic, weakly-typed, and asynchronous nature can make it challenging to write maintainable code for developers without in-depth knowledge of the language. Consequently, many JavaScript applications tend to contain code smells that adversely influence program comprehension, maintenance, and debugging. Due to the widespread usage of JavaScript, code security is an important matter. While JavaScript code smells and detection techniques have been studied in the past, current work on security smells for JavaScript is scarce. Security code smells are coding patterns indicative of potential vulnerabilities or security weaknesses. Identifying security code smells can help developers to focus on areas where additional security measures may be needed. We present a set of 24 JavaScript security code smells, map them to a possible security awareness defined by Common Weakness Enumeration (CWE), explain possible refactoring, and explain our detection mechanism. We implement our security code smell detection on top of an existing open source tool that was proposed to detect general code smells in JavaScript.
title Characterizing JavaScript Security Code Smells
topic Cryptography and Security
Software Engineering
D.2.3; D.2.3; D.2.3
url https://arxiv.org/abs/2411.19358