A Server-Side JavaScript Security Architecture for Secure Integration of Third-Party Libraries

Joint Authors

van Ginkel, Neline
De Groef, Willem
Massacci, Fabio
Piessens, Frank

Source

Security and Communication Networks

Issue

Vol. 2019, Issue 2019 (31 Dec. 2019), pp.1-21, 21 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2019-05-02

Country of Publication

Egypt

No. of Pages

21

Main Subjects

Information Technology and Computer Science

Abstract EN

The popularity of the JavaScript programming language for server-side programming has increased tremendously over the past decade.

The Node.js framework is a popular JavaScript server-side framework with an efficient runtime for cloud-based event-driven architectures.

One of its strengths is the presence of thousands of third-party libraries which allow developers to quickly build and deploy applications.

These very libraries are a source of security threats as a vulnerability in one library can (and in some cases did) compromise an entire server.

In order to support the secure integration of libraries, we developed NODESENTRY, the first security architecture for server-side JavaScript.

Our policy enforcement infrastructure supports an easy deployment of web hardening techniques and access control policies on interactions between libraries and their environment, including any dependent library.

We discuss the design and implementation of NODESENTRY and present its performance and security evaluation.

American Psychological Association (APA)

van Ginkel, Neline& De Groef, Willem& Massacci, Fabio& Piessens, Frank. 2019. A Server-Side JavaScript Security Architecture for Secure Integration of Third-Party Libraries. Security and Communication Networks،Vol. 2019, no. 2019, pp.1-21.
https://search.emarefa.net/detail/BIM-1210655

Modern Language Association (MLA)

van Ginkel, Neline…[et al.]. A Server-Side JavaScript Security Architecture for Secure Integration of Third-Party Libraries. Security and Communication Networks No. 2019 (2019), pp.1-21.
https://search.emarefa.net/detail/BIM-1210655

American Medical Association (AMA)

van Ginkel, Neline& De Groef, Willem& Massacci, Fabio& Piessens, Frank. A Server-Side JavaScript Security Architecture for Secure Integration of Third-Party Libraries. Security and Communication Networks. 2019. Vol. 2019, no. 2019, pp.1-21.
https://search.emarefa.net/detail/BIM-1210655

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1210655