Skip to search boxSkip to navigationSkip to main content

Fixing Vulnerabilities Automatically with Linters

Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-review

Open access

Publication Information

Output type

Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-review

Original language

English

Publication milestones

  • Published - 2020

Publication status

Published - 2020

Publisher

Springer, United States, Germany

Host publication title

14th International Conference on Network and System Security

Abstract

Static analysis is a tried-and-tested approach to eliminate vulnerabilities in software. However, despite decades of successful use by experts, mainstream programmers often deem static analysis too costly to use. Mainstream programmers do routinely use linters, which are static analysis tools geared towards identifying simple bugs and stylistic issues in software. Can linters serve as a medium for delivering vulnerability detection to mainstream programmers?
We investigate the extent of which linters can be leveraged to help programmers write secure software. We present new rules for ESLint that detect---and automatically fix---certain classes of cross-site scripting, SQL injection, and misconfiguration vulnerabilities in JavaScript. Evaluating our experience, we find that there is enormous potential in using linters to eliminate vulnerabilities in software, due to the relative ease with which linter rules can be implemented and shared to the community. We identify several open challenges, including third-party library dependencies and linter configuration, and propose ways to address them.

Publication metrics

PlumX, opens in new tab

Captures
20
Citations
1

Related Event

Title

Network and System Security

Event type

Conference

Degree of recognition

International event

Date

25/11/2020 - 27/11/2020

Location

MelbourneAustralia