Skip to main content
QUICK REVIEW

[논문 리뷰] On the Threat of npm Vulnerable Dependencies in Node.js Applications

Mahmoud Alfadel, Diego Elias Costa|arXiv (Cornell University)|2020. 09. 18.
Security and Verification in Computing참고 문헌 25인용 수 11
한 줄 요약

이 연구는 실세계 Node.js 애플리케이션에서 npm의 취약한 종속성의 실제 위협을 분류하여 분석함으로써, 취약성을 저위험(알 수 없음), 중위험(보고되었지만 공개되지 않음), 고위험(공개된 바 있음)의 세 가지 위협 수준으로 나누어 6,673개의 성숙한 오픈소스 애플리케이션을 분석함. 그 결과, 취약한 종속성의 94.91%가 저위협으로 평가되었으며, 대부분의 고위협 사례는 애플리케이션의 업데이트 미흡에서 기인함을 확인함.

ABSTRACT

Software vulnerabilities have a large negative impact on the software systems that we depend on daily. Reports on software vulnerabilities always paint a grim picture, with some reports showing that 83% of organizations depend on vulnerable software. However, our experience leads us to believe that, in the grand scheme of things, these software vulnerabilities may have less impact than what is reported. Therefore, we perform a study to better understand the threat of npm vulnerable packages used in Node.js applications. We define three threat levels for vulnerabilities in packages, based on their lifecycle, where a package vulnerability is assigned a low threat level if it was hidden or still unknown at the time it was used in the dependent application (t), medium threat level if the vulnerability was reported but not yet published at t, and high if it was publicly announced at t. Then, we perform an empirical study involving 6,673 real-world, active, and mature open source Node.js applications. Our findings show that although 67.93% of the examined applications depend on at least one vulnerable package, 94.91% of the vulnerable packages in those affected applications are classified as having low threat. Moreover, we find that in the case of vulnerable packages classified as having high threat, it is the application's lack of updating that makes them vulnerable, i.e., it is not the existence of the vulnerability that is the real problem. Furthermore, we verify our findings at different stages of the application's lifetime and find that our findings still hold. Our study argues that when it comes to software vulnerabilities, things may not be as bad as they seem and that considering vulnerability threat is key.

연구 동기 및 목표

  • 실세계 Node.js 애플리케이션에서 npm 취약한 종속성의 실제 위협을 이해하고, 모든 취약성이 동일하게 위험하다는 가정을 도전함.
  • 기존 연구의 격차를 메우기 위해 단지 취약성 존재 여부를 넘어서, 생명주기 단계에 기반한 실제 위협 수준을 분석함.
  • 수정이 가능함에도 불구하고 일부 애플리케이션이 고위협 취약한 종속성을 사용하게 되는 이유를 조사함.
  • 취약성 위협 수준이 애플리케이션 개발 생명주기 동안 어떻게 변화하는지 평가함.
  • 소프트웨어 생태계에서 종속성의 실제 위험을 평가하기 위한 위협 인식 기반 프레임워크 제공.

제안 방법

  • 취약성의 생명주기에 기반해 저위험(알 수 없음), 중위험(보고되었지만 공개되지 않음), 고위험(공개된 바 있음)의 세 단계로 위협 분류 체계를 정의함.
  • 공개 저장소에서 6,673개의 성숙하고 활성화된 오픈소스 Node.js 애플리케이션을 수집하고, package.json 파일을 사용해 직접 종속성을 추출함.
  • npm 고위험 공고 데이터셋을 활용해 각 종속성을 취약성 상태와 매핑함. 이 데이터셋은 공식적인 취약성 기록을 제공함.
  • 버전 기록과 취약성 공개 시점의 시간적 흐름을 분석하여, 취약성 위협 수준의 변화를 애플리케이션 버전 간 추적함.
  • 애플리케이션 개발의 다양한 단계에서 위협 수준 추세를 평가하기 위해 종단적 분석 수행함.
  • 수정이 가능했음에도 적용되지 않은 경우를 확인함으로써 고위협 취약성의 근본 원인 규명함.

실험 결과

연구 질문

  • RQ1RQ1: 종속성의 사용 시점에 따라 취약한 종속성의 위협 수준은 어떻게 평가되는가? (생명주기 단계 기반)
  • RQ2RQ2: 애플리케이션의 개발 역사 전반에 걸쳐 취약한 종속성의 위협 수준은 어떻게 변화하는가?
  • RQ3RQ3: 수정이 가능함에도 불구하고 일부 애플리케이션이 고위협 취약한 종속성을 사용하게 되는 이유는 무엇인가?

주요 결과

  • 조사한 6,673개의 실세계 Node.js 애플리케이션 중 67.93%가 최소한 하나의 취약한 패키지에 의존함으로써 광범위한 노출이 있음을 시사함.
  • 이 애플리케이션 내 전체 취약한 종속성의 94.91%가 저위협으로 분류되었으며, 이는 사용 시점에 알려지지 않았거나 공개되지 않은 상태였음을 의미함.
  • 고위협 취약성의 90.8%는 애플리케이션의 수동성 때문이었으며, 특히 수정 버전이 가용한 상태에서도 업데이트하지 않은 경우가 대부분임.
  • 저위협 우세성의 경향은 애플리케이션 개발의 모든 단계에서 유지되어, 위협 분류가 시간에 따라 안정적임을 확인함.
  • 이 연구는 모든 취약성이 동일하게 위험한 것은 아니며, 실제 위협은 취약성 존재 여부보다는 공개 시점과 업데이트 행동에 따라 달라짐을 확인함.
  • 연구 결과는 종종 종합 보고서에서 위협 위험이 과대평가되고 있으며, 실제 공격 가능성에 영향을 미치는 핵심 요소로 애플리케이션 유지보수 관행이 있음을 시사함.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.