PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
September 1, 201938 citations

CryptoAPI-Bench: A Comprehensive Benchmark on Java Cryptographic API Misuses

View Full Paper
SASharmin AfroseSRSazzadur RahamanDYDanfeng Yao

Key Points

Key points are not available for this paper at this time.

Abstract

Several studies showed that misuses of cryptographic APIs are common in real-world code (e.g., Apache projects and Android apps). There exist several open-sourced and commercial security tools that automatically screen Java programs to detect misuses. In order to compare their accuracy and security guarantees, we develop a comprehensive benchmark named CryptoAPI-Bench. CryptoAPI-Bench consists of 171 unit test cases that cover basic cases, as well as complex cases, including interprocedural, field sensitive, multiple class test cases, and path sensitive data flow of misuse cases. The benchmark also includes correct cases for testing false positive rates. We evaluate CryptoAPI-Bench on four tools, namely, SpotBugs, CryptoGuard, CrySL, and Coverity and present their performance and comparative analysis. Our benchmark is useful for advancing state-of-the-art solutions in the space of misuse detection.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Afrose et al. (2019) studied this question.

synapsesocial.com/papers/6a1537a7814bf8ec9a4e404bhttps://doi.org/10.1109/secdev.2019.00017
Ask AI
Helpful
Bookmark
Share
View Full Paper