A Comprehensive Benchmark on Java Cryptographic API Misuses


연구 분야: Cryptography



학회: CODASPY '20: Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy


초록

Misuses of cryptographic APIs are prevalent in existing real-world Java code. Some open-sourced and commercial cryptographic vulnerability detection tools exist that capture misuses in Java program. To analyze their efficiency and coverage, we build a comprehensive benchmark named CryptoAPI-Bench that consists of 171 unit test cases. The test cases include basic cases and complex cases. We assess four tools i.e., SpotBugs, CryptoGuard, CrySL, and Coverity using CryptoAPI-Bench and show their relative performance.


Author Profile
Danfeng (Dasphne) Yao

Virginia Tech Blacksburg VA USA

United States
Author Profile
Sharmin Afrose

Virginia Tech Blacksburg VA USA

United States
Author Profile
Sazzadur Rahaman

Virginia Tech Blacksburg VA USA

United States

📄 논문 정보

발행 연도 2020년
인용수 1
출판 국가 United States
사이트 ACM
좋아요 수 0

연관 논문 목록 (277건)