亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

Methods and Benchmark for Detecting Cryptographic API Misuses in Python

Python(编程语言) 计算机科学 密码学 水准点(测量) 程序设计语言 计算机安全 地理 大地测量学
作者
Miles Frantz,Ya Xiao,Tanmoy Sarkar Pias,Na Meng,Danfeng Yao
出处
期刊:IEEE Transactions on Software Engineering [IEEE Computer Society]
卷期号:50 (5): 1118-1129 被引量:3
标识
DOI:10.1109/tse.2024.3377182
摘要

Extensive research has been conducted to explore cryptographic API misuse in Java. However, despite the tremendous popularity of the Python language, uncovering similar issues has not been fully explored. The current static code analysis tools for Python are unable to scan the increasing complexity of the source code. This limitation decreases the analysis depth, resulting in more undetected cryptographic misuses. In this research, we propose Cryptolation, a Static Code Analysis (SCA) tool that provides security guarantees for complex Python cryptographic code. Most existing analysis tools for Python solely focus on specific Frameworks such as Django or Flask. However, using a SCA approach, Cryptolation focuses on the language and not any framework. Cryptolation performs an inter-procedural data-flow analysis to handle many Python language features through variable inference (statically predicting what the variable value is) and SCA. Cryptolation covers 59 Python cryptographic modules and can identify 18 potential cryptographic misuses that involve complex language features. In this paper, we also provide a comprehensive analysis and a state-of-the-art benchmark for understanding the Python cryptographic Application Program Interface (API) misuses and their detection. Our state-of-the-art benchmark PyCryptoBench includes 1,836 Python cryptographic test cases that covers both 18 cryptographic rules and five language features. PyCryptoBench also provides a framework for evaluating and comparing different cryptographic scanners for Python. To evaluate the performance of our proposed cryptographic Python scanner, we evaluated Cryptolation against three other state-of-the-art tools: Bandit, Semgrep, and Dlint. We evaluated these four tools using our benchmark PyCryptoBench and manual evaluation of (four Top-Ranked and 939 Un-Ranked) real-world projects. Our results reveal that, overall, Cryptolation achieved the highest precision throughout our testing; and the highest accuracy on our benchmark. Cryptolation had 100% precision on PyCryptoBench, and the highest precision on the real-world projects.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
19秒前
三三发布了新的文献求助10
24秒前
aa完成签到,获得积分10
40秒前
44秒前
47秒前
wangdong发布了新的文献求助10
48秒前
pete发布了新的文献求助10
50秒前
wangdong完成签到,获得积分10
57秒前
星辰大海应助pete采纳,获得10
1分钟前
大模型应助三三采纳,获得10
1分钟前
aa发布了新的文献求助10
1分钟前
1分钟前
1分钟前
科研通AI2S应助科研通管家采纳,获得10
1分钟前
情怀应助科研通管家采纳,获得10
1分钟前
杨飞完成签到,获得积分10
1分钟前
怡然的灵波完成签到,获得积分20
1分钟前
1分钟前
ucas大菠萝完成签到,获得积分10
1分钟前
三三发布了新的文献求助10
1分钟前
1分钟前
希望天下0贩的0应助三三采纳,获得10
1分钟前
1分钟前
1分钟前
2分钟前
2分钟前
2分钟前
2分钟前
2分钟前
NexusExplorer应助darcyz采纳,获得10
2分钟前
爆米花应助darcyz采纳,获得10
2分钟前
桐桐应助darcyz采纳,获得10
2分钟前
2分钟前
2分钟前
2分钟前
2分钟前
2分钟前
2分钟前
2分钟前
2分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Psychopathic Traits and Quality of Prison Life 1000
Development Across Adulthood 1000
Chemistry and Physics of Carbon Volume 18 800
The formation of Australian attitudes towards China, 1918-1941 660
Signals, Systems, and Signal Processing 610
天津市智库成果选编 600
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6451227
求助须知:如何正确求助?哪些是违规求助? 8263198
关于积分的说明 17606061
捐赠科研通 5515989
什么是DOI,文献DOI怎么找? 2903573
邀请新用户注册赠送积分活动 1880624
关于科研通互助平台的介绍 1722625