Runtime Verification of Crypto APIs: An Empirical Study

Runtime Verification of Crypto APIs: An Empirical Study
复制标题

DOI:
10.1109/tse.2023.3301660
复制
发表时间:
2023-10
影响因子:
7.4
通讯作者:
Adriano Torres;P. Costa;L. Amaral;Jonata T. Pastro;R. Bonifácio;Marcelo d’Amorim;Owolabi Legunsen;E. Bodden;Edna Dias Canedo
Adriano Torres;P. Costa;L. Amaral;Jonata T. Pastro;R. Bonifácio;Marcelo d’Amorim;Owolabi Legunsen;E. Bodden;Edna Dias Canedo
中科院分区:
计算机科学1区
文献类型:
--
作者:
Adriano Torres;P. Costa;L. Amaral;Jonata T. Pastro;R. Bonifácio;Marcelo d’Amorim;Owolabi Legunsen;E. Bodden;Edna Dias Canedo

文献摘要

相似文献

滥用加密(crypto) api是安全漏洞的一个值得注意的原因。出于这个原因,最近提出了静态分析器来检测加密API的滥用。它们的优点和缺点各不相同,而且它们可能会遗漏错误。由于静态分析器的固有局限性,本文报告了一项关于运行时验证(RV)作为基于动态分析的加密API误用检测替代方案的研究。RV监控程序运行是否符合正式规范;结果表明,该方法能够有效地提高软件测试的bug发现能力。我们专注于流行的JCA加密API,并在静态分析器中基于专家验证的规则编写了22个RV规范。我们在五个基准测试中运行测试时监视这些规范。最后,我们将基于rv的方法RVSec的准确性与三种最先进的加密API滥用检测器(CogniCrypt, CryptoGuard和CryLogger)的准确性进行了比较。结果表明,RVSec在四个基准测试中具有更高的准确性,并且在第五个基准测试中与CryptoGuard相当。总体而言,RVSec实现了95%的平均${\boldsymbol{F}}_{1}$ f1测量,而CogniCrypt, CryptoGuard和CryLogger分别为83%,78%和86%。我们强调了这些工具的优势和局限性,并表明RV对于检测加密API的滥用是有效的。我们还讨论了静态和动态分析如何在检测加密API滥用方面相互补充。
Misuse of cryptographic (crypto) APIs is a noteworthy cause of security vulnerabilities. For this reason, static analyzers were recently proposed for detecting crypto API misuses. They differ in strengths and weaknesses, and they might miss bugs. Motivated by the inherent limitations of static analyzers, this article reports on a study of runtime verification (RV) as a dynamic-analysis-based alternative for crypto API misuse detection. RV monitors program runs against formal specifications; it was shown to be effective and efficient for amplifying the bug-finding ability of software tests. We focus on the popular JCA crypto API and write 22 RV specifications based on expert-validated rules in a static analyzer. We monitor these specifications while running tests in five benchmarks. Lastly, we compare the accuracy of our RV-based approach, RVSec, with those of three state-of-the-art crypto API misuses detectors: CogniCrypt, CryptoGuard, and CryLogger. Results show that RVSec has higher accuracy in four benchmarks and is on par with CryptoGuard in the fifth. Overall, RVSec achieves an average ${\boldsymbol{F}}_{1}$ F 1 measure of 95%, compared with 83%, 78%, and 86% for CogniCrypt, CryptoGuard, and CryLogger, respectively. We highlight the strengths and limitations of these tools and show that RV is effective for detecting crypto API misuses. We also discuss how static and dynamic analysis can complement each other for detecting crypto API misuses.