CrySL: An Extensible Approach to Validating the Correct Usage of Cryptographic APIs

CrySL: An Extensible Approach to Validating the Correct Usage of Cryptographic APIs
复制标题

DOI:
10.4230/lipics.ecoop.2018.10
复制
发表时间:
2018-07
影响因子:
7.4
通讯作者:
Stefan Krüger;Johannes Späth;Karim Ali;E. Bodden;M. Mezini
Stefan Krüger;Johannes Späth;Karim Ali;E. Bodden;M. Mezini
中科院分区:
计算机科学1区
文献类型:
--
作者:
Stefan Krüger;Johannes Späth;Karim Ali;E. Bodden;M. Mezini

文献摘要

相似文献

从经验上讲,各种研究表明,大多数Java和Android应用程序滥用加密库,从而造成了毁灭性的数据安全性。在开发过程的早期发现这种滥用至关重要。为了检测密码学的滥用,必须首先定义安全用途,这是一个主要由密码学专家掌握的过程,而不是由开发人员掌握的。在本文中,我们提出了Crysl,这是一种弥合密码专家与开发人员之间认知差距的规范语言。 Crysl使密码学专家能够指定其提供的加密库的安全用法。我们已经实施了一个编译器,该编译器将这种CRYSL规范转化为上下文敏感和流动敏感的需求驱动静态分析。然后,该分析通过自动检查给定的Java或Android应用程序以符合CRYSL编码的规则来帮助开发人员。我们为Java加密体系结构(JCA)设计了广泛的CRYSL规则集,并通过分析了10,000个当前的Android应用程序以及MAVEN CENTRAL上的所有204,788当前Java软件伪像,从而对其进行了经验评估。我们的结果表明,滥用加密API仍然很普遍,其中95%的应用程序和63%的Maven文物包含至少一种滥用。我们易于扩展的CRYSL规则集比以前包含硬编码规则的特殊用途工具涵盖了更多的违规行为,同时仍提供更精确的分析。
Various studies have empirically shown that the majority of Java and Android applications misuse cryptographic libraries, causing devastating breaches of data security. It is crucial to detect such misuses early in the development process. To detect cryptography misuses, one must define secure uses first, a process mastered primarily by cryptography experts but not by developers. In this paper, we present CrySL, a specification language for bridging the cognitive gap between cryptography experts and developers. CrySL enables cryptography experts to specify the secure usage of the cryptographic libraries they provide. We have implemented a compiler that translates such CrySL specification into a context-sensitive and flow-sensitive demand-driven static analysis. The analysis then helps developers by automatically checking a given Java or Android app for compliance with the CrySL-encoded rules. We have designed an extensive CrySL rule set for the Java Cryptography Architecture (JCA), and empirically evaluated it by analyzing 10,000 current Android apps and all 204,788 current Java software artefacts on Maven Central. Our results show that misuse of cryptographic APIs is still widespread, with 95 percent of apps and 63 percent of Maven artefacts containing at least one misuse. Our easily extensible CrySL rule set covers more violations than previous special-purpose tools that contain hard-coded rules, while still offering a more precise analysis.