USENIX Security2024Top-tier venue
Inference of Error Specifications and Bug Detection Using Structural Similarities
Nora Dossche, Bart Coppens
Abstract
Error-handling code is a crucial part of software to ensure stability and security. We propose a novel approach to automatically infer error specifications for system software without a priori domain knowledge, while still achieving a high recall and precision, and leverage this information to find missing error checks, incorrect error checks, and error propagation bugs. We implemented this approach in a tool called ESSS. In our evaluation, we demonstrate the effectiveness and efficiency of our approach on 7 well-tested, widely-used open-source software projects: OpenSSL, OpenSSH, PHP, zlib, libpng, freetype2, and libwebp. First, we show that ESSS is scalable with regards to both computation time as well as memory usage. Then, we show that the inferred error specifications are more precise than those inferred by the prior state of the art, EESI. Then, we evaluate the effectiveness of our tool to find bugs. On the aforementioned open source projects, our tool reports 827 potential bugs in total for all 7 projects combined. We manually categorised these 827 issues into 279 false positives and 541 true positives. Finally, we evaluate false negatives on the APIMU4C dataset, and compare against CodeQL and APISan.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9cb73a06-1880-4a61-9085-b98a2dffde88Cited by top-tier papers1
Ask how each one uses itRelated papers
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang et al.USENIX Security 2016 · 107 citations
- Automatically Detecting Error Handling Bugs Using Error SpecificationsSuman Jana, Yuan Jochen Kang, Samuel Roth, Baishakhi RayUSENIX Security 2016 · 79 citations
- Uncovering the iceberg from the tip: Generating API Specifications for Bug Detection via Specification Propagation AnalysisMiaoqian Lin, Kai Chen, Yi Yang, Jinghua LiuNDSS 2025
- Detecting API Post-Handling Bugs Using Code and Description in PatchesMiaoqian Lin, Kai Chen, Yang XiaoUSENIX Security 2023
- ARBITRAR: User-Guided API Misuse DetectionZiyang Li, Aravind Machiry, Binghong Chen, Mayur Naik et al.S&P 2021 · 30 citations
