SFA-Miner: Mining Path-Sensitive API Usage Patterns Via Symbolic Finite Automata
Jiasheng Jiang, Mingwei Zheng, Qingkai Shi, Xiangyu Zhang
Abstract
APIs are fundamental to modern software development, enabling integration across components. However, API misuses remain a significant concern, often stemming from an incomplete understanding of requirements and constraints. These misuses can introduce critical security vulnerabilities, impacting software reliability and safety. Avoiding API misuses requires effective detection and prevention mechanisms. In particular, understanding and enforcing correct API usage patterns play a crucial role in mitigating risks and improving API robustness. Recent work has demonstrated the effectiveness of frequent mining techniques in extracting API usage patterns from code. However, state-of-the-art studies focus only on frequently co-occurring operations, overlooking the pre-conditions of the operations. This paper introduces SFA-Miner (Symbolic Finite Automata Miner), a static analysis framework that extracts the frequent usage patterns of each API under different path conditions as SFAs, where states represent abstract program states and transitions correspond to conditions involving APIs and symbolic variables representing their parameters. The key insight is that APIs can have different usage patterns under different path conditions. Violations of the SFA indicate potential API misuses. Leveraging frequent mining techniques, we extract SFAs hidden within code. We implemented SFA-Miner and evaluated it on four widely used open-source projects: Linux kernel, OpenSSL, FFmpeg, and Apache httpd, identifying 181 API misuses. Additionally, we discovered 1 CVE, demonstrating the tool's effectiveness in detecting API misuses.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get cf8abdf3-3c2d-4b65-9d45-94ff5ce832f7Cited by top-tier papers1
Ask how each one uses itRelated papers
- APP-Miner: Detecting API Misuses via Automatically Mining API Path PatternsJiasheng Jiang, Jingzheng Wu, Xiang Ling, Tianyue Luo et al.S&P 2024 · 8 citations
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang et al.USENIX Security 2016 · 107 citations
- API-Misuse Detection Driven by Fine-Grained API-Constraint Knowledge GraphXiaoxue Ren, Xinyuan Ye, Zhenchang Xing, Xin Xia et al.ASE 2020 · 62 citations
- API Misuse Detection via Probabilistic Graphical ModelYunlong Ma, Wentong Tian, Xiang Gao, Hailong Sun et al.ISSTA 2024 · 1 citation
- Towards Precise Reporting of Cryptographic MisusesYikang Chen, Yibo Liu, Ka Lok Wu, Duc Viet Le et al.NDSS 2024
