ARBITRAR: User-Guided API Misuse Detection
Ziyang Li, Aravind Machiry, Binghong Chen, Mayur Naik, Ke Wang, Le Song
Abstract
Software APIs exhibit rich diversity and complexity which not only renders them a common source of programming errors but also hinders program analysis tools for checking them. Such tools either expect a precise API specification, which requires program analysis expertise, or presume that correct API usages follow simple idioms that can be automatically mined from code, which suffers from poor accuracy. We propose a new approach that allows regular programmers to find API misuses. Our approach interacts with the user to classify valid and invalid usages of each target API method. It minimizes user burden by employing an active learning algorithm that ranks API usages by their likelihood of being invalid. We implemented our approach in a tool called ARBITRAR for C/C++ programs, and applied it to check the uses of 18 API methods in 21 large real-world programs, including OpenSSL and Linux Kernel. Within just 3 rounds of user interaction on average per API method, ARBITRAR found 40 new bugs, with patches accepted for 18 of them. Moreover, ARBITRAR finds all known bugs reported by a state-of-the-art tool APISAN in a benchmark suite comprising 92 bugs with a false positive rate of only 51.5% compared to APISAN's 87.9%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext de346820-aeed-456a-b080-a6bb2ed45a8aCited by top-tier papers15
- TRACER: Signature-based Static Analysis for Detecting Recurring VulnerabilitiesWooseok Kang, Byoungho Son, Kihong HeoCCS 2022 · 23 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-ProgramsYue Zhang, Yuqing Yang, Zhiqiang LinCCS 2023 · 14 citations
- Sporq: An Interactive Environment for Exploring Code using Query-by-ExampleAaditya Naik, Jonathan Mendelson, Nathaniel Sands, Yuepeng Wang et al.UIST 2021 · 11 citations
- Samba: Detecting SSL/TLS API Misuses in IoT Binary ApplicationsKaizheng Liu, Ming Yang, Zhen Ling, Yuan Zhang et al.INFOCOM 2024 · 3 citations
Builds on6
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang et al.USENIX Security 2016 · 107 citations
- BootStomp: On the Security of Bootloaders in Mobile DevicesNilo Redini, Aravind Machiry, Dipanjan Das, Yanick Fratantonio et al.USENIX Security 2017 · 66 citations
- Provenance-guided synthesis of Datalog programsMukund Raghothaman, Jonathan Mendelson, David Zhao, Mayur Naik et al.POPL 2020 · 49 citations
- VulDeePecker: A Deep Learning-Based System for Vulnerability DetectionZhen Li, Deqing Zou, Shouhuai Xu, Xinyu Ou et al.NDSS 2018
- FuzzGen: Automatic Fuzzer GenerationKyriakos K. Ispoglou, Daniel Austin, Vishwath Mohan, Mathias PayerUSENIX Security 2020
Related papers
- APICAD: Augmenting API Misuse Detection through Specifications from Code and DocumentsXiaoke Wang, Lei ZhaoICSE 2023 · 7 citations
- SFA-Miner: Mining Path-Sensitive API Usage Patterns Via Symbolic Finite AutomataJiasheng Jiang, Mingwei Zheng, Qingkai Shi, Xiangyu ZhangS&P 2026 · 1 citation
- APP-Miner: Detecting API Misuses via Automatically Mining API Path PatternsJiasheng Jiang, Jingzheng Wu, Xiang Ling, Tianyue Luo et al.S&P 2024 · 8 citations
- Uncovering the iceberg from the tip: Generating API Specifications for Bug Detection via Specification Propagation AnalysisMiaoqian Lin, Kai Chen, Yi Yang, Jinghua LiuNDSS 2025
- Inference of Error Specifications and Bug Detection Using Structural SimilaritiesNora Dossche, Bart CoppensUSENIX Security 2024 · 2 citations
