AURC: Detecting Errors in Program Code and Documentation
Peiwei Hu, Ruigang Liang, Ying Cao, Kai Chen, Runze Zhang
摘要
Error detection in program code and documentation is a critical problem in computer security. Previous studies have shown promising vulnerability discovery performance by extensive code or document-guided analysis. However, the state-of-the-arts have the following significant limitations: (i) They assume the documents are correct and treat the code that violates documents as bugs, thus cannot find documents' defects and code's bugs if APIs have defective documents or no documents. (ii) They utilize majority voting to judge the inconsistent code snippets and treat the deviants as bugs, thus cannot cope with situations where correct usage is minor or all use cases are wrong.
In this paper, we present AURC, a static framework for detecting code bugs of incorrect return checks and document defects. We observe that three objects participate in the API invocation, the document, the caller (code that invokes API), and the callee (the source code of API). Mutual corroboration of these three objects eliminates the reliance on the above assumptions. AURC contains a context-sensitive backward analysis to process callees, a pre-trained model-based document classifier, and a container that collects conditions of if statements from callers. After cross-checking the results from callees, callers, and documents, AURC delivers them to the correctness inference module to infer the defective one. We evaluated AURC on ten popular codebases. AURC discovered 529 new bugs that can lead to security issues like heap buffer overflow and sensitive information leakage, and 224 new document defects. Maintainers acknowledge our findings and have accepted 222 code patches and 76 document patches.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- DeGPT: Optimizing Decompiler Output with LLMPeiwei Hu, Ruigang Liang, Kai ChenNDSS 2024
- Uncovering the iceberg from the tip: Generating API Specifications for Bug Detection via Specification Propagation AnalysisMiaoqian Lin, Kai Chen, Yi Yang, Jinghua LiuNDSS 2025
- Generating API Parameter Security Rules with LLM for API Misuse DetectionJinghua Liu, Yi Yang, Kai Chen, Miaoqian LinNDSS 2025
- Patch-Guided Vulnerability Detection: Extracting Java API Security Rules via Attack–Defense Cross-AnalysisBofei Chen, Shuang Liao, Lei Zhang, Chibin Zhang 等USENIX Security 2026
它引用的顶会 Paper10
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang 等USENIX Security 2016 · 被引用 107 次
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 被引用 97 次
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes 等S&P 2018 · 被引用 95 次
- Automatically Detecting Error Handling Bugs Using Error SpecificationsSuman Jana, Yuan Jochen Kang, Samuel Roth, Baishakhi RayUSENIX Security 2016 · 被引用 79 次
- API-Misuse Detection Driven by Fine-Grained API-Constraint Knowledge GraphXiaoxue Ren, Xinyuan Ye, Zhenchang Xing, Xin Xia 等ASE 2020 · 被引用 62 次
相关 Paper
- Detecting API Post-Handling Bugs Using Code and Description in PatchesMiaoqian Lin, Kai Chen, Yang XiaoUSENIX Security 2023
- APICAD: Augmenting API Misuse Detection through Specifications from Code and DocumentsXiaoke Wang, Lei ZhaoICSE 2023 · 被引用 7 次
- RTFM! Automatic Assumption Discovery and Verification Derivation from Library Document for API Misuse DetectionTao Lv, Ruishi Li, Yi Yang, Kai Chen 等CCS 2020 · 被引用 27 次
- Detecting Missed Security Operations Through Differential Checking of Object-based Similar PathsDinghao Liu, Qiushi Wu, Shouling Ji, Kangjie Lu 等CCS 2021 · 被引用 11 次
- Finding and Understanding Defects in Static Analyzers by Constructing Automated OraclesWeigang He, Peng Di, Mengli Ming, Chengyu Zhang 等FSE 2024 · 被引用 6 次
