Cryptbara: Dependency-Guided Detection of Python Cryptographic API Misuses
Seogyeong Cho, Seungeun Yu, Seunghoon Woo
摘要
We present Cryptbara, a precise approach for detecting Python cryptographic API misuses. Cryptographic APIs are widely used to ensure data security, but their improper use can inadvertently compromise the security of entire systems. Existing approaches often fail to capture how cryptographic objects are initialized and used across inter-procedural contexts, limiting their ability to detect context-dependent misuses. In contrast, the key innovation of Cryptbara lies in synergistically combining static dependency analysis with LLM reasoning guided by dependency context, enabling context-sensitive misuse detection. To this end, Cryptbara extracts intra- and inter-procedural dependencies from Python code and encodes them into context-rich prompts, allowing the LLM to perform semantically-aware analysis despite syntactic complexity. We evaluated Cryptbara on two benchmarks containing real-world cryptographic API misuses. Cryptbara achieved F1 scores of 95.43% and 84%, outperforming existing approaches that achieved at most 73.68% and 70.59% F1 scores, respectively. Cryptbara further demonstrated its practical impact by discovering previously unknown misuses in popular Python repositories, with 22 representative cases reported to and confirmed by maintainers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper18
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 被引用 388 次
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim 等S&P 2016 · 被引用 325 次
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel 等S&P 2017 · 被引用 261 次
- CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsSazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon 等CCS 2019 · 被引用 159 次
- Identifying Open-Source License Violation and 1-day Security Risk at Large ScaleRuian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim 等CCS 2017 · 被引用 126 次
相关 Paper
- Beyond Static Pattern Matching? Rethinking Automatic Cryptographic API Misuse Detection in the Era of LLMsYifan Xia, Zichen Xie, Peiyu Liu, Kangjie Lu 等ISSTA 2025 · 被引用 2 次
- Gopher: High-Precision and Deep-Dive Detection of Cryptographic API Misuse in the Go EcosystemYuexi Zhang, Bingyu Li, Jingqiang Lin, Linghui Li 等CCS 2024 · 被引用 2 次
- Towards Precise Reporting of Cryptographic MisusesYikang Chen, Yibo Liu, Ka Lok Wu, Duc Viet Le 等NDSS 2024
- JScamd: An Automated Static Taint Analysis Framework for Detecting Cryptographic API Misuses in JavaScriptShijie Jia, Bowen Xu, Yuan Ma, Yingjiao Niu 等USENIX Security 2026
- Improving Data Leakage Detection in Machine Learning Notebooks through Static Slicing and Structured LLM PromptsTaha Draoui, Mohamed Wiem Mkaouer, Christian D. NewmanFSE 2026 · 被引用 1 次
