SFA-Miner: Mining Path-Sensitive API Usage Patterns Via Symbolic Finite Automata
Jiasheng Jiang, Mingwei Zheng, Qingkai Shi, Xiangyu Zhang
摘要
APIs are fundamental to modern software development, enabling integration across components. However, API misuses remain a significant concern, often stemming from an incomplete understanding of requirements and constraints. These misuses can introduce critical security vulnerabilities, impacting software reliability and safety. Avoiding API misuses requires effective detection and prevention mechanisms. In particular, understanding and enforcing correct API usage patterns play a crucial role in mitigating risks and improving API robustness. Recent work has demonstrated the effectiveness of frequent mining techniques in extracting API usage patterns from code. However, state-of-the-art studies focus only on frequently co-occurring operations, overlooking the pre-conditions of the operations. This paper introduces SFA-Miner (Symbolic Finite Automata Miner), a static analysis framework that extracts the frequent usage patterns of each API under different path conditions as SFAs, where states represent abstract program states and transitions correspond to conditions involving APIs and symbolic variables representing their parameters. The key insight is that APIs can have different usage patterns under different path conditions. Violations of the SFA indicate potential API misuses. Leveraging frequent mining techniques, we extract SFAs hidden within code. We implemented SFA-Miner and evaluated it on four widely used open-source projects: Linux kernel, OpenSSL, FFmpeg, and Apache httpd, identifying 181 API misuses. Additionally, we discovered 1 CVE, demonstrating the tool's effectiveness in detecting API misuses.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- APP-Miner: Detecting API Misuses via Automatically Mining API Path PatternsJiasheng Jiang, Jingzheng Wu, Xiang Ling, Tianyue Luo 等S&P 2024 · 被引用 8 次
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang 等USENIX Security 2016 · 被引用 107 次
- API-Misuse Detection Driven by Fine-Grained API-Constraint Knowledge GraphXiaoxue Ren, Xinyuan Ye, Zhenchang Xing, Xin Xia 等ASE 2020 · 被引用 62 次
- API Misuse Detection via Probabilistic Graphical ModelYunlong Ma, Wentong Tian, Xiang Gao, Hailong Sun 等ISSTA 2024 · 被引用 1 次
- Towards Precise Reporting of Cryptographic MisusesYikang Chen, Yibo Liu, Ka Lok Wu, Duc Viet Le 等NDSS 2024
