ARBITRAR: User-Guided API Misuse Detection
Ziyang Li, Aravind Machiry, Binghong Chen, Mayur Naik, Ke Wang, Le Song
摘要
Software APIs exhibit rich diversity and complexity which not only renders them a common source of programming errors but also hinders program analysis tools for checking them. Such tools either expect a precise API specification, which requires program analysis expertise, or presume that correct API usages follow simple idioms that can be automatically mined from code, which suffers from poor accuracy. We propose a new approach that allows regular programmers to find API misuses. Our approach interacts with the user to classify valid and invalid usages of each target API method. It minimizes user burden by employing an active learning algorithm that ranks API usages by their likelihood of being invalid. We implemented our approach in a tool called ARBITRAR for C/C++ programs, and applied it to check the uses of 18 API methods in 21 large real-world programs, including OpenSSL and Linux Kernel. Within just 3 rounds of user interaction on average per API method, ARBITRAR found 40 new bugs, with patches accepted for 18 of them. Moreover, ARBITRAR finds all known bugs reported by a state-of-the-art tool APISAN in a benchmark suite comprising 92 bugs with a false positive rate of only 51.5% compared to APISAN's 87.9%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- TRACER: Signature-based Static Analysis for Detecting Recurring VulnerabilitiesWooseok Kang, Byoungho Son, Kihong HeoCCS 2022 · 被引用 23 次
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-ProgramsYue Zhang, Yuqing Yang, Zhiqiang LinCCS 2023 · 被引用 14 次
- Sporq: An Interactive Environment for Exploring Code using Query-by-ExampleAaditya Naik, Jonathan Mendelson, Nathaniel Sands, Yuepeng Wang 等UIST 2021 · 被引用 11 次
- Samba: Detecting SSL/TLS API Misuses in IoT Binary ApplicationsKaizheng Liu, Ming Yang, Zhen Ling, Yuan Zhang 等INFOCOM 2024 · 被引用 3 次
它引用的顶会 Paper6
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang 等USENIX Security 2016 · 被引用 107 次
- BootStomp: On the Security of Bootloaders in Mobile DevicesNilo Redini, Aravind Machiry, Dipanjan Das, Yanick Fratantonio 等USENIX Security 2017 · 被引用 66 次
- Provenance-guided synthesis of Datalog programsMukund Raghothaman, Jonathan Mendelson, David Zhao, Mayur Naik 等POPL 2020 · 被引用 49 次
- VulDeePecker: A Deep Learning-Based System for Vulnerability DetectionZhen Li, Deqing Zou, Shouhuai Xu, Xinyu Ou 等NDSS 2018
- FuzzGen: Automatic Fuzzer GenerationKyriakos K. Ispoglou, Daniel Austin, Vishwath Mohan, Mathias PayerUSENIX Security 2020
相关 Paper
- APICAD: Augmenting API Misuse Detection through Specifications from Code and DocumentsXiaoke Wang, Lei ZhaoICSE 2023 · 被引用 7 次
- SFA-Miner: Mining Path-Sensitive API Usage Patterns Via Symbolic Finite AutomataJiasheng Jiang, Mingwei Zheng, Qingkai Shi, Xiangyu ZhangS&P 2026 · 被引用 1 次
- APP-Miner: Detecting API Misuses via Automatically Mining API Path PatternsJiasheng Jiang, Jingzheng Wu, Xiang Ling, Tianyue Luo 等S&P 2024 · 被引用 8 次
- Uncovering the iceberg from the tip: Generating API Specifications for Bug Detection via Specification Propagation AnalysisMiaoqian Lin, Kai Chen, Yi Yang, Jinghua LiuNDSS 2025
- Inference of Error Specifications and Bug Detection Using Structural SimilaritiesNora Dossche, Bart CoppensUSENIX Security 2024 · 被引用 2 次
