Abstract
Misuses of cryptographic APIs are prevalent in existing real-world Java code. Some open-sourced and commercial cryptographic vulnerability detection tools exist that capture misuses in Java program. To analyze their efficiency and coverage, we build a comprehensive benchmark named CryptoAPI-Bench that consists of 171 unit test cases. The test cases include basic cases and complex cases. We assess four tools i.e., SpotBugs, CryptoGuard, CrySL, and Coverity using CryptoAPI-Bench and show their relative performance.
Author supplied keywords
Cite
CITATION STYLE
Afrose, S., Rahaman, S., & Yao, D. (2020). A Comprehensive Benchmark on Java Cryptographic API Misuses. In CODASPY 2020 - Proceedings of the 10th ACM Conference on Data and Application Security and Privacy (pp. 177–178). Association for Computing Machinery, Inc. https://doi.org/10.1145/3374664.3379537
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.