Fetching the paper…
Reading the bibliography…
While the automated detection of cryptographic API misuses has progressed significantly, its precision diminishes for intricate targets due to the reliance on manually defined patterns.
S. Fahl, M. Harbach, T. Muders, L. Baumgärtner, B. Freisleben, and M. Smith, “Why eve and mallory love android: an analysis of android ssl (in)security,” in Proceedings of the 2012 ACM Conference on Computer and Communications Security
2012
Earlier work this paper cites.
M. Egele, D. Brumley, Y. Fratantonio, and C. Kruegel, “An empirical study of cryptographic misuse in android applications,” in Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security
2013
Earlier work this paper cites.
K. Bhargavan and G. Leurent, “Transcript collision attacks: Breaking authentication in tls, ike, and ssh,” 01 2016
2016
Earlier work this paper cites.
V. van der Veen, Y. Fratantonio, M. Lindorfer, D. Gruss, C. Maurice, G. Vigna, H. Bos, K. Razavi, and C. Giuffrida, “Drammer: Deterministic rowhammer attacks on mobile platforms,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
2016
Earlier work this paper cites.
S. Krüger, S. Nadi, M. Reif, K. Ali, M. Mezini, E. Bodden, F. Göpfert, F. Günther, C. Weinert, D. Demmler, and R. Kamath, “Cognicrypt: Supporting developers in using cryptography,” in 2017 32nd IEEE/ACM International Conference on Automated Software Engineering (ASE)
2017
Earlier work this paper cites.
S. Rahaman and D. D. Yao, “Program analysis of cryptographic implementations for security,” pp. 61–68, 09 2017
2017
Earlier work this paper cites.
“List of rainbow tables.” http://project-rainbowcrack.com/table.htm , 2017
2017
Earlier work this paper cites.
https://eprint.iacr.org/2017/190
M. Stevens, E. Bursztein, P. Karpman, A. Albertini, and Y. Markov, “The first collision for full sha-1.” Cryptology ePrint Archive, Paper 2017/190, 2017 · 2017
Earlier work this paper cites.
K. Moriarty, “Pkcs# 5: Password-based cryptography specification version 2.1,” 2017
2017
Earlier work this paper cites.
A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser, and I. Polosukhin, “Attention is all you need,” Advances in neural information processing systems
2017
Earlier work this paper cites.
N. Meng, S. Nagy, D. Yao, W. Zhuang, and G. Arango-Argoty, “Secure coding practices in java: Challenges and vulnerabilities,” in 2018 IEEE/ACM 40th International Conference on Software Engineering (ICSE)
2018
Earlier work this paper cites.
M. Chen, F. Fischer, N. Meng, X. Wang, and J. Grossklags, “How reliable is the crowdsourced knowledge of security implementation?,” in 2019 IEEE/ACM 41st International Conference on Software Engineering (ICSE)
2019
Earlier work this paper cites.
S. Rahaman, Y. Xiao, S. Afrose, F. Shaon, K. Tian, M. Frantz, M. Kantarcioglu, and D. D. Yao, “Cryptoguard: High precision detection of cryptographic vulnerabilities in massive-sized java projects,” in Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
2019
Earlier work this paper cites.
L. Zhang, J. Chen, W. Diao, S. Guo, J. Weng, and K. Zhang, “CryptoREX: Large-scale analysis of cryptographic misuse in IoT devices,” in 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019)
2019
Earlier work this paper cites.
S. Afrose, S. Rahaman, and D. Yao, “Cryptoapi-bench: A comprehensive benchmark on java cryptographic api misuses,” in 2019 IEEE Cybersecurity Development (SecDev)
2019
Earlier work this paper cites.
T. Brown, B. Mann, N. Ryder, M. Subbiah, J. D. Kaplan, P. Dhariwal, A. Neelakantan, P. Shyam, G. Sastry, A. Askell, et al
2020
Earlier work this paper cites.
“Androguard: Reverse engineering, malware and goodware analysis of android applications.” https://github.com/androguard/androguard , 2020
2020
Earlier work this paper cites.
Z. Xu, X. Hu, Y. Tao, and S. Qin, “Analyzing cryptographic api usages for android applications using hmm and n-gram,” in 2020 International Symposium on Theoretical Aspects of Software Engineering (TASE)
2020
Earlier work this paper cites.
Oracle, “Java cryptography architecture.” https://docs.oracle.com/javase/9/security/java-cryptography-architecture-jca-reference-guide.htm , 2021
2021
Earlier work this paper cites.
S. Krüger, J. Späth, K. Ali, E. Bodden, and M. Mezini, “Crysl: An extensible approach to validating the correct usage of cryptographic apis,” IEEE Transactions on Software Engineering
2021
Earlier work this paper cites.
A.-K. Wickert, L. Baumgärtner, F. Breitfelder, and M. Mezini, “Python crypto misuses in the wild,” in Proceedings of the 15th ACM / IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)
2021
Cited alongside, same era.
L. Piccolboni, G. Di Guglielmo, L. P. Carloni, and S. Sethumadhavan, “Crylogger: Detecting crypto misuses dynamically,” in 2021 IEEE Symposium on Security and Privacy (SP)
2021
Cited alongside, same era.
A. S. Ami, N. Cooper, K. Kafle, K. Moran, D. Poshyvanyk, and A. Nadkarni, “Why crypto-detectors fail: A systematic evaluation of cryptographic misuse detection techniques,” in 2022 IEEE Symposium on Security and Privacy (SP)
2022
Cited alongside, same era.
“Codex suffix api.” https://beta.openai.com/docs/api-reference/completions/create#completions/create-suffix , 2022
2022
Cited alongside, same era.
J. Liu, C. S. Xia, Y. Wang, and L. Zhang, “Is your code generated by chatGPT really correct? rigorous evaluation of large language models for code generation,” in Thirty-seventh Conference on Neural Information Processing Systems
2023
Later among the works it cites.
2023
Later among the works it cites.
PyCryptodome, “Cryptographic library for python.” https://pypi.org/project/pycryptodome/ , 2024
2024
Closest in time.
Y. Chen, Y. Liu, K. Wu, D. Le, and S. Chau, “Towards precise reporting of cryptographic misuses,” 01 2024
2024
Closest in time.
D. Guo, Q. Zhu, D. Yang, Z. Xie, K. Dong, W. Zhang, G. Chen, X. Bi, Y. Wu, Y. Li, et al
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
W. Li, S. Jia, L. Liu, F. Zheng, Y. Ma, and J. Lin, “Cryptogo: Automatic detection of go cryptographic api misuses,” in Proceedings of the 38th Annual Computer Security Applications Conference
2022
Cited alongside, same era.
2022
Cited alongside, same era.
L. Ouyang, J. Wu, X. Jiang, D. Almeida, C. Wainwright, P. Mishkin, C. Zhang, S. Agarwal, K. Slama, A. Ray, et al
2022
Cited alongside, same era.
F. F. Xu, U. Alon, G. Neubig, and V. J. Hellendoorn, “A systematic evaluation of large language models of code,” in Proceedings of the 6th ACM SIGPLAN International Symposium on Machine Programming
2022
Cited alongside, same era.
2023
Cited alongside, same era.
P. Liu, J. Liu, L. Fu, K. Lu, Y. Xia, X. Zhang, W. Chen, H. Weng, S. Ji, and W. Wang, “How chatgpt is solving vulnerability management problem,” 2023
2023
Cited alongside, same era.
W. X. Zhao, K. Zhou, J. Li, T. Tang, X. Wang, Y. Hou, Y. Min, B. Zhang, J. Zhang, Z. Dong, et al
2023
Cited alongside, same era.
S. Afrose, Y. Xiao, S. Rahaman, B. P. Miller, and D. Yao, “Evaluation of static vulnerability detection tools with java cryptographic api benchmarks,” IEEE Transactions on Software Engineering
2023
Cited alongside, same era.
2024
Closest in time.
“Scala.” https://www.scala-lang.org/ , 2024
2024
Closest in time.
“Spark. unified engine for large-scale data analytics.” https://spark.apache.org/ , 2024
2024
Closest in time.
Oracle, “Classes and interfaces for cryptographic operations.” https://docs.oracle.com/javase/8/docs/api/javax/crypto/package-summary.html , 2024
2024
Closest in time.
H. Li, Y. Hao, Y. Zhai, and Z. Qian, “Enhancing static analysis for practical bug detection: An llm-integrated approach,” Proc. ACM Program. Lang
2024
Closest in time.
“Spotbugs: Find bugs in java programs.” https://spotbugs.github.io/ , 2024
2024
Closest in time.
“Apache deltaspike.” https://deltaspike.apache.org/index.html , 2024
2024
Closest in time.
“Apache® druid, a high performance, real-time analytics database.” https://druid.apache.org/ , 2024
2024
Closest in time.
“Github advisory database.” https://github.com/advisories , 2024
2024
Closest in time.
“Project planning for developers.” https://github.com/features/issues , 2024
2024
Closest in time.
“Hugging face.” https://huggingface.co/ , 2024
2024
Closest in time.
T. A. Java, “All algorithms implemented in java.” https://github.com/TheAlgorithms/Java , 2024
2024
Closest in time.
Localstack, “A fully functional local aws cloud stack..” https://github.com/localstack/localstack , 2024
2024
Closest in time.
CrackMapExec, “A swiss army knife for pentesting networks.” https://github.com/byt3bl33d3r/CrackMapExec , 2024
2024
Closest in time.