A machine learning approach to detect misuse of cryptographic APIs in source code

Gustavo Eloi de Paula Rodrigues, Alexandre Melo Braga, Ricardo Dahab · 2020

Cryptography is an indispensable tool for achieving security requirements such as software security. However, most software developers do not have enough knowledge regarding the proper use of cryptography and its APIs. This leads to incorrect use and exploitable vulnerabilities in software applications. Here, we propose an approach based on machine learning techniques to detect different kinds of cryptographic misuse in known java source code representations, achieving an average 52 percentage points improvement with respect to previous works.

Read the paper · More papers on PaperTik