Method and system for detecting misuse of cryptographic API (Application Program Interface) combination based on automatic rule extraction

By adopting a rule-based automated extraction method in the blockchain infrastructure, extracting and detecting the combination and use mode of cryptography APIs, the difficulty of misuse detection of cryptography API combination is solved, and high accuracy and automated detection effects are achieved.

CN120074803AActive Publication Date: 2025-05-30INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202411493246.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-10-24
Publication Date
2025-05-30
Estimated Expiration
2044-10-24

AI Technical Summary

Technical Problem

In blockchain infrastructure, there are difficulties in misuse detection of cryptography API combinations, existing technologies are difficult to achieve accurate detection, and automated detection technology has universality and accuracy problems.

Method used

The rules-based automated extraction method is adopted to extract cryptography API sequences from the project source code, and the correct usage patterns are automatically extracted through data flow and control dependency analysis, combined with the sequence pattern mining algorithm, and misuse detection is carried out based on this.

Benefits of technology

Accurate extraction and misuse detection of cryptographic API combination usage patterns are realized, improving the accuracy and automation of detection, and reducing the need for manual participation and data labeling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074803A_ABST
    Figure CN120074803A_ABST
Patent Text Reader

Abstract

The invention relates to a cryptographic API combination misuse detection method and system based on automatic rule extraction. The method comprises the steps that a cryptographic API sequence is extracted from a project source code based on data flow and control dependency analysis; a correct use mode is automatically extracted from the cryptographic API sequence through a sequence mode mining algorithm; the cryptographic API combination misuse is detected based on the correct usage pattern. The method has a more accurate detection effect, does not need data set marking and manual participation, has more lightweight preparatory work and a higher automation degree, can automatically extract correct cryptography API misuse detection rules for different actual projects, and can meet the use requirements of programming, testing and safety analysis personnel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of program analysis, and particularly to a detection technology for misuse of cryptographic API combinations for blockchain infrastructure, specifically a detection technology for misuse of cryptographic API combinations based on rule automation extraction. This technology can assist programmers, testers, and security analysts in understanding the correct patterns of using cryptographic API combinations, extracting the correct rules for using cryptographic API combinations, and discovering relevant security issues of misuse of cryptographic API combinations in blockchain infrastructure. Background Art

[0002] Blockchain infrastructure refers to a network service facility composed of a public chain network with wide access capabilities, public service capabilities, and flexible deployment, as well as an inter-chain system connecting these blockchains. It is a series of underlying infrastructures that support blockchain technology, mainly involving the data layer, network layer, and consensus layer. Blockchain infrastructure ensures security through various cryptographic technologies. For example, cryptographic technologies are used to achieve secure storage and protection of keys, digital signatures, zero-knowledge proofs, secure multi-party computing, etc. However, the correct use of cryptographic technologies requires an in-depth understanding of their principles. Even experienced software developers may inadvertently introduce vulnerabilities due to a lack of cryptographic expertise. In recent years, the cases of misuse of cryptographic algorithms and protocols caused by misuse of cryptographic APIs in blockchains have increased significantly, resulting in major security vulnerabilities. According to the causes of misuse, the misuse of cryptographic APIs in blockchain infrastructure can be divided into two categories: one is the misuse of a single cryptographic API, and the other is the misuse of cryptographic API combinations. The misuse of cryptographic API combinations refers to the misuse caused by improper call order or the absence of a certain API in the sequence when multiple cryptographic APIs are combined to implement a cryptographic function. It may trigger serious security vulnerabilities, such as replay attacks, data leaks, unauthorized access, etc.

[0003] Currently, there is little research on the detection of misuse of cryptographic API combinations, and it is difficult to accurately detect it in blockchain infrastructure. Therefore, the present invention mainly focuses on the detection research of misuse of cryptographic API combinations.

[0004] Since the use of cryptographic APIs in blockchain is closely related to actual scenarios, and the scenarios of combined use of multiple APIs are complex, it is impossible to achieve comprehensive detection through manual induction of rules. Moreover, existing automated detection techniques for misuses of cryptographic API combinations have problems in terms of generality, accuracy, etc. Representative techniques include: (1) The method of learning correct patterns based on model training: Through machine learning techniques, model training is carried out on a labeled dataset and then applied to actual projects for detecting misuses of cryptographic API combinations. This method mainly faces the problem of insufficient generality. When it is necessary to analyze misuses of cryptographic API combinations in different scenarios, a dataset needs to be reconstructed, and it cannot be guaranteed that the dataset is comprehensive enough. (2) The method of deriving rules based on code changes: Extract code changes related to cryptographic APIs from the fixed code of the project source code, use clustering algorithms to extract the commonalities of the code changes and derive detection rules, and then conduct misuse detection. However, this method is difficult to derive the ways of combining cryptographic APIs that have not been misused from code changes, resulting in accuracy problems. Summary of the Invention

[0005] In view of the above problems, the present invention provides a method and system for detecting misuses of cryptographic API combinations based on automated rule extraction.

[0006] The technical solution adopted by the present invention is as follows:

[0007] A method for detecting misuses of cryptographic API combinations based on automated rule extraction includes the following steps:

[0008] Extract cryptographic API sequences from the project source code based on data flow and control dependence analysis;

[0009] Automatically extract correct usage patterns for the cryptographic API sequences through a sequence pattern mining algorithm;

[0010] Detect misuses of cryptographic API combinations based on the correct usage patterns.

[0011] Further, the extracting of cryptographic API sequences from the project source code based on data flow and control dependence analysis includes:

[0012] Collect information on cryptographic APIs in cryptographic standard libraries and third-party libraries during the preprocessing stage;

[0013] Construct a function call graph for the entire project, conduct data flow and control dependence analysis between function nodes for the collected cryptographic APIs, extract the cryptographic API sequences corresponding to each function, and obtain a set of cryptographic API sequences.

[0014] Further, the conducting of data flow and control dependence analysis between function nodes includes:

[0015] For the transfer of data flow, specify the parameter positions that need to be concerned in the cryptographic API, retain the cryptographic APIs that transfer the data flow at the specified parameter positions in the sequence, and delete the APIs that do not involve the transfer of data flow at the specified positions;

[0016] For the control flow relationship, determine whether there is a control dependence relationship between the front and back APIs, retain the API sequences with control dependence, and filter out the remaining APIs;

[0017] During the process of data flow analysis, record the key parameter information of the cryptographic API into the mode of this API.

[0018] Further, the automated extraction of the correct usage patterns from the cryptographic API sequences by the sequence pattern mining algorithm includes:

[0019] Use the clustering algorithm to classify the cryptographic API sequences so that the cryptographic API sequences with the same cryptographic function are grouped into one category;

[0020] In each category of cryptographic API sequences, use the sequence pattern mining algorithm to extract the frequent sequences as the correct usage patterns.

[0021] Further, the sequence pattern mining algorithm mines the frequent sequences that meet the minimum support degree from the set of cryptographic API sequences, so as to obtain the frequently occurring cryptographic API sequences; the minimum support degree represents the frequency of the cryptographic API sequences in the set of cryptographic API sequences.

[0022] Further, the detection of misuse of cryptographic API combinations based on the correct usage patterns includes:

[0023] Based on the extracted correct usage patterns, detect the misuse problems of cryptographic API combinations in the actual project. If it does not conform to the correct usage pattern, report it as a misuse.

[0024] Further, the non - conformity to the correct usage pattern includes:

[0025] Violating the bundling relationship, that is, any one of the APIs in the correct usage pattern P is missing in the cryptographic API sequence of the project;

[0026] Violating the timing relationship, that is, the order of the APIs in the cryptographic API sequence of the project is different from the correct usage pattern P;

[0027] Violating the occurrence frequency, that is, the number of times the APIs appear in the cryptographic API sequence of the project is different from the correct usage pattern P.

[0028] A misuse detection system for cryptographic API combinations based on rule automation extraction, comprising:

[0029] A preprocessing module for collecting cryptographic API information in cryptographic standard libraries and third-party libraries;

[0030] A cryptographic API sequence extraction module for analyzing the data flow and control dependence relationships between function nodes of the collected cryptographic APIs, extracting the cryptographic API sequences corresponding to each function, and obtaining a set of cryptographic API sequences;

[0031] A sequence classification module for classifying the cryptographic API sequences using a clustering algorithm;

[0032] A correct usage pattern extraction module for automatically extracting correct usage patterns from the cryptographic API sequences through a sequence pattern mining algorithm;

[0033] A vulnerability detection module for detecting misuse of cryptographic API combinations based on the correct usage patterns.

[0034] The beneficial effects of the present invention are as follows:

[0035] The present invention proposes an automated extraction technology for the usage patterns of cryptographic API combinations for blockchain infrastructure. This technology first extracts cryptographic API sequences from project source code based on data flow and control dependence relationship analysis, then automatically extracts correct usage patterns through a sequence pattern mining algorithm, and finally detects misuse of cryptographic API combinations based on the correct usage patterns. Compared with similar technologies, the present invention extracts cryptographic API sequences based on taint analysis technology of source code, has a more accurate detection effect; does not require a labeled data set and manual participation, has lighter preparation work and a higher degree of automation; at the same time, for different actual projects, it can automatically extract correct cryptographic API misuse detection rules to meet the usage needs of programming, testing, and security analysis personnel. Description of the Drawings

[0036] Figure 1 is the step flow chart of the method of the present invention.

[0037] Figure 2 is an extracted cryptographic API sequence.

[0038] Figure 3 is a partial sequence of one category of cryptographic API sequences after classification.

[0039] Figure 4 is a frequent sequence extracted from one category of cryptographic API sequences.

[0040] Figure 5It is a code snippet of the ECDH algorithm in CVE-2023-49292.

[0041] Figure 6 They are the incorrect API sequence and the correct API sequence. Specific implementation manners

[0042] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below through specific embodiments and accompanying drawings.

[0043] The present invention proposes an automated extraction technology for the combined usage pattern of cryptographic APIs for blockchain infrastructure. This technology first extracts cryptographic API sequences from the project source code based on data flow and control dependency analysis, then automatically extracts the correct usage patterns through sequence pattern mining algorithms, and finally detects misuses of cryptographic API combinations based on the correct usage patterns. The basic process of the method is as Figure 1 shown, and its steps include: 1) Preprocessing stage: Collect information about cryptographic APIs in the cryptographic standard library and third-party libraries, specifically including information such as API function names and the types and positions of input parameters. The collected cryptographic APIs will be the targets for subsequent sequence analysis and extraction. 2) Extraction of cryptographic API sequences: Build a function call graph for the entire project, and perform data flow and control dependency analysis between function nodes with the cryptographic APIs collected in the previous step as the targets, so as to extract the cryptographic API sequences corresponding to each function and obtain a set of cryptographic API sequences. 3) Sequence classification: For the set of extracted cryptographic API sequences, use a clustering algorithm to classify the sequences so that sequences with the same cryptographic function are grouped into one category. The purpose of classification is to extract the correct API sequences for each type of cryptographic function and prevent some functions from being ignored due to infrequent use. 4) Extraction of correct usage patterns: In each category of sequences, use sequence pattern mining algorithms to extract frequent sequences as the correct usage patterns, which will be used as the basis for vulnerability detection in step 5. 5) Vulnerability detection: Based on the correct usage patterns of the extracted sequences, detect misuses of cryptographic API combinations in the actual project. If it does not conform to the correct pattern, it is reported as a misuse.

[0044] The detailed steps of the above inventive method are as follows:

[0045] 1. Preprocessing stage

[0046] Since the blockchain infrastructure is mainly developed based on the Go language, the cryptographic APIs in the standard library crypto of the Go language and the supplementary library golang.org / x / crypto developed by the community are first collected. At the same time, third-party cryptographic libraries commonly used in other blockchains are collected. In the present invention, 22 third-party cryptographic libraries are collected from open-source blockchain infrastructure projects on GitHub, blockchain-related papers, and official description websites of various infrastructures. The cryptographic APIs that need to be concerned are selected from these libraries and added to the set of target cryptographic APIs to be detected.

[0047] 2. Extraction of Cryptographic API Sequences

[0048] In this step, the cryptographic API sequences called within each function are extracted, including the cryptographic APIs and the key parameters in each cryptographic API, which are recorded as a combined usage pattern of cryptographic APIs, that is, P = {API 1 : param 1 ; API 2 : param 2 ;...}. Among them, the key parameters are used for data flow and control dependency analysis.

[0049] First of all, the present invention constructs a function call graph for the entire project and analyzes the data flow and control flow dependency relationships of function nodes in the graph. For the transfer of data flow, the positions of the parameters that need to be concerned are specified in the cryptographic API, and the cryptographic APIs that transfer data flow at the specified parameter positions are retained in the sequence, while the APIs that do not involve data flow transfer at the specified positions are deleted. For the control flow relationship, it is necessary to judge whether there is a control dependency relationship between the front and back APIs, and retain the cryptographic API sequences with control dependencies, and filter out the remaining cryptographic APIs. At the same time, during the process of data flow analysis, the key parameter information of the cryptographic API is recorded into the pattern of the cryptographic API for convenient analysis. Finally, through the analysis of each function, the set of cryptographic API sequences of the entire project is obtained. Figure 2 is a extracted cryptographic API sequence.

[0050] 3. Sequence Classification

[0051] In this step, the set of extracted cryptographic API sequences is classified. The present invention uses similarity measurement algorithms, such as edit distance, Cosine Similarity, etc. to describe the similarity between two sequences, and then uses clustering algorithms, such as agglomerative hierarchical clustering, K-means, etc. to classify the cryptographic API sequences.

[0052] To determine the number of clusters, the present invention uses clustering evaluation metrics, such as silhouette coefficient, Davies - Bouldin Index, etc. to evaluate the clustering effect. Since the cryptographic APIs have diversity at the implementation level and involve cryptographic libraries at different levels, and there is no standard classification method currently, the present invention determines the number of classifications through clustering evaluation metrics combined with experiments. According to this method, the present invention divides the cryptographic API sequences into 20 categories, obtaining 20 sets of cryptographic API sequences. Figure 3 It is a partial sequence of one of the cryptographic API sequences after classification.

[0053] 4. Extraction of correct usage patterns

[0054] In this step, correct usage patterns are extracted from the sets of cryptographic API sequences classified in the previous step. According to the characteristics of cryptographic sequence extraction and the requirement of efficiency, sequence pattern mining algorithms are used to perform frequent sequence extraction on each category of cryptographic API sequences, such as PrefixSpan algorithm, Apriori - based algorithm, SPADE algorithm, etc. Sequence pattern mining algorithms can mine frequent sequences that meet the minimum support from the sequence dataset, thus obtaining frequently occurring cryptographic API sequences. The minimum support represents the frequency of the sequence in the set of cryptographic API sequences.

[0055] The reason that frequent sequences can be regarded as the basis of correct usage patterns is that in most cases, the code developed by developers is correct. A large number of previous studies on API usage pattern extraction have shown that the more frequently a pattern appears in the code, the more credible it is.

[0056] Since the number of sequences in different categories of cryptographic API sequence sets is different, setting a unified minimum support will result in either not being able to mine sequences or mining a very large number of frequent sequences. Therefore, the present invention uses the absolute value of the number of occurrences to divide frequent sequences. We record the frequency of occurrence of each sequence, and consider the sequences that appear at least more than 10 times in the sequence set as frequent sequences, that is, the correct usage patterns extracted. Figure 4 It is the frequent sequence extracted from one category of cryptographic API sequences.

[0057] 5. Vulnerability detection

[0058] In this step, based on the combined usage patterns of cryptographic APIs extracted previously, the misuse of combined cryptographic APIs in the project is detected. Based on the extracted correct combined usage patterns of cryptographic APIs P = {API 1 :param 1 ; API 2 :param 2 ; …}, where, API 1, API 2 … indicates the cryptographic APIs included in the frequent sequence, param 1 , param 2 … indicates the key parameters in each cryptographic API. If the cryptographic API sequence meets any of the following 3 conditions, it is considered misused.

[0059] The sequence does not conform to the pattern of P = {API 1 : param 1 ; API 2 : param 2 ; …}, such as missing any API or incorrect API order. The specific situations are as follows:

[0060] a. Violating the bundling relationship. If the sequence is missing any of the APIs 1 , API 2 , API 3 ;

[0061] b. Violating the timing relationship. If the sequence contains all of the APIs 1 , API 2 , API 3 , but the order of these APIs appears differently from P;

[0062] c. Violating the occurrence frequency. If the sequence contains all of the APIs 1 , API 2 , API 3 , and the order is the same as P, but in a subsequence starting with API 1 and ending with API 3 , the number of occurrences of API 1 , API 2 , API 3 is different from P.

[0063] The following introduces an example of misuse detection:

[0064] Taking CVE-2023-49292 (https: / / cve.mitre.org / cgi-bin / cvename.cgi?name=2023-49292) as an example, Figure 5It is the code snippet after its repair. secp256k1 is a commonly used elliptic curve parameter. Based on secp256k1, integrated elliptic curve encryption can be implemented. ECDH (Elliptic Curve Diffie-Hellman) is a key agreement protocol based on elliptic curve cryptography, which is used to establish a shared key between two or more participating parties. This key can be used to encrypt and decrypt data, or to verify the integrity and authenticity of messages. The ECDH algorithm calls cryptographic APIs such as IsOnCurve(), ScalarMult(), and Params() in sequence to implement. Among them, the IsOnCurve() function in the secp256k1 library is used to check the legality of the public key. However, in CVE-2023-49292, due to the absence of this key function, attackers can recover any private key that interacts with them by calling the ECDH() function.

[0065] In step 2, extract the corresponding cryptographic API sequence of the function, which is crypto / elliptic.IsOnCurve, crypto / elliptic.ScalarMult, crypto / elliptic.Params, as Figure 6 shown in (b) of. In step 3, extract the set of all cryptographic API sequences of the project, and classify them in step 4. The frequently extracted API sequences in this category are as Figure 6 shown in (c) of. In step 5, an incorrect API sequence detected in this category is as Figure 6 shown in (d) of.

[0066] Another embodiment of the present invention provides a cryptographic API combination misuse detection system based on rule automation extraction, which includes:

[0067] A preprocessing module for collecting cryptographic API information in cryptographic standard libraries and third-party libraries;

[0068] A cryptographic API sequence extraction module for analyzing the data flow and control dependence relationship between function nodes of the collected cryptographic APIs, extracting the cryptographic API sequence corresponding to each function, and obtaining a set of cryptographic API sequences;

[0069] A sequence classification module for classifying cryptographic API sequences using a clustering algorithm;

[0070] A correct usage pattern extraction module for automatically extracting the correct usage pattern of cryptographic API sequences through a sequence pattern mining algorithm;

[0071] A vulnerability detection module for detecting the misuse of cryptographic API combinations based on the correct usage patterns.

[0072] The division of the above modules is only for illustrative purposes. In actual applications, the above functions can be allocated to different functional modules according to needs to complete all or part of the functions described in the foregoing method. The specific working processes of the above modules can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0073] Another embodiment of the present invention provides a computer device (such as a computer, a server, a smart phone, etc.), which includes a memory and a processor. The memory stores a computer program, and the computer program is configured to be executed by the processor. The computer program includes instructions for executing the steps in the method of the present invention.

[0074] Another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, a disk, an optical disc). When the computer program stored in the computer-readable storage medium is executed by a computer, the steps of the method of the present invention are implemented.

[0075] The specific embodiments of the present invention disclosed above are intended to help understand the content of the present invention and implement it accordingly. Those of ordinary skill in the art can understand that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention. The present invention should not be limited to the content disclosed in the embodiments of this specification, and the protection scope of the present invention is subject to the scope defined by the claims.

Claims

1. A cryptographic API combination misuse detection method based on rule-based automated extraction, characterized in that: The following steps are involved: Extract cryptographic API sequences from project source code based on data flow and control dependency analysis; Automatically extract the correct usage patterns from cryptographic API sequences through sequential pattern mining algorithms; Detect cryptographic API misuse based on correct usage patterns.

2. The method according to claim 1, characterized in that The cryptography API sequence is extracted from the project source code based on data flow and control dependency analysis, including: In the preprocessing stage, cryptographic API information in cryptographic standard libraries and third-party libraries is collected; A function call graph is constructed for the entire project, and the data flow and control dependency between function nodes of the collected cryptographic APIs are analyzed. The cryptographic API sequence corresponding to each function is extracted to obtain a cryptographic API sequence set.

3. The method according to claim 2, characterized in that The data flow and control dependency analysis between function nodes includes: For data stream transmission, specify the parameter position that needs to be paid attention to in the cryptography API, keep the cryptography API that transmits the data stream at the specified parameter position in the sequence, and delete the API that does not involve the data stream transmission at the specified position; For control flow relationships, determine whether there is a control dependency relationship between the previous and next APIs, retain the API sequence with control dependency, and filter out the rest of the APIs; During the data flow analysis, key parameter information of the cryptographic API is recorded into the pattern of the API.

4. The method according to claim 1, characterized in that The method of automatically extracting the correct usage pattern from the cryptography API sequence through the sequence pattern mining algorithm includes: Use a clustering algorithm to classify cryptographic API sequences so that cryptographic API sequences with the same cryptographic functions are grouped together; In each category of cryptographic API sequences, a sequence pattern mining algorithm is used to extract frequent sequences as the correct usage patterns.

5. The method according to claim 4, characterized in that The sequence pattern mining algorithm mines frequent sequences that meet the minimum support from the cryptographic API sequence set, thereby obtaining frequently occurring cryptographic API sequences; the minimum support represents the frequency of occurrence of the cryptographic API sequence in the cryptographic API sequence set.

6. The method according to claim 1, characterized in that The detection of cryptographic API combination misuse based on the correct usage pattern includes: Based on the extracted correct usage patterns, the cryptographic API combination misuse issues are detected in actual projects. If it does not conform to the correct usage pattern, it is reported as a misuse.

7. The method according to claim 6, characterized in that The incorrect usage patterns include: Violation of the binding relationship, that is, the cryptographic API sequence of the project lacks any API in the correct usage pattern P; Violation of the timing relationship, that is, the order in which the APIs appear in the project's cryptography API sequence is different from the correct usage pattern P; Violation frequency, that is, the number of times the API appears in the project's cryptography API sequence is different from the correct usage pattern P.

8. A cryptographic API combination misuse detection system based on rule-based automated extraction, characterized in that: include: Preprocessing module, used to collect cryptographic API information in cryptographic standard libraries and third-party libraries; The cryptography API sequence extraction module is used to analyze the data flow and control dependency between function nodes of the collected cryptography APIs, extract the cryptography API sequence corresponding to each function, and obtain the cryptography API sequence set; Sequence classification module, used to classify cryptography API sequences using clustering algorithms; Correct usage pattern extraction module, used to automatically extract the correct usage pattern from the cryptographic API sequence through the sequence pattern mining algorithm; Vulnerability detection module, used to detect the misuse of cryptographic API combinations based on correct usage patterns.

9. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program comprises instructions for executing the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Code detection method and device and storage medium

    CN113836020A

  • API misuse detection method based on decision tree algorithm

    CN114153721A

  • C / C + + cryptography misuse classification and detection method

    CN116243970A

  • Intelligent malicious software detection method based on API (Application Program Interface) characteristics

    CN116702143A

  • Application behavior detection method and device based on API calling

    CN117892299A