Java cryptography API misuse detection method based on taint analysis

By applying a stain analysis method in the misuse detection of Java cryptography API, combined with pointer analysis and multi-type misuse detectors, the problems of insufficient detection coverage and large operation overhead in the existing technology are solved, and accurate detection and efficient analysis of misuse of Java cryptography API are realized.

CN120196547APending Publication Date: 2025-06-24NANJING UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510287388.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

When detecting the misuse of Java cryptography API, the existing technology has problems such as insufficient coverage, large operation overhead and inaccurate data flow analysis, making it difficult to fully identify the misuse scenarios of APIs.

Method used

The method based on stain analysis is adopted, through the combination of full-program stain analysis and multiple types of misuse detectors, the Source point, stain conversion rules, Sink points and misuse detection rules for stain analysis are configured, and combined with pointer analysis and method call diagrams, the propagation of password information and the misuse of API is tracked.

Benefits of technology

It realizes accurate detection of misuse of Java cryptography API, improves the coverage and accuracy of misuse detection, and reduces operational overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120196547A_ABST
    Figure CN120196547A_ABST
Patent Text Reader

Abstract

The invention discloses a Java cryptography API misuse detection method based on taint analysis, which comprises the following steps: S1, setting a taint analysis rule according to the type of cryptography API misuse; s2, processing a to-be-detected target program to obtain a result IR for static analysis; s3, performing pointer analysis on the IR generated in the step S2 in combination with a target program code, and generating a pointing flow graph and a method calling graph of the to-be-detected target program; and S4, on the basis of the pointing flow graph and the method calling graph obtained in the step S3, performing taint analysis driven by pointer analysis on the IR generated in the step S2, analyzing a program path through which a taint flow passes, and detecting whether misuse occurs according to different types of cryptographic API misuse rules. Compared with a traditional Java cryptography API misuse detection method, the Java cryptography API misuse detection method introduces taint analysis to establish the taint flow of the API related parameters from the creation point to the use point, so that Java cryptography API misuse is detected, and the Java cryptography API misuse detection method has the advantages of being complete in detection capacity and high in detection precision.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for detecting misuse of Java cryptographic APIs based on taint analysis, belonging to the technical field of static analysis for vulnerability detection. Background Art

[0002] In modern software development, cryptography plays a crucial role in protecting sensitive data, ensuring the security of transactions and communications, verifying identities, and many other aspects. The Java platform provides cryptographic-related functions through the Java Cryptography Architecture (JCA for short) and the Java Secure Sockets Extension (JSSE for short), which can implement encryption, key generation, secure communication, and other tasks. However, the complexity of using application programming interfaces, combined with the general lack of security knowledge among developers, often leads to the misuse of encryption APIs, thereby triggering security vulnerabilities. These misuses of APIs include using weak encryption algorithms and insecure random number generation methods, etc., which may lead to security vulnerabilities such as sensitive data leakage, authentication failure, and man-in-the-middle attacks.

[0003] Currently, the techniques for detecting misuse of cryptographic APIs are mainly divided into static analysis and dynamic analysis. Dynamic analysis requires real-time monitoring of the calls to cryptographic APIs during the program execution. For example, by inserting monitoring points in critical code segments, recording information such as the input parameters, call timing, and return values of each API call to track the flow of encrypted information. However, this method has many drawbacks. On the one hand, since it is difficult to exhaust all possible running scenarios with test cases, its coverage is significantly insufficient, and misuse cases triggered by low-frequency or special conditions are easily missed. On the other hand, continuous monitoring and data recording will bring a large running overhead and slow down the overall execution efficiency of the program. Other static analysis tools usually parse the program source code or bytecode and use means such as data flow analysis to identify known misuse patterns of cryptographic APIs. However, the data flow analysis of these analysis tools is difficult to accurately and comprehensively analyze the flow of information related to API misuse in the program, and the coverage of API misuse scenarios is not comprehensive. Summary of the Invention

[0004] Object of the Invention: Aiming at the problems and deficiencies in the prior art, the present invention provides a method for detecting misuse of Java cryptographic APIs based on taint analysis, which realizes the accurate detection of misuse of cryptographic APIs through the combination of whole-program taint analysis and multi-type misuse detectors.

[0005] Technical Solution: A method for detecting misuse of Java cryptographic APIs based on taint analysis, the method includes the following steps: S1. According to the categories of misuse of cryptographic APIs, set taint analysis rules to guide the subsequent analysis process: Configure the Source points for taint analysis to identify the creation of sensitive information in the program; configure the taint transformation rules for taint analysis, including transfer points, starting variables, and ending variables, to assist in the propagation of encrypted information; configure the Sink points and misuse detection rules for taint analysis. The Sink points determine the locations of API calls that need to be checked, and the misuse detection rules are used to subsequently determine whether there is a misuse of cryptographic APIs; configure the taint propagation rules to track the flow of sensitive information in the program. S2. Process the target program to be detected to obtain the result IR for static analysis. S3. Combine the target program code and perform pointer analysis on the IR generated in step S2 to generate the pointing flow graph and method call graph of the target program to be detected. S4. Based on the pointing flow graph and method call graph obtained in step S3, perform taint analysis driven by pointer analysis on the IR generated in step S2, analyze the program paths through which the taint flows, and detect whether there is a misuse of cryptographic APIs according to the misuse detection rules.

[0006] Preferably, the configuration of the Source points in step S1 includes: the creation points of string constants, such as algorithm names, key materials, etc.; the creation points of integer constants, such as iteration times, key lengths, etc.; the creation points of insecure random number generators, such as the creation of java.util.Random objects, etc.

[0007] Preferably, the configuration of the Sink points in step S1 includes: the call points of cryptographic algorithm initialization APIs (such as Cipher.getInstance()); the call points of key generator parameter setting APIs; the call points of cryptographic component initialization APIs, etc.

[0008] Preferably, the misuse detection rules in step S1 include: S11. Insecure algorithm detection: Check whether insecure and easily breakable encryption algorithms are used when using encryption algorithms (such as when creating passwords). S12. Invalid range detection: Check whether the iteration times or key sizes in cryptographic API calls meet the minimum security standards. S13. Predictable source detection: Check whether parameters that are expected to be random are generated using non-random methods. S14. Insecure method detection: Check whether methods with known security risks are used. S15. Verification missing detection: Check whether sensitive external inputs are not verified. S16. Combined Detection: Combined detection is used to monitor the situation where multiple cryptographic APIs are enabled simultaneously. In this case, there is usually a combined variable among these APIs. For example, when initializing a key generator for encryption, the key generator serves as the combined variable, and two APIs are called respectively to configure the algorithm name and key length. This detection synthesizes the results of multiple detections (such as insecure algorithm detection and invalid range detection) and gives a comprehensive judgment result.

[0009] Preferably, in step S2, during the processing of the target program code to be detected, an open-source framework Tai-e is used to process the target program code, including: bytecode parsing, three-address code IR generation, and program structure analysis, to obtain the three-address code IR for static analysis and the class hierarchy.

[0010] Preferably, the pointer analysis in step S3 is to use the traditional basic pointer analysis statements for the five types of IRs, and perform selective context-sensitive pointer analysis to construct the points-to graph and method call graph.

[0011] Preferably, the taint analysis in step S4 includes: S41. Inject taint objects into the points-to set of the corresponding object according to the Source point configuration: S411. Scan the sources of cryptographic information objects in the program. Specifically, detect the creation locations of string-related and integer constant values in the program, and create cryptographic information objects. At the same time, detect the calls to the Source points configured in S1 in the program, and also create the cryptographic information objects generated by the calls to the Source points.

[0012] S412. Create corresponding taint objects for each identified taint source: For the constant creation points, generate taint objects representing the constant values. For the sake of analysis efficiency, the present invention proposes an optimization scheme: merge the objects generated for those constants that are obviously irrelevant to the misuse detection of value judgment (i.e., strings that are not the insecure encryption algorithms defined in S11) and those constants that can be directly determined to be insecure (i.e., integers with values less than the lowest security standard of all invalid range detectors in S12). That is, for these taint objects, use the same merged object to represent a class of taint objects; for the specified API call points, generate taint objects representing their return values.

[0013] S413. For the combined variables specified in the combined detection in S16, establish combined objects (such as key pair generator objects) to associate the relevant cryptographic information (such as algorithm name and key length).

[0014] S42. Process the propagation and conversion of misused information objects between strings and related types. By propagating encrypted objects in the call graph and the points-to flow graph modules constructed by pointer analysis, and supplementing the points-to flow graph when the transfer points in the taint conversion rules defined in S1 are detected, establish the points-to flow graph edges between the starting variable and the ending variable, and use it to propagate the encrypted objects together to ensure the complete propagation of password information.

[0015] S43. At the Sink points corresponding to the misuse detection rules defined in S1, according to the usage methods of different types of APIs and the detected propagation situation of misused information, combined with their corresponding misuse detection rules, determine whether there is a misuse of cryptographic APIs.

[0016] A computer device, which includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the above computer program, it implements the steps of the above-mentioned method for detecting misuse of Java cryptographic APIs based on taint analysis.

[0017] A computer-readable storage medium, characterized in that: the computer-readable storage medium stores a computer program for executing the above-mentioned method for detecting misuse of Java cryptographic APIs based on taint analysis.

[0018] Beneficial effects: Compared with the existing technical solutions, the present invention has the following advantages: 1) The present invention provides a method for detecting misuse of cryptographic APIs based on whole-program taint. This method is based on the complete points-to flow graph and call graph constructed by pointer analysis, and can accurately track the propagation process of password information in the program.

[0019] 2) The present invention provides various types of misuse detectors for detecting misuse of Java cryptographic APIs, which can effectively identify potential misuse problems of cryptographic APIs in Java applications by combining the detected password information. Description of the Drawings

[0020] Figure 1 is the flowchart of the method of the embodiment of the present invention. Detailed Embodiments

[0021] The following further clarifies the present invention in conjunction with specific embodiments. It should be understood that these embodiments are only used to illustrate the present invention and not to limit the scope of the present invention. After reading the present invention, various equivalent forms of modification of the present invention by those skilled in the art all fall within the scope defined by the appended claims of this application.

[0022] As Figure 1 shown, the method for detecting misuse of Java cryptographic APIs based on taint analysis includes the following steps: S1. Set taint analysis rules according to the categories of cryptographic API misuse; S11. Configure the Source points of taint analysis to identify the creation of misuse information objects.

[0023] S12. Set taint conversion rules to track the flow of sensitive information in the program.

[0024] S13. Configure the Sink points of taint analysis and misuse detection rules to determine the API call locations that need to be checked, guiding subsequent judgments on whether there is misuse of cryptographic APIs.

[0025] S2. Process the target program to be detected to obtain the result IR for static analysis. Use the static analysis framework Tai-e to process the target program code to obtain the three-address code IR for static analysis and the relevant class hierarchy; S3. Perform pointer analysis on the IR generated in step S2 to generate the pointing flow graph and method call graph of the target program to be detected; S4. Construct taint analysis based on the IR of the program, propagate information related to misuse of cryptographic APIs in the program with the help of pointer analysis, and determine whether there is misuse of cryptographic APIs according to the misuse detection rules defined in S12.

[0026] Since the present invention belongs to a static analysis method for Java programs, the specific implementation method will be introduced below in combination with Java code examples. The example code shows an insecure encryption implementation: Line 1, class PasswordEncryptor { Line 2, Crypto crypto; Line 3, / / Initialize crypto object Line 4, PasswordEncryptor() { Line 5, String passKey = getKey("pass.key"); Line 6, crypto = new Crypto(); Line 7, crypto.setDefaultKey(passKey); Line 8,} Line 9, / / Obtain the key value Line 10, String getKey(String src) { Line 11, String key = String.valueOf(0X123DAD); Line 12, return key; Line 13,} Line 14, / / Encrypt txt using crypto object Line 15, byte[] encrypt(String txt) { Line 16, return crypto.encrypt(txt); Line 17,} Line 18,} Line 19, class Crypto { Line 20, String defaultKey; Line 21, void setDefaultKey(String defKey) { Line 22, defaultKey = defKey; Line 23,} Line 24, byte[] encrypt(String txt) { Line 25, / / Generate secretKey Line 26, byte[] keyBytes = defaultKey.getBytes(); Line 27, Key secKey = new SecretKeySpec(keyBytes, "AES"); Line 28, / / Use secKey for subsequent encryption Line 29, ... Line 30,} Line 31,} For the example code, the analysis process of step S3 is as follows: S31. Construct a method call graph. For static calls, directly call the static method through the class name. For instance method calls, obtain the reference information of the receiving object and then determine the specific method to be called according to the object type: S311. Identify the call of the getKey() method in the constructor PasswordEncryptor(): Analyze the internal call sequence of classes in the constructor, and establish a call edge from the constructor to the getKey() method.

[0027] S312. Identify the call of the crypto.encrypt() method in the encrypt() method: Analyze the calls within the encrypt method body, resolve the actually called method according to the type of the crypto object, and establish a call edge from encrypt() to crypto.encrypt().

[0028] S313. Analyze the call relationship of the setDefaultKey() method: Trace the call of setDefaultKey in the constructor, establish a call edge from the constructor to the setDefaultKey method, and record the passing path of the parameter passKey.

[0029] S32. Build a pointing graph, and establish the passing relationship between objects through statements such as direct assignment, field assignment, and field loading: S321. Analyze the constant assignment operation on line 11, and establish a pointing relationship from 0X123DAD to the key variable: Identify the string object created by the String.valueOf(0X123DAD) statement, add the string object to the pointing set of the key variable, and record this direct assignment relationship in the pointing graph.

[0030] S322. Analyze the object creation and method calls on lines 5 - 7, and establish a pointing relationship from passKey to the defaultKey field of the crypto object: Identify the object instance created by new Crypto(), trace the call of the setDefaultKey(passKey) method, establish a pointing edge from the method parameter passKey to the defaultKey field of the crypto object, and record this field assignment passing relationship in the pointing graph.

[0031] S323. Analyze the type conversion and object creation on lines 26 - 27, and establish a pointing relationship from defaultKey to keyBytes and then to secKey: Identify the type conversion operation of defaultKey.getBytes(), establish a conversion edge from the String - type defaultKey to the byte[] - type keyBytes, trace the call of the new SecretKeySpec(keyBytes, "AES") constructor, and establish a pointing edge from the keyBytes parameter to the field of the newly created secKey object.

[0032] For the example code, the analysis process of step S4 is as follows: S41. Based on the taint source configuration, identify the hard-coded constant 0X123DAD on line 11 as a taint source, and create a misuse object for this constant. For the sake of analysis efficiency, at this time, this constant has nothing to do with the misuse value judgment, so a merged type of misuse object is created.

[0033] S42. Use pointer analysis to drive the propagation of the misuse object on the pointing flow graph: Analyze the return statement of the getKey() method, establish the pointing relationship of each propagation link, and track the entire propagation path. Specifically, it includes: S421. Analyze the return statement in the getKey() method, and propagate the created misuse object to the passKey variable through the return statement, and record this propagation edge in the pointing flow graph.

[0034] S422. Analyze the parameter passing and field assignment operations of the setDefaultKey() method, and establish a propagation path from the parameter passKey to the defaultKey field of the crypto object.

[0035] S423. Process the getBytes() type conversion call in the encrypt() method to ensure that the misuse object maintains its semantics during the conversion process, and establish a propagation edge of this misuse object from the String type to the byte[] type.

[0036] S424. Analyze the parameter passing of the SecretKeySpec constructor call, establish a propagation edge from keyBytes to the constructor parameter, and mark this call point as a potential misuse location.

[0037] S43. Detect according to different types of cryptographic API misuse rules: Scan the identified API call points, analyze the taint sources of the parameters, and check whether the security rules are violated. For the case where the SecretKeySpec parameter detected in this example comes from a hard-coded constant, since it violates the rule that "key material should be generated using secure random numbers", a corresponding misuse warning is generated.

[0038] From this example, it can be seen that the method of the present invention can: 1) Use pointer analysis and method call graph to accurately track the data flow across methods.

[0039] 2) Combine taint analysis means to effectively handle string-related type conversions and ensure the completeness of tracking the flow of taint information.

[0040] 3) Identify Java cryptographic API misuse based on predefined misuse rules through the configuration mode of taint analysis rules.

[0041] Obviously, those skilled in the art should understand that each step of the method of the embodiment of the present invention described above can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. Optionally, they can be implemented by program code executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order than here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. In this way, the embodiments of the present invention are not limited to any specific combination of hardware and software.

[0042] Obviously, those skilled in the art should understand that each step of the method for detecting Java cryptographic API misuse based on taint analysis in the embodiment of the present invention described above can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. Optionally, they can be implemented by program code executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order than here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. In this way, the embodiments of the present invention are not limited to any specific combination of hardware and software.

Claims

1. A Java cryptography API misuse detection method based on taint analysis, characterized in that: The method comprises the following steps: S1. According to the category of cryptographic API misuse, set the taint analysis rules to guide the subsequent analysis process: Configure the Source point of taint analysis to identify the creation of sensitive information in the program; configure the taint conversion rules of taint analysis, including transfer points, starting variables and end variables, to assist in the propagation of encrypted information; configure the Sink point and misuse detection rules of taint analysis. The Sink point determines the API call location that needs to be checked, and the misuse detection rules are used to subsequently determine whether there is misuse of the cryptographic API; configure the taint propagation rules to track the flow of sensitive information in the program; S2, processing the target program to be tested to obtain the result IR for static analysis; S3, combining the target program code and performing pointer analysis on the IR generated in step S2, to generate a pointing flow graph and a method call graph of the target program to be detected; S4. Based on the pointing flow graph and method call graph obtained in step S3, the IR generated in step S2 is subjected to pointer analysis-driven taint analysis to analyze the program path through which the taint flow passes, and whether cryptographic API misuse occurs according to the misuse detection rules.

2. The Java cryptography API misuse detection method based on taint analysis according to claim 1 is characterized in that: The configuration of the Source point in step S1 includes: a creation point for a string constant, a creation point for an integer constant, and a creation point for an insecure random number generator.

3. The Java cryptography API misuse detection method based on taint analysis according to claim 1 is characterized in that: The configuration of the Sink point in step S1 includes: the calling point of the cryptographic algorithm initialization API, the calling point of the key generator parameter setting API and the calling point of the cryptographic component initialization API.

4. The Java cryptography API misuse detection method based on taint analysis according to claim 1 is characterized in that: The misuse detection rules in step S1 include: S11, unsafe algorithm detection: Check whether the encryption algorithm used is an unsafe and easily cracked encryption algorithm; S12, invalid range detection: Checks whether the number of iterations or key size in the encryption API call meets the minimum security standards; S13, Predictable source detection: Check whether the parameters that are expected to be random are generated using non-random methods; S14, Unsafe method detection: Check whether methods with known security risks are used; S15, missing verification detection: Check whether sensitive external inputs are not verified; S16. Combined detection: Combined detection is used to monitor the situation where multiple encryption APIs are enabled at the same time.

5. The Java cryptography API misuse detection method based on taint analysis according to claim 1 is characterized in that: In step S2, during the processing of the target program code to be detected, the open source framework Tai-e is used to process the target program code, including: bytecode parsing, three-address code IR generation, program structure analysis, and obtaining the result three-address code IR and class hierarchy for static analysis.

6. The Java cryptography API misuse detection method based on taint analysis according to claim 1 is characterized in that: The stain analysis in step S4 includes: S41. According to the Source point configuration, inject the tainted object into the corresponding object's pointing set: S411, scanning the source of cryptographic information objects in the program, specifically, detecting the creation locations of string-related and integer value constants in the program; and creating cryptographic information objects, while detecting the Source point calls configured in S1 in the program, and also creating cryptographic information objects generated by the Source point calls; S412, creating a corresponding stain object for each identified stain source; S413, for the combination variables specified by the combination detection in S16, establishing a combination object to associate related password information; S42, handle the propagation and conversion of misused information objects between strings and related types, propagate encrypted objects in the call graph and pointing flow graph modules constructed by pointer analysis, and supplement the pointing flow graph when the transfer point in the taint conversion rule defined in S1 is detected, establish the pointing flow graph edge from the starting variable to the end variable, and use it to propagate the encrypted objects together, so as to ensure the complete propagation of the cryptographic information; S43. At the Sink point corresponding to the misuse detection rule defined in S1, based on different types of API usage methods and the propagation of detected misuse information, combined with its corresponding misuse detection rule, determine whether cryptographic API misuse occurs.

7. The Java cryptography API misuse detection method based on taint analysis according to claim 1 is characterized in that: In S412, a corresponding stain object is created for each identified stain source: Objects generated by constants that are not relevant to value misuse detection and those that can be directly determined to be unsafe are merged.

8. A computer device, characterized in that: The computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the Java cryptography API misuse detection method based on taint analysis as described in any one of claims 1 to 7 are implemented.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program for executing the Java cryptography API misuse detection method based on taint analysis as described in any one of claims 1 to 7.