Helping Java developers reduce cryptographic API misuses / Michael Schlichtig ; Advisor Prof. Dr. Eric Bodden. Paderborn, 2026
Inhalt
- Abstract
- Acknowledgments
- Contents
- 1 Introduction
- 2 Background
- 2.1 State of the Art
- 2.1.1 Usability of Static Analysis Tools
- 2.1.2 API Usage Constraints and Misuses
- 2.1.3 Benchmarking of Static Analysis Tools
- 2.2 Detection of Java Cryptographic API Misuses
- 3 Large-Scale Tool Study of Usability Criteria Addressed by Static Analysis Tools
- 3.1 Introduction
- 3.2 Methodology
- 3.3 Results
- 3.3.1 Warning Messages
- 3.3.2 Fix Support
- 3.3.3 False Positives
- 3.3.4 User Feedback
- 3.3.5 Workflow Integration
- 3.3.6 User Interface
- 3.4 Threats to Validity
- 3.5 Related Work
- 3.6 Conclusion
- 4 FUM — A Framework for API Usage Constraint and Misuse Classification
- 4.1 Introduction
- 4.2 Background
- 4.3 Related Work — A Survey of Definitions and Perspectives
- 4.3.1 API Documentation Types and Definitions
- 4.3.2 API Usage Constraint Types and Definitions
- 4.3.3 API Misuse Types and Definitions
- 4.4 Definitions
- 4.4.1 Definition of ``API.''
- 4.4.2 Definition of ``API Directive.''
- 4.4.3 Definition of ``API Usage Constraint.''
- 4.4.4 Definition of ``API Misuse.''
- 4.5 Classification of API Usage Constraints — FUM
- 4.5.1 FUM Types Associated With the ``Return Value.''
- 4.5.2 FUM Types Associated With the ``Method Call.''
- 4.5.3 FUM Types Associated With ``Passed Arguments.''
- 4.5.4 FUM Types With Multiple API Method Call Associations
- 4.5.5 FUM— Limitations
- 4.5.6 Overlapping Characteristics of FUM Types
- 4.6 Discussing Differences of Classifications
- 4.7 Case Study: CogniCrypt
- 4.8 Conclusion
- 5 Cryptographic API Misuses
- 5.1 To Fix or Not to Fix: A Critical Study of Cryptographic API Misuses in the Wild
- 5.1.1 Introduction
- 5.1.2 Risk Model of Vulnerabilities Introduced by Cryptographic API Misuses
- 5.1.3 Empirical Study
- 5.1.4 Manual Analysis of Reports (RQ1)
- 5.1.5 Vulnerabilities (RQ2)
- 5.1.6 Related Work
- 5.1.7 Conclusion
- 5.2 Supporting Error Chains in Static Analysis for Precise Evaluation Results and Enhanced Usability
- 5.2.1 Introduction
- 5.2.2 Cryptographic Misuse Example
- 5.2.3 Analysis Algorithm
- 5.2.4 Design
- 5.2.5 Evaluation
- 5.2.6 Related Work
- 5.2.7 Limitations & Future Work
- 5.2.8 Conclusion
- 5.3 CamBench — Cryptographic API Misuse Detection Tool Benchmark Suite
- 6 LLM-SASTRepair — Can SAST Tools Support LLMs in Automatically Repairing Cryptographic API Misuses?
- 6.1 Introduction
- 6.2 Approach
- 6.3 Implementation
- 6.4 Evaluation
- 6.4.1 Setup
- 6.4.2 Definition of Metrics
- 6.4.3 Benchmarking
- 6.4.4 Research Question 1
- 6.4.5 Research Question 2
- 6.4.6 Limitations
- 6.4.7 Threats to Validity
- 6.5 Related Work
- 6.6 Conclusion and Outlook
- 7 SecAI — Supporting Developers in Secure Coding: Systematically Improving SAST Tool Usability Through AI-Enhanced Feedback
- 7.1 Introduction
- 7.2 Foundations
- 7.3 SecAI — SonarQube-plugin Design and Implementation
- 7.4 Features of SecAI
- 7.4.1 Exact Error Localization
- 7.4.2 Error Message and Description
- 7.4.3 Visualization of Interconnected Errors
- 7.4.4 Quick Fixes
- 7.4.5 AI-assisted Code Enhancement
- 7.4.6 Secure Code Generation
- 7.4.7 Severity Score
- 7.4.8 False Positive Detection — FPPredictor
- 7.5 Results
- 7.6 Conclusion
- 8 Conclusion and Outlook
- 9 Implementations and Data
- Bibliography
- List of Figures
- List of Tables
- Listings
