Detecting Misuse of Security APIs: A Systematic Review

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Mousavi, Zahra, Islam, Chadni, Babar, M. Ali, Abuadbba, Alsharif, Moore, Kristen
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918019461021696
author Mousavi, Zahra
Islam, Chadni
Babar, M. Ali
Abuadbba, Alsharif
Moore, Kristen
author_facet Mousavi, Zahra
Islam, Chadni
Babar, M. Ali
Abuadbba, Alsharif
Moore, Kristen
contents Security Application Programming Interfaces (APIs) are crucial for ensuring software security. However, their misuse introduces vulnerabilities, potentially leading to severe data breaches and substantial financial loss. Complex API design, inadequate documentation, and insufficient security training often lead to unintentional misuse by developers. The software security community has devised and evaluated several approaches to detecting security API misuse to help developers and organizations. This study rigorously reviews the literature on detecting misuse of security APIs to gain a comprehensive understanding of this critical domain. Our goal is to identify and analyze security API misuses, the detection approaches developed, and the evaluation methodologies employed along with the open research avenues to advance the state-of-the-art in this area. Employing the systematic literature review (SLR) methodology, we analyzed 69 research papers. Our review has yielded (a) identification of 6 security API types; (b) classification of 30 distinct misuses; (c) categorization of detection techniques into heuristic-based and ML-based approaches; and (d) identification of 10 performance measures and 9 evaluation benchmarks. The review reveals a lack of coverage of detection approaches in several areas. We recommend that future efforts focus on aligning security API development with developers' needs and advancing standardized evaluation methods for detection technologies.
format Preprint
id arxiv_https___arxiv_org_abs_2306_08869
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Detecting Misuse of Security APIs: A Systematic Review
Mousavi, Zahra
Islam, Chadni
Babar, M. Ali
Abuadbba, Alsharif
Moore, Kristen
Cryptography and Security
Software Engineering
Security Application Programming Interfaces (APIs) are crucial for ensuring software security. However, their misuse introduces vulnerabilities, potentially leading to severe data breaches and substantial financial loss. Complex API design, inadequate documentation, and insufficient security training often lead to unintentional misuse by developers. The software security community has devised and evaluated several approaches to detecting security API misuse to help developers and organizations. This study rigorously reviews the literature on detecting misuse of security APIs to gain a comprehensive understanding of this critical domain. Our goal is to identify and analyze security API misuses, the detection approaches developed, and the evaluation methodologies employed along with the open research avenues to advance the state-of-the-art in this area. Employing the systematic literature review (SLR) methodology, we analyzed 69 research papers. Our review has yielded (a) identification of 6 security API types; (b) classification of 30 distinct misuses; (c) categorization of detection techniques into heuristic-based and ML-based approaches; and (d) identification of 10 performance measures and 9 evaluation benchmarks. The review reveals a lack of coverage of detection approaches in several areas. We recommend that future efforts focus on aligning security API development with developers' needs and advancing standardized evaluation methods for detection technologies.
title Detecting Misuse of Security APIs: A Systematic Review
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2306.08869