Symmaries: Automatic Inference of Formal Security Summaries for Java Programs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Khakpour, Narges, Berthier, Nicolas
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908730495336448
author Khakpour, Narges
Berthier, Nicolas
author_facet Khakpour, Narges
Berthier, Nicolas
contents We introduce a scalable, modular, and sound approach for automatically constructing formal security specifications for Java bytecode programs in the form of method summaries. A summary provides an abstract representation of a method's security behavior, consisting of the conditions under which the method can be securely invoked, together with specifications of information flows and aliasing updates. Such summaries can be consumed by static code analysis tools and also help developers understand the behavior of code segments, such as libraries, in order to evaluate their security implications when reused in applications. Our approach is implemented in a tool called Symmaries, which automates the generation of security summaries. We applied Symmaries to Java API libraries to extract their security specifications and to large real-world applications to evaluate its scalability. Our results show that the tool successfully scales to analyze applications with hundreds of thousands of lines of code, and that Symmaries achieves a promising precision depending on the heap model used. We prove the soundness of our approach in terms of guaranteeing termination-insensitive non-interference.
format Preprint
id arxiv_https___arxiv_org_abs_2512_20396
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Symmaries: Automatic Inference of Formal Security Summaries for Java Programs
Khakpour, Narges
Berthier, Nicolas
Cryptography and Security
Formal Languages and Automata Theory
Programming Languages
Software Engineering
We introduce a scalable, modular, and sound approach for automatically constructing formal security specifications for Java bytecode programs in the form of method summaries. A summary provides an abstract representation of a method's security behavior, consisting of the conditions under which the method can be securely invoked, together with specifications of information flows and aliasing updates. Such summaries can be consumed by static code analysis tools and also help developers understand the behavior of code segments, such as libraries, in order to evaluate their security implications when reused in applications. Our approach is implemented in a tool called Symmaries, which automates the generation of security summaries. We applied Symmaries to Java API libraries to extract their security specifications and to large real-world applications to evaluate its scalability. Our results show that the tool successfully scales to analyze applications with hundreds of thousands of lines of code, and that Symmaries achieves a promising precision depending on the heap model used. We prove the soundness of our approach in terms of guaranteeing termination-insensitive non-interference.
title Symmaries: Automatic Inference of Formal Security Summaries for Java Programs
topic Cryptography and Security
Formal Languages and Automata Theory
Programming Languages
Software Engineering
url https://arxiv.org/abs/2512.20396