Pith. sign in

REVIEW 1 cited by

CamBench -- Cryptographic API Misuse Detection Tool Benchmark Suite

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2204.06447 v1 pith:6HXAOUSS submitted 2022-04-13 cs.SE

classification cs.SE
keywords benchmarkdetectionmisusecambenchcryptographictoolsdomaingeneration
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Context: Cryptographic APIs are often misused in real-world applications. Therefore, many cryptographic API misuse detection tools have been introduced. However, there exists no established reference benchmark for a fair and comprehensive comparison and evaluation of these tools. While there are benchmarks, they often only address a subset of the domain or were only used to evaluate a subset of existing misuse detection tools. Objective: To fairly compare cryptographic API misuse detection tools and to drive future development in this domain, we will devise such a benchmark. Openness and transparency in the generation process are key factors to fairly generate and establish the needed benchmark. Method: We propose an approach where we derive the benchmark generation methodology from the literature which consists of general best practices in benchmarking and domain-specific benchmark generation. A part of this methodology is transparency and openness of the generation process, which is achieved by pre-registering this work. Based on our methodology we design CamBench, a fair "Cryptographic API Misuse Detection Tool Benchmark Suite". We will implement the first version of CamBench limiting the domain to Java, the JCA, and static analyses. Finally, we will use CamBench to compare current misuse detection tools and compare CamBench to related benchmarks of its domain.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Hidden Ciphers and Where to Find Them: Static Discovery and Assessment of Cryptographic Assets in Software

    cs.CR 2026-08 conditional novelty 6.0 of 10

    A classification-driven static scanner with a separate rule repository discovers and assesses cryptographic assets at rest, achieving F1 0.75 on a synthetic benchmark and finding 370 assets in ten real services.

Pith tools