Detecting Functionality-Specific Vulnerabilities via Retrieving Individual Functionality-Equivalent APIs in Open-Source Repositories
Обнаружение уязвимостей, специфичных для функциональности, путем поиска индивидуальных эквивалентных по функциональности API в открытых репозиториях
2025-01-01
SCID: 54.1/9fkf7arm
Discuss with AI
API docstrings and signaturesAPISSCVEJava repositoriesLarge Language Model API embeddingProof-of-Concept (PoC) migrationTop-1 Accuracyfunctionality-equivalent APIsfunctionality-specific vulnerabilities
Figures from the paper
Abstract (AI)
Functionality-specific vulnerabilities, which mainly occur in Application Programming Interfaces (APIs) with specific functionalities, are crucial for software developers to detect and avoid. When detecting individual functionality-specific vulnerabilities, the existing two categories of approaches are ineffective because they consider only the API bodies and are unable to handle diverse implementations of functionality-equivalent APIs. To effectively detect functionality-specific vulnerabilities, we propose APISS, the first approach to utilize API doc strings and signatures instead of API bodies. APISS first retrieves functionality-equivalent APIs for APIs with existing vulnerabilities and then migrates Proof-of-Concepts (PoCs) of the existing vulnerabilities for newly detected vulnerable APIs. To retrieve functionality-equivalent APIs, we leverage a Large Language Model for API embedding to improve the accuracy and address the effectiveness and scalability issues suffered by the existing approaches. To migrate PoCs of the existing vulnerabilities for newly detected vulnerable APIs, we design a semi-automatic schema to substantially reduce manual costs. We conduct a comprehensive evaluation to empirically compare APISS with four state-of-the-art approaches of detecting vulnerabilities and two state-of-the-art approaches of retrieving functionality-equivalent APIs. The evaluation subjects include 180 widely used Java repositories using 10 existing vulnerabilities, along with their PoCs. The results show that APISS effectively retrieves functionality-equivalent APIs, achieving a Top-1 Accuracy of 0.81 while the best of the baselines under comparison achieves only 0.55. APISS is highly efficient: the manual costs are within 10 minutes per vulnerability and the end-to-end runtime overhead of testing one candidate API is less than 2 hours. APISS detects 179 new vulnerabilities and receives 60 new CVE IDs, bringing high value to security practice.
Key Findings
1
APISS detected 179 new vulnerabilities and led to 60 new CVE IDs, demonstrating practical value to security practice.
2
APISS is efficient: manual costs are within 10 minutes per vulnerability and end-to-end runtime to test one candidate API is under 2 hours.
3
APISS is the first approach that uses API docstrings and signatures (not API bodies) to detect functionality-specific vulnerabilities.
4
APISS migrates Proof-of-Concepts (PoCs) from known vulnerable APIs to newly detected vulnerable APIs using a semi-automatic schema, substantially reducing manual costs.
5
APISS retrieves functionality-equivalent APIs by leveraging a Large Language Model for API embedding, improving accuracy and scalability over existing methods.
6
In evaluation on 180 Java repositories with 10 vulnerabilities and their PoCs, APISS achieved Top-1 Accuracy of 0.81 for retrieving functionality-equivalent APIs versus 0.55 for the best baseline.
Research Object
Functionality-equivalent APIs in open-source Java repositories
Research Subject
Detection of functionality-specific vulnerabilities by retrieving functionality-equivalent APIs using API docstrings and signatures, embedding via a Large Language Model, and migrating PoCs to newly identified vulnerable APIs
Publication Details
Publication Date
2025-01-01
Journal
Publisher
ISSN
Cited by
0
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest
Cited by5
A Survey on Knowledge Graphs: Representation, Acquisition, and Applications2021
Semi-supervised Credit Card Fraud Detection via Attribute-Driven Graph Representation2023
Abstracts of the 2022 Joint Annual Conference of the Austrian (ÖGBMT), German (VDE DGBMT) and Swiss (SSBE) Societies for Biomedical Engineering, including the 14th Vienna International Workshop on Functional Electrical Stimulation2022
MAGNN: Metapath Aggregated Graph Neural Network for Heterogeneous Graph Embedding2020
Graph neural networks: A review of methods and applications2020