用ChatGPT检测加密API误用,效果优于传统静态分析工具
ChatGPT's Potential in Cryptography Misuse Detection: A Comparative Analysis with Static Analysis Tools
- 通过提示工程优化,让ChatGPT识别加密调用错误
- 在CryptoAPI-Bench上表现超越主流静态分析工具
- 适合开发者快速发现代码中的加密漏洞
正确使用加密API对主流开发者而言极具挑战,常导致广泛存在的API误用问题。目前的加密误用检测工具性能参差不齐,且多数开发者难以获取。本文基于CryptoAPI-Bench基准,评估ChatGPT检测加密误用的能力,并与当前最先进的静态分析工具进行对比。结果表明,经过提示工程优化后,ChatGPT不仅能有效识别加密API误用,甚至在多个测试场景中表现优于领先静态分析工具。该研究揭示了大模型在安全代码检测中的潜力。
原文摘要 · Abstract (English)
The correct adoption of cryptography APIs is challenging for mainstream developers, often resulting in widespread API misuse. Meanwhile, cryptography misuse detectors have demonstrated inconsistent performance and remain largely inaccessible to most developers. We investigated the extent to which ChatGPT can detect cryptography misuses and compared its performance with that of the state-of-the-art static analysis tools. Our investigation, mainly based on the CryptoAPI-Bench benchmark, demonstrated that ChatGPT is effective in identifying cryptography API misuses, and with the use of prompt engineering, it can even outperform leading static cryptography misuse detectors.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。