inklap

CryptoBinaryRz: a binary detection framework based on regional centralization dynamic analysis of cryptographic misuse

Xi Luo, Zecheng Zhang, Lihua Yin, Shijie Jia, Runda Huang, Haiyang Zhang · Cybersecurity · 2026

Abstract The correct application of cryptography is crucial for protecting confidentiality, integrity, and sensitive information in modern software systems. However, cryptographic APIs are frequently misused in practice because they are difficult to apply correctly and their security implications are often highly context dependent. Existing misuse detection research mainly targets source code, while binary-level detection remains underexplored despite its ability to access concrete runtime states and validate misuse conditions more directly. Binary analysis for cryptographic misuse faces three major challenges: severe path explosion, difficult parameter provenance recovery, and limited credibility of purely static results. To address these challenges, we present CryptoBinaryRz, a binary-level cryptographic misuse detection framework that combines locality-based region construction, context-aware dynamic provenance, path reuse-aware state management, and constraint-based misuse verification. Our method constrains analysis to sink-centered local regions, recovers parameter influence through symbolic mutation, restores nearby cryptographic calling environments throug

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً