APP-Miner: Detecting API Misuses via Automatically Mining API Path Patterns

Jiasheng Jiang, Jingzheng Wu, Xiang Ling, Tianyue Luo, Sheng Qu, Yanjun Wu

IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 4

Overview

The talk "APP-Miner: Detecting API Misuses via Automatically Mining API Path Patterns" by Jiasheng Jiang and his co-authors from the Institute of Software, Chinese Academy of Sciences, introduces a novel framework designed to automatically identify API misuses in software. In modern software development, programmers frequently utilize Application Programming Interfaces (APIs) to implement complex functionalities without necessarily understanding their intricate internal mechanisms or the specific API patterns required for correct usage. Violations of these patterns can lead to severe security implications, ranging from memory leaks and integer overflows to stack overflows.

Watch on YouTube

Visual summary for APP-Miner: Detecting API Misuses via Automatically Mining API Path Patterns by Jiasheng Jiang, Jingzheng Wu, Xiang Ling, Tianyue Luo, Sheng Qu, Yanjun Wu
Visual summary for APP-Miner: Detecting API Misuses via Automatically Mining API Path Patterns by Jiasheng Jiang, Jingzheng Wu, Xiang Ling, Tianyue Luo, Sheng Qu, Yanjun Wu

Key moments

  1. 0:00 Introduction to API misuses and detection challenge
  2. 2:00 Motivating example: uscttojiffies misuse in Linux kernel
  3. 3:17 High-level overview of the APP-Miner system design
  4. 4:20 Addressing unconnected subgraphs with topologizing and completion
  5. 6:00 Efficient frequent subgraph mining using index matrices and Apriori
  6. 8:00 How APP-Miner detects API misuses via binary discriminant
  7. 8:20 Evaluation results: new bugs, CVEs, and tool comparison

APP-Miner: Detecting API Misuses via Automatically Mining API Path Patterns

Speakers: Jiasheng Jiang, Jingzheng Wu, Xiang Ling, Tianyue Luo, Sheng Qu, Yanjun Wu

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=7YgqAM2LTbQ

Overview

The talk "APP-Miner: Detecting API Misuses via Automatically Mining API Path Patterns" by Jiasheng Jiang and his co-authors from the Institute of Software, Chinese Academy of Sciences, introduces a novel framework designed to automatically identify API misuses in software. In modern software development, programmers frequently utilize Application Programming Interfaces (APIs) to implement complex functionalities without necessarily understanding their intricate internal mechanisms or the specific API patterns required for correct usage. Violations of these patterns can lead to severe security implications, ranging from memory leaks and integer overflows to stack overflows.

The critical challenge in detecting such misuses lies in accurately obtaining these underlying API patterns. Existing approaches often suffer from limitations such as requiring manual pattern templates, demanding extensive manual effort for test case generation, or struggling with the implicit nature of patterns not explicitly documented. APP-Miner addresses these shortcomings by proposing a general framework that leverages frequent subgraph mining techniques to automatically extract API path patterns directly from source code, without the need for predefined templates.

This research is significant because it offers an automated, scalable solution to a pervasive security problem. By discovering the "probable correct usage" of APIs, APP-Miner can proactively identify deviations that indicate potential vulnerabilities. The framework's ability to operate on large-scale software projects and its demonstrated success in uncovering numerous new bugs and CVEs underscore its practical importance for improving software security and reliability in an increasingly API-driven development landscape.

Background

▶ Watch: Introduction to API misuses and detection challenge (0:00)

The proliferation of APIs in software development has enabled rapid innovation, yet it has also introduced a subtle but significant class of vulnerabilities: API misuses. Programmers, often working under tight deadlines, frequently integrate APIs based on functional requirements without a deep understanding of their precise operational sequences or preconditions—what the authors refer to as API patterns. When these patterns are violated, the consequences can be severe. A classic example cited is the kmalloc family of APIs in the Linux kernel: the correct pattern involves checking the allocation size, calling kmalloc, checking the returned pointer, using the pointer, and finally, freeing the allocated memory via kfree. Deviating from this pattern, such as omitting the check allocation size step, can lead to a stack overflow, while forgetting kfree results in a memory leak.

The core problem, therefore, is the difficulty in obtaining these critical API patterns. Current research efforts in this domain can be broadly categorized into three approaches:

  1. Source Code-based Extraction: Many tools in this category rely on manually provided pattern templates. These templates require prior knowledge of the software's intricacies and inherently limit the scope of pattern discovery to what is already anticipated by human experts. This approach is labor-intensive and not scalable to novel or undocumented patterns.
  2. Dynamic Analysis via Test Cases: This method involves generating test cases to execute the software and then monitoring dynamic traces to identify frequent sequences of API calls. While capable of discovering real-world execution paths, generating comprehensive test cases is a significant manual effort. Furthermore, the inherent challenge of achieving high code coverage means that these methods often fail to capture complete API patterns, leaving many potential misuses undetected.
  3. Documentation-based Extraction: Utilizing Natural Language Processing (NLP) technologies, this category attempts to extract patterns from API documentation. However, a major hurdle is that many API patterns, especially those related to security-critical preconditions or post-conditions, are often implicit, complex, and not thoroughly documented by programmers. They are effectively "hidden in the source code."

APP-Miner addresses these limitations by taking a different approach. Its critical insight is that API patterns, particularly those involving security-relevant checks and operations, usually consist of data-related operations to the API under scrutiny and are commonly present throughout the source code. The talk motivates this insight with a concrete example from the Linux kernel involving the usct_to_jiffies function, which converts microseconds into jiffies. Out of 147 usages of this function, 146 correctly incorporated a data-related check to prevent integer overflow. A single misuse, however, lacked this crucial check, demonstrating a clear pattern violation with potential security implications. By constructing Control Flow Graphs (CFGs) consisting only of operations data-related to usct_to_jiffies, the authors observed that the maximum frequent subgraphs revealed the correct pattern, which could then be used to detect the observed misuse. This observation forms the foundation for APP-Miner's automated pattern mining strategy.

Key Findings

▶ Watch: High-level overview of the APP-Miner system design (3:17)

APP-Miner presents a robust and automated framework for uncovering API misuses by systematically mining API path patterns. The key findings and contributions of this research are multi-faceted:

Firstly, APP-Miner successfully demonstrates the feasibility of automatically extracting API path patterns from source code using frequent subgraph mining techniques. This approach eliminates the need for manual pattern templates or extensive prior knowledge, offering a significant improvement over traditional methods that are often labor-intensive and limited in scope. By focusing on data-related operations within Control Flow Graphs (CFGs), the system can infer the probable correct usage sequences of APIs.

Secondly, the research identifies and effectively addresses two primary challenges inherent in applying frequent subgraph mining to API pattern extraction: the issue of unconnected subgraphs and the exponential complexity of the mining process. APP-Miner introduces novel techniques such as topologizing and completion to ensure the extracted patterns remain connected and semantically meaningful. To tackle computational efficiency, it employs index matrices and an A-priori based algorithm, making the process scalable for large codebases.

Thirdly, the practical efficacy of APP-Miner was rigorously evaluated on four widely used, large-scale open-source software projects: the Linux kernel, OpenSSL, FFMPEG, and Apache HTTPD. This evaluation yielded impressive results, with APP-Miner extracting a total of 4,788 API path patterns. More critically, the system detected 157 new bugs and contributed to the identification of 19 CVEs (Common Vulnerabilities and Exposures), underscoring its capability to uncover previously unknown security vulnerabilities.

Finally, comparative analysis against state-of-the-art tools in the domain, such as CIGs and APISign, revealed that APP-Miner consistently outperformed them. The evaluation showed that APP-Miner was superior in identifying "the most true patterns" and achieving "the most true positives" when detecting API misuses, positioning it as a leading solution for automated API misuse detection. These findings collectively establish APP-Miner as a significant advancement in static analysis for software security, providing an automated, scalable, and highly effective method for preventing API-related vulnerabilities.

Technical Deep Dive

▶ Watch: Addressing unconnected subgraphs with topologizing and completion (4:20)

APP-Miner's architecture is designed to systematically transform source code into actionable API path patterns, employing a series of sophisticated steps. The high-level idea centers on leveraging frequent subgraph mining to infer these patterns.

The system's workflow begins with the source code and proceeds through several stages:

  1. API Path Generation: This initial phase converts raw source code into a structured representation suitable for pattern mining. APP-Miner utilizes the Clang compiler to convert the source code into a Control Flow Graph (CFG). From this comprehensive CFG, the system then traverses and prunes operations, retaining only those that exhibit a direct data relationship with the API under analysis. The resulting API path specifically focuses on three types of program elements: the APIs themselves, condition checks (e.g., if statements, comparisons), and return statements. Nodes within this API path are labeled using API names, check, and return keywords, effectively creating a simplified, API-centric CFG for each usage instance.
  1. Addressing Challenges in Frequent Subgraph Mining: Two significant challenges typically plague frequent subgraph mining in this context:
  • Unconnected Subgraphs: Standard frequent subgraph mining algorithms may remove infrequent nodes and their associated edges. If a frequent node A is connected to another frequent node E via an infrequent node C, the removal of C would result in an unconnected subgraph (e.g., A and E become disconnected). However, an API path pattern must represent a connected sequence of operations.
  • APP-Miner tackles this with topologizing and completion techniques. First, it unrolls loops only once to prevent infinite paths and simplify graph structures. Next, it assists the graph by adding "dotted line" edges from each node to its direct and indirect descendants within the original CFG, effectively capturing potential control flow without explicit intermediate nodes. Finally, it aggregates multiple paths into a single, complete topology. This process ensures that even if infrequent nodes are later pruned, the newly added edges can bridge the gaps, connecting frequent nodes and allowing for the extraction of truly connected API path patterns.
  • Exponential Complexity: Frequent subgraph mining is inherently an NP-hard problem. For an N-node graph, there can be 2^N possible subgraphs, making direct enumeration and frequency counting computationally infeasible for large software projects.
  • APP-Miner addresses this by building index matrices and employing an A-priori based frequent subgraph mining algorithm.
  • Index Matrices: After labeling nodes (API names, check, return) and edges (by their head and tail nodes), each API path graph is treated as a set of edges. APP-Miner constructs lexicons of API paths and edges. It then builds a binary index matrix where each column represents a potential edge (a forward index) and each row represents an API path (an inverted index). A 0 indicates the absence of an edge in a path, while a 1 indicates its presence. This matrix facilitates highly efficient binary arithmetic for graph operations, drastically speeding up subgraph matching and frequency counting.
  • A-priori Algorithm: The core principle of A-priori is that "all subgraphs of a frequent graph must also be frequent." This property is used to prune the search space. Instead of generating all possible 2^N subgraphs, APP-Miner starts by finding frequent 1-edge subgraphs. Then, it only generates candidate 2-edge subgraphs by combining only the frequent 1-edge subgraphs. For instance, if a frequency threshold is 2, and E1 and E2 are frequent 1-edge subgraphs while E3 and E4 are not, the algorithm will only consider E1-E2 as a candidate for a 2-edge subgraph, ignoring combinations involving E3 or E4. This pruning strategy significantly reduces the number of candidates (e.g., from 15 to 5 in the example given), making the mining process tractable for large codebases.
  1. API Misuse Detection: The final step involves using the extracted API path patterns to identify violations. Benefiting from the efficiency of the index matrix, APP-Miner employs a binary arithmetic discriminant to match API paths (G) against API path patterns (P). The discriminant G AND P = P efficiently checks if a given API path G contains a specific pattern P. If this condition is not met for a known pattern P, the API path G is flagged as a potential misuse. The system then ranks these violations to help prioritize investigation, focusing on the most probable API misuses.

Demo / Proof of Concept

▶ Watch: How APP-Miner detects API misuses via binary discriminant (8:00)

While the talk did not feature a live, interactive demonstration of the APP-Miner tool, its effectiveness as a proof of concept was thoroughly validated through an extensive evaluation on real-world, large-scale open-source software projects. This evaluation served as the ultimate demonstration of APP-Miner's capabilities.

The experiments were conducted on a virtual machine equipped with 48 cores and 128 GB of RAM, utilizing LLVM 10 for compilation. This robust environment allowed for the analysis of significant codebases, including the Linux kernel, OpenSSL, FFMPEG, and Apache HTTPD. These projects were chosen due to their vast quantity of code and active, ongoing maintenance, representing challenging and realistic targets for security analysis.

The results of this evaluation were compelling:

  • APP-Miner successfully extracted a total of 4,788 API path patterns across the analyzed software. This demonstrates its ability to automatically learn a comprehensive set of correct API usage behaviors.
  • More importantly, the framework detected 157 new bugs within these projects. These were not theoretical findings but concrete vulnerabilities identified in widely used software.
  • Of these findings, 19 CVEs (Common Vulnerabilities and Exposures) were gained, signifying that the identified issues were recognized as legitimate security vulnerabilities by the broader security community.

To provide a comparative context, APP-Miner's performance was benchmarked against other state-of-the-art tools in the field, specifically CIGs and APISign. The comparison focused on the top 10 violated API patterns and the top five violations for each pattern. The results indicated that APP-Miner consistently found "the most true patterns" and "the most true positives" for API misuses, suggesting superior accuracy and coverage compared to existing methodologies. For instance, the talk highlighted the usct_to_jiffies example where 146 out of 147 usages followed the correct pattern, and APP-Miner was able to identify the single outlier as a misuse, demonstrating its precision in distinguishing correct from incorrect usage. The efficient detection of misuses was attributed to the binary arithmetic discriminant (G AND P = P), which rapidly checks if an API path G conforms to a pattern P, flagging G2 as a potential bug if it doesn't satisfy the pattern.

The presenters briefly mentioned that APP-Miner "has some limitations that need to be solved in the future," though specific details about these limitations were not elaborated upon in the transcript. Despite this, the extensive evaluation and the tangible results in terms of bug and CVE discovery provide strong evidence of APP-Miner's practical utility and its significant advancement in automated API misuse detection.

Defensive Implications

▶ Watch: Evaluation results: new bugs, CVEs, and tool comparison (8:20)

The development of APP-Miner offers critical insights and actionable strategies for various stakeholders in the software security ecosystem. Its capabilities can significantly enhance defensive postures against API-related vulnerabilities.

  1. For Software Developers and Development Teams: Developers should consider integrating tools like APP-Miner into their Continuous Integration/Continuous Deployment (CI/CD) pipelines. By automatically scanning code for API misuses as part of the build or commit process, potential vulnerabilities can be identified and remediated early in the development lifecycle, significantly reducing the cost and effort of fixing them post-deployment. This shifts API misuse detection left, making it a proactive rather than reactive measure.
  1. For Security Auditors and Penetration Testers: APP-Miner provides a powerful static analysis capability that can augment traditional security audits. Auditors can leverage such tools to quickly uncover hidden API patterns and identify deviations in large, complex codebases that might be missed by manual review or dynamic testing. This allows for a more comprehensive and efficient assessment of an application's security posture, particularly for critical APIs where misuse could have severe consequences.
  1. For Software Architects and API Designers: The patterns mined by APP-Miner highlight how APIs are actually used (or misused) in practice. This feedback can be invaluable for architects and designers to refine API contracts, improve documentation, and design more robust APIs that are harder to misuse. Clearer guidelines, better examples, and perhaps even built-in runtime checks for common misuse patterns could be informed by the insights gained from such tools.
  1. For Static Analysis Tool Vendors: The novel techniques employed by APP-Miner, particularly topologizing and completion for connected pattern extraction and the use of index matrices with A-priori based algorithms for efficiency, represent significant advancements. Vendors of existing static analysis tools can incorporate these methodologies to enhance their API misuse detection capabilities, offering more comprehensive and accurate vulnerability scanning to their customers.
  1. For Researchers and Educators: The methodology of automatically mining implicit API patterns from source code provides a fertile ground for further research into program comprehension and automated security analysis. Educators can use APP-Miner's approach as a case study to teach advanced static analysis techniques and the importance of API security, fostering a new generation of security-aware developers and researchers.

By leveraging tools like APP-Miner, organizations can move beyond manual, template-driven approaches to API security, embracing automated, data-driven methods that are more scalable, comprehensive, and effective in protecting against a common and critical class of software vulnerabilities.

Key Takeaways

  • API Misuses are a Critical Security Vector: Violations of proper API usage patterns, often due to implicit knowledge gaps, are a pervasive source of security vulnerabilities such as memory leaks, integer overflows, and stack overflows.
  • Automated Pattern Extraction is Achievable: APP-Miner introduces a novel, template-free framework that automatically extracts API path patterns from source code using frequent subgraph mining, eliminating the need for manual pattern definitions or extensive prior knowledge.
  • Overcoming Technical Challenges: The framework successfully addresses key challenges in frequent subgraph mining, including ensuring connected patterns through topologizing and completion, and managing computational complexity with index matrices and an A-priori based algorithm.
  • Demonstrated Effectiveness on Real-World Software: Evaluated on major open-source projects (Linux kernel, OpenSSL, FFMPEG, Apache HTTPD), APP-Miner identified 157 new bugs and contributed to 19 CVEs, proving its practical utility and superior performance compared to existing tools like CIGs and APISign.
  • Efficient Misuse Detection: The system uses a highly efficient binary arithmetic discriminant to match API paths against learned patterns, enabling rapid and accurate identification of potential API misuses.
  • Advancing Static Analysis for API Security: APP-Miner represents a significant step forward in automated static analysis, providing a scalable and effective method for proactively detecting API misuses and enhancing overall software security.

About the Speaker(s)

Jiasheng Jiang is one of the authors of the APP-Miner research. He, along with his co-authors Jingzheng Wu, Xiang Ling, Tianyue Luo, Sheng Qu, and Yanjun Wu, is affiliated with the Institute of Software, Chinese Academy of Sciences. Their work focuses on advancing automated techniques for detecting API misuses and improving software security.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

APP-Miner presents a robust, automated framework for detecting API misuses by mining implicit patterns from source code. Its novel approach to frequent subgraph mining, addressing connectivity and computational complexity, yielded 19 CVEs in critical projects. This is a significant advancement in practical static analysis for software security.

Heather Calloway (CISO) — STRONG ACCEPT

APP-Miner presents a credible, automated framework for detecting API misuses, a significant source of vulnerabilities in critical software. Its proven ability to uncover 19 CVEs in major open-source projects validates its practical impact. This work offers a clear path for security leaders to integrate automated pattern detection into their development lifecycles.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024