kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Evaluating Cryptographic API Misuse Detectors for Go
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Theoretical Computer Science, TCS.ORCID iD: 0009-0000-6519-625X
KTH, School of Electrical Engineering and Computer Science (EECS), Theoretical Computer Science.ORCID iD: 0000-0003-3505-3383
2026 (English)In: Proceedings 2026 IEEE/ACM 4th International Workshop on Software Vulnerability Management, SVM 2026, Association for Computing Machinery (ACM) , 2026, p. 25-32Conference paper, Published paper (Refereed)
Abstract [en]

Cryptographic API misuse represents a critical vulnerability class that undermines the security foundations of modern software. Yet, it remains largely unexplored in Go despite its dominance in security-critical infrastructure. This paper presents the first comprehensive study of cryptographic API misuse detection in Go, identifying and analyzing 4 state-of-the-art tools (CodeQL, Gopher, Gosec, and Snyk Code) and establishing a consolidated taxonomy of 14 relevant misuse classes. Through an experimental evaluation of 328 security-critical open-source Go projects, we discovered 7,473 cryptographic API misuses, providing insights into the prevalence and distribution of these vulnerabilities. Our systematic comparison reveals significant variations in misuse coverage, with immediate practical implications for security engineers and long-term implications for research in this domain.

Place, publisher, year, edition, pages
Association for Computing Machinery (ACM) , 2026. p. 25-32
Keywords [en]
Cryptographic API misuse, Go, Security tool comparison
National Category
Other Electrical Engineering, Electronic Engineering, Information Engineering Software Engineering
Identifiers
URN: urn:nbn:se:kth:diva-383422DOI: 10.1145/3786165.3788440Scopus ID: 2-s2.0-105040578376OAI: oai:DiVA.org:kth-383422DiVA, id: diva2:2070249
Conference
IEEE/ACM 4th International Workshop on Software Vulnerability Management, SVM 2026, Rio de Janeiro, Brazil, Apr 12 2026 - Apr 18 2026
Note

Part of ISBN 9798400723971

QC 20260611

Available from: 2026-06-11 Created: 2026-06-11 Last updated: 2026-06-11Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Andersson, ViviMonperrus, Martin

Search in DiVA

By author/editor
Andersson, ViviMonperrus, Martin
By organisation
Theoretical Computer Science, TCSTheoretical Computer Science
Other Electrical Engineering, Electronic Engineering, Information EngineeringSoftware Engineering

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 16 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf