隐藏的密码及其发现途径:软件中密码资产的静态发现与评估
Hidden Ciphers and Where to Find Them: Static Discovery and Assessment of Cryptographic Assets in Software
浏览论文内容
中文总结 AI 辅助
本文提出分类驱动的静态方法,可在不到6分钟处理57610个文件,发现370个密码资产(含6个CVE漏洞、52个后量子迁移候选),F1达0.75,助力密码资产发现与后量子迁移规划
中文摘要 AI 辅助
现代软件系统依靠密码学实现数据保护、身份认证与信任建立,但企业往往缺乏对部署在源代码、配置文件、依赖项及密码文件中的密码学组件的结构化视图。这种可见性的缺失会增加安全治理与后量子迁移规划的难度。本文提出一种用于发现和评估软件系统中密码资产的静态方法。我们引入了密码材料(Crypto-Material)、密码制品(Crypto-Artifacts)与密码调用(Crypto-Invocations)的分类,基于该分类推导了一个可扩展的、与扫描器无关的规则库,并实现了一个静态扫描器,应用这些规则生成面向密码组件清单(CBOM)的输出。我们在带有已知真值的合成基准测试集,以及包含10个已部署服务的真实基础设施上对该方法进行评估。该扫描器在资产发现任务中达到了0.75的F1分数,且能正确标注91%的预期弱点与漏洞。在真实场景中,它在不到6分钟内处理了57610个文件,发现了370个密码资产,其中包括6个与CVE关联的漏洞和52个后量子迁移候选项。我们针对真实场景的覆盖度是与手动编制的参考列表进行评估,而非穷尽式评估。这些结果表明,由分类驱动的静态发现能够为安全治理与后量子迁移规划提供实用的密码学透明度。
英文摘要
Modern software systems rely on cryptography for data protection, authentication, and trust establishment, yet organizations often lack a structured view of the cryptography deployed across source code, configuration, dependencies, and cryptographic files. This lack of visibility complicates security governance and post-quantum migration planning. This paper presents a static approach for discovering and assessing cryptographic assets in software systems. We introduce a classification of Crypto-Material, Crypto-Artifacts, and Crypto-Invocations, derive an extensible scanner-independent rule repository from it, and implement a static scanner that applies these rules to produce CBOM-oriented output. We evaluate the approach on a synthetic benchmark with known ground truth and on a real-world infrastructure of ten deployed services. The scanner achieves an F1 score of 0.75 for asset discovery and correctly annotates 91% of expected weaknesses and vulnerabilities. In the realworld setting, it processes 57 610 files in under six minutes and discovers 370 cryptographic assets, including six CVE-linked vulnerabilities and 52 post-quantum migration candidates. Real-world coverage is assessed against a manually compiled reference list rather than an exhaustive one. These results show that classification-driven static discovery can provide practical cryptographic transparency for governance and post-quantum migration planning.