UPB Bildmarke
Press, Communications and Marketing Office
Contact
  • Deutsch
  • English
    • Open Page "Studies"
    • Prospective students
    • Students
    • International students & prospective students
    • School & teachers
    • Open Page "Teaching"
      • Open Page "Profile"
      • Academic Mission Statement
      • Digitalization & E-Learning
      • Open Source
      • Open Page "Teaching"
      • Competence-Oriented Education
      • Exam design
      • Organizing Courses
      • Course Evaluations
      • General Education Requirements
      • Lecture series on sustainability
    • AI in teaching
      • Open Page "Digital Teaching"
      • Digital Teaching
      • Digital learning rooms
      • Digital test formats
      • Digital test formats
      • Digital tools
      • FAQs
      • Open Page "Qualification and service"
      • Higher Education Development Unit
      • Writing Center
      • Internal Professional Development and Further Education
      • Interdisciplinary Cooperation to Improve Quality in Teacher Education (PLAZ)
      • Faculty-Specific Initiatives
      • Internationally Focused Academics
      • Open Page "Educational innovations"
      • Teaching Awards at UPB
      • Fellowship
      • Best-Practices Teaching Symposium
      • Teaching Projects
      • E-Learning Label
      • Open Page "Teaching research networks"
      • DH.NRW
      • Foundation for Innovation in Higher Education
      • Centre for Higher Mathematics Education (khdm)
      • Academic quality
    • Open Page "Research"
      • Open Page "Research profile"
      • Key research areas
      • Interdisciplinary research institutes
      • Research in the faculties
      • Collaborative Research Centres
      • Graduate Programmes and Schools
      • DFG Research Units
      • DFG Priority Programmes
      • ERC Grants
      • Leibniz Prize Winners
      • Heinz Maier Leibnitz Prize Winners
      • Open Page "Academic career"
      • Early career stages
      • Professorship at Paderborn University
      • Job portal
      • University as an employer
      • Open Page "Research funding and services"
      • Funding and application advice
      • Legal advice in research and development
      • Ethics Committee
      • Research Information at UPB
      • Research data management
      • Publication Service of the University Library
      • Open Access Portal
      • Inventions & patents
      • Start-ups and entrepreneurship
      • Network for Interdisciplinary Research
      • Internal grants (Committee for Research and Junior Academics)
      • Open Page "Research culture"
      • Research-Oriented Standards on Gender Equality
      • Gender & Diversity Consulting
      • Ethics committee
      • Good Research Practice
      • Human Resources Strategy for Researchers
    • Open Page "Transfer"
    • Creating together
    • Innovating together
    • Reflecting together
    • Contacts
    • Open Page "International"
    • International Profile
    • International Campus
    • Open Page "University"
      • Open Page "About us"
      • Mission Statement
      • History
      • Important Personalities and Pioneers
      • University Society
      • Alumni
      • Unishop
      • Open Page "Our organisation"
      • University Executive Board
      • Advisory Board
      • Senate
      • Faculties
      • Central University Administration
      • Central research institutes
      • Central operating units
      • Agencies and authorised representatives
      • Anlauf- und Beratungsstellen
      • Universitätskommissionen
      • Open Page "Working at UPB"
      • Vacancies
      • Equality, Compatibility and Diversity
      • Welcome Services
      • Personnel development
      • Scientific career paths
      • Dual Career Service
      • Healthy university
      • Social, sporting and cultural activities
    • Maps & directions
    • Open Page "Faculties"
    • Faculty of Arts and Humanities
    • Faculty of Business Administration and Economics
    • Faculty of Science
    • Faculty of Mechanical Engineering
    • Faculty of Computer Science, Electrical Engineering and Mathematics
  • Press
Researchers at the Heinz Nixdorf Institute in Paderborn develop specifiable analysis tool
Researchers at the Heinz Nixdorf Institute in Paderborn develop specifiable analysis tool
Contact
  1. Paderborn University
  2. University
  3. Press, Communications and Marketing Office
Back to the news list

Avoid­ing se­cur­ity vul­ner­ab­il­it­ies in in­dus­tri­al soft­ware

29.11.2023  |  Digitalization,  Research,  Economy & Business,  Press release,  Secure Software Engineering / Heinz Nixdorf Institut

Share post on:

  • Share on Instagram
  • Teilen auf Twitter
  • Teilen auf Facebook
  • Teilen auf Xing
  • Teilen auf LinkedIn
  • Teilen über E-Mail
  • Link kopieren

Researchers at the Heinz Nixdorf Institute in Paderborn develop specifiable analysis tool

We encounter software in many different places in our digitalised everyday lives, from chatting with friends and family to online banking. To simplify software development, programmers often use so-called "Application Programming Interfaces" (API) - codes that contain commands for general functions or enable interactions with an external system, for example. The use of APIs is helpful when there are standards to be adhered to or complicated programming tasks. However, incorrect use can also lead to security vulnerabilities and enormous costs. In order to recognise potential misuse at an early stage, scientists at the Heinz Nixdorf Institute at Paderborn University are working with TRUMPF SE + Co KG to develop an appropriate analysis tool. The "API_ASSIST - Specifiable automatic detection of API misuse in CI pipelines" project of the "Secure Software Engineering" group is being funded with 100,000 euros as part of the Software Campus programme of the Federal Ministry of Education and Research (BMBF). The project will run for 19 months.

From a general to a specifically customisable analysis tool

"The incorrect use of APIs often leads to security vulnerabilities, which can have catastrophic consequences in the financial sector, for example," says project manager Michael Schlichtig from Paderborn's Department of Computer Science. In the Collaborative Research Centre SFB 1119 "CROSSING", the research assistant has already developed the "CogniCrypt" programme, which detects the incorrect use of cryptographic APIs. As part of the new project, the static analysis tool is to be adapted so that programmers can use it for their individual areas of application. "Our goal is a precise and, above all, easily adaptable analysis programme for developers in the industry. The tool should be integrated into CI pipelines and be able to cover any APIs of the Java programming language," he explains. When designing the tool, the focus is not only on the simple adaptability of the analysis to the application context, but also on comprehensible feedback for developers. This is intended to help them recognise where the programming error or API misuse is.

From theory to practice

The basis for the project idea came from Schlichtig's "FUM" framework, which classifies API usage restrictions and the resulting misuses. This classification can be used to better categorise and explain API misuse. "By working together with industrial companies, we can now achieve practical results that can be used in real programming situations at medium-sized companies," summarises Schlichtig.

This text has been translated automatically.

Contact

business-card image

Michael Schlichtig

Secure Software Engineering / Heinz Nixdorf Institut

Write email +49 5251 60-6580
More about the person
In the foreground, a part of building Q with the lettering "Universität Paderborn", in front of which more than 20 students are passing by; in the background, building I.
Universität Paderborn

Warburger Str. 100
33098 Paderborn
Germany

Phone University

+49 5251 60-0
Quick links
  • Cafeteria
  • Online application
  • Library
  • PAUL
  • PANDA
Social networks
Legal notice
  • Imprint
  • Data privacy
  • Whistleblower system
  • Accessibility Declaration