{"repo":"CROSSINGTUD/CryptoAnalysis","free":true,"listed":false,"github":"https://github.com/CROSSINGTUD/CryptoAnalysis","clone":"git clone https://github.com/CROSSINGTUD/CryptoAnalysis.git","description":"CogniCrypt_SAST: CrySL-to-Static Analysis Compiler","language":"Java","stars":81,"topics":["static-analysis","jca","cryptoanalysis","cryptography","misuse-detection","command-line-tool","java"],"license":"EPL-2.0","category":"dev-tools","readme_excerpt":"CogniCrypt SAST This repository contains CogniCrypt SAST , the static analysis component for CogniCrypt. The static analysis CogniCrypt SAST takes rules written in the specification language CrySL as input and performs a static analysis based on the specification of the rules. CrySL is a domain-specific language (DSL) designed to encode usage specifications for cryptographic libraries (e.g. the JCA in particular). More information on CrySL and the static analysis may be found in this paper. Features CogniCrypt SAST consists of the following features: - A context-sensitive, field-sensitive and flow-sensitive typestate and pointer analysis - A CLI to analyze Java and Android applications - Support for the static analysis frameworks Soot, SootUp and Opal We provide a complete documentation for all technical details and options. Releases You can check out a pre-compiled version of CogniCrypt SAST here. We recommend using the latest version. You can find CogniCrypt SAST also on Maven Central. Checkout and Build CogniCrypt SAST uses Maven as build tool. You can compile and build this project via The packaged jar artifacts including all dependencies can be found in /apps . Building requires at least Java 17. Running CogniCrypt SAST CogniCrypt SAST analyzes Java and Android apps to detect cryptographic misuses based on CrySL rules. 1. Prepare Your Inputs - Compile your application to a .jar or .apk file - Download the HeadlessJavaScanner-x.y.z-jar-with-dependencies.jar for analyzing ","default_branch":null,"files":null,"tree":[],"storefront":"/r/CROSSINGTUD","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/CROSSINGTUD/CryptoAnalysis/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}