Static Crypto Scanner Sweeps 57,610 Files in Under Six Minutes, Surfacing 370 Assets, 6 CVE-Linked Flaws, and 52 Post-Quantum Migration Candidates
The approach classifies cryptography into Crypto-Material, Crypto-Artifacts, and Crypto-Invocations, derives a scanner-independent rule repository from that taxonomy, and emits CBOM-oriented output for governance and post-quantum migration planning. On a synthetic benchmark with known ground truth it hits an F1 of 0.75 for asset discovery and correctly annotates 91% of expected weaknesses and vulnerabilities. Applied to a real deployment of ten services it processed 57,610 files in under six minutes and found 370 cryptographic assets including six CVE-linked vulnerabilities and 52 post-quantum migration candidates, though the authors note real-world coverage was measured against a manually compiled rather than exhaustive reference list.
↳ Follow the thread