State of the art: Dynamic symbolic execution for automated test generation

State of the art: Dynamic symbolic execution for automated test generation
复制标题

DOI:
10.1016/j.future.2012.02.006
复制
发表时间:
2013-09-01
影响因子:
7.5
通讯作者:
Wu, Yue
Wu, Yue
中科院分区:
计算机科学2区
文献类型:
--
作者:
Chen, Ting;Zhang, Xiao-song;Wu, Yue

文献摘要

被引文献

相似文献

自动测试生成的动态符号执行包括在从分支指令中遇到的谓词收集输入的路径约束的同时检测和运行程序,以及通过SMT (Satisfiability Modulo Theories)求解器从先前的路径约束中派生新的输入,以便将下一次执行转向新的程序路径。由于其低误报和高代码覆盖率的内在特性,它已被引入到自动化测试生成、自动化过滤器生成和恶意软件分析等多个应用中。在本文中,我们关注与自动化测试生成密切相关的主题。我们的贡献是五倍。首先,总结了动态符号执行的理论基础。第二,我们强调将理念变为现实的挑战。此外,我们描述了最先进的解决方案,包括这些挑战的优点和缺点。此外,还分析了12种典型工具,并对这些工具的许多特性进行了概述。最后,对该研究领域的发展前景进行了展望。(C) 2012 Elsevier B.V.版权所有
Dynamic symbolic execution for automated test generation consists of instrumenting and running a program while collecting path constraint on inputs from predicates encountered in branch instructions, and of deriving new inputs from a previous path constraint by an SMT (Satisfiability Modulo Theories) solver in order to steer next executions toward new program paths. It has been introduced into several applications, such as automated test generation, automated filter generation and malware analysis mainly for its two intrinsic properties: low false positives and high code-coverage. In this paper, we focus on the topics that are closely related to automated test generation. Our contributions are five-fold. First, we summarize the theoretical foundation of dynamic symbolic execution. Second, we highlight the challenges when turning ideas into reality. Besides, we describe the state-of-the-art solutions including advantages and disadvantages for those challenges. In addition, twelve typical tools are analyzed and many properties of those tools are censused. Finally, we outline the prospects of this research field in detail. (C) 2012 Elsevier B.V. All rights reserved.