Effective error-specification inference via domain-knowledge expansion

Effective error-specification inference via domain-knowledge expansion
复制标题

DOI:
10.1145/3338906.3338960
复制
发表时间:
2019-08
期刊:
Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering
影响因子:
--
通讯作者:
Daniel DeFreez;Haaken Martinson Baldwin;Cindy Rubio-González;Aditya V. Thakur
Daniel DeFreez;Haaken Martinson Baldwin;Cindy Rubio-González;Aditya V. Thakur
中科院分区:
其他
文献类型:
--
作者:
Daniel DeFreez;Haaken Martinson Baldwin;Cindy Rubio-González;Aditya V. Thakur

文献摘要

被引文献

相似文献

错误处理代码响应运行时错误的发生。不能正确处理错误可能导致安全漏洞和数据丢失。本文讨论了用C语言编写的软件中使用返回代码习惯的错误处理:错误的存在和类型编码在函数的返回值中。本文描述了EESI,这是一种静态分析,可以推断出函数在出错时可能返回的一组值。这样的函数错误规范可以用来识别与错误处理相关的错误。EESI的关键见解是使用开发人员提供的与错误处理相关的领域知识引导分析。EESI结合了流程内、流程敏感的分析和流程间、上下文不敏感的分析,以确保准确性和可扩展性。我们构建了一个工具ECC来演示如何使用EESI推断的函数错误规范来自动查找与不正确的错误处理相关的错误。ECC在9个程序中检测到246个bug,其中110个已经确认。ECC检测到220个以前未知的bug,其中99个得到确认。两个补丁已经合并到OpenSSL中。
Error-handling code responds to the occurrence of runtime errors. Failure to correctly handle errors can lead to security vulnerabilities and data loss. This paper deals with error handling in software written in C that uses the return-code idiom: the presence and type of error is encoded in the return value of a function. This paper describes EESI, a static analysis that infers the set of values that a function can return on error. Such a function error-specification can then be used to identify bugs related to incorrect error handling. The key insight of EESI is to bootstrap the analysis with domain knowledge related to error handling provided by a developer. EESI uses a combination of intraprocedural, flow-sensitive analysis and interprocedural, context-insensitive analysis to ensure precision and scalability. We built a tool ECC to demonstrate how the function error-specifications inferred by EESI can be used to automatically find bugs related to incorrect error handling. ECC detected 246 bugs across 9 programs, of which 110 have been confirmed. ECC detected 220 previously unknown bugs, of which 99 are confirmed. Two patches have already been merged into OpenSSL.