Fast and Precise Application Code Analysis using a Partial Library

Fast and Precise Application Code Analysis using a Partial Library
复制标题

DOI:
10.1145/3510003.3510046
复制
发表时间:
2022-05
期刊:
2022 IEEE/ACM 44th International Conference on Software Engineering (ICSE)
影响因子:
--
通讯作者:
Akshay Utture;J. Palsberg
Akshay Utture;J. Palsberg
中科院分区:
其他
文献类型:
--
作者:
Akshay Utture;J. Palsberg

文献摘要

相似文献

长期分析时间是广泛采用全程静态分析工具的关键瓶颈。但是,幸运的是,用户通常只对在应用程序代码中查找错误感兴趣,这构成了整个程序的一小部分。当前以应用程序为中心的分析工具过度陈述了库的效果,因此降低了分析结果的精度。但是,经验研究表明,用户对精确度的期望很高,并且会忽略不符合这些期望的工具结果。在本文中,我们介绍了第一个工具QueryMax,该工具可以大大加快应用程序代码分析而不删除任何精度。 QueryMax是现有分析工具的预处理器,以选择与应用程序代码中分析查询最相关的部分库。选定的部分库加上应用程序作为现有静态分析工具的输入,其余的库指针被视为抽象域中的底部元素。这在整个程序分析中取得了重大的加速,以几个错误的损失,而精确却没有损失。我们在QueryMax上实例化并运行实验,以进行铸造分析和无效分析。对于特定的配置,QueryMax可以使这两个分析相对于整个程序分析,平均召回率为87%,精度为100%,几何平均速度为10倍。
Long analysis times are a key bottleneck for the widespread adoption of whole-program static analysis tools. Fortunately, however, a user is often only interested in finding errors in the application code, which constitutes a small fraction of the whole program. Current application-focused analysis tools overapproximate the effect of the library and hence reduce the precision of the analysis results. However, empirical studies have shown that users have high expectations on precision and will ignore tool results that don't meet these expectations. In this paper, we introduce the first tool QueryMax that significantly speeds up an application code analysis without dropping any precision. QueryMax acts as a pre-processor to an existing analysis tool to select a partial library that is most relevant to the analysis queries in the application code. The selected partial library plus the application is given as input to the existing static analysis tool, with the remaining library pointers treated as the bottom element in the abstract domain. This achieves a significant speedup over a whole-program analysis, at the cost of a few lost errors, and with no loss in precision. We instantiate and run experiments on QueryMax for a cast-check analysis and a null-pointer analysis. For a particular configuration, QueryMax enables these two analyses to achieve, relative to a whole-program analysis, an average recall of 87%, a precision of 100% and a geometric mean speedup of 10x.