Eventually Sound Points-To Analysis with Specifications

Eventually Sound Points-To Analysis with Specifications
复制标题

最终合理的要点分析与规范

DOI:
10.4230/lipics.ecoop.2019.11
复制
发表时间:
2019
期刊:
ArXiv
影响因子:
--
通讯作者:
A. Aiken
A. Aiken
中科院分区:
--
文献类型:
--
作者:
O. Bastani;Rahul Sharma;Lazaro Clapp;Saswat Anand;A. Aiken

文献摘要

参考文献

被引文献

相似文献

静态分析做出了一个越来越脆弱的假设,即所有源代码都可用于分析;例如,大型库经常调用无法分析的本机代码。我们提出一种点对点分析,它最初对缺失的代码做出乐观的假设,然后插入运行时检查,报告在执行期间发生的这些假设的反例。我们的方法保证了最终的稳健性,它结合了两个保证:(i)运行时检查保证捕获任何执行期间发生的第一个反例,在这种情况下,执行可以终止以防止伤害,以及(ii)只发生有限的反例,这意味着静态分析最终相对于所有剩余的执行变得静态可靠。我们实现了Optix,这是一个针对Android应用程序的最终声音指向分析,而Android框架却缺失了。我们展示了Optix添加的运行时检查在实际程序中产生的低开销,并演示了Optix如何改进用于检测Android恶意软件的客户端信息流分析。2012 ACM计算分类理论:程序分析
Static analyses make the increasingly tenuous assumption that all source code is available for analysis; for example, large libraries often call into native code that cannot be analyzed. We propose a points-to analysis that initially makes optimistic assumptions about missing code, and then inserts runtime checks that report counterexamples to these assumptions that occur during execution. Our approach guarantees eventual soundness, which combines two guarantees: (i) the runtime checks are guaranteed to catch the first counterexample that occurs during any execution, in which case execution can be terminated to prevent harm, and (ii) only finitely many counterexamples ever occur, implying that the static analysis eventually becomes statically sound with respect to all remaining executions. We implement Optix, an eventually sound points-to analysis for Android apps, where the Android framework is missing. We show that the runtime checks added by Optix incur low overhead on real programs, and demonstrate how Optix improves a client information flow analysis for detecting Android malware. 2012 ACM Subject Classification Theory of computation æ Program analysis
乐观混合分析:通过预测静态分析加速动态分析
DOI: 10.1145/3173162.3177153
发表时间: 2018
期刊: Architectural Support for Programming Languages and Operating Systems
影响因子: --
作者:
Devecsery, David;Chen, Peter M.;Flinn, Jason;Narayanasamy, Satish
通讯作者: Narayanasamy, Satish