Towards Optimal Concolic Testing
Towards Optimal Concolic Testing
复制标题
DOI:
10.1145/3180155.3180177
复制
发表时间:
2018-05
期刊:
影响因子:
--
通讯作者:
Xinyu Wang;Jun Sun;Zhenbang Chen;Peixin Zhang;Jingyi Wang;Yun Lin
中科院分区:
文献类型:
--
作者:
Xinyu Wang;Jun Sun;Zhenbang Chen;Peixin Zhang;Jingyi Wang;Yun Lin
Concolic testing integrates concrete execution (e.g., random testing) and symbolic execution for test case generation. It is shown to be more cost-effective than random testing or symbolic execution sometimes. A concolic testing strategy is a function which decides when to apply random testing or symbolic execution, and if it is the latter case, which program path to symbolically execute. Many heuristics-based strategies have been proposed. It is still an open problem what is the optimal concolic testing strategy. In this work, we make two contributions towards solving this problem. First, we show the optimal strategy can be defined based on the probability of program paths and the cost of constraint solving. The problem of identifying the optimal strategy is then reduced to a model checking problem of Markov Decision Processes with Costs. Secondly, in view of the complexity in identifying the optimal strategy, we design a greedy algorithm for approximating the optimal strategy. We conduct two sets of experiments. One is based on randomly generated models and the other is based on a set of C programs. The results show that existing heuristics have much room to improve and our greedy algorithm often outperforms existing heuristics.