Heaps Don't Lie: Countering Unsoundness with Heap Snapshots

Heaps Don't Lie: Countering Unsoundness with Heap Snapshots
复制标题

DOI:
10.1145/3133892
复制
发表时间:
2017-10-01
影响因子:
1.8
通讯作者:
Smaragdakis, Yannis
Smaragdakis, Yannis
中科院分区:
其他
文献类型:
--
作者:
Grech, Neville;Fourtounis, George;Smaragdakis, Yannis

文献摘要

被引文献

相似文献

静态分析渴望探索所有可能的执行,以实现健全。然而,在实践中,它们未能捕捉到共同的动态行为。用动态信息增强静态分析是一种常见的模式,可以使用Tamiflex等工具。然而,由于本机代码、不支持的功能(例如,invokedynamic或Java中的Invokedynamic)等。我们提出的技术,大大抵消了静态分析的不健全,几乎没有入侵的分析逻辑。我们的方法在HeapDL工具链中得到了具体化,包括在程序执行期间获取整个堆快照,这些快照被进一步丰富以捕获动态行为的重要方面,而不管这种行为的原因。然后将快照用作静态分析的额外输入。该方法既具有可移植性,又显著增加了覆盖范围。一组动态输入下的堆信息允许静态分析覆盖其他输入下的更多行为。DaCapo基准测试的HeapDL增强静态分析计算出了99.5%(中位数)的不可见动态执行的调用图边缘(而Tamiflex工具为76.9%)。
Static analyses aspire to explore all possible executions in order to achieve soundness. Yet, in practice, they fail to capture common dynamic behavior. Enhancing static analyses with dynamic information is a common pattern, with tools such as Tamiflex. Past approaches, however, miss significant portions of dynamic behavior, due to native code, unsupported features (e.g., invokedynamic or lambdas in Java), and more. We present techniques that substantially counteract the unsoundness of a static analysis, with virtually no intrusion to the analysis logic. Our approach is reified in the HeapDL toolchain and consists in taking whole-heap snapshots during program execution, that are further enriched to capture significant aspects of dynamic behavior, regardless of the causes of such behavior. The snapshots are then used as extra inputs to the static analysis. The approach exhibits both portability and significantly increased coverage. Heap information under one set of dynamic inputs allows a static analysis to cover many more behaviors under other inputs. A HeapDL-enhanced static analysis of the DaCapo benchmarks computes 99.5% (median) of the call-graph edges of unseen dynamic executions (vs. 76.9% for the Tamiflex tool).