课题基金 / 基金详情

CAREER: Improving the Practicality of Configurable Static Analysis Tools through Analysis, Testing, Refinement and Adaptation

CAREER: Improving the Practicality of Configurable Static Analysis Tools through Analysis, Testing, Refinement and Adaptation
职业:通过分析、测试、细化和适应提高可配置静态分析工具的实用性
批准号:
2047682
负责人:
Shiyi Wei
金额:
$45.88万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-06-15 至 2026-05-31

项目摘要

项目成果

Shiyi Wei的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Due to the scale and complexity of modern software, critical errors, such as security vulnerabilities, are hard to discover. In the past few decades, researchers and practitioners have invented many static-analysis algorithms for bug detection and program verification. To take advantage of the theoretical advances, static-analysis algorithms are often implemented as configuration options in static-analysis tools. For example, taint-analysis tools for Android apps incorporate different algorithms, underlying frameworks, and programming styles to support language features that complicate the detection of critical security vulnerabilities. These configuration options allow developers and users to tune the tool behavior to achieve the right balance between precision, soundness, and performance. However, the unique challenges of the large and complex configuration space in configurable static-analysis tools have prevented them from being broadly adopted in practice. Improving configurable static-analysis tools will lead to higher software quality, a potentially large societal impact.This project proposes to improve the maintainability, correctness, usability, and performance of the configurable static-analysis tools through configuration analysis, testing, evaluation, refinement and adaptation. The project will initially focus on the configurable taint-analysis tools for Android apps to address the following specific research goals. First, unspecified relationships between configuration options, which makes it difficult to tune the tools’ configurations, will be identified and analyzed. The result will be presented to users via a unified configuration-aware user interface. Second, configurable static-analysis tools will be better tested and evaluated via test-case generation and benchmark collection. Third, a human-in-the-loop iterative-refinement process will be designed to explore the configuration space and classify the results to significantly reduce the manual efforts needed in this process. Fourth, learning-based adaptive analysis will be developed to selectively apply analysis algorithms at fine granularity to produce practical results. The practical impact of the research will be evaluated in terms of the tools’ capabilities of detecting real-world vulnerabilities. Once the key research problems are addressed in Android taint-analysis tools, the project will generalize the research to configurable static-analysis tools for different programming languages. The project will significantly improve the state-of-the-art of configurable static-analysis tools and result in their broader adoption in practice.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3597926.3604918
发表时间: 2023-07
期刊: Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis
影响因子: --
作者: [Austin Mordahl;Dakota Soles;Miao Miao-Miao;Zenong Zhang;Shiyi Wei]
通讯作者: Austin Mordahl;Dakota Soles;Miao Miao-Miao;Zenong Zhang;Shiyi Wei
DOI: 10.1145/3580597
发表时间: 2023-02
期刊: ACM Transactions on Software Engineering and Methodology
影响因子: 4.4
作者: [Zenong Zhang;George Klees;E. Wang;M. Hicks;Shiyi Wei]
通讯作者: Zenong Zhang;George Klees;E. Wang;M. Hicks;Shiyi Wei
DOI: 10.1145/3460319.3464823
发表时间: 2021-07
期刊: Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis
影响因子: --
作者: [Austin Mordahl;Shiyi Wei]
通讯作者: Austin Mordahl;Shiyi Wei
DOI: 10.1109/icse48619.2023.00056
发表时间: 2023-05
期刊: 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE)
影响因子: --
作者: [Austin Mordahl;Zenong Zhang;Dakota Soles;Shiyi Wei]
通讯作者: Austin Mordahl;Zenong Zhang;Dakota Soles;Shiyi Wei
Collaborative Research: SHF: Small: An Automated Full-Lifecycle Approach for Improving the Development and Use of Static Analysis
  • 批准号:
    2008905
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.99万
  • 财政年份:
    2020
  • 负责人:
    Shiyi Wei
  • 依托单位:
SHF: Small: Automated Fine-Grained Requirements Traceability
  • 批准号:
    1910976
  • 项目类别:
    Standard Grant
  • 资助金额:
    $44.5万
  • 财政年份:
    2019
  • 负责人:
    Shiyi Wei
  • 依托单位:
SHF: Small: Collaborative Research: Static Analysis Infrastructure for Variability-Aware Bug Detection and Translation of Highly-Configurable Software Systems
  • 批准号:
    1816951
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.13万
  • 财政年份:
    2018
  • 负责人:
    Shiyi Wei
  • 依托单位:
国内基金
海外基金
Improving modelling of compact binary evolution.
  • 批准号:
    10903001
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2009
  • 负责人:
    史蒂芬
  • 依托单位: