Systematic evaluation of the unsoundness of call graph construction algorithms for Java

Systematic evaluation of the unsoundness of call graph construction algorithms for Java
复制标题

Java调用图构造算法不健全性的系统评估

DOI:
10.1145/3236454.3236503
复制
发表时间:
2018
期刊:
Companion Proceedings for the ISSTA/ECOOP 2018 Workshops
影响因子:
--
通讯作者:
M. Mezini
M. Mezini
中科院分区:
--
文献类型:
--
作者:
Michael Reif;Florian Kübler;Michael Eichberg;M. Mezini

文献摘要

被引文献

相似文献

呼叫图是许多静态分析的核心,从未使用方法的检测到高级控制和数据流分析。因此,对各个图的精确和回忆的全面理解对于启用评估哪种呼叫构造算法的评估至关重要。例如,恶意软件通常被混淆,并试图通过反射来隐藏其意图。因此,在分析此类应用程序时,不代表反射方法调用的呼叫图的使用有限。通常,精确度已得到充分理解,但召回不是,即,在哪些情况下,呼叫图将不包含任何呼叫边缘。在本文中,我们讨论了一个综合测试套件的设计,该套件使我们能够计算各自的呼叫式构造算法的不健全性。该套件还使我们能够对静态分析框架进行比较评估。比较烟灰和瓦拉(Wala)表明,瓦拉(Wala)目前对新Java 8功能以及Java反射有更好的支持。但是,在某些情况下,两者都无法包括预期边缘。
Call graphs are at the core of many static analyses ranging from the detection of unused methods to advanced control-and data-flow analyses. Therefore, a comprehensive understanding of the precision and recall of the respective graphs is crucial to enable an assessment which call-graph construction algorithms are suited in which analysis scenario. For example, malware is often obfuscated and tries to hide its intent by using Reflection. Call graphs that do not represent reflective method calls are, therefore, of limited use when analyzing such apps. In general, the precision is well understood, but the recall is not, i.e., in which cases a call graph will not contain any call edges. In this paper, we discuss the design of a comprehensive test suite that enables us to compute a fingerprint of the unsoundness of the respective call-graph construction algorithms. This suite also enables us to make a comparative evaluation of static analysis frameworks. Comparing Soot and WALA shows that WALA currently has better support for new Java 8 features and also for Java Reflection. However, in some cases both fail to include expected edges.