On the Soundness of Call Graph Construction in the Presence of Dynamic Language Features - A Benchmark and Tool Evaluation

On the Soundness of Call Graph Construction in the Presence of Dynamic Language Features - A Benchmark and Tool Evaluation
复制标题

动态语言特征存在下调用图构建的稳健性——基准和工具评估

DOI:
10.1007/978-3-030-02768-1_4
复制
发表时间:
2018
期刊:
Proceedings of the 2013 International Conference on Principles and Practices of Programming on the Java Platform: Virtual Machines, Languages, and Tools
影响因子:
--
通讯作者:
Amjed Tahir
Amjed Tahir
中科院分区:
--
文献类型:
--
作者:
Li Sui;Jens Dietrich;Michael Emery;Shawn Rasheed;Amjed Tahir

文献摘要

被引文献

相似文献

静态程序分析被广泛用于在软件生命周期的早期检测错误和漏洞。它在不执行程序的情况下对可能的程序执行进行建模,因此必须同时处理假阳性(精度)和假阴性(可靠性)。声音静态分析的一个特别挑战是动态语言功能的存在,这些功能在现代编程语言中很普遍,并在实践中广泛使用。
Static program analysis is widely used to detect bugs and vulnerabilities early in the life cycle of software. It models possible program executions without executing a program, and therefore has to deal with both false positives (precision) and false negatives (soundness). A particular challenge for sound static analysis is the presence of dynamic language features, which are prevalent in modern programming languages, and widely used in practice.