On the Soundness of Call Graph Construction in the Presence of Dynamic Language Features - A Benchmark and Tool Evaluation
On the Soundness of Call Graph Construction in the Presence of Dynamic Language Features - A Benchmark and Tool Evaluation
复制标题
动态语言特征存在下调用图构建的稳健性——基准和工具评估
DOI:
10.1007/978-3-030-02768-1_4
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Amjed Tahir
中科院分区:
文献类型:
--
作者:
Li Sui;Jens Dietrich;Michael Emery;Shawn Rasheed;Amjed Tahir
Static program analysis is widely used to detect bugs and vulnerabilities early in the life cycle of software. It models possible program executions without executing a program, and therefore has to deal with both false positives (precision) and false negatives (soundness). A particular challenge for sound static analysis is the presence of dynamic language features, which are prevalent in modern programming languages, and widely used in practice.