课题基金 / 基金详情

SHF: Medium: Exposing and Eliminating Errors at Component Boundaries

SHF: Medium: Exposing and Eliminating Errors at Component Boundaries
SHF:中:暴露并消除组件边界处的错误
批准号:
0905244
负责人:
Martin Rinard
金额:
$60.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2013-08-31

项目摘要

项目成果

Martin Rinard的其他基金

相似基金

相关文献

中文摘要
翻译
该研究探索了一种新的方法,用于检测在涉及复杂应用程序接口的模块边界处发生的错误。该方法首先动态观察正在运行的程序以获得表征模块边界处的成功交互的约束。然后,它使用符号动态污点跟踪来获得符号表达式,这些符号表达式描述了输入区域如何映射到出现在模块边界的特定值。然后,约束求解器生成新的输入区域,该输入区域在模块边界处产生违反观察到的约束的值。最后一步是在产生的新输入上运行程序,看看输入是否暴露了涉及模块之间交互的错误。研究的意义在于,许多可重用模块提供了开发人员难以理解的复杂接口。因此,模块边界是软件系统中错误和安全漏洞的主要位置。这项研究承诺开发新的测试技术,以发现和消除这些错误和漏洞。更广泛的影响包括为我们的社会提供更可靠的软件基础设施,以及对熟练劳动力的教育。智力上的优点包括更好地理解软件系统中的错误,以及发现和消除这些错误的新技术。
英文摘要
The research investigates a new method for detecting errors that occur at module boundaries involving complex application program interfaces. The method first dynamically observes running programs to obtain constraints that characterize successful interactions at module boundaries. It then uses symbolic dynamic taint tracing to obtain symbolic expressions that characterize how regions of the input map to specific values that appear at module boundaries. A constraint solver then generates new input regions that produce values at module boundaries that violate the observed constraints. The final step is to run the program on the resulting new inputs to see if the inputs expose errors involving interactions between modules.The significance of the research is that many reusable modules present complex interfaces that are difficult for developers to understand.Module boundaries therefore comprise a prime location for errors and security vulnerabilities in software systems. The research promises to develop new testing techniques for finding and eliminating these errors and vulnerabilities. Broader impacts include more reliable software infrastructure for our society and the education of a skilled workforce. Intellectual merit includes a better understanding of errors in software systems and new techniques for finding and eliminating these errors.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
EAGER: Profile and Transformation Driven Automatic Parallelization with Interactive Reports
CPA-CPL: Automatic Parallelization Using Semantic Commutativity Analysis
CDI-Type II: Exploiting Collective Human Knowledge to Understand and Evolve Complex Networked Systems
CSR----SMA Modular Pluggable Program Analyses
海外基金