课题基金 / 基金详情

CSR: Medium: Systems Support for Scalable, Easy-to-Implement, and Multilingual Static Analyses of Modern Software

CSR: Medium: Systems Support for Scalable, Easy-to-Implement, and Multilingual Static Analyses of Modern Software
CSR:中:对现代软件的可扩展、易于实施和多语言静态分析的系统支持
批准号:
1763172
负责人:
Ardalan Amiri Sani
金额:
$119.97万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-08-15 至 2023-07-31

项目摘要

项目成果

Ardalan Amiri Sani的其他基金

相似基金

相关文献

中文摘要
翻译
静态程序分析在学术界和工业界被广泛用于发现错误、安全漏洞和性能优化机会。几十年来,在大型代码库上支持复杂的分析算法一直是程序分析研究中的一个关键挑战。这种无能为力是阻碍基于分析的技术在工业中广泛采用的主要因素。这个项目从数据驱动的角度重新审视了这个问题,并开发了新的系统解决方案,使静态程序分析易于实现,支持大型代码库,并支持用多种语言编写的程序。该项目将开发一种具有四个要素的变革性方法:(1)开发基于磁盘的核心外系统以并行化和扩展基于约束的路径敏感分析;(2)通过将流敏感分析视为演化图形处理来开发系统支持;(3)开发一个分布式系统解决方案来解决SAT问题-一个50年的问题-使基于SAT的应用程序能够利用现代计算中可用的资源解决更大的问题;以及(4)分析Android操作系统和应用程序,以发现复杂的(A)错误,(B)安全漏洞,(C)性能问题,涉及系统与应用程序之间的交互以及多个应用程序。该项目开发的系统将使精确的静态分析算法更高效和可扩展,使它们能够处理现有技术无法分析的现代软件程序。由于许多用户和企业每天都在使用这些程序,因此使它们更加健壮和安全将惠及更广泛的社区。该项目将开发用于复杂代码分析的大数据系统,为规模化程序分析开辟新的方向。它将涉及几名博士生,并将研究注入本科生和研究生课程,以培养未来的开发人员。所有系统实施、实验数据和项目文件将在https://www.ics.uci.edu/~guoqingx/research/projects/analysis.html公开和维护。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Static program analysis has been widely used in academia and industry to find bugs, security vulnerabilities, and performance optimization opportunities. Supporting sophisticated analysis algorithms on large codebases has been a key challenge in the program analysis research for decades. This inability is the major factor that prevents analysis-based techniques from being widely adopted in industry. This project revisits this problem from a data-driven perspective and develops novel system solutions that can make static program analyses easy to implement, support large codebases, and support programs written in multiple languages.The project will develop a transformative approach with four elements: (1) develop disk-based out-of-core systems to parallelize and scale constraint-based path-sensitive analysis; (2) develop system support for flow-sensitive analysis by treating it as evolving graph processing; (3) develop a distributed system solution to SAT solving --- a 50-year old problem --- to enable SAT-based applications to solve larger problems with the resources available in modern computing; and (4) analyze the Android operating system and apps together to find complicated (a) bugs, (b) security vulnerabilities, and (c) performance problems, which involve interactions between the system and an app as well as multiple apps.The systems developed by the project will make precise static analysis algorithms more efficient and scalable, enabling them to process modern software programs that existing techniques could not analyze. Since these programs are used every day by many users and businesses, making them more robust and secure extends the benefit to a broad community. The project will develop big data systems for sophisticated code analysis, opening a new direction to scale program analysis. It will involve several PhD students and infuse research into the undergraduate and graduate curricula to train developers of the future.All the system implementations, experimental data, and documents from the project will be publicly available and maintained at https://www.ics.uci.edu/~guoqingx/research/projects/analysis.html .This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(30)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2021-05
期刊:
影响因子: --
作者: [John Thorpe;Yifan Qiao;Jon Eyolfson;Shen Teng;Guanzhou Hu;Zhihao Jia;Jinliang Wei;Keval Vora-Keval-Vor]
通讯作者: John Thorpe;Yifan Qiao;Jon Eyolfson;Shen Teng;Guanzhou Hu;Zhihao Jia;Jinliang Wei;Keval Vora-Keval-Vor
DOI: 10.1145/3552326.3567489
发表时间: 2023-05
期刊: Proceedings of the Eighteenth European Conference on Computer Systems
影响因子: --
作者: [Kasra Jamshidi;Harry Xu;Keval Vora]
通讯作者: Kasra Jamshidi;Harry Xu;Keval Vora
Systemizing Interprocedural Static Analysis of Large-scale Systems Code with Graspan
使用 Graspan 系统化大型系统代码的过程间静态分析
DOI: 10.1145/3466820
发表时间: 2021-07
期刊: ACM Transactions on Computer Systems, (TOCS'21)
影响因子: --
作者: [Zuo Zhiqiang, Wang Kai, Hussain Aftab, Sani Ardalan Amiri, Zhang Yiyu, Lu Shenming, Dou Wensheng, Wang Linzhang, Li Xu, ong, Wang Chenxi, Xu Guoqing Harry]
通讯作者: Xu Guoqing Harry
DOI: 10.1145/3341301.3359643
发表时间: 2019-10
期刊: Proceedings of the 27th ACM Symposium on Operating Systems Principles
影响因子: --
作者: [Christian Navasca;Cheng Cai;Khanh Nguyen;Brian Demsky;Shan Lu;Miryung Kim;G. Xu]
通讯作者: Christian Navasca;Cheng Cai;Khanh Nguyen;Brian Demsky;Shan Lu;Miryung Kim;G. Xu
共 30 条
    Collaborative Research: SaTC: CORE: Small: Self-Driving Continuous Fuzzing
    • 批准号:
      2247880
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $30.0万
    • 财政年份:
      2023
    • 负责人:
      Ardalan Amiri Sani
    • 依托单位:
    SaTC: CORE: Small: Collaborative: Deep and Efficient Dynamic Analysis of Operating System Kernels
    • 批准号:
      1953932
    • 项目类别:
      Standard Grant
    • 资助金额:
      $25.0万
    • 财政年份:
      2020
    • 负责人:
      Ardalan Amiri Sani
    • 依托单位:
    CAREER: Securing Mobile Devices by Hardening their System Software
    • 批准号:
      1846230
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $49.67万
    • 财政年份:
      2019
    • 负责人:
      Ardalan Amiri Sani
    • 依托单位:
    SaTC: CORE: Small: Collaborative: Guarding the Integrity of Mobile Graphical User Interfaces
    • 批准号:
      1718923
    • 项目类别:
      Standard Grant
    • 资助金额:
      $25.0万
    • 财政年份:
      2017
    • 负责人:
      Ardalan Amiri Sani
    • 依托单位:
    海外基金