On the recall of static call graph construction in practice
Li Sui, Jens Dietrich, Amjed Tahir, George Fourtounis
Abstract
Static analyses have problems modelling dynamic language features soundly while retaining acceptable precision. The problem is wellunderstood in theory, but there is little evidence on how this impacts the analysis of real-world programs. We have studied this issue for call graph construction on a set of 31 real-world Java programs using an oracle of actual program behaviour recorded from executions of built-in and synthesised test cases with high coverage, have measured the recall that is being achieved by various static analysis algorithms and configurations, and investigated which language features lead to static analysis false negatives. We report that (1) the median recall is 0.884 suggesting that standard static analyses have significant gaps with respect to the proportion of the program modelled (2) built-in tests are significantly better to expose dynamic program behaviour than synthesised tests (3) adding precision to the static analysis has little impact on recall indicating that those are separate concerns (4) state-of-the-art support for dynamic language features can significantly improve recall (the median observed is 0.935 ), but it comes with a hefty performance penalty, and (5) the main sources of unsoundness are not reflective method invocations, but objects allocated or accessed via native methods, and invocations initiated by the JVM, without matching call sites in the program under analysis. These results provide some novel insights into the interaction between static and dynamic program analyses that can be used to assess the utility of static analysis results and to guide the development of future static and hybrid analyses. CCS CONCEPTS • Software and its engineering → Automated static analysis; Software defect analysis; Dynamic analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0b0562fe-1e9d-4a7a-bafd-115f17b6e5a3Cited by top-tier papers13
- Improving Java Deserialization Gadget Chain Mining via Overriding-Guided Object GenerationSicong Cao, Xiaobing Sun, Xiaoxue Wu, Lili Bo et al.ICSE 2023 · 24 citations
- Identifying Java calls in native code via binary scanningGeorge Fourtounis, Leonidas Triantafyllou, Yannis SmaragdakisISSTA 2020 · 23 citations
- AutoPruner: transformer-based call graph pruningThanh Le-Cong, Hong Jin Kang, Truong Giang Nguyen, Stefanus Agus Haryono et al.FSE 2022 · 21 citations
- Striking a Balance: Pruning False-Positives from Static Call GraphsAkshay Utture, Shuyang Liu, Christian Gram Kalhauge, Jens PalsbergICSE 2022 · 18 citations
- That's a Tough Call: Studying the Challenges of Call Graph Construction for WebAssemblyDaniel Lehmann, Michelle Thalakottur, Frank Tip, Michael PradelISSTA 2023 · 11 citations
Related papers
- Total Recall? How Good Are Static Call Graphs Really?Dominik Helm, Sven Keidel, Anemone Kampkötter, Johannes Düsing et al.ISSTA 2024 · 3 citations
- Redefining Indirect Call Analysis with KallGraphGuoren Li, Manu Sridharan, Zhiyun QianS&P 2025
- Call Graph Soundness in Android Static AnalysisJordan Samhi, René Just, Tegawendé F. Bissyandé, Michael D. Ernst et al.ISSTA 2024 · 8 citations
- Reducing Static Analysis Unsoundness with Approximate InterpretationMathias Rud Laursen, Wenyuan Xu, Anders MøllerPLDI 2024 · 5 citations
- Hybrid Inlining: A Framework for Compositional and Context-Sensitive Static AnalysisJiangchao Liu, Jierui Liu, Peng Di, Diyu Wu et al.ISSTA 2023 · 3 citations
