Java Ranger: statically summarizing regions for efficient symbolic execution of Java
Vaibhav Sharma, Soha Hussein, Michael W. Whalen, Stephen McCamant, Willem Visser
摘要
Merging execution paths is a powerful technique for reducing path explosion in symbolic execution. One approach, introduced and dubbed łveritestingž by Avgerinos et al., works by translating a bounded control flow region into a single constraint. This approach is a convenient way to achieve path merging as a modification to a pre-existing single-path symbolic execution engine. Previous work evaluated this approach for symbolic execution of binary code, but different design considerations apply when building tools for other languages. In this paper, we extend the previous approach for symbolic execution of Java.
Because Java code typically contains many small dynamically dispatched methods, it is important to include them in multi-path regions; we introduce dynamic inlining of method-regions to do so modularly. Java's typed memory structure is very different from the binary representation, but we show how the idea of static single assignment (SSA) form can be applied to object references to statically account for aliasing.
We have implemented our algorithms in Java Ranger, an extension to the widely used Symbolic Pathfinder tool. In a set of nine benchmarks, Java Ranger reduces the running time and number of execution paths by a total of 38% and 71% respectively as compared to SPF. Our results are a significant improvement over the performance of JBMC, a recently released verification tool for Java bytecode. We also participated in a static verification competition at a top theory conference where other participants included stateof-the-art Java verifiers. JR won first place in the competition's Java verification track.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- A bounded symbolic-size model for symbolic executionDavid Trabish, Shachar Itzhaky, Noam RinetzkyFSE 2021 · 被引用 10 次
- Eunomia: Enabling User-Specified Fine-Grained Search in Symbolically Executing WebAssembly BinariesNingyu He, Zhehao Zhao, Jikai Wang, Yubin Hu 等ISSTA 2023 · 被引用 10 次
- State Merging with Quantifiers in Symbolic ExecutionDavid Trabish, Noam Rinetzky, Sharon Shoham, Vaibhav SharmaFSE 2023 · 被引用 5 次
- Taming the Hydra: Targeted Control-Flow Transformations for Dynamic Symbolic ExecutionCharitha Saumya, Muhammad Hassan, Rohan Gangaraju, Milind Kulkarni 等OOPSLA 2026
它引用的顶会 Paper2
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
相关 Paper
- Empc: Effective Path Prioritization for Symbolic Execution with Path CoverShuangjie Yao, Dongdong SheS&P 2025
- Multiplex Symbolic Execution: Exploring Multiple Paths by Solving OnceYufeng Zhang, Zhenbang Chen, Ziqi Shuai, Tianqi Zhang 等ASE 2020 · 被引用 17 次
- Grammar-agnostic symbolic execution by token symbolizationWeiyu Pan, Zhenbang Chen, Guofeng Zhang, Yunlai Luo 等ISSTA 2021 · 被引用 5 次
- Learning to Explore Paths for Symbolic ExecutionJingxuan He, Gishor Sivanrupan, Petar Tsankov, Martin T. VechevCCS 2021 · 被引用 39 次
- Partial Solution Based Constraint Solving Cache in Symbolic ExecutionZiqi Shuai, Zhenbang Chen, Kelin Ma, Kunlin Liu 等FSE 2024 · 被引用 3 次
