Validating static warnings via testing code fragments
Ashwin Kallingal Joshy, Xueyuan Chen, Benjamin Steenhoek, Wei Le
摘要
Static analysis is an important approach for finding bugs and vulnerabilities in software. However, inspecting and confirming static warnings are challenging and time-consuming. In this paper, we present a novel solution that automatically generates test cases based on static warnings to validate true and false positives. We designed a syntactic patching algorithm that can generate syntactically valid, semantic preserving executable code fragments from static warnings. We developed a build and testing system to automatically test code fragments using fuzzers, KLEE and Valgrind. We evaluated our techniques using 12 real-world C projects and 1955 warnings from two commercial static analysis tools. We successfully built 68.5% code fragments and generated 1003 test cases. Through automatic testing, we identified 48 true positives and 27 false positives, and 205 likely false positives. We matched 4 CVE and real-world bugs using Helium, and they are only triggered by our tool but not other baseline tools. We found that testing code fragments is scalable and useful; it can trigger bugs that testing entire programs or testing procedures failed to trigger. CCS CONCEPTS • Software and its engineering → Software testing and debugging; Software verification and validation; Software defect analysis.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Combining static analysis error traces with dynamic symbolic execution (experience paper)Frank Busse, Pritam M. Gharat, Cristian Cadar, Alastair F. DonaldsonISSTA 2022 · 被引用 11 次
- Sound and Partially-Complete Static Analysis of Data-Races in GPU ProgramsDennis Liew, Tiago Cogumbreiro, Julien LangeOOPSLA 2024 · 被引用 10 次
- FuzzSlice: Pruning False Positives in Static Analysis Warnings through Function-Level FuzzingAniruddhan Murali, Noble Saji Mathews, Mahmoud Alfadel, Meiyappan Nagappan 等ICSE 2024 · 被引用 9 次
- An Empirical Study of Suppressed Static Analysis WarningsHuimin Hu, Yingying Wang, Julia Rubin, Michael PradelFSE 2025 · 被引用 1 次
- CodeCureAgent: Automatic Classification and Repair of Static Analysis WarningsPascal Joos, Islem Bouzenia, Michael PradelFSE 2026
相关 Paper
- An empirical study on the effectiveness of static C code analyzers for vulnerability detectionStephan Lipp, Sebastian Banescu, Alexander PretschnerISSTA 2022 · 被引用 99 次
- LAVA: Large-Scale Automated Vulnerability AdditionBrendan Dolan-Gavitt, Patrick Hulin, Engin Kirda, Tim Leek 等S&P 2016 · 被引用 354 次
- Precise Divide-By-Zero Detection with Affirmative EvidenceYiyuan Guo, Jinguo Zhou, Peisen Yao, Qingkai Shi 等ICSE 2022 · 被引用 4 次
- Statfier: Automated Testing of Static Analyzers via Semantic-Preserving Program TransformationsHuaien Zhang, Yu Pei, Junjie Chen, Shin Hwei TanFSE 2023 · 被引用 15 次
- Constraint-Based Test Oracles for Program AnalyzersMarkus Fleischmann, David Kaindlstorfer, Anastasia Isychev, Valentin Wüstholz 等ASE 2024 · 被引用 2 次
