Finding and Understanding Defects in Static Analyzers by Constructing Automated Oracles
Weigang He, Peng Di, Mengli Ming, Chengyu Zhang, Ting Su, Shijie Li, Yulei Sui
摘要
Static analyzers are playing crucial roles in helping find programming mistakes and security vulnerabilities. The correctness of their analysis results is crucial for the usability in practice. Otherwise, the potential defects in these analyzers (e.g., implementation errors, improper design choices) could affect the soundness (leading to false negatives) and precision (leading to false positives). However, finding the defects in off-the-shelf static analyzers is challenging because these analyzers usually lack clear and complete specifications, and the results of different analyzers may differ. To this end, this paper designs two novel types of automated oracles to find defects in static analyzers with randomly generated programs. The first oracle is constructed by using dynamic program executions and the second one leverages the inferred static analysis results. We applied these two oracles on three state-of-the-art static analyzers: Clang Static Analyzer (CSA), GCC Static Analyzer (GSA), and Pinpoint. We found 38 unique defects in these analyzers, 28 of which have been confirmed or fixed by the developers. We conducted a case study on these found defects followed by several insights and lessons learned for improving and better understanding static analyzers. We have made all the artifacts publicly available at https://github.com/Geoffrey1014/SA_Bugs for replication and benefit the community.
CCS Concepts: • Software and its engineering → Software testing and debugging.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Interrogation Testing of Program Analyzers for Soundness and Precision IssuesDavid Kaindlstorfer, Anastasia Isychev, Valentin Wüstholz, Maria ChristakisASE 2024 · 被引用 2 次
- Constraint-Based Test Oracles for Program AnalyzersMarkus Fleischmann, David Kaindlstorfer, Anastasia Isychev, Valentin Wüstholz 等ASE 2024 · 被引用 2 次
- Arguzz: Testing zkVMs for Soundness and Completeness BugsChristoph Hochrainer, Valentin Wüstholz, Maria ChristakisUSENIX Security 2026 · 被引用 2 次
- Fuzzing Processing Pipelines for Zero-Knowledge CircuitsChristoph Hochrainer, Anastasia Isychev, Valentin Wüstholz, Maria ChristakisCCS 2025 · 被引用 1 次
- Statically Discover Cross-Entry Use-After-Free Vulnerabilities in the Linux KernelHang Zhang, Jangha Kim, Chuhong Yuan, Zhiyun Qian 等NDSS 2025
它引用的顶会 Paper5
- An empirical study on the effectiveness of static C code analyzers for vulnerability detectionStephan Lipp, Sebastian Banescu, Alexander PretschnerISSTA 2022 · 被引用 99 次
- GrayC: Greybox Fuzzing of Compilers and Analysers for CKarine Even-Mendoza, Arindam Sharma, Alastair F. Donaldson, Cristian CadarISSTA 2023 · 被引用 52 次
- Context-aware in-process crowdworker recommendationJunjie Wang, Ye Yang, Song Wang, Yuanzhe Hu 等ICSE 2020 · 被引用 23 次
- Statfier: Automated Testing of Static Analyzers via Semantic-Preserving Program TransformationsHuaien Zhang, Yu Pei, Junjie Chen, Shin Hwei TanFSE 2023 · 被引用 15 次
- Precise Sparse Abstract Execution via Cross-Domain InteractionXiao Cheng, Jiawei Wang, Yulei SuiICSE 2024 · 被引用 6 次
相关 Paper
- ECSTATIC: An Extensible Framework for Testing and Debugging Configurable Static AnalysisAustin Mordahl, Zenong Zhang, Dakota Soles, Shiyi WeiICSE 2023 · 被引用 7 次
- Testing Static Taint Analyzers with Equivalence Modulo TaintMaria Christakis, Anastasia Isychev, Samuel Pilz, Florian Tesarek 等ISSTA 2026
- AURC: Detecting Errors in Program Code and DocumentationPeiwei Hu, Ruigang Liang, Ying Cao, Kai Chen 等USENIX Security 2023
- On the Real-World Effectiveness of Static Bug Detectors at Finding Null Pointer ExceptionsDavid A. Tomassi, Cindy Rubio-GonzálezASE 2021 · 被引用 24 次
- State Field Coverage: A Metric for Oracle QualityFacundo Molina, Nazareno Aguirre, Alessandra GorlaASE 2025 · 被引用 1 次
