A symbolic analysis framework for static analysis of imperative programming languages

被引:6
作者
Burgstaller, Bernd [1 ]
Scholz, Bernhard [2 ]
Blieberger, Johann [3 ]
机构
[1] Yonsei Univ, Seoul 120749, South Korea
[2] Univ Sydney, Sydney, NSW 2006, Australia
[3] Vienna Univ Technol, A-1040 Vienna, Austria
基金
新加坡国家研究基金会; 澳大利亚研究理事会;
关键词
Static program analysis; Symbolic analysis; Path expression algebra; Programming language semantics; INDUCTION VARIABLES; EXECUTION; CHECKING;
D O I
10.1016/j.jss.2011.11.1039
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
We present a generic symbolic analysis framework for imperative programming languages. Our framework is capable of computing all valid variable bindings of a program at given program points. This information is invaluable for domain-specific static program analyses such as memory leak detection, program parallelization, and the detection of superfluous bound checks, variable aliases and task deadlocks. We employ path expression algebra to model the control flow information of programs. A homomorphism maps path expressions into the symbolic domain. At the center of the symbolic domain is a compact algebraic structure called supercontext. A supercontext contains the complete control and data flow analysis information valid at a given program point. Our approach to compute supercontexts is based purely on algebra and is fully automated. This novel representation of program semantics closes the gap between program analysis and computer algebra systems, which makes supercontexts an ideal symbolic intermediate representation for all domain-specific static program analyses. Our approach is more general than existing methods because it can derive solutions for arbitrary (even intra-loop and nested loop) nodes of reducible and irreducible control flow graphs. We prove the correctness of our symbolic analysis method. Our experimental results show that the problem sizes arising from real-world applications such as the SPEC95 benchmark suite are tractable for our symbolic analysis framework. (C) 2011 Elsevier Inc. All rights reserved.
引用
收藏
页码:1418 / 1439
页数:22
相关论文
共 50 条
  • [21] Symbolic timing analysis of asynchronous systems
    Hulgaard, H
    Amon, T
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2000, 19 (10) : 1093 - 1104
  • [22] Universally Composable Symbolic Security Analysis
    Canetti, Ran
    Herzog, Jonathan
    JOURNAL OF CRYPTOLOGY, 2011, 24 (01) : 83 - 147
  • [23] Transaction allocation symbolic analysis method
    Skokljev, I
    Maksimovic, V
    EUROPEAN TRANSACTIONS ON ELECTRICAL POWER, 2004, 14 (05): : 261 - 275
  • [24] Symbolic Analysis of Timed Petri Nets
    Zuberek, Wlodek M.
    THEORY AND ENGINEERING OF COMPLEX SYSTEMS AND DEPENDABILITY, 2015, 365 : 593 - 602
  • [25] Topology Reduction for Approximate Symbolic Analysis
    Kolka, Zdenek
    Vlk, Martin
    Horak, Martin
    RADIOENGINEERING, 2011, 20 (01) : 252 - 257
  • [26] Universally Composable Symbolic Security Analysis
    Ran Canetti
    Jonathan Herzog
    Journal of Cryptology, 2011, 24 : 83 - 147
  • [27] Symbolic Distortion Analysis of Multistage Amplifiers
    Shi, Guoyong
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS I-REGULAR PAPERS, 2019, 66 (01) : 369 - 382
  • [28] Symbolic analysis for automatic model generation
    Monti, A
    Santi, E
    Dougal, R
    Ponci, F
    Riva, M
    2001 POWER ENGINEERING SOCIETY SUMMER MEETING, VOLS 1-3, CONFERENCE PROCEEDINGS, 2001, : 1445 - 1450
  • [29] A Symbolic Method for Distortion Analysis and Optimization
    Chen, J.
    Shi, G.
    Zhang, A.
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND INDUSTRIAL ENGINEERING (AIIE 2015), 2015, 123 : 433 - 436
  • [30] Expediting Binary Fuzzing with Symbolic Analysis
    Xu, Luhang
    Yin, Liangze
    Dong, Wei
    Jia, Weixi
    Li, Yongjun
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2018, 28 (11-12) : 1701 - 1718