Efficient and formal generalized symbolic execution
dc.citation.doi | 10.1007/s10515-011-0089-9 | en_US |
dc.citation.epage | 301 | en_US |
dc.citation.issue | 3 | en_US |
dc.citation.jtitle | Automated Software Engineering | en_US |
dc.citation.spage | 233 | en_US |
dc.citation.volume | 19 | en_US |
dc.contributor.author | Deng, Xianghua | |
dc.contributor.author | Lee, Jooyong | |
dc.contributor.author | Robby | |
dc.contributor.authoreid | robby | en_US |
dc.date.accessioned | 2012-11-12T16:51:52Z | |
dc.date.available | 2012-11-12T16:51:52Z | |
dc.date.issued | 2011-06-09 | |
dc.date.published | 2012 | en_US |
dc.description.abstract | Programs that manipulate dynamic heap objects are difficult to analyze due to issues like aliasing. Lazy initialization algorithm enables the classical symbolic execution to handle such programs. Despite its successes, there are two unresolved issues: (1) inefficiency; (2) lack of formal study. For the inefficiency issue, we have proposed two improved algorithms that give significant analysis time reduction over the original lazy initialization algorithm. In this article, we formalize the lazy initialization algorithm and the improved algorithms as operational semantics of a core subset of the Java Virtual Machine (JVM) instructions, and prove that all algorithms are relatively sound and complete with respect to the JVM concrete semantics. Finally, we conduct a set of extensive experiments that compare the three algorithms and demonstrate the efficiency of the improved algorithms. | en_US |
dc.description.version | Article (author version) | |
dc.identifier.uri | http://hdl.handle.net/2097/14930 | |
dc.language.iso | en_US | en_US |
dc.relation.uri | http://doi.org/10.1007/s10515-011-0089-9 | en_US |
dc.rights | This Item is protected by copyright and/or related rights. You are free to use this Item in any way that is permitted by the copyright and related rights legislation that applies to your use. For other uses you need to obtain permission from the rights-holder(s). | en_US |
dc.rights.uri | https://rightsstatements.org/page/InC/1.0/?language=en | |
dc.subject | Symbolic execution | en_US |
dc.subject | Operational semantics | en_US |
dc.subject | JVM | en_US |
dc.subject | Soundness | en_US |
dc.subject | Completeness | en_US |
dc.title | Efficient and formal generalized symbolic execution | en_US |
dc.type | Text | en_US |