Publication Type
Conference Paper
Version
acceptedVersion
Publication Date
10-2019
Abstract
Symbolic execution is a well established method for test input generation. Despite of having achieved tremendous success over numerical domains, existing symbolic execution techniques for heap-based programs are limited due to the lack of a succinct and precise description for symbolic values over unbounded heaps. In this work, we present a new symbolic execution method for heap-based programs based on separation logic. The essence of our proposal is context-sensitive lazy initialization, a novel approach for efficient test input generation. Our approach differs from existing approaches in two ways. Firstly, our approach is based on separation logic, which allows us to precisely capture preconditions of heap-based programs so that we avoid generating invalid test inputs. Secondly, we generate only fully initialized test inputs, which are more useful in practice compared to those partially initialized test inputs generated by the state-of-the-art tools. We have implemented our approach as a tool, called Java StarFinder, and evaluated it on a set of programs with complex heap inputs. The results show that our approach significantly reduces the number of invalid test inputs and improves the test coverage.
Discipline
Information Security
Research Areas
Cybersecurity
Publication
International Symposium on Automated Technology for Verification and Analysis (ATVA 2019), Taipei City, Taiwan, 2019 October 27-30
Publisher
Barclays Research
City or Country
Taipei City, Taiwan
Citation
PHAM, Long H.; LOC LE, Quang; PHAN, Quoc-Sang; SUN, Jun; and QIN, Shengchao.
Enhancing symbolic execution of heap-based programs with separation logic for test input generation. (2019). International Symposium on Automated Technology for Verification and Analysis (ATVA 2019), Taipei City, Taiwan, 2019 October 27-30.
Available at: https://ink.library.smu.edu.sg/sis_research/4640
Creative Commons License
This work is licensed under a Creative Commons Attribution-NonCommercial-No Derivative Works 4.0 International License.