kirancodes.me
To Proof Maintenance & Beyond!

Marco: A Stochastic Asynchronous Concolic Explorer

Jie Hu, Yue Duan, Heng Yin

Abstract

Concolic execution is a powerful program analysis technique for code path exploration. Despite recent advances that greatly improved the efficiency of concolic execution engines, path constraint solving remains a major bottleneck of concolic testing. An intelligent scheduler for inputs/branches becomes even more crucial. Our studies show that the previously under-studied branch-flipping policy adopted by state-of-the-art concolic execution engines has several limitations. We propose to assess each branch by its potential for new code coverage from a global view, concerning the path divergence probability at each branch. To validate this idea, we implemented a prototype Marco and evaluated it against the state-of-the-art concolic executor on 30 real-world programs from Google's Fuzzbench, Binutils, and UniBench. The result shows that Marco can outperform the baseline approach and make continuous progress after the baseline approach terminates.

BibTeX
@inproceedings{Hu-al:ICSE24,
  author    = {Jie Hu and
               Yue Duan and
               Heng Yin},
  title     = {Marco: A Stochastic Asynchronous Concolic Explorer},
  booktitle = {ICSE},
  pages     = {59:1--59:12},
  publisher = {{ACM}},
  year      = {2024},
}

Related papers