kirancodes.me
To Proof Maintenance & Beyond!

FuzzSlice: Pruning False Positives in Static Analysis Warnings through Function-Level Fuzzing

Aniruddhan Murali, Noble Saji Mathews, Mahmoud Alfadel, Meiyappan Nagappan, Meng Xu

Abstract

Manual confirmation of static analysis reports is a daunting task. This is due to both the large number of warnings and the high density of false positives among them. Fuzzing techniques have been proposed to verify static analysis warnings. However, a major limitation is that fuzzing the whole project to reach all static analysis warnings is not feasible. This can take several days and exponential machine time to increase code coverage linearly.

BibTeX
@inproceedings{Murali-al:ICSE24,
  author    = {Aniruddhan Murali and
               Noble Saji Mathews and
               Mahmoud Alfadel and
               Meiyappan Nagappan and
               Meng Xu},
  title     = {{FuzzSlice:} Pruning False Positives in Static Analysis Warnings through {Function-Level} Fuzzing},
  booktitle = {ICSE},
  pages     = {65:1--65:13},
  publisher = {{ACM}},
  year      = {2024},
}

Related papers