kirancodes.me
To Proof Maintenance & Beyond!

A general approach to modeling Java framework behaviors

Linghui Luo

Abstract

Interprocedural static analysis tools such as security analyses need good call graphs, which are challenging to scale for framework-based applications. So most tools model rather than analyzing frameworks. These models are manually crafted to capture framework semantics crucial for the particular analysis, and are inherently incomplete. We propose a general approach to modeling Java frameworks. It is not limited to any framework or analysis tool, therefore, highly reusable. While a generic approximation can be noisy, we show our carefully-constructed one does well. Experiments on Android with a client taint analysis show that our approach produces more complete call graphs than the original analysis. As a result, the client analysis works better: both precision (from 0.83 to 0.86) and recall (from 0.20 to 0.31) are improved.

BibTeX
@inproceedings{Luo:FSE21,
  author    = {Linghui Luo},
  title     = {A general approach to modeling Java framework behaviors},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {1680--1682},
  publisher = {{ACM}},
  year      = {2021},
}

Related papers