Jalangi: a tool framework for concolic testing, selective record-replay, and dynamic analysis of JavaScript
Abstract
We describe a tool framework, called Jalangi, for dynamic analysis and concolic testing of JavaScript programs. The framework is written in JavaScript and allows implementation of various heavy-weight dynamic analyses for JavaScript. Jalangi incorporates two key techniques: 1) selective record-replay, a technique which enables to record and to faithfully replay a user-selected part of the program, and 2) shadow values and shadow execution, which enables easy implementation of heavy-weight dynamic analyses such as concolic testing and taint tracking. Jalangi works through source-code instrumentation which makes it portable across platforms. Jalangi is available at https://github.com/SRA-SiliconValley/jalangi under Apache 2.0 license. Our evaluation of Jalangi on the SunSpider benchmark suite and on five web applications shows that Jalangi has an average slowdown of 26X during recording and 30X slowdown during replay and analysis. The slowdowns are comparable with slowdowns reported for similar tools, such as PIN and Valgrind for x86 binaries.
BibTeX
@inproceedings{Sen-al:FSE13,
author = {Koushik Sen and
Swaroop Kalasapur and
Tasneem G. Brutch and
Simon Gibbs},
title = {Jalangi: a tool framework for concolic testing, selective record-replay, and dynamic analysis of {JavaScript}},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {615--618},
publisher = {{ACM}},
year = {2013},
}