Journal ArticleDOI
Model checking programs
Willem Visser,Klaus Havelund,Guillaume Brat,Seungjoon Park +3 more
- Vol. 10, Iss: 2, pp 203-232
TLDR
A verification and testing environment for Java, called Java PathFinder (JPF), which integrates model checking, program analysis and testing, and uses state compression to handle big states and partial order and symmetry reduction, slicing, abstraction, and runtime analysis techniques to reduce the state space.Abstract:
The majority of the work carried out in the formal methods community throughout the last three decades has (for good reasons) been devoted to special languages designed to make it easier to experiment with mechanized formal methods such as theorem provers and model checkers. In this paper, we give arguments for why we believe it is time for the formal methods community to shift some of its attention towards the analysis of programs written in modern programming languages. In keeping with this philosophy, we have developed a verification and testing environment for Java, called Java PathFinder (JPF), which integrates model checking, program analysis and testing. Part of this work has consisted of building a new Java Virtual Machine that interprets Java bytecode. JPF uses state compression to handle large states, and partial order reduction, slicing, abstraction and run-time analysis techniques to reduce the state space. JPF has been applied to a real-time avionics operating system developed at Honeywell, illustrating an intricate error, and to a model of a spacecraft controller, illustrating the combination of abstraction, run-time analysis and slicing with model checking.read more
Citations
More filters
Book ChapterDOI
Enhanced Property Specification and Verification in BLAST
TL;DR: A significant performance improvement can be achieved by tracking state of the behavior rules aside from the source code instead of instrumenting them, and an experiment with two Linux kernel drivers confirms the performance gain.
Proceedings ArticleDOI
System Service Call-oriented Symbolic Execution of Android Framework with Applications to Vulnerability Discovery and Exploit Generation
Lannan Luo,Qiang Zeng,Chen Cao,Kai Chen,Jian Liu,Limin Liu,Neng Gao,Min Yang,Xinyu Xing,Peng Liu +9 more
TL;DR: This work designs and builds the first system, Centaur, that enables symbolic execution of Android Framework, and demonstrates how the system can be applied to discovering new vulnerability instances, which can be exploited by several recently uncovered attacks against the framework, and to generating PoC exploits.
Proceedings ArticleDOI
Automatically computing path complexity of programs
TL;DR: This work defines the path complexity of a program as a function that takes a depth bound as input and returns the number of paths in the control flow graph that are within that bound, and shows how to automatically compute this function in closed form.
Journal Article
Enforcer : Efficient failure injection
TL;DR: The tool, Enforcer, combines the structure of unit tests, coverage information, and fault injection, which can be improved by orders of magnitude compared to previous approaches by taking advantage of a unit test infrastructure.
Error explanation and fault localization with distance metrics
Alex Groce,Edmund M. Clarke +1 more
TL;DR: This work presents a novel and successful approach to error explanation based on distance metrics for program executions, inspired by the counterfactual theory of causality proposed by philosopher David Lewis, and the insights gained from previous work on providing practical error explanation.
References
More filters
Journal ArticleDOI
Statecharts: A visual formalism for complex systems
TL;DR: It is intended to demonstrate here that statecharts counter many of the objections raised against conventional state diagrams, and thus appear to render specification by diagrams an attractive and plausible approach.
Book
The Unified Modeling Language User Guide
TL;DR: In The Unified Modeling Language User Guide, the original developers of the UML provide a tutorial to the core aspects of the language in a two-color format designed to facilitate learning.
Journal ArticleDOI
The model checker SPIN
TL;DR: An overview of the design and structure of the verifier, its theoretical foundation, and an overview of significant practical applications are given.
Book
The Z notation: a reference manual
TL;DR: Tutorial introduction background the Z language the mathematical tool-kit sequential systems syntax summary and how to use it to solve sequential systems problems.