Score
Design, build, and apply analyses and tooling that examine program code and models without executing them — including data-flow, fixed-point, timing, and software-composition analyses — to detect defects, verify properties, compute resource/timing bounds, and support system-level reasoning. Integrate static analysis tools into development pipelines and, when appropriate, coordinate with dynamic analyses to produce actionable reports, automated checks, and analysis infrastructure.
Existing program comprehension tools struggle to balance scalability and precision in static analysis. This paper addresses C# programs by proposing an interactive, progressive analysis framework: developers first employ lightweight interprocedural data-flow analysis to rapidly identify critical code subregions; subsequently, high-precision symbolic execution is selectively applied to those regions. The framework introduces a novel composable analysis and visualization architecture—inspired by Moldable Development—that enables on-demand assembly of customized comprehension tools directly within Visual Studio. Evaluated on real-world industrial case studies, the approach maintains analytical efficiency while significantly improving precision, thereby enhancing reasoning about complex code behaviors. Key contributions include (1) a progressive, developer-guided analysis paradigm that bridges coarse-grained scalability and fine-grained accuracy; (2) a modular, extensible architecture supporting tool composition without recompilation; and (3) empirical validation demonstrating substantial precision gains—up to 3.2× improvement in path-sensitive defect detection—without compromising analysis throughput.
Verifying the soundness of abstract-interpretation-based static analyzers remains challenging due to the difficulty of systematically validating their analysis results. Method: This paper proposes a lightweight, practical assertion-driven testing approach that statically generates program property assertions and dynamically validates their satisfaction during program execution, thereby enabling automated soundness verification. The method integrates static assertion inference with runtime checking and leverages the Ciao assertion framework to achieve zero-intrusion, fully automated testing. Contribution/Results: It is the first work to systematically uncover and fix previously unknown soundness violations and multi-component coordination bugs in the CiaoPP analyzer. Evaluated on real-world benchmarks, the approach efficiently detects and confirms dozens of defects—most of which have since been fixed—with manageable verification overhead. This work establishes a scalable, deployable paradigm for enhancing the trustworthiness of static analyzers.
Traditional static analysis struggles to balance precision, reliability, and automation, limiting its practical applicability. This work proposes a novel parameterized static analysis approach that introduces user-provided local assumptions at selected program locations and incorporates them via a nondeterministic semantics, thereby constructing a mapping from sets of assumptions to analysis results. This formulation enables optimization-based search over large assumption spaces, overcoming conventional precision bottlenecks. The method’s effectiveness is demonstrated through experiments in two representative scenarios, significantly enhancing the adaptability and flexibility of static analysis in real-world applications.
This study addresses the lack of systematic evaluation of static code analysis tools, particularly regarding their effectiveness in detecting exploitable vulnerabilities. Through a comprehensive literature review, it presents the first holistic mapping of 246 tools across dimensions including vulnerability types, application domains, underlying analysis techniques, and evaluation methodologies. The findings reveal that most tools cover only a limited set of weaknesses, often identifying vulnerabilities that are not practically exploitable. Furthermore, evaluations commonly rely on small-scale, ad hoc benchmarks, which undermines the reliability of reported results. By exposing critical gaps in both the coverage of exploitable vulnerabilities and the rigor of empirical assessment, this work provides an evidence-based foundation and clear direction for future research and tool development in static analysis.
Manual tuning of abstraction strategies in static program analysis is labor-intensive and struggles to balance precision and efficiency. Method: This paper proposes a fully automated, adaptive abstraction-parameter tuning method for the Frama-C/Eva analyzer. It innovatively models abstraction parameters as probability distributions over lattices and employs an iterative sampling–analysis–Bayesian distribution refinement mechanism to automatically converge on optimal strategy combinations. The method further supports dominant-parameter identification and interpretable analysis. It is implemented as a Frama-C/Eva plugin with an integrated web-based visualization interface. Results: Experiments on multiple complex real-world C programs—including industrial-scale projects—demonstrate significant improvements: average false-positive rate reduction of 32% and average analysis time reduction of 28%. These results validate the method’s effectiveness and state-of-the-art performance in large-scale program analysis.
Existing Datalog engines struggle to simultaneously achieve efficiency, scalability, and extensible semantics in static analysis, while also lacking robust support for rule debugging and incremental updates. This work proposes a novel approach that compiles Soufflé-style Datalog programs into executable Differential Dataflow programs, yielding a high-performance, memory-efficient static analysis framework capable of millisecond-scale incremental recomputation. The framework natively supports non-standard semantics—such as k-core analysis—and integrates in-browser performance profiling and rule-tuning capabilities. Evaluated on 24 real-world static analysis benchmarks, the system outperforms state-of-the-art engines in both runtime performance and scalability.
This work addresses the inherent limitations of individual program analysis techniques—particularly their constrained precision, coverage, and insight—which hinder comprehensive software reliability assurance. Through a systematic mapping study of 248 relevant publications, the paper presents the first taxonomy of combined program analysis approaches explicitly centered on synergistic effects and interaction patterns. The proposed multidimensional classification framework is structured around three core dimensions: collaboration objectives, workflow architectures, and types of mapping functions. This framework systematically uncovers commonalities and distinctions in the design of existing methods, offering a clear conceptual foundation for understanding, comparing, and developing novel combined analysis techniques. Furthermore, it delineates current research trends and identifies promising directions for future investigation.
This work addresses the challenges of high-precision interprocedural static analysis in Python, which arise from its dynamic typing, dynamic dispatch, metaprogramming capabilities, and complex object model. To tackle these issues, we present PyFlow—the first general-purpose static analysis framework for Python based on the Interprocedural Finite Distributive Subset (IFDS) formulation. PyFlow leverages a multi-stage intermediate representation and parameterized abstract domains, enabling developers to specify only the data-flow semantics while automatically handling interprocedural hypergraph construction, fixed-point computation, and summary caching. Experimental evaluation demonstrates that PyFlow achieves the highest recall and F1 scores among nine state-of-the-art tools on both synthetic and real-world benchmarks, while maintaining precision comparable to advanced taint analysis engines—marking the first efficient and highly accurate application of IFDS to Python.
This study addresses the significant challenge of verifying termination in real-world C/C++ programs, where loop interactions and nondeterministic inputs complicate analysis. The authors propose a lightweight, tool-agnostic, source-level preprocessing approach that isolates loop obligations via loop slicing and enhances termination analysis by generating input-driven concrete variants tailored to specific scenarios. An empirical evaluation integrating six termination analyzers on 117 real programs demonstrates that slicing conservatively achieves structural isolation, while concretization improves detectability in targeted scenarios at the cost of reduced semantic coverage. Crucially, the combined effect of these techniques is non-additive, indicating that preprocessing should complement—rather than replace—analysis of the original program. The work further reveals substantial variation in how different analyzers respond to preprocessing, offering practical guidance for adaptive usage by developers.