Reducing False Alarms for Static Analysis via Weakest Precondition

Jie Chen · International Conference on Electric Information and Control Engineering · 2012

Software security becomes more and more important. But bugs in programs are still inevitable. Compared to dynamic test, static analysis techniques is powerful to detect bugs before software release. However, static analyzers always suffer the problem of high rate of false alarms. In this paper we propose a false alarm reducing framework for static analysis via weakest precondition propagation. It can be instantiated for reducing different kinds of false alarms in a demand-driven way. We evaluated the framework by instantiating it for reducing false alarms of array bounds violation. We get the alarm reports produced by existed static analysis tools first, and then reduce the false alarms by our framework. The results show that our technique is successful and suitable for reducing false alarms for static analysis.

Read the paper · More papers on PaperTik