Assessing work for static software bug detection

Eric B. Larson · 2007

A common static software bug detection technique is to use path simulation. Each execution path is simulated using symbolic variables to determine if any software errors could occur. The scalability of these approaches is dependent on the number of paths in the program. This paper uses number of paths in a program to estimate the amount of work necessary to determine if a particular pointer or array operation is safe. A unique aspect in the study is that we explore the amount of work necessary for verifying the operations together versus verifying operations individually. Results show that the work for the worst-case operation individually generally improves but the magnitude of this improvement is dependent on the program. Often, there are one or two functions that contribute a large percentage of the paths. The results depend on how critical these functions are to verifying an individual operation.

Read the paper · More papers on PaperTik