Augmenting Counterexample-Guided Abstraction Refinement with Proof Templates

Thomas E. Hart, Kelvin Ku, Arie Gurfinkel, Marsha Chećhik, David Lie · 2008

Existing software model checkers based on predicate abstraction and refinement typically perform poorly at verifying the absence of buffer overflows, with analyses depending on the sizes of the arrays checked. We observe that many of these analyses can be made efficient by providing proof templates for common array traversal idioms idioms, which guide the model checker towards proofs that are independent of array size. We have integrated this technique into our software model checker, PtYasm, and have evaluated our approach on a set of testcases derived from the Verisec suite, demonstrating that our technique enables verification of the safety of array accesses independently of array size.

Read the paper · More papers on PaperTik