IntRepair: Informed Repairing of Integer Overflows

Paul Muntean, Martin Monperrus, Hao Sun, Jens Großklags, Claudia Margot Eckert · IEEE Transactions on Software Engineering · 2019

Integer overflows have threatened software applications for decades. Thus, in this paper, we propose a novel technique to provide automatic repairs of integer overflows inCsource code. Our technique, based on static symbolic execution, fusesdetection,repair generationandvalidation. This technique is implemented in a prototype namedIntRepair. We appliedIntRepairto 2,052Cprograms (approx. 1 million lines of code) contained in SAMATE's Juliet test suite and 50 synthesized programs that range up to 20 KLOC. Our experimental results show thatIntRepairis able to effectively detect integer overflows and successfully repair them, while only increasing the source code (LOC) and binary (Kb) size by around 1 percent, respectively. Further, we present the results of a user study with 30 participants which shows thatIntRepairrepairs are more than 10x efficient as compared to manually generated code repairs.

Read the paper · More papers on PaperTik