Efficient Data Flow Constraint Analysis
Jonas Kunz · Zenodo (CERN European Organization for Nuclear Research) · 2018
With recent trends such as cloud computing and micro services modern software systems become more and more decentralized. As a result more and more data processed by the systems ows across public networks and environments hosted by third parties. With recent legal regulations, such as the General Data Protection Regulations of the EU, it becomes even more important for software developers to ensure that all data ows of their software adhere to legal constraints. While several model-based approaches have been proposed for modeling data ows and related constraints on architecture level their automated analysis capabilities are limited. In many cases no automated analysis is available or an analysis has to be implemented on a per-scenario basis. We therefore propose a novel meta-model for modeling data ows of software systems. Alongside we provide a translation transforming model instances to programs based on the logic programming language Prolog. This combination allows to easily dene automated analysis of software systems regarding data ow constraint violations. For the design and implementation we ensure that our approach is ecient regarding the scalability. For this purpose we introduce several techniques for optimizing Prolog programs which are not only limited to our approach. In addition we provide an extensive evaluation of our approach. Hereby we investigate the accuracy, the scalability and the genericness of our approach. We show that our approach is able to accurately analyse various types of scenarios while maintaining a good scalability. We show that our proposed Prolog optimizations are eective as they potentially reduce the run time from exponential to constant scaling in certain scenarios.