13 papers · ranked by Valyu relevance
Safeeullah Soomro, Mohammad Riyaz Belgaum, Zainab Alansari, Mahdi H. Miraz
'Mahdi H. Miraz'] Abstract— In the domain of Software Engineering, program analysis and understanding has been considered to be a very challenging task since decade, as it demands dedicated time and efforts. The analysis of source code may occasionally be comparatively easier due to its static nature, however, the…
M. Paganoni, Carlo A. Furia
The breakneck evolution of modern programming languages aggravates the development of deductive verification tools, which struggle to timely and fully support all new language features. To address this challenge, we present BYTEBACK: a verification technique that works on Java bytecode. Compared to high-level…
Krzysztof Stuglik, Piotr Listkiewicz, Mateusz Kulczyk, Marcin Pietroń
'Marcin Pietroń'] Manual translation of the algorithms from sequential version to its parallel counterpart is time consuming and can be done only with the specific knowledge of hardware accelerator architecture, parallel programming or programming environment. The automation of this process makes porting the code much…
Davide Pizzolotto, Mariano Ceccato
—Code obfuscation is a popular approach to turn program comprehension and analysis harder, with the aim of mitigating threats related to malicious reverse engineering and code tampering. However, programming languages that compile to high level bytecode (e.g., Java) can be obfuscated only to a limited extent. In fact…
Julien Ponge, Frédéric Le Mouël
Modifier les portions fonctionnelles et non-fonctionnelles des applications au cours de leur exécution est utile et parfois critique tant lors des phases de développement que de suivi en production. JooFlux est un agent JVM qui permet à la fois de remplacer dynamiquement des implémentations de méthodes que d'appliquer…
Alexandre Bartel, Jacques Klein, Yves Le Traon, Martin Monperrus
This paper introduces Dexpler, a software package which converts Dalvik bytecode to Jimple. Dexpler is built on top of Dedexer and Soot. As Jimple is Soot's main internal representation of code, the Dalvik bytecode can be manipulated with any Jimple based tool, for instance for performing point-to or flow analysis.
Nicolas Harrand, César Soto-Valero, Martin Monperrus, Benoît Baudry
—During compilation from Java source code to bytecode, some information is irreversibly lost. In other words, compilation and decompilation of Java code is not symmetric. Consequently, the decompilation process, which aims at producing source code from bytecode, must establish some strategies to reconstruct the…
Romain Brenguier, Lucas C. Cordeiro, Daniel Kroening, Peter Schrammel
'Peter Schrammel'] Abstract. JBMC is an open-source SAT- and SMT-based bounded model checking tool for verifying Java bytecode. JBMC relies on an operational model of the Java libraries, which conservatively approximates their semantics, to verify assertion violations, array out-of-bounds, unintended arithmetic…
Matthias Güdemann, Peter Schrammel
Automated test case generation tools help businesses to write tests and increase the safety net provided by high regression test coverage when making code changes. Test generation needs to cover as much as possible of the uncovered code while avoiding generating redundant tests for code that is already covered by an…
Nicolas Harrand, César Soto-Valero, Martin Monperrus, Benoît Baudry
During compilation from Java source code to bytecode, some information is irreversibly lost. In other words, compilation and decompilation of Java code is not symmetric. Consequently, decompilation, which aims at producing source code from bytecode, relies on strategies to reconstruct the information that has been…
George Fourtounis, Yannis Smaragdakis
Java 7 introduced programmable dynamic linking in the form of the invokedynamic framework. Static analysis of code containing programmable dynamic linking has often been cited as a significant source of unsoundness in the analysis of Java programs. For example, Java lambdas, introduced in Java 8, are a very popular…
Aman Sharma, Martin Wittlinger, Benoît Baudry, Martin Monperrus
Materials in Java Authors: ['Aman Sharma' 'Martin Wittlinger' 'Benoît Baudry' 'Martin Monperrus'] Abstract—Software supply chain attacks have become a significant threat as software development increasingly relies on contributions from multiple, often unverified sources. The code from unverified sources does not pose a…
François Gauthier, Sora Bae
Untrusted deserialization exploits, where a serialised object graph is used to achieve denial-of-service or arbitrary code execution, have become so prominent that they were introduced in the 2017 OWASP Top 10. In this paper, we present a novel and lightweight approach for runtime prevention of deserialization attacks…