14 papers · ranked by Valyu relevance
Matthias Güdemann, Peter Schrammel
Automated test case generation tools help businesses to write tests and increase the safety net provided by high regression test coverage when making code changes. Test generation needs to cover as much as possible of the uncovered code while avoiding generating redundant tests for code that is already covered by an…
M. Paganoni, Carlo A. Furia
The breakneck evolution of modern programming languages aggravates the development of deductive verification tools, which struggle to timely and fully support all new language features. To address this challenge, we present BYTEBACK: a verification technique that works on Java bytecode. Compared to high-level…
Krzysztof Stuglik, Piotr Listkiewicz, Mateusz Kulczyk, Marcin Pietroń
'Marcin Pietroń'] Manual translation of the algorithms from sequential version to its parallel counterpart is time consuming and can be done only with the specific knowledge of hardware accelerator architecture, parallel programming or programming environment. The automation of this process makes porting the code much…
Thomas S. Heinze, André Schäfer, Wolfram Amme
Copy & paste is a widespread practice when developing software and, thus, duplicated and subsequently modified code occurs frequently in software projects. Since such code clones, i.e., identical or similar fragments of code, can bloat software projects and cause issues like bug or vulnerability propagation, their…
Romain Brenguier, Lucas C. Cordeiro, Daniel Kroening, Peter Schrammel
'Peter Schrammel'] Abstract. JBMC is an open-source SAT- and SMT-based bounded model checking tool for verifying Java bytecode. JBMC relies on an operational model of the Java libraries, which conservatively approximates their semantics, to verify assertion violations, array out-of-bounds, unintended arithmetic…
Aman Sharma, Martin Wittlinger, Benoît Baudry, Martin Monperrus
Materials in Java Authors: ['Aman Sharma' 'Martin Wittlinger' 'Benoît Baudry' 'Martin Monperrus'] Abstract—Software supply chain attacks have become a significant threat as software development increasingly relies on contributions from multiple, often unverified sources. The code from unverified sources does not pose a…
M. Paganoni, Carlo A. Furia
In this paper, we present a novel approach to verify the exceptional behavior of Java programs, which extends our previous work on BYTEBACK. BYTEBACK works on a program's bytecode, while providing means to specify the intended behavior at the source-code level; this approach sets BYTEBACK apart from most…
Jiawen Xiong, Yong Shi, Boyuan Chen, Filipe R. Cogo + 1 more
'Zhen Ming Jiang'] Build verifiability refers to the property that the build of a software system can be verified by independent third parties and it is crucial for the trustworthiness of a software system. Various efforts towards build verifiability have been made to C/C++-based systems, yet the techniques for…
François Gauthier, Sora Bae
Untrusted deserialization exploits, where a serialised object graph is used to achieve denial-of-service or arbitrary code execution, have become so prominent that they were introduced in the 2017 OWASP Top 10. In this paper, we present a novel and lightweight approach for runtime prevention of deserialization attacks…
C. Katharina Spieß
Software reverse engineering is an essential task in software engineering and security, but it can be a challenging process, especially for adversarial artifacts. To address this challenge, we present STraceBERT, a novel approach that utilizes a Java dynamic analysis tool to record calls to core Java libraries, and…
Jonathan Lambert, Kevin Casey, Rosemary Monahan
Although the advantages of just-in-time compilation over traditional interpretive execution are widely recognised, there needs to be more current research investigating and repositioning the performance differences between these two execution models relative to contemporary workloads. Specifically, there is a need to…
Zhiqiang Zang, Fu-Yao Yu, Aditya Thimmaiah, August Shi + 1 more
'Milos Gligoric'] We present LeJit, a template-based framework for testing Java just-in-time (JIT) compilers. Like recent template-based frameworks, LeJit executes a template—a program with holes to be filled—to generate concrete programs given as inputs to Java JIT compilers. LeJit automatically generates template…
Miles Frantz
The increasing development speed via Agile[1] may introduce overlooked security steps in the process, with an example being the Iowa Caucus application[2]. Verifying the protection of confidential information such as social security numbers requires security at all levels, providing protection through any connected…
Juan Fumero, György Réthy, Athanasios Stratikopoulos, Nikos Foutris + 1 more
'Christos Kotselidis'] This paper presents the Beehive SPIR-V Toolkit; a framework that can automatically generate a Java composable and functional library for dynamically building SPIR-V binary modules. The Beehive SPIR-V Toolkit can be used by optimizing compilers and runtime systems to generate and validate SPIR-V…