Integrated static code analysis and runtime verification

Title Integrated static code analysis and runtime verification
Author Sözer, Hasan
Publication Date: 2015-10
Publication Place - Wiley
Subject Software verification, Runtime verification, Static code analysis, Model transformations, Tool integration
Type Periodical
Language English
Digital Yes
Manuscript No
Library: Özyeğin University
Library Asset ID 1097-024X
Record ID 3148c4b7-ec38-41e5-95da-9391124210a5
Library Location Computer Science
Date 2015-10
Notes Due to copyright restrictions, the access to the full text of this article is only available via subscription.
Sample Text Static code analysis tools automatically generate alerts for potential software faults that can lead to failures. However, these tools usually generate a very large number of alerts, some of which are subject to false positives. Because of limited resources, it is usually hard to inspect all the alerts. As a complementary approach, runtime verification techniques verify dynamic system behavior with respect to a set of specifications. However, these specifications are usually created manually based on system requirements and constraints. In this paper, we introduce a noval approach and a toolchain for integrated static code analysis and runtime verification. Alerts that are generated by static code analysis tools are utilized for automatically generating runtime verification specifications. On the other hand, runtime verification results are used for automatically generating filters for static code analysis tools to eliminate false positives. The approach is illustrated for the static analysis and runtime verification of an open-source bibliography reference manager software.
DOI 10.1002/spe.2287
Cilt 45
View in source Özyeğin University Özyeğin University - Historical works, archives, and periodicals search engine
Özyeğin University - Historical works, archives, and periodicals search engine Özyeğin University

Integrated static code analysis and runtime verification

Author Sözer, Hasan
Publication Date 2015-10
Publication Place - Wiley
Subject Software verification, Runtime verification, Static code analysis, Model transformations, Tool integration
Type Periodical
Language English
Digital Yes
Manuscript No
Library Özyeğin University
Library Asset ID 1097-024X
Record ID 3148c4b7-ec38-41e5-95da-9391124210a5
Library Location Computer Science
Date 2015-10
Notes Due to copyright restrictions, the access to the full text of this article is only available via subscription.
Sample Text Static code analysis tools automatically generate alerts for potential software faults that can lead to failures. However, these tools usually generate a very large number of alerts, some of which are subject to false positives. Because of limited resources, it is usually hard to inspect all the alerts. As a complementary approach, runtime verification techniques verify dynamic system behavior with respect to a set of specifications. However, these specifications are usually created manually based on system requirements and constraints. In this paper, we introduce a noval approach and a toolchain for integrated static code analysis and runtime verification. Alerts that are generated by static code analysis tools are utilized for automatically generating runtime verification specifications. On the other hand, runtime verification results are used for automatically generating filters for static code analysis tools to eliminate false positives. The approach is illustrated for the static analysis and runtime verification of an open-source bibliography reference manager software.
DOI 10.1002/spe.2287
Cilt 45
Özyeğin University - Historical works, archives, and periodicals search engine
Özyeğin University You are being redirected...

Please wait