• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. Explaining Static Analysis with Rule Graphs
 
  • Details
  • Full
Options
2022
Journal Article
Title

Explaining Static Analysis with Rule Graphs

Abstract
As static data-flow analysis becomes able to report increasingly complex bugs, using an evergrowing set of complex internal rules encoded into flow functions, the analysis tools themselves grow more and more complex. In result, for users to be able to effectively use those tools on specific codebases, they require special configurations - a task which in industry is typically performed by individual developers or dedicated teams. To efficiently use and configure static analysis tools, developers need to build a certain understanding of the analysis' rules, i.e., how the underlying analyses interpret the analyzed code and their reasoning for reporting certain warnings. In this article, we explore how to assist developers in understanding the analysis' warnings, and finding weaknesses in the analysis' rules. To this end, we introduce the concept of rule graphs that expose to the developer selected information about the internal rules of data-flow analyses. We have implemented rule graphs on top of a taint analysis, and show how the graphs can support the abovementioned tasks. Our user study and empirical evaluation show that using rule graphs helps developers understand analysis warnings more accurately than using simple warning traces, and that rule graphs can help developers identify causes for false positives in analysis rules.
Author(s)
Do, L.N.Q.
Universität Paderborn  
Bodden, Eric  
Univ. Paderborn  
Journal
IEEE transactions on software engineering  
DOI
10.1109/TSE.2020.2999534
Language
English
Fraunhofer-Institut für Entwurfstechnik Mechatronik IEM  
Keyword(s)
  • Analysis configuration

  • Data-flow analysis

  • Explainability

  • Program analysis

  • Rule graphs

  • Usability

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024