Master'sOpen Access

Statik kod analiz uyarılarından koşum zamanı doğrulama belirtimlerinin oluşturulması

2017
0 views
0 downloads
Advisor: Doç. Hasan Sözer

Abstract (EN)

There are various approaches in order to find bugs in a software system. One of these approaches is static code analysis, which tries to achieve this goal by analyzing code without executing it. Another complementary approach is runtime verification, which is employed to verify dynamic system behavior with respect to a set of specifications at runtime. These specifications are often created manually based on system requirements and constraints. In this thesis, we propose a novel methodology and tool support for automatically generating runtime verification specifications based on alerts that are reported by static code analysis tools. We introduce a domain specific language for defining a set of rules to be checked for an alert type. Violations of the rules indicate either the absence or existence of an actual bug designated by the instances of that alert type. Formal verification specifications are automatically generated for each reported alert instance based on the defined rules. Then, runtime monitors are automatically synthesized and integrated into the system. These monitors report detected errors or false positive alerts during software execution. The set of rules can be reused across different projects. We performed case studies with two open source software systems to illustrate this. Our tool currently supports the use of two different static code analysis tools for generating runtime monitors in Java language. It is designed to be extendible for supporting other tools as well.

Author

Dr. Yunus Kılıç

How to Cite

Yunus Kılıç (Master Thesis). Statik kod analiz uyarılarından koşum zamanı doğrulama belirtimlerinin oluşturulması, 2017, Özyegin University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Özyegin University