喵ID:0hBCiN免责声明

Jasmine: A Static Analysis Framework for Spring Core Technologies

Jasmine:Spring核心技术的静态分析框架

基本信息

DOI:
10.1145/3551349.3556910
发表时间:
2022
期刊:
Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineering
影响因子:
--
通讯作者:
Weihang Wang
中科院分区:
文献类型:
--
作者: Miao Chen;Tengfei Tu;Hua Zhang;Q. Wen;Weihang Wang研究方向: -- MeSH主题词: --
关键词: --
来源链接:pubmed详情页地址

文献摘要

The Spring framework is widely used in developing enterprise web applications. Spring core technologies, such as Dependency Injection and Aspect-Oriented Programming, make development faster and easier. However, the implementation of Spring core technologies uses a lot of dynamic features. Those features impose significant challenges when using static analysis to reason about the behavior of Spring-based applications. In this paper, we propose Jasmine, a static analysis framework for Spring core technologies extends from Soot to enhance the call graph’s completeness while not greatly affecting its performance. We evaluate Jasmine’s completeness, precision, and performance using Spring micro-benchmarks and a suite of 18 real-world Spring programs. Our experiments show that Jasmine effectively enhances the state-of-the-art tools based on Soot and Doop to better support Spring core technologies. We also add Jasmine support to FlowDroid and discovered twelve sensitive information leakage paths in our benchmarks. Jasmine is expected to provide significant benefits for many program analyses scenes of Spring applications where more complete call graphs are required.
弹簧框架被广泛用于开发企业Web应用程序,例如依赖性注入和面向方面的编程,使开发更快,更容易在使用静态分析来推理基于春季的应用程序的行为时,我们提出了茉莉花的挑战使用Spring Micro-Benchs和一组18个现实世界的春季程序来评估茉莉花的完整性,精度和性能。技术。我们还为流质添加了茉莉花的支持,并在我们的基准中发现了十二个敏感的信息泄漏路径。
参考文献(4)
被引文献(2)
Chianina: an evolving graph system for flow- and context-sensitive analyses of million lines of C code
DOI:
10.1145/3453483.3454085
发表时间:
2021-06
期刊:
Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation
影响因子:
0
作者:
Zhiqiang Zuo;Yiyu Zhang;Qiuhong Pan;S. Lu;Yue Li;Linzhang Wang;Xuandong Li;G. Xu
通讯作者:
Zhiqiang Zuo;Yiyu Zhang;Qiuhong Pan;S. Lu;Yue Li;Linzhang Wang;Xuandong Li;G. Xu
A Study of Call Graph Construction for JVM-Hosted Languages
JVM 托管语言的调用图构建研究
DOI:
发表时间:
2019
期刊:
IEEE transactions on software engineering
影响因子:
7.4
作者:
Ali, Karim;Lai, Xiaoni;Luo, Zhaoyi;Lhotak, Ondrej;Dolby, Julian;Tip, Frank
通讯作者:
Tip, Frank
IccTA: Detecting Inter-Component Privacy Leaks in Android Apps
DOI:
10.1109/icse.2015.48
发表时间:
2015-01-01
期刊:
2015 IEEE/ACM 37TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, VOL 1
影响因子:
0
作者:
Li, Li;Bartel, Alexandre;McDaniel, Patrick
通讯作者:
McDaniel, Patrick
Meibomian glands, meibum, and meibogenesis.
DOI:
10.1016/j.exer.2017.06.020
发表时间:
2017-10
期刊:
Experimental eye research
影响因子:
3.4
作者:
Butovich IA
通讯作者:
Butovich IA

数据更新时间:{{ references.updateTime }}

Weihang Wang
通讯地址:
--
所属机构:
--
电子邮件地址:
--
免责声明免责声明
1、猫眼课题宝专注于为科研工作者提供省时、高效的文献资源检索和预览服务;
2、网站中的文献信息均来自公开、合规、透明的互联网文献查询网站,可以通过页面中的“来源链接”跳转数据网站。
3、在猫眼课题宝点击“求助全文”按钮,发布文献应助需求时求助者需要支付50喵币作为应助成功后的答谢给应助者,发送到用助者账户中。若文献求助失败支付的50喵币将退还至求助者账户中。所支付的喵币仅作为答谢,而不是作为文献的“购买”费用,平台也不从中收取任何费用,
4、特别提醒用户通过求助获得的文献原文仅用户个人学习使用,不得用于商业用途,否则一切风险由用户本人承担;
5、本平台尊重知识产权,如果权利所有者认为平台内容侵犯了其合法权益,可以通过本平台提供的版权投诉渠道提出投诉。一经核实,我们将立即采取措施删除/下架/断链等措施。
我已知晓