Many security and software testing applications require checking whether certain properties of a program hold for any possible usage scenario. For instance, a tool for identifying software vulnerabilities may need to rule out the existence of any backdoor to bypass a program’s authentication. One approach would be to test the program using different, possibly random inputs. As the backdoor may only be hit for very specific program workloads, automated exploration of the space of possible inputs is of the essence. Symbolic execution provides an elegant solution to the problem, by systematically exploring many possible execution paths at the same time without necessarily requiring concrete inputs. Rather than taking on fully specified input values, the technique abstractly represents them as symbols, resorting to constraint solvers to construct actual instances that would cause property violations. Symbolic execution has been incubated in dozens of tools developed over the last four decades, leading to major practical breakthroughs in a number of prominent software reliability applications. The goal of this survey is to provide an overview of the main ideas, challenges, and solutions developed in the area, distilling them for a broad audience.

A Survey of Symbolic Execution Techniques / Baldoni, Roberto; Coppa, Emilio; D'Elia, Daniele Cono; Demetrescu, Camil; Finocchi, Irene. - In: ACM COMPUTING SURVEYS. - ISSN 0360-0300. - ELETTRONICO. - 51:3(2018). [10.1145/3182657]

A Survey of Symbolic Execution Techniques

Baldoni, Roberto;Coppa, Emilio;D'Elia, Daniele Cono;Demetrescu, Camil
;
Finocchi, Irene
2018

Abstract

Many security and software testing applications require checking whether certain properties of a program hold for any possible usage scenario. For instance, a tool for identifying software vulnerabilities may need to rule out the existence of any backdoor to bypass a program’s authentication. One approach would be to test the program using different, possibly random inputs. As the backdoor may only be hit for very specific program workloads, automated exploration of the space of possible inputs is of the essence. Symbolic execution provides an elegant solution to the problem, by systematically exploring many possible execution paths at the same time without necessarily requiring concrete inputs. Rather than taking on fully specified input values, the technique abstractly represents them as symbols, resorting to constraint solvers to construct actual instances that would cause property violations. Symbolic execution has been incubated in dozens of tools developed over the last four decades, leading to major practical breakthroughs in a number of prominent software reliability applications. The goal of this survey is to provide an overview of the main ideas, challenges, and solutions developed in the area, distilling them for a broad audience.
2018
Symbolic execution; static analysis; concolic execution; software testing
01 Pubblicazione su rivista::01a Articolo in rivista
A Survey of Symbolic Execution Techniques / Baldoni, Roberto; Coppa, Emilio; D'Elia, Daniele Cono; Demetrescu, Camil; Finocchi, Irene. - In: ACM COMPUTING SURVEYS. - ISSN 0360-0300. - ELETTRONICO. - 51:3(2018). [10.1145/3182657]
File allegati a questo prodotto
File Dimensione Formato  
Baldoni_Preprint-A-Survey_2018.pdf

accesso aperto

Note: 10.1145/3182657
Tipologia: Documento in Pre-print (manoscritto inviato all'editore, precedente alla peer review)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 750.07 kB
Formato Adobe PDF
750.07 kB Adobe PDF
Baldoni_A-Survey_2018.pdf

solo gestori archivio

Tipologia: Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 1.3 MB
Formato Adobe PDF
1.3 MB Adobe PDF   Contatta l'autore

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/1077050
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 428
  • ???jsp.display-item.citation.isi??? 301
social impact