A Static Analyzer for Large Safety-Critical Software
arXiv:cs/0701193 · doi:10.1145/781131.781153
Abstract
We show that abstract interpretation-based static program analysis can be made efficient and precise enough to formally verify a class of properties for a family of large programs with few or no false alarms. This is achieved by refinement of a general purpose static analyzer and later adaptation to particular programs of the family by the end-user through parametrization. This is applied to the proof of soundness of data manipulation operations at the machine level for periodic synchronous safety critical embedded software. The main novelties are the design principle of static analyzers by refinement and adaptation through parametrization, the symbolic manipulation of expressions to improve the precision of abstract transfer functions, the octagon, ellipsoid, and decision tree abstract domains, all with sound handling of rounding errors in floating point computations, widening strategies (with thresholds, delayed) and the automatic determination of the parameters (parametrized packing).
Cited by in corpus (18)
- The pitfalls of verifying floating-point computations
- Loop invariants: analysis, classification, and examples
- Inferring Loop Invariants using Postconditions
- Static Analysis of Run-Time Errors in Embedded Real-Time Parallel C Programs
- Using Dynamic Analysis to Generate Disjunctive Invariants
- A Survey on Product Operators in Abstract Interpretation
- Modular Construction of Shape-Numeric Analyzers
- The parallel implementation of the Astrée static analyzer
- Invariant Generation through Strategy Iteration in Succinctly Represented Control Flow Graphs
- The Trusted Computing Base of the CompCert Verified Compiler
- Automatic Repair of Overflowing Expressions with Abstract Interpretation
- Generating Property-Directed Potential Invariants By Backward Analysis
- Sufficient Incorrectness Logic: SIL and Separation SIL
- Exploiting array manipulation habits to optimize garbage collection and type flow analysis
- Identifying Minimal Changes in the Zone Abstract Domain
- U-Turn: Enhancing Incorrectness Analysis by Reversing Direction
- PARF: An Adaptive Abstraction-Strategy Tuner for Static Analysis
- Minimally Comparing Relational Abstract Domains