TY - GEN
T1 - Postconditioned symbolic execution
AU - Yi, Qiuping
AU - Yang, Zijiang
AU - Guo, Shengjian
AU - Wang, Chao
AU - Liu, Jian
AU - Zhao, Chen
N1 - Publisher Copyright:
© 2015 IEEE.
PY - 2015/5/5
Y1 - 2015/5/5
N2 - Symbolic execution is emerging as a powerful technique for generating test inputs systematically to achieve exhaustive path coverage of a bounded depth. However, its practical use is often limited by path explosion because the number of paths of a program can be exponential in the number of branch conditions encountered during the execution. To mitigate the path explosion problem, we propose a new redundancy removal method called postconditioned symbolic execution. At each branching location, in addition to determine whether a particular branch is feasible as in traditional symbolic execution, our approach checks whether the branch is subsumed by previous explorations. This is enabled by summarizing previously explored paths by weakest precondition computations. Postconditioned symbolic execution can identify path suffixes shared by multiple runs and eliminate them during test generation when they are redundant. Pruning away such redundant paths can lead to a potentially exponential reduction in the number of explored paths. We have implemented our method in the symbolic execution engine KLEE and conducted experiments on a large set programs from the GNU Coreutils suite. Our results confirm that redundancy due to common path suffix is both abundant and widespread in real- world applications.
AB - Symbolic execution is emerging as a powerful technique for generating test inputs systematically to achieve exhaustive path coverage of a bounded depth. However, its practical use is often limited by path explosion because the number of paths of a program can be exponential in the number of branch conditions encountered during the execution. To mitigate the path explosion problem, we propose a new redundancy removal method called postconditioned symbolic execution. At each branching location, in addition to determine whether a particular branch is feasible as in traditional symbolic execution, our approach checks whether the branch is subsumed by previous explorations. This is enabled by summarizing previously explored paths by weakest precondition computations. Postconditioned symbolic execution can identify path suffixes shared by multiple runs and eliminate them during test generation when they are redundant. Pruning away such redundant paths can lead to a potentially exponential reduction in the number of explored paths. We have implemented our method in the symbolic execution engine KLEE and conducted experiments on a large set programs from the GNU Coreutils suite. Our results confirm that redundancy due to common path suffix is both abundant and widespread in real- world applications.
UR - https://www.scopus.com/pages/publications/84935080689
U2 - 10.1109/ICST.2015.7102601
DO - 10.1109/ICST.2015.7102601
M3 - 会议稿件
AN - SCOPUS:84935080689
T3 - 2015 IEEE 8th International Conference on Software Testing, Verification and Validation, ICST 2015 - Proceedings
BT - 2015 IEEE 8th International Conference on Software Testing, Verification and Validation, ICST 2015 - Proceedings
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 8th IEEE International Conference on Software Testing, Verification and Validation, ICST 2015
Y2 - 13 April 2015 through 17 April 2015
ER -