TY - JOUR
T1 - Composite Constant Propagation and its Application to Android Program Analysis
AU - Octeau, Damien
AU - Luchaup, Daniel
AU - Jha, Somesh
AU - McDaniel, Patrick
N1 - Publisher Copyright:
© 2016 IEEE.
PY - 2016/11/1
Y1 - 2016/11/1
N2 - Many program analyses require statically inferring the possible values of composite types. However, current approaches either do not account for correlations between object fields or do so in an ad hoc manner. In this paper, we introduce the problem of composite constant propagation. We develop the first generic solver that infers all possible values of complex objects in an interprocedural, flow and context-sensitive manner, taking field correlations into account. Composite constant propagation problems are specified using COAL, a declarative language. We apply our COAL solver to the problem of inferring Android Inter-Component Communication (ICC) values, which is required to understand how the components of Android applications interact. Using COAL, we model ICC objects in Android more thoroughly than the state-of-the-art. We compute ICC values for 489 applications from the Google Play store. The ICC values we infer are substantially more precise than previous work. The analysis is efficient, taking two minutes per application on average. While this work can be used as the basis for many whole-program analyses of Android applications, the COAL solver can also be used to infer the values of composite objects in many other contexts.
AB - Many program analyses require statically inferring the possible values of composite types. However, current approaches either do not account for correlations between object fields or do so in an ad hoc manner. In this paper, we introduce the problem of composite constant propagation. We develop the first generic solver that infers all possible values of complex objects in an interprocedural, flow and context-sensitive manner, taking field correlations into account. Composite constant propagation problems are specified using COAL, a declarative language. We apply our COAL solver to the problem of inferring Android Inter-Component Communication (ICC) values, which is required to understand how the components of Android applications interact. Using COAL, we model ICC objects in Android more thoroughly than the state-of-the-art. We compute ICC values for 489 applications from the Google Play store. The ICC values we infer are substantially more precise than previous work. The analysis is efficient, taking two minutes per application on average. While this work can be used as the basis for many whole-program analyses of Android applications, the COAL solver can also be used to infer the values of composite objects in many other contexts.
UR - http://www.scopus.com/inward/record.url?scp=84997542798&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84997542798&partnerID=8YFLogxK
U2 - 10.1109/TSE.2016.2550446
DO - 10.1109/TSE.2016.2550446
M3 - Article
AN - SCOPUS:84997542798
SN - 0098-5589
VL - 42
SP - 999
EP - 1014
JO - IEEE Transactions on Software Engineering
JF - IEEE Transactions on Software Engineering
IS - 11
M1 - 7447806
ER -