(2015) Test Complement Exclusion: Guarantees from Dynamic Analysis.
Abstract
Modern test generation techniques allow to generate as many executions as needed; combined with dynamic analysis, they allow for understanding program behavior in situations where static analysis is challenged or impossible. However, all these dynamic techniques would still suffer from the incompleteness of testing: If some behavior has not been observed so far, there is no guarantee that it may not occur in the future. In this talk, I introduce a method called Test Complement Exclusion that combines test generation and sandboxing to provide such a guarantee. Test Complement Exclusion will have significant impact in the security domain, as it effectively detects and protects against unexpected changes of program behavior; however, guarantees would also strengthen findings in dynamic software comprehension. First experiments on real-world Android programs demonstrate the feasibility of the approach.
Item Type: | Conference or Workshop Item (A Paper) (Paper) |
---|---|
Additional Information: | pub_id: 1026 Bibtex: Zeller:2015:TCE:2820282.2820284 URL date: None |
Uncontrolled Keywords: | dynamic analysis,testing |
Divisions: | Andreas Zeller (Software Engineering, ST) |
Depositing User: | Sebastian Weisgerber |
Date Deposited: | 26 Jul 2017 10:32 |
Last Modified: | 18 Jul 2019 12:12 |
Primary Research Area: | NRA5: Empirical & Behavioral Security |
URI: | https://publications.cispa.saarland/id/eprint/967 |
Actions
Actions (login required)
View Item |