[New: openFATE 311146] Verify static analysis reports by symbolic execution
![](https://seccdn.libravatar.org/avatar/0295f9d5d76379b5da73427b67acd395.jpg?s=120&d=mm&r=g)
Feature added by: Jiri Slaby (jirislaby) Feature #311146, revision 1 Title: Verify static analysis reports by symbolic execution Hackweek VI: Unconfirmed Priority Requester: Neutral Requested by: Jiri Slaby (jirislaby) Partner organization: openSUSE.org Description: Static analysis tools report many false positives caused by improper state tracking during the check. These false positives may be easily (at least I think so) pruned by running the symbolic execution on that. More concretely, let's try it with Stanse and Klee. Papers: J.C. King: Symbolic execution and program testing Engler et al.: Klee : Unassisted and automatic generation of high-coverage tests for complex systems programs Godefroid et al.: DART: Directed Automated Random Testing -- openSUSE Feature: https://features.opensuse.org/311146
![](https://seccdn.libravatar.org/avatar/0295f9d5d76379b5da73427b67acd395.jpg?s=120&d=mm&r=g)
Feature changed by: Jiri Slaby (jirislaby) Feature #311146, revision 2 Title: Verify static analysis reports by symbolic execution - Hackweek VI: Unconfirmed + Hackweek VI: Implementation Priority Requester: Neutral Requested by: Jiri Slaby (jirislaby) + Developer: (Novell) Partner organization: openSUSE.org Description: Static analysis tools report many false positives caused by improper state tracking during the check. These false positives may be easily (at least I think so) pruned by running the symbolic execution on that. More concretely, let's try it with Stanse and Klee. Papers: J.C. King: Symbolic execution and program testing Engler et al.: Klee : Unassisted and automatic generation of high-coverage tests for complex systems programs Godefroid et al.: DART: Directed Automated Random Testing -- openSUSE Feature: https://features.opensuse.org/311146
![](https://seccdn.libravatar.org/avatar/0295f9d5d76379b5da73427b67acd395.jpg?s=120&d=mm&r=g)
Feature changed by: Jiri Slaby (jirislaby) Feature #311146, revision 4 Title: Verify static analysis reports by symbolic execution - Hackweek VI: Implementation + Hackweek VI: Done Priority Requester: Neutral Requested by: Jiri Slaby (jirislaby) Developer: (Novell) Partner organization: openSUSE.org Description: Static analysis tools report many false positives caused by improper state tracking during the check. These false positives may be easily (at least I think so) pruned by running the symbolic execution on that. More concretely, let's try it with Stanse and Klee. Papers: J.C. King: Symbolic execution and program testing Engler et al.: Klee : Unassisted and automatic generation of high-coverage tests for complex systems programs Godefroid et al.: DART: Directed Automated Random Testing -- openSUSE Feature: https://features.opensuse.org/311146
participants (1)
-
fate_noreply@suse.de