ICSE 2019
Sat 25 - Fri 31 May 2019 Montreal, QC, Canada
Wed 29 May 2019 17:00 - 17:20 at Laurier - Analysis and Verification Chair(s): Domenico Bianculli

The paper presents the Mockingbird framework that combines static and dynamic analyses to yield an efficient and scalable approach to analyze large Java software. The framework is an innovative integration of existing static and dynamic analysis tools and a newly developed component called the Object Mocker that enables the integration. The static analyzers are used to extract potentially vulnerable parts from large software. Targeted dynamic analysis is used to analyze just the potentially vulnerable parts to check whether the vulnerability can actually be exploited.

We present a case study to illustrate the use of the framework to analyze complex software vulnerabilities. The case study is based on a challenge application from the DARPA Space/Time Analysis for Cybersecurity (STAC) program. Interestingly, the challenge program had been hardened and was thought not to be vulnerable. Yet, using the framework we could discover an unintentional vulnerability that can be exploited for a denial of service attack. The accompanying demo video depicts the case study.


Wed 29 May
16:00 - 18:00: Papers - Analysis and Verification at Laurier
Chair(s): Domenico BianculliUniversity of Luxembourg
icse-2019-Technical-Papers16:00 - 16:20
Minxue PanNanjing University, Shouyu ChenNanjing University, Yu PeiThe Hong Kong Polytechnic University, Tian ZhangNanjing University, Xuandong LiNanjing University
icse-2019-Technical-Papers16:20 - 16:40
Sora BaeOracle Labs, Australia, Sungho LeeKAIST, South Korea, Sukyoung RyuKAIST, South Korea
icse-2019-Demonstrations16:40 - 17:00
Mitchell GerrardUniversity of Virginia, Matthew DwyerUniversity of Virginia
icse-2019-Demonstrations17:00 - 17:20
Derrick LockwoodIowa State University, Benjamin Holland, Suresh KothariIowa State University, USA
icse-2019-Technical-Papers17:20 - 17:40
Richard RutledgeGeorgia Institute of Technology, Sunjae ParkGeorgia Institute of Technology, Haider KhanGeorgia Institute of Technology, Alessandro OrsoGeorgia Tech, Milos PrvulovicGeorgia Institute of Technology, Alenka ZajicGeorgia Institute of Technology
icse-2019-Journal-First-Paper17:40 - 17:50
Rezwana KarimSamsung Research America, Frank TipNortheastern University, Alena SochurkovaAvast, Koushik SenUniversity of California, Berkeley
icse-2019-Paper-Presentations17:50 - 18:00