Striking a Balance: Pruning False-Positives from Static Call Graphs

22Citations
Citations of this article
25Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Researchers have reported that static analysis tools rarely achieve a false-positive rate that would make them attractive to developers. We overcome this problem by a technique that leads to reporting fewer bugs but also much fewer false positives. Our technique prunes the static call graph that sits at the core of many static analyses. Specifically, static call-graph construction proceeds as usual, after which a call-graph pruner removes many false-positive edges but few true edges. The challenge is to strike a balance between being aggressive in removing false-positive edges but not so aggressive that no true edges remain. We achieve this goal by automatically producing a call-graph pruner through an automatic, ahead-of-time learning process. We added such a call-graph pruner to a software tool for null-pointer analysis and found that the false-positive rate decreased from 73% to 23%. This improvement makes the tool more useful to developers.

Cite

CITATION STYLE

APA

Utture, A., Liu, S., Kalhauge, C. G., & Palsberg, J. (2022). Striking a Balance: Pruning False-Positives from Static Call Graphs. In Proceedings - International Conference on Software Engineering (Vol. 2022-May, pp. 2043–2055). IEEE Computer Society. https://doi.org/10.1145/3510003.3510166

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free