* ICSE 2018 *
Sun 27 May - Sun 3 June 2018 Gothenburg, Sweden
Wed 30 May 2018 15:15 - 15:30 at E3 room - Programming and Code Analysis Chair(s): Thorsten Berger

Static code analysis is a powerful approach to detect quality deficiencies such as performance bottlenecks, safety violations or security vulnerabilities already during a software system’s implementation. Yet, as current software systems continue to grow, current static-analysis systems more frequently face the problem of insufficient scalability. We argue that this is mainly due to the fact that current static analyses are implemented fully manually, often in general-purpose programming languages such as Java or C, or in declarative languages such as Datalog. This design choice predefines the way in which the static analysis evaluates, and limits the optimizations and extensions static-analysis designers can apply. To boost scalability to a new level, we propose to fuse static-analysis with just-in-time-optimization technology, introducing for the first time static analyses that are managed and inherently self-adaptive. Those analyses automatically adapt themselves to yield a performance/precision tradeoff that is optimal with respect to the analyzed software system and to the analysis itself. Self-adaptivity is enabled by the novel idea of designing a dedicated intermediate representation, not for the analyzed program but for the analysis itself. This representation allows for an automatic optimization and adaptation of the analysis code, both ahead-of-time (through static analysis of the static analysis) as well as just-in-time during the analysis’ execution, similar to just-in-time compilers.

Eric Bodden is one of the leading experts on secure software engineering, with a specialty in building highly precise tools for automated program analysis. He is Professor for Software Engineering at Paderborn University and co-director of Fraunhofer IEM. Further, he is a member of the directorate of the Collaborative Research Center CROSSING at TU Darmstadt.

At Fraunhofer IEM, Bodden is heading the Attract-Group on Secure Software Engineering. In this function he is developing code analysis technology for security, in collaboration with the leading national and international software development companies. In 2014, the DFG awarded Bodden the Heinz Maier-Leibnitz-Preis. In 2013, BITKOM elected him into their mentoring program BITKOM Management Club.

Bodden is one of the chief maintainers of the Soot program analysis and optimization framework, a contributor to the AspectBench Compiler, the open research compiler for AspectJ, the inventor of the Clara and TamiFlex frameworks. Together with his research group, he has created the FlowDroid analysis framework for Android and the DroidBench benchmark suite.

Wed 30 May

icse-2018-New-Ideas-and-Emerging-Results
14:00 - 15:30: NIER - New Ideas and Emerging Results - Programming and Code Analysis at E3 room
Chair(s): Thorsten BergerChalmers University of Technology, Sweden
icse-2018-New-Ideas-and-Emerging-Results14:00 - 14:15
Talk
DOI Pre-print File Attached
icse-2018-New-Ideas-and-Emerging-Results14:15 - 14:30
Talk
Marcelino Rodriguez-Cancio, Benoit BaudryKTH Royal Institute of Technology, Sweden, Jules WhiteVanderbilt University
icse-2018-New-Ideas-and-Emerging-Results14:30 - 14:45
Short-paper
Nghi Duy Quoc BuiSingapore Management University, Singapore, Lingxiao JiangSingapore Management University
Pre-print
icse-2018-New-Ideas-and-Emerging-Results14:45 - 15:00
Talk
Fernando Lopez de La MoraUniversity of Alberta, Sarah NadiUniversity of Alberta
Pre-print
icse-2018-New-Ideas-and-Emerging-Results15:00 - 15:15
Talk
Federico CiccozziMalardalen University
Link to publication
icse-2018-New-Ideas-and-Emerging-Results15:15 - 15:30
Talk
Eric BoddenHeinz Nixdorf Institut, Paderborn University and Fraunhofer IEM
Pre-print