首页 | 本学科首页   官方微博 | 高级检索  
     检索      

航天嵌入式软件数组越界缺陷特征研究
引用本文:陈睿,于婷婷,贾春鹏,李超,高栋栋,江云松,杨孟飞.航天嵌入式软件数组越界缺陷特征研究[J].空间控制技术与应用,2021,47(2):1-9.
作者姓名:陈睿  于婷婷  贾春鹏  李超  高栋栋  江云松  杨孟飞
作者单位:北京轩宇信息技术有限公司
基金项目:国家自然科学基金资助项目
摘    要:根据统计,数组越界是航天嵌入式软件开发过程中出现最多且最容易被遗漏的缺陷类型之一.目前自动化检测数组越界多基于抽象解释、符号执行、程序模型检验等方法,这些方法在误报、漏报、可扩展性等方面的表现依赖于软件及缺陷特征.分析了近三年航天嵌入式软件第三方测试中发现的94个数组越界问题,从缺陷模式和缺陷表现形式两方面分析得出10项航天嵌入式软件数组越界缺陷特征,并提出对设计具体检测方法关键的若干启示.进一步基于这些特征和启示探讨了数组越界检测算法针对中断驱动型程序的改进方向.

关 键 词:航天嵌入式软件  数组越界  程序分析  中断驱动型程序  

Out-of-Bounds Array Access Bug Characteristics in Aerospace Embedded Software
CHEN Rui,YU Tingting,JIA Chunpeng,LI Chao,GAO Dongdong,JIANG Yunsong,YANG Mengfei.Out-of-Bounds Array Access Bug Characteristics in Aerospace Embedded Software[J].Aerospace Contrd and Application,2021,47(2):1-9.
Authors:CHEN Rui  YU Tingting  JIA Chunpeng  LI Chao  GAO Dongdong  JIANG Yunsong  YANG Mengfei
Abstract:According to statistics, out of bounds array access is one of the most common and easily missed bugs in aerospace embedded software. At present, program analysis methods for automatically detecting out of bounds array access mostly base on abstract interpretation theory, symbolic execution, model checking and etc. The performances of these methods in false positives, false negatives, and extensibility and so on mainly rely on the characteristics of the software and defects. Therefore, we firstly analyze 94 real world out of bounds array access errors in recent 3 years, which are from aerospace embedded software left to the third party testing part. We carefully examine the bug pattern and manifestation of these bugs, and extract 10 characteristics about the out of bounds array access errors in aerospace embedded software, as well as some important implications. According to these characteristics and implications, we explore the improvement of detection methods for out of bounds array access with respect to interrupt driven programs.
Keywords:aerospace embedded software  out of bounds array access  program analysis      
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《空间控制技术与应用》浏览原始摘要信息
点击此处可从《空间控制技术与应用》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号