Show simple item record

dc.contributor.advisorMartin Rinard
dc.contributor.authorQi, Zichaoen_US
dc.contributor.authorLong, Fanen_US
dc.contributor.authorAchour, Saraen_US
dc.contributor.authorRinard, Martinen_US
dc.contributor.otherProgram Analysisen
dc.date.accessioned2015-05-26T23:00:02Z
dc.date.available2015-05-26T23:00:02Z
dc.date.issued2015-05-26
dc.identifier.urihttp://hdl.handle.net/1721.1/97089
dc.description.abstractWe analyze reported patches for three existing generate-and-validate patch generation systems (GenProg, RSRepair, and AE). The basic principle behind generate-and-validate systems is to accept only plausible patches that produce correct outputs for all inputs in the test suite used to validate the patches. Because of errors in the patch evaluation infrastructure, the majority of the reported patches are not plausible --- they do not produce correct outputs even for the inputs in the validation test suite. The overwhelming majority of the reported patches are not correct and are equivalent to a single modification that simply deletes functionality. Observed negative effects include the introduction of security vulnerabilities and the elimination of desirable standard functionality. We also present Kali, a generate-and-validate patch generation system that only deletes functionality. Working with a simpler and more effectively focused search space, Kali generates at least as many correct patches as prior GenProg, RSRepair, and AE systems. Kali also generates at least as many patches that produce correct outputs for the inputs in the validation test suite as the three prior systems. We also discuss patches produced by ClearView, a generate-and-validate binary hot patching system that leverages learned invariants to produce patches that enable systems to survive otherwise fatal defects and security attacks. Our analysis indicates that ClearView successfully patches 9 of the 10 security vulnerabilities used to evaluate the system. At least 4 of these patches are correct.en_US
dc.format.extent24 p.en_US
dc.relation.ispartofseriesMIT-CSAIL-TR-2015-020
dc.titleAn Analysis of Patch Plausibility and Correctness for Generate-And-Validate Patch Generation Systemsen_US
dc.date.updated2015-05-26T23:00:02Z


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record