Title
Just-in-time static analysis.
Abstract
We present the concept of Just-In-Time (JIT) static analysis that interleaves code development and bug fixing in an integrated development environment. Unlike traditional batch-style analysis tools, a JIT analysis tool presents warnings to code developers over time, providing the most relevant results quickly, and computing less relevant results incrementally later. In this paper, we describe general guidelines for designing JIT analyses. We also present a general recipe for transforming static data-flow analyses to JIT analyses through a concept of layered analysis execution. We illustrate this transformation through CHEETAH, a JIT taint analysis for Android applications. Our empirical evaluation of CHEETAH on real-world applications shows that our approach returns warnings quickly enough to avoid disrupting the normal workflow of developers. This result is confirmed by our user study, in which developers fixed data leaks twice as fast when using CHEETAH compared to an equivalent batch-style analysis.
Year
DOI
Venue
2017
10.1145/3092703.3092705
ISSTA
Keywords
DocType
Citations 
Static analysis, Just-in-Time, Layered analysis
Conference
7
PageRank 
References 
Authors
0.47
12
6
Name
Order
Citations
PageRank
Lisa Nguyen Quang Do1111.22
Karim Ali219012.96
Ben Livshits32108123.83
Eric Bodden42017107.73
Justin Smith59711.74
Emerson R. Murphy-hill6128474.35