ISSTA 2025
Wed 25 - Sat 28 June 2025 Trondheim, Norway
co-located with FSE 2025
Sat 28 Jun 2025 14:36 - 14:54 at Cosmos 3C - Afternoon 1

Static analysis is a well-established method for detecting program defects and ensuring software security. However, developers often refrain from utilizing static analysis tools in production environments due to the significant time wasted on eliminating false positives. Effective techniques are missing for confirming the reports from static analyzers. This paper replicates and extends the work of Busse et al., who designed and evaluated a technique to automate the process of confirming potential bugs reported by static analysis using dynamic symbolic execution (DSE) to eliminate false positives. Our replication reveals that traces generated by static analysis reports still hold value in guiding DSE to confirm bugs. After making minor improvement modifications, we found that the performance of the technique was significantly improved and further studied the effects of false positives and inaccurate information on the performance. We also extend the benchmarks for the task by leveraging Software Verification Benchmarks (SV-benchmarks) which contain non-trivial injected bugs and is compatible with both static analysis and DSE. Our goal is to demonstrate and understand the potential of combining static analysis and symbolic execution techniques for accelerating the confirmation of true positives and the elimination of false positives.

Sat 28 Jun

Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change

14:00 - 15:30
Afternoon 1FUZZING at Cosmos 3C
14:00
18m
Talk
On the Applicability of Benford’s Law to Detect Saturation in Fuzzing
FUZZING
Jungwoo Lee KAIST, Haeun Lee KAIST, Sangjun Park KAIST, Sang Kil Cha KAIST
14:18
18m
Talk
Trailblazer: Practical End-to-end Web API Fuzzing
FUZZING
Lianglu Pan University of Melbourne, Shaanan Cohney University of Melbourne, Toby Murray University of Melbourne, Thuan Pham University of Melbourne
14:36
18m
Talk
Revisiting the Combination of Static Analysis Error Traces and Dynamic Symbolic Execution: A Potential Approach for True Positive Confirmation
FUZZING
Yihua Xu East China Normal University, Chengyu Zhang Loughborough University, Geguang Pu East China Normal University, China
14:54
18m
Talk
MQueez: Specification-Driven Fuzzing for MQTT Broker
FUZZING
Xinpeng Liu Zhejiang University, Qinying Wang Zhejiang University, Peiyu Liu Zhejiang University, Wenhai Wang Zhejiang University, Shouling Ji Zhejiang University
15:12
18m
Talk
Shepherd: High-Precision Coverage Inference for Response-guided Blackbox Fuzzing
FUZZING
Takuya Shimizu Ricerca Security, Inc., Ryuichi Yoshizawa Ricerca Security, Inc., Kaoru Otsuka Ricerca Security, Inc., Yudai Fujiwara Ricerca Security, Inc., Yuichi Sugiyama Ricerca Security, Inc.

Information for Participants
Sat 28 Jun 2025 14:00 - 15:30 at Cosmos 3C - Afternoon 1
Info for room Cosmos 3C:

Cosmos 3C is the third room in the Cosmos 3 wing.

When facing the main Cosmos Hall, access to the Cosmos 3 wing is on the left, close to the stairs. The area is accessed through a large door with the number “3”, which will stay open during the event.

:
:
:
: