Static program analysis abstract domain optimization method based on multi-objective optimization and parallel solution
By constructing a method of parallel solution of multi-objective optimization model, the efficiency and reliability problems of abstract domain selection in large-scale program analysis are solved, and the fast and accurate optimal abstract domain selection is achieved, which improves the accuracy and efficiency of program analysis.
Patent Information
- Application Number
- CN202510474455.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-25
AI Technical Summary
When finding the optimal abstract domain of program analysis, existing heuristics and optimization algorithms have problems of low efficiency and insufficient reliability, especially in large-scale complex problems, it is difficult to quickly find the global optimal solution.
Using a method based on multi-objective optimization and parallel solution, a multi-objective optimization model is constructed by abstracting program variables into interval fields, and transforming bit expansion into a combined paradigm CNF, and using multi-threaded parallel solution to find the optimal abstract domain.
Improve the efficiency and accuracy of program analysis, reduce false positives and missed reports, shorten analysis time, make full use of the performance of multi-core processors, and ensure the reliability and stability of the results.
Smart Images

Figure CN120372951A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of program analysis, and more specifically, to an optimization method for an abstract domain of static program analysis based on multi-objective optimization and parallel solution. Background Art
[0002] Program analysis technology is a very important field in computer science, which mainly studies how to automatically analyze and understand the behavior and properties of programs. Program analysis can check the code quality, find problems such as syntax errors and logical errors in the code, and improve the readability of the code; it can identify performance bottlenecks, such as dead code and redundant variables, optimize the code structure, and improve the running efficiency.
[0003] Abstract interpretation is a program analysis technique used to statically analyze the behavior of a program to infer its possible properties at runtime. It simplifies the analysis process by constructing an abstract model of the program, so that its characteristics can be understood without executing the program. The core idea of abstract interpretation is to map the concrete execution state of the program to an abstract state space. This process involves abstracting the variables, control flow, and data types of the program in order to capture the overall behavior of the program rather than each specific step of execution. In abstract interpretation, choosing the appropriate abstract domain is crucial because these abstract domains directly affect how the program's state and variables are represented. The design of the abstract domain not only determines the expressive power of the analysis, but also affects the complexity and computational cost of the analysis. A suitable abstract domain can effectively capture the behavioral characteristics of the program, thereby improving the accuracy and reliability of the analysis.
[0004] Currently, there are mainly two categories of methods for choosing the appropriate abstract domain. The first category is heuristic methods. When looking for the optimal abstract domain, heuristic methods are usually used to quickly evaluate and select the most promising abstract domains. These methods use empirical rules and heuristic strategies, based on an intuitive understanding of program characteristics, to quickly narrow down the range of candidate abstract domains. For example, a greedy strategy can be used to select the abstract domain with better performance, or local search can be used to optimize the parameters of the abstract domain within a certain range.
[0005] The second category is optimization algorithms. In the process of looking for the optimal abstract domain, optimization algorithms are usually used to systematically explore the abstract domain space to find the optimal solution or an approximate optimal solution. Common optimization algorithms such as genetic algorithms, simulated annealing, and linear programming can effectively handle complex abstract domain selection problems. These algorithms evaluate and optimize multiple candidate abstract domains to find the optimal solution in a large search space. Optimization algorithms usually have strong global search capabilities, can effectively avoid local optima, increase the probability of finding the optimal abstract domain, and have a relatively solid theoretical basis, which can provide convergence and stability analysis of the solution. At the same time, they can handle multi-objective optimization and constraint conditions to adapt to more complex abstract domain selection requirements.
[0006] The prior art has the following technical problems:
[0007] Heuristic methods are experience-based search techniques commonly used to solve NP-hard problems or complex optimization problems. They guide the search process by introducing heuristic rules to quickly find acceptable solutions. Although heuristic methods can find feasible solutions in a relatively short time, they are usually limited to local search and may not be able to find the global optimal abstract domain. Different heuristic strategies may lead to different results, and the reliability and stability of the results are relatively low. Moreover, heuristic methods lack a rigorous theoretical basis, and the interpretability of the results may be low.
[0008] Optimization algorithms aim to find the optimal solution or an approximate optimal solution and are commonly used in function optimization, constraint optimization problems, etc. Common optimization algorithms include genetic algorithms, simulated annealing, and linear programming. However, optimization algorithms usually require a long computation time, especially when dealing with high-dimensional and complex problems, the computational cost may increase significantly. When the search space is large, the convergence speed of optimization algorithms may be slow.
[0009] In summary, in the face of large-scale complex problems, neither method can provide efficient and reliable results. Summary of the Invention
[0010] As software is getting larger and the amount of code is increasing today, during the program analysis process, the scale of constraints is also getting larger and more complex. Current methods cannot efficiently and reliably find the optimal abstract domain for large-scale abstract interpretation in program analysis. To address this problem, the present invention uses a parallelization method to propose a multi-objective optimization algorithm for bit-vector constraints to help find the optimal abstract domain and improve the efficiency of program analysis. The technical problem to be solved by the present invention is the efficiency and reliability problems existing in the method of finding the optimal abstract domain during the abstract interpretation of large-scale program analysis. Belonging to the field of program analysis, a static program analysis abstract domain optimization method based on multi-objective optimization and parallel solution is proposed.
[0011] The present invention is implemented through the following technical solutions:
[0012] The present invention discloses a static program analysis abstract domain optimization method based on multi-objective optimization and parallel solution for generating the optimal abstract domain of program analysis, including:
[0013] Taking abstract program variables as interval domains and collecting path constraints;
[0014] Constructing a multi-objective optimization model based on path constraints and program variables;
[0015] According to the multi-objective optimization model, the constraint formula and the optimization objective are determined, and the bit-vector constraint formula is transformed into a conjunctive normal form (CNF) using the bit-blasting method;
[0016] Using a parallel optimization method, the optimal values of each objective under the constraint of the conjunctive normal form (CNF) are solved in parallel by multiple threads;
[0017] The results are updated into the abstract domain, and using the optimal abstract domain analysis program, security vulnerability problems are discovered.
[0018] As a further improvement, the abstract program variables in the present invention are the interval domain, and path constraints are collected, specifically: the variables in the program are abstracted into interval representations, the interval states of the variables are maintained at each program point, and all possible path constraints are collected at key program points. Each program point includes one of branch, loop entry, and loop exit, and the key program points are one of conditional branches and loop bodies.
[0019] As a further improvement, the construction of the multi-objective optimization model according to the path constraints and program variables in the present invention is specifically: transforming the variable extreme value problem into a mathematical optimization problem:
[0020] Objective function: maximize or minimize the objective variable;
[0021] Constraint conditions: constraints obtained by combining the program path conditions and interval abstraction.
[0022] As a further improvement, the transformation of the bit-vector constraint formula into a conjunctive normal form (CNF) using the bit-blasting method in the present invention is specifically:
[0023] By recursively applying bit-level operations to the variables represented by bit vectors and the extended formula, the formula is transformed into a series of Boolean logic expressions. The expressions use Boolean variables to represent the bits in the bit vector and are connected by Boolean logic operators. The logic operators include AND, OR, and NOT.
[0024] As a further improvement, the parallel optimization method in the present invention specifically includes:
[0025] Obtain the conjunctive normal form (CNF) and the optimization objective, and store the optimization objective in the shared queue;
[0026] The shared queue dynamically allocates objectives, and idle threads actively pull unprocessed objectives;
[0027] After a thread obtains an unprocessed objective, starting from the most significant bit (MSB) to the least significant bit (LSB) bit by bit, the maximum value of the bit-vector objective is determined through the SAT engine;
[0028] When a thread finishes the current target calculation, it extracts the next target from the shared queue and continues the solution process;
[0029] When all the targets in the shared queue are processed, all threads are terminated and the maximum value of all targets is output.
[0030] The beneficial effects of the present invention are as follows:
[0031] By constructing a multi-objective optimization model, the interval analysis of program variables can be modeled as a multi-objective optimization problem and solved objectively and accurately using mathematical methods.
[0032] By transforming the bit-vector constraint formula into conjunctive normal form (CNF), it is possible to support the use of efficient SAT solvers and improve the solution efficiency; the CNF structure allows the application of clause simplification and conflict-driven clause learning, which can accelerate the solution process.
[0033] By using the parallel optimization method, multiple threads can solve the optimal values of each objective under the conjunctive normal form (CNF) constraints in parallel, making full use of the performance of multi-core processors and shortening the solution time; using a task scheduling algorithm to balance the thread load and avoid idle cores, maximizing the hardware performance.
[0034] By using the optimal abstract domain to analyze the program, the accuracy of program analysis can be improved, reducing false positives and false negatives in program analysis; it can shorten the time of program analysis, including reducing redundant path analysis and shortening the location time of critical vulnerabilities.
[0035] Although heuristic methods can find feasible solutions in a relatively short time, it is often difficult to guarantee the global optimality of the solutions, resulting in relatively low reliability and stability of the results. In contrast, this method relies on an accurate optimization model and a powerful SAT solving engine, which can ensure the accuracy and reliability of the solution results. By introducing an accurate mathematical model, this method can avoid the common local optimum traps in heuristic algorithms, thus providing a more guaranteed global optimum solution for the selection of the abstract domain.
[0036] Although optimization algorithms can theoretically achieve optimal results, their calculation time is often long, especially when dealing with high-dimensional and complex problems, the calculation cost may increase sharply. When the search space is large, the convergence speed of traditional optimization algorithms may be slow, resulting in a time-consuming solution process. However, this method adopts a multi-thread parallel solution strategy, giving full play to the computing power of multi-core processors and greatly improving the solution efficiency. By decomposing the problem into multiple sub-tasks for parallel processing, it can effectively accelerate the calculation speed, reduce the bottleneck of long-running operations, and ensure that the optimal solution can still be quickly found in large-scale problems.
[0037] Heuristic methods are experience - based search techniques that introduce heuristic rules to guide the search process, resulting in lower reliability and stability of the results. This method relies on an accurate optimization model and a powerful SAT solver engine, which can ensure the accuracy and reliability of the solution results.
[0038] Optimization algorithms usually require a long computation time. Especially when dealing with high - dimensional and complex problems, the computational cost may increase significantly. When the search space is large, the optimization algorithm may have a slow convergence speed. This method adopts a multi - thread parallel solution strategy, fully leveraging the computing power of multi - core processors, and greatly improving the solution efficiency. By decomposing the problem into multiple sub - tasks for parallel processing, it can effectively accelerate the computing speed, reduce the bottleneck of long - term operation, and ensure that the optimal solution can still be quickly found in large - scale problems. Description of the Drawings
[0039] Figure 1 It is a flowchart of the static program analysis abstract domain optimization method based on multi - objective optimization and parallel solution. Detailed Implementation Manner
[0040] The following further illustrates the technical solution of the present invention through specific embodiments in combination with the drawings of the specification. Figure 1 It is a flowchart of the static program analysis abstract domain optimization method based on multi - objective optimization and parallel solution:
[0041] The present invention discloses a static program analysis abstract domain optimization method based on multi - objective optimization and parallel solution. When analyzing the security vulnerabilities of program code, the static analysis tool can effectively capture potential vulnerabilities and memory problems, including the following steps:
[0042] 1. Abstract program variables into interval domains and collect path constraints.
[0043] According to the program control flow graph, search for new variables at each program point. If there are new variables, assign values to them and maintain the variable intervals.
[0044] Input variables: Initialize according to user - defined or global constraints (e.g., x ∈ [0, 100]).
[0045] Local variables: Initialize to the full interval (e.g., y ∈ [-∞, +∞]), and gradually tighten them through subsequent operations. Then collect path constraints at key program points (such as conditional branches, loop bodies).
[0046] Conditional branches:
[0047] For each branch - point conditional expression, extract variable constraints:
[0048] if (x > 5) → True branch constraint: x ∈ (5, +∞), False branch constraint: x ∈ (-∞, 5].
[0049] Loop body
[0050] Initial loop variable range: Assume the loop variable i is initially i ∈ (0, 0).
[0051] Iterative update: Update the range of i after each execution of the loop body (e.g., i = i + 1 → i ∈
[0052] [prev low + 1, prev high + 1]).
[0053] Termination condition constraint: The loop condition i < n, combined with the range of n, infers the upper limit of the number of loop iterations.
[0054] 2. Construct a multi-objective optimization model based on path constraints and program variables
[0055] To obtain the range of program variables, this problem is transformed into the problem of obtaining the maximum and minimum values of program variables under path constraint conditions.
[0056] Definition of objective function:
[0057] Maximize the objective variable: maximize x
[0058] Minimize the objective variable: minimize x
[0059] Transformation of constraint conditions:
[0060] Linear constraint: Directly mapped to a linear inequality, such as y ∈ [a, b] → a ≤ y ≤ b.
[0061] Nonlinear constraint: Multiplication, division, etc. need to retain the nonlinear form, such as x * y ≤ 10.
[0062] 3. According to the objective optimization model, determine the constraint formula and optimization objective, and use the bit-blasting method to transform the bit-vector constraint formula into a conjunctive normal form CNF.
[0063] By recursively applying bit-level operations to the variables represented by bit vectors and the extended formula, the formula is transformed into a series of Boolean logic expressions. The expressions use Boolean variables to represent the bits in the bit vector and are connected by Boolean logic operators, including AND, OR, and NOT.
[0064] For a 2-bit bit-vector variable x and variable constraint The optimization objective is to obtain the maximum value of x. After the bit-blasting method, the variable is transformed into x = 2 * t1 + t0, and the constraint is transformed into Convert to conjunctive normal form.
[0065] 4. Use a parallel optimization method to solve the optimal values of each objective under the constraints of conjunctive normal form CNF in parallel with multiple threads.
[0066] a) Obtain the conjunctive normal form CNF and the optimization objectives, and store the optimization objectives in a shared queue;
[0067] b) The shared queue dynamically allocates objectives, and idle threads actively pull unprocessed objectives;
[0068] c) After a thread obtains an unprocessed objective, starting from the most significant bit MSB to the least significant bit LSB, determine the maximum value of the bit vector objective through the SAT engine;
[0069] d) When a thread completes the calculation of the current objective, extract the next objective from the shared queue and continue the solution;
[0070] e) When all the objectives in the shared queue are processed, terminate all threads and output the maximum and minimum values of all objectives.
[0071] After the variable is transformed into x = 2*t1 + t0, the method for obtaining the maximum value of the variable x is to solve sequentially from the most significant bit t1 to the least significant bit t0. If the current bit to be solved can be assigned a value of 1, then set this bit to 1, otherwise to 0, and then solve the next bit. The final result is [t1 = 1, t0 = 1], that is, x = 3.
[0072] When there are multiple objectives to be solved, save the objectives to be solved in a shared queue. After a thread solves the current objective, obtain the next objective to be solved from the shared queue. When the shared queue is empty, all objectives are solved, and the maximum and minimum values of all objectives are output.
[0073] 5. Update the results to the abstract domain, and use the optimal abstract domain combination to analyze the program to discover problems such as security vulnerabilities.
[0074] Update the maximum / minimum value of the obtained program variables to the interval analysis results of the program, and use the updated optimal abstract domain to analyze the target code. The tool will automatically detect security vulnerabilities in the code, such as memory leaks and integer overflow problems, and feedback the discovered potential vulnerabilities to the developer.
[0075] In this process, the static analysis tool can not only identify common security problems, but also reduce false positives through a more accurate optimal abstract domain, thereby improving the user experience. The analysis results can help developers quickly locate security risks in the code and ensure the stability and security of the software system.
[0076] The above description of the embodiments is to enable those of ordinary skill in the art to understand and apply the present invention. It is obvious that those skilled in the art can easily make various modifications to the above embodiments and apply the general principles described herein to other embodiments without creative labor. Therefore, the present invention is not limited to the above embodiments, and all improvements and modifications made by those skilled in the art based on the disclosure of the present invention should fall within the protection scope of the present invention.
Claims
1. A static program analysis abstract domain optimization method based on multi-objective optimization and parallel solution, characterized in that For generating an optimal abstract domain for program analysis, including: Abstract program variables into an interval domain and collect path constraints; Construct a multi-objective optimization model based on path constraints and program variables; According to the multi-objective optimization model, determine the constraint formula and optimization objective, and use the bit-blasting method to transform the bit-vector constraint formula into conjunctive normal form (CNF); Use a parallel optimization method to solve the optimal values of each objective under the CNF constraints in parallel with multiple threads; update the results to the abstract domain, and use the optimal abstract domain to analyze the program to discover security vulnerability problems.
2. The static program analysis abstract domain optimization method based on multi-objective optimization and parallel solution according to claim 1, characterized in that The abstract program variables are in the interval domain and path constraints are collected. Specifically: abstract the variables in the program into interval representations, maintain the interval states of variables at each program point, and collect all possible path constraints at key program points. Each program point includes branches, loop entrances, and loop exits, and the key program points include conditional branches and loop bodies.
3. The static program analysis abstract domain optimization method based on multi-objective optimization and parallel solution according to claim 1, characterized in that The construction of the multi-objective optimization model based on path constraints and program variables is specifically: transform the variable extreme value problem into a mathematical optimization problem: Objective function: maximize or minimize the objective variable; Constraint conditions: combine the program path conditions and the constraints obtained from interval abstraction.
4. The static program analysis abstract domain optimization method based on multi-objective optimization and parallel solution according to claim 1, wherein The transformation of the bit-vector constraint formula into CNF using the bit-blasting method is specifically: By recursively applying bit-level operations to the variables represented by bit vectors and the extended formula, transform the formula into a series of Boolean logic expressions. The expressions use Boolean variables to represent the bits in the bit vector and are connected by Boolean logic operators. The logic operators include AND, OR, and NOT.
5. The static program analysis abstract domain optimization method based on multi-objective optimization and parallel solution according to claim 1, characterized in that The parallel optimization method specifically includes: a) Obtain the CNF and optimization objectives, and store the optimization objectives in a shared queue; b) The shared queue dynamically allocates objectives, and idle threads actively pull unprocessed objectives; c) After a thread obtains an unprocessed objective, determine the maximum value of the bit-vector objective bit by bit from the most significant bit (MSB) to the least significant bit (LSB) through a SAT engine; d) When a thread completes the calculation of the current objective, extract the next objective from the shared queue and continue the solution; e) When all the objectives in the shared queue are processed, terminate all threads and output the maximum values of all objectives.