@inbook{20891,
  abstract     = {{Today, software systems are rarely developed monolithically, but may be composed of numerous individually developed features. Their modularization facilitates independent development and verification. While feature-based strategies to verify features in isolation have existed for years, they cannot address interactions between features. The problem with feature interactions is that they are typically unknown and may involve any subset of the features. Contrary, a family-based verification strategy captures feature interactions, but does not scale well when features evolve frequently. To the best of our knowledge, there currently exists no approach with focus on evolving features that combines both strategies and aims at eliminating their respective drawbacks. To fill this gap, we introduce Fefalution, a feature-family-based verification approach based on abstract contracts to verify evolving features and their interactions. Fefalution builds partial proofs for each evolving feature and then reuses the resulting partial proofs in verifying feature interactions, yielding a full verification of the complete software system. Moreover, to investigate whether a combination of both strategies is fruitful, we present the first empirical study for the verification of evolving features implemented by means of feature-oriented programming and by comparing Fefalution with another five family-based approaches varying in a set of optimizations. Our results indicate that partial proofs based on abstract contracts exhibit huge reuse potential, but also come with a substantial overhead for smaller evolution scenarios.
}},
  author       = {{Knüppel, Alexander and Krüger, Stefan and Thüm, Thomas and Bubel, Richard and Krieter, Sebastian and Bodden, Eric and Schaefer, Ina}},
  booktitle    = {{Lecture Notes in Computer Science}},
  isbn         = {{9783030643539}},
  issn         = {{0302-9743}},
  title        = {{{Using Abstract Contracts for Verifying Evolving Features and Their Interactions}}},
  doi          = {{10.1007/978-3-030-64354-6_5}},
  year         = {{2020}},
}

@inproceedings{23376,
  author       = {{Piskachev, Goran and Nguyen Quang Do, Lisa and Johnson, Oshando and Bodden, Eric}},
  booktitle    = {{2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE)}},
  title        = {{{SWAN_ASSIST: Semi-Automated Detection of Code-Specific, Security-Relevant Methods}}},
  doi          = {{10.1109/ase.2019.00110}},
  year         = {{2020}},
}

@inbook{23377,
  author       = {{Piskachev, Goran and Petrasch, Tobias and Späth, Johannes and Bodden, Eric}},
  booktitle    = {{Lecture Notes in Computer Science}},
  issn         = {{0302-9743}},
  title        = {{{AuthCheck: Program-State Analysis for Access-Control Vulnerabilities}}},
  doi          = {{10.1007/978-3-030-54997-8_34}},
  year         = {{2020}},
}

@inproceedings{20510,
  author       = {{Benz, Manuel and Krogh Kristensen, Erik and Luo, Linghui and P. Borges Jr., Nataniel and Bodden, Eric and Zeller, Andreas}},
  booktitle    = {{International Conference for Software Engineering (ICSE)}},
  title        = {{{Heaps'n Leaks: How Heap Snapshots Improve Android Taint Analysis}}},
  year         = {{2020}},
}

@article{20508,
  author       = {{Nguyen Quang Do, Lisa and Bodden, Eric}},
  journal      = {{IEEE Transactions on Software Engineering}},
  title        = {{{Explaining Static Analysis with Rule Graphs}}},
  year         = {{2020}},
}

@phdthesis{20522,
  author       = {{Holzinger, Philipp}},
  publisher    = {{Universität Paderborn}},
  title        = {{{A Systematic Analysis and Hardening of the Java Security Architecture}}},
  year         = {{2019}},
}

@phdthesis{20524,
  author       = {{Nguyen Quang Do, Lisa}},
  publisher    = {{Universität Paderborn}},
  title        = {{{User-Centered Tool Design for Data-Flow Analysis}}},
  year         = {{2019}},
}

@inproceedings{20525,
  author       = {{Stockmann, Lars and Laux, Sven and Bodden, Eric}},
  booktitle    = {{2019 IEEE International Conference on Software Architecture Companion (ICSA-C)}},
  pages        = {{77--84}},
  title        = {{{Architectural Runtime Verification}}},
  doi          = {{10.1109/ICSA-C.2019.00021}},
  year         = {{2019}},
}

@inproceedings{20527,
  author       = {{Hazhirpasand, Mohammadreza and Ghafari, Mohammad and Krüger, Stefan and Bodden, Eric and Nierstrasz, Oskar}},
  booktitle    = {{2019 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)}},
  issn         = {{1949-3770}},
  pages        = {{1--6}},
  title        = {{{The Impact of Developer Experience in Using Java Cryptography}}},
  doi          = {{10.1109/ESEM.2019.8870184}},
  year         = {{2019}},
}

@inproceedings{20528,
  author       = {{Piskachev, Goran and Petrasch, Tobias and Späth, Johannes and Bodden, Eric}},
  booktitle    = {{10th Workshop on Tools for Automatic Program Analysis (TAPAS)}},
  title        = {{{AuthCheck: Program-state Analysis for Access-control Vulnerabilities}}},
  year         = {{2019}},
}

@inproceedings{20529,
  author       = {{Nachtigall, Marcus and Nguyen Quang Do, Lisa and Bodden, Eric}},
  booktitle    = {{1st International Workshop on Explainable Software (EXPLAIN) at ASE}},
  title        = {{{Explaining Static Analysis -- A Perspective}}},
  year         = {{2019}},
}

@inproceedings{20531,
  author       = {{Luo, Linghui and Bodden, Eric and Späth, Johannes}},
  booktitle    = {{IEEE/ACM International Conference on Automated Software Engineering (ASE 2019)}},
  title        = {{{A Qualitative Analysis of Android Taint-Analysis Results}}},
  year         = {{2019}},
}

@inproceedings{20532,
  author       = {{Piskachev, Goran and Nguyen Quang Do, Lisa and Johnson, Oshando and Bodden, Eric}},
  booktitle    = {{IEEE/ACM International Conference on Automated Software Engineering (ASE 2019), Tool Demo Track}},
  title        = {{{SWAN_ASSIST: Semi-Automated Detection of Code-Specific, Security-Relevant Methods}}},
  year         = {{2019}},
}

@article{20533,
  author       = {{Krüger, Stefan and Späth, Johannes and Ali, Karim and Bodden, Eric and Mezini, Mira}},
  issn         = {{2326-3881}},
  journal      = {{IEEE Transactions on Software Engineering}},
  keywords     = {{Java, Encryption, Static analysis, Tools, Ciphers, Semantics, cryptography, domain-specific language, static analysis}},
  pages        = {{1--1}},
  title        = {{{CrySL: An Extensible Approach to Validating the Correct Usage of Cryptographic APIs}}},
  doi          = {{10.1109/TSE.2019.2948910}},
  year         = {{2019}},
}

@inproceedings{20534,
  author       = {{Piskachev, Goran and Nguyen Quang Do, Lisa and Bodden, Eric}},
  booktitle    = {{ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA)}},
  title        = {{{Codebase-Adaptive Detection of Security-Relevant Methods}}},
  year         = {{2019}},
}

@inproceedings{20535,
  author       = {{Luo, Linghui and Dolby, Julian and Bodden, Eric}},
  booktitle    = {{European Conference on Object-Oriented Programming (ECOOP)}},
  title        = {{{MagpieBridge: A General Approach to Integrating Static Analyses into IDEs and Editors}}},
  year         = {{2019}},
}

@phdthesis{20536,
  author       = {{Späth, Johannes}},
  publisher    = {{Universität Paderborn}},
  title        = {{{Synchronized Pushdown Systems for Pointer and Data-Flow Analysis}}},
  year         = {{2019}},
}

@techreport{20537,
  author       = {{Piskachev, Goran and Nguyen, Lisa and Bodden, Eric}},
  title        = {{{Codebase-Adaptive Detection of Security-Relevant Methods}}},
  year         = {{2019}},
}

@inproceedings{20538,
  author       = {{Albert Gorski Iii, Sigmund and Andow, Benjamin and Nadkarni, Adwait and Manandhar, Sunil and Enck, William and Bodden, Eric and Bartel, Alexandre}},
  booktitle    = {{ACM Conference on Data and Application Security and Privacy (CODASPY 2019)}},
  keywords     = {{ITSECWEBSITE, CROSSING}},
  title        = {{{ACMiner: Extraction and Analysis of Authorization Checks in Android's Middleware}}},
  year         = {{2019}},
}

@article{20539,
  author       = {{Späth, Johannes and Ali, Karim and Bodden, Eric}},
  issn         = {{2475-1421}},
  journal      = {{Proceedings of the ACM SIGPLAN Symposium on Principles of Programming Languages}},
  keywords     = {{ATTRACT, ITSECWEBSITE, CROSSING}},
  number       = {{POPL}},
  pages        = {{48:1--48:29}},
  publisher    = {{ACM}},
  title        = {{{Context-, Flow-, and Field-sensitive Data-flow Analysis Using Synchronized Pushdown Systems}}},
  doi          = {{10.1145/3290361}},
  volume       = {{3}},
  year         = {{2019}},
}

