VLDB 2026 Research / reviewers in the wild / expert
William G. J. Halfond
dblp:04/4583
· DBLP profile ↗
67ranked-venue papers
13as first author
17since 2021 · last 2026
0000-0003-4951-9367ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 60 · 13 first-author · 14 since 2021Computer networks · 3Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Lost in Navigation: Detecting Keyboard Navigation Accessibility Issues in Web Pages
Robert Winn, Paul T. Chiou, William G. J. Halfond |
ICST | 3 |
| 2025 | Automatic Action Space Specification for Deep Reinforcement Learning in Games via Program AnalysisabstractReinforcement learning has numerous applications for the testing and analysis of video game content. However, deploying it in existing games is a challenging engineering effort, requiring suitable representations of states, actions, and rewards based on the game rules. We propose using the program analysis technique of symbolic execution on the game code to automatically determine a precise action model when deploying reinforcement learning in existing games. Our technique automatically computes appropriate discrete action spaces for games, including action masks indicating the validity of actions depending on the agent's current state. We conduct a comprehensive evaluation of the technique on a varied dataset of seven Unity games with the Proximal Policy Optimization (PPO) and Deep Q Learning (DQN) deep reinforcement learning approaches. The results show that the agents using the analysis significantly out-perform those using generic action spaces covering the input device, and perform on par with those using manually specified action spaces. Sasha Volokh, William G. J. Halfond |
CoG | 2 |
| 2025 | An Empirical Study on Leveraging Images in Automated Bug Report ReproductionabstractAutomated bug reproduction is a challenging task, with existing tools typically relying on textual steps-to-reproduce, videos, or crash logs in bug reports as input. However, images provided in bug reports have been overlooked. To address this gap, this paper presents an empirical study investigating the necessity of including images as part of the input in automated bug reproduction. We examined the characteristics and patterns of images in bug reports, focusing on (1) the distribution and types of images (e.g., UI screenshots), (2) documentation patterns associated with images (e.g., accompanying text, annotations), and (3) the functional roles they served, particularly their contribution to reproducing bugs. Furthermore, we analyzed the impact of images on the performance of existing tools, identifying the reasons behind their influence and the ways in which they can be leveraged to improve bug reproduction. Our findings reveal several key insights that demonstrate the importance of images in supporting automated bug reproduction. Specifically, we identified six distinct functional roles that images serve in bug reports, each exhibiting unique patterns and specific contributions to the bug reproduction process. This study offers new insights into tool advancement and suggests promising directions for future research. Dingbang Wang, Sidong Feng, William G. J. Halfond, Tingting Yu 0001 |
MSR | 4 |
| 2024 | Automatically Detecting Reflow Accessibility Issues in Responsive Web PagesabstractMany web applications today use responsive design to adjust the view of web pages to match the screen size of end users. People with disabilities often use an alternative view either due to zooming on a desktop device to enlarge text or viewing within a smaller viewport when using assistive technologies. When web pages are not implemented to correctly adjust the page's content across different screen sizes, it can lead to both a loss of content and functionalities between the different versions. Recent studies show that these reflow accessibility issues are among the most prevalent modern web accessibility issues. In this paper, we present a novel automated technique to automatically detect reflow accessibility issues in web pages for keyboard users. The evaluation of our approach on real-world web pages demonstrated its effectiveness in detecting reflow accessibility issues, outperforming state-of-the-art techniques. Paul T. Chiou, Robert Winn, Ali Alotaibi, William G. J. Halfond |
ICSE | 4 |
| 2024 | Feedback-Driven Automated Whole Bug Report Reproduction for Android AppsabstractIn software development, bug report reproduction is a challenging task. This paper introduces ReBL, a novel feedback-driven approach that leverages GPT-4, a large-scale language model (LLM), to automatically reproduce Android bug reports. Unlike traditional methods, ReBL bypasses the use of Step to Reproduce (S2R) entities. Instead, it leverages the entire textual bug report and employs innovative prompts to enhance GPT’s contextual reasoning. This approach is more flexible and context-aware than the traditional step-by-step entity matching approach, resulting in improved accuracy and effectiveness. In addition to handling crash reports, ReBL has the capability of handling non-crash functional bug reports. Our evaluation of 96 Android bug reports (73 crash and 23 non-crash) demonstrates that ReBL successfully reproduced 90.63% of these reports, averaging only 74.98 seconds per bug report. Additionally, ReBL outperformed three existing tools in both success rate and speed. Dingbang Wang, Yu Zhao 0010, Sidong Feng, William G. J. Halfond, Chunyang Chen 0001, Xiaoxia Sun, Jiangfan Shi, Tingting Yu 0001 |
ISSTA | 5 |
| 2023 | BAGEL: An Approach to Automatically Detect Navigation-Based Web Accessibility Barriers for Keyboard UsersabstractThe Web has become an essential part of many people’s daily lives, enabling them to complete everyday and essential tasks online and access important information resources. The ability to navigate the Web via the keyboard interface is critical to people with various types of disabilities. However, modern websites often violate web accessibility guidelines for keyboard navigability. In this paper, we present a novel approach for automatically detecting web accessibility barriers that prevent or hinder keyboard users’ ability to navigate web pages. An extensive evaluation of our technique on real-world subjects showed that our technique was able to detect navigation-based keyboard accessibility barriers in web applications with high precision and recall. Paul T. Chiou, Ali Alotaibi, William G. J. Halfond |
CHI | 3 |
| 2023 | Detecting Dialog-Related Keyboard Navigation Failures in Web ApplicationsabstractThe ability to navigate the Web via the keyboard interface is critical to people with various types of disabilities. However, modern websites often violate web accessibility guidelines for keyboard navigability with respect to web dialogs. In this paper, we present a novel approach for automatically detecting web accessibility bugs that prevent or hinder keyboard users' ability to navigate dialogs in web pages. An extensive evaluation of our technique on real-world subjects showed that our technique is effective in detecting these dialog-related keyboard navigation failures. Paul T. Chiou, Ali Alotaibi, William G. J. Halfond |
ICSE | 3 |
| 2023 | A Component-Sensitive Static Analysis Based Approach for Modeling Intents in Android AppsabstractThe Android Inter Component Communication (ICC) model plays an important role in providing users with a wide range of features both within and across apps. Accurate information about ICCs is important for a range of program analysis-based security and verification techniques. These techniques use static analysis to infer links between Android components in bundles of apps and then identify potential security problems with these communications. However, existing ICC analyses have limitations in terms of their accuracy when Intents are constructed using ICC information. To address these limitations, we introduce a multi-level component-sensitive static analysis technique to efficiently and accurately compute ICC information in these scenarios. We compared our approach with state of the art ICC analysis techniques and found that our approach is more accurate and has a faster execution time. Negarsadat Abolhassani, William G. J. Halfond |
ICSME | 2 |
| 2023 | ScaleFix: An Automated Repair of UI Scaling Accessibility Issues in Android ApplicationsabstractMany people with disabilities often struggle to interact with small UI content or comprehend small text displayed on mobile app user interfaces (UIs). To overcome these difficulties, they rely on scaling assistive services to adjust and increase the size of UI content. Unfortunately, recent studies have shown that a large number of mobile apps are not compatible with these services, leading to inconsistencies that can distort the layout of the UIs of these apps. These distortions make it even more troublesome for people with disabilities to use these mobile apps, which defeats the purpose of these scaling assistive services. Existing techniques are limited in terms of repairing these issues. In this paper, we present ScaleFix, a novel approach to automatically repair UI scaling accessibility issues in mobile apps. ScaleFix is the first-ever technique to repair such issues. The evaluation of ScaleFix on real-world Android apps demonstrated its ability to effectively repair UI scaling accessibility issues. Additionally, in a user study with individuals affected by these issues, the results demonstrated that ScaleFix was able to improve the accessibility of mobile UIs without negatively impacting the readability or aesthetics of the UI. Ali Alotaibi, Paul T. Chiou, Fazle M. Tawsif, William G. J. Halfond |
ICSME | 4 |
| 2023 | Automatically Reproducing Android Bug Reports using Natural Language Processing and Reinforcement LearningabstractAs part of the process of resolving issues submitted by users via bug reports, Android developers attempt to reproduce and observe the crashes described by the bug reports. Due to the low-quality of bug reports and the complexity of modern apps, the reproduction process is non-trivial and time-consuming. Therefore, automatic approaches that can help reproduce Android bug reports are in great need. However, current approaches to help developers automatically reproduce bug reports are only able to handle limited forms of natural language text and struggle to successfully reproduce crashes for which the initial bug report had missing or imprecise steps. In this paper, we introduce a new fully automated approach to reproduce crashes from Android bug reports that addresses these limitations. Our approach accomplishes this by leveraging natural language processing techniques to more holistically and accurately analyze the natural language in Android bug reports and designing new techniques, based on reinforcement learning, to guide the search for successful reproducing steps. We conducted an empirical evaluation of our approach on 77 real world bug reports. Our approach achieved 67% precision and 77% recall in accurately extracting reproduction steps from bug reports, reproduced 74% of the total bug reports, and reproduced 64% of the bug reports that contained missing steps, significantly outperforming state of the art techniques. Robert Winn, Yu Zhao 0010, Tingting Yu 0001, William G. J. Halfond |
ISSTA | 5 |
| 2022 | Static Analysis for Automated Identification of Valid Game Actions During ExplorationabstractAutomated exploration has many important applications for testing and analysis of games. Techniques for automated exploration require the capability of identifying the set of available user actions at a given game state, then performing the action selected by the exploration logic. This has been traditionally supported by having the game developer provide an API for this purpose or randomly guessing inputs. In this paper we develop a program analysis based technique for performing an automated analysis of the input-handling logic of the game code, then using this information to provide the set of player actions available at a game state (as well as the device inputs that should be simulated to perform a chosen action). We focus on developing such a technique for games built with the Unity game engine. We implemented an automatic exploration tool based on our technique and evaluated its state exploration performance for six open-source Unity games. We found that our approach is competitive with manually specified actions and is fast enough to play the games in real time. Sasha Volokh, William G. J. Halfond |
FDG | 2 |
| 2022 | Automated Detection of TalkBack Interactive Accessibility Failures in Android ApplicationsabstractTalkBack is one of the most popular screen readers for the 304 million visually impaired users worldwide to access Android devices. Yet, many popular Android apps lack a proper TalkBack accessible mechanism, which could cause failures that make apps unusable. Existing accessibility related techniques are limited in terms of detecting these issues. In this paper, we present a novel approach for automatically detecting TalkBack interactive accessibility failures that prevent TalkBack users from interacting with core functionalities in Android apps. Our evaluation of our technique on real-world Android apps showed that it is able to detect these TalkBack accessibility failures with high precision and recall. Ali Alotaibi, Paul T. Chiou, William G. J. Halfond |
ICST | 3 |
| 2022 | ReCDroid+: Automated End-to-End Crash Reproduction from Bug Reports for Android AppsabstractThe large demand of mobile devices creates significant concerns about the quality of mobile applications (apps). Developers heavily rely on bug reports in issue tracking systems to reproduce failures (e.g., crashes). However, the process of crash reproduction is often manually done by developers, making the resolution of bugs inefficient, especially given that bug reports are often written in natural language. To improve the productivity of developers in resolving bug reports, in this paper, we introduce a novel approach, called ReCDroid+, that can automatically reproduce crashes from bug reports for Android apps. ReCDroid+ uses a combination of natural language processing (NLP) , deep learning, and dynamic GUI exploration to synthesize event sequences with the goal of reproducing the reported crash. We have evaluated ReCDroid+ on 66 original bug reports from 37 Android apps. The results show that ReCDroid+ successfully reproduced 42 crashes (63.6% success rate) directly from the textual description of the manually reproduced bug reports. A user study involving 12 participants demonstrates that ReCDroid+ can improve the productivity of developers when resolving crash bug reports. Yu Zhao 0010, Ting Su 0001, Yang Liu 0003, Wei Zheng 0006, Xiaoxue Wu 0001, Ramakanth Kavuluru, William G. J. Halfond, Tingting Yu 0001 |
ACM Trans. Softw. Eng. Methodol. | 7 |
| 2021 | SAND: a static analysis approach for detecting SQL antipatternsabstractLocal databases underpin important features in many mobile applications, such as responsiveness in the face of poor connectivity. However, failure to use such databases correctly can lead to high resource consumption or even security vulnerabilities. We present SAND, an extensible static analysis approach that checks for misuse of local databases, also known as SQL antipatterns, in mobile apps. SAND features novel abstractions for common forms of application/database interactions, which enables concise and precise specification of the antipatterns that SAND checks for. To validate the efficacy of SAND, we have experimented with a diverse suite of 1,000 Android apps. We show that the abstractions that power SAND allow concise specification of all the known antipatterns from the literature (12-74 LOC), and that the antipatterns are modeled accurately (99.4-100% precision). As for performance, SAND requires on average 41 seconds to complete a scan on a mobile app. Yingjun Lyu, Sasha Volokh, William G. J. Halfond, Omer Tripp |
ISSTA | 3 |
| 2021 | Automated Repair of Size-Based Inaccessibility Issues in Mobile ApplicationsabstractAn increasing number of people are dependent on mobile devices to access data and complete essential tasks. For people with disabilities, mobile apps that violate accessibility guidelines can prevent them from carrying out these activities. Size-Based Inaccessibility is one of the top accessibility issues in mobile applications. These issues make apps difficult to use, especially for older people and people with motor disabilities. Existing accessibility related techniques are limited in terms of helping developers to resolve these issues. In this paper, we present our novel automated approach for repairing Size-Based Inaccessibility issues in mobile applications. Our empirical evaluation showed that our approach was able to successfully resolve 99% of the reported Size-Based Inaccessibility issues and received a high approval rating in a user study of the appearance of the repaired user interfaces. Ali Alotaibi, Paul T. Chiou, William G. J. Halfond |
ASE | 3 |
| 2021 | Detecting and localizing keyboard accessibility failures in web applicationsabstractThe keyboard is the most universally supported input method operable by people with disabilities. Yet, many popular websites lack keyboard accessible mechanism, which could cause failures that make the website unusable. In this paper, we present a novel approach for automatically detecting and localizing keyboard accessibility failures in web applications. Our extensive evaluation of our technique on real world web pages showed that our technique was able to detect keyboard failures in web applications with high precision and recall and was able to accurately identify the underlying elements in the web pages that led to the observed problems. Paul T. Chiou, Ali Alotaibi, William G. J. Halfond |
ESEC/SIGSOFT FSE | 3 |
| 2021 | Effective automated repair of internationalization presentation failures in web applications using style similarity clustering and search-based techniquesabstractSummary Companies often employ (i18n) frameworks to provide translated text and localized media content on their websites in order to effectively communicate with a global audience. However, the varying lengths of text from different languages can cause undesired distortions in the layout of a web page. Such distortions, called Internationalization Presentation Failures (IPFs), can negatively affect the aesthetics or usability of the website. Most of the existing automated techniques developed for assisting repair of IPFs either produce fixes that are likely to significantly reduce the legibility and attractiveness of the pages or are limited to only detecting IPFs, with the actual repair itself remaining a labour intensive manual task. To address this problem, we propose a search‐based technique for automatically repairing IPFs in web applications, while ensuring a legible and attractive page. The empirical evaluation of our approach reported that our approach was able to successfully resolve 94% of the detected IPFs for 46 real‐world web pages. In a user study, participants rated the visual quality of our fixes significantly higher than the unfixed versions and also considered the repairs generated by our approach to be notably more legible and visually appealing than the repairs generated by existing techniques. Sonal Mahajan, Abdulmajeed Alameer, Phil McMinn, William G. J. Halfond |
Softw. Test. Verification Reliab. | 4 |
| 2020 | Mobile App Energy Consumption: A Study of Known Energy Issues in Mobile Applications and their Classification Schemes - Summary PlanabstractWork in Mobile App Energy Consumption (MAEC) has drawn participants from a broad range of communities such as systems, networking, hardware, testing, analysis and design. This diversity has enriched and informed the research from many different angles. For example, knowledge about the physical properties of batteries (e.g., that their performance is temperature dependent) is necessary to control for con-founding variables during experiments. However, it has also led to a confusing and conflicting mix of terms, names, and expressions as researchers from different domains each attempt to apply their existing terminology or invent new terms to describe various kinds of energy related issues. Ali Alotaibi, James Clause, William G. J. Halfond |
ICSME | 3 |
| 2019 | ReCDroid: automatically reproducing Android application crashes from bug reportsabstractThe large demand of mobile devices creates significant concerns about the quality of mobile applications (apps). Developers heavily rely on bug reports in issue tracking systems to reproduce failures (e.g., crashes). However, the process of crash reproduction is often manually done by developers, making the resolution of bugs inefficient, especially that bug reports are often written in natural language. To improve the productivity of developers in resolving bug reports, in this paper, we introduce a novel approach, called ReCDroid, that can automatically reproduce crashes from bug reports for Android apps. ReCDroid uses a combination of natural language processing (NLP) and dynamic GUI exploration to synthesize event sequences with the goal of reproducing the reported crash. We have evaluated ReCDroid on 51 original bug reports from 33 Android apps. The results show that ReCDroid successfully reproduced 33 crashes (63.5% success rate) directly from the textual description of bug reports. A user study involving 12 participants demonstrates that ReCDroid can improve the productivity of developers when resolving crash bug reports. Yu Zhao 0010, Tingting Yu 0001, Ting Su 0001, Yang Liu 0003, Wei Zheng 0006, Jingzhi Zhang, William G. J. Halfond |
ICSE | 7 |
| 2019 | Quantifying the Performance Impact of SQL Antipatterns on Mobile ApplicationsabstractIn mobile applications, local databases have become an important component, providing mobile users with a responsive and secure service for data access and management. However, using local databases comes with a cost. Studies have shown that they are one of the most resource consuming components on mobile devices. Improper usage of the local database can even severely impact the responsiveness of an application. In this paper, we conducted a literature review and a benchmark study to investigate problematic programming practices with respect to database usage. Our results present a comprehensive overview of the current knowledge about these practices, and introduce new knowledge about the impact of these practices on the resource consumption of mobile applications. Yingjun Lyu, Ali Alotaibi, William G. J. Halfond |
ICSME | 3 |
| 2019 | An Empirical Study of UI Implementations in Android ApplicationsabstractMobile app developers are able to design sophisticated user interfaces (UIs) that can improve a user's experience and contribute to an app's success. Developers invest in automated UI testing techniques, such as crawlers, to ensure that their app's UIs have a high level of quality. However, UI implementation mechanisms have changed significantly due to the availability of new APIs and mechanisms, such as fragments. In this paper, we study a large set of real-world apps to identify whether the mechanisms developers use to implement app UIs cause problems for those automated techniques. In addition, we examined the changes in these practices over time. Our results indicate that dynamic analyses face challenges in terms of completeness and changing development practices motivate the use of additional analyses, such as static analyses. We also discuss the implications of our results for current testing techniques and the design of new analyses. Mian Wan, Negarsadat Abolhassani, Ali Alotaibi, William G. J. Halfond |
ICSME | 4 |
| 2019 | Efficiently Repairing Internationalization Presentation Failures by Solving Layout ConstraintsabstractWeb developers employ internationalization frameworks to automate web page translations and enable their web apps to more easily communicate with a global audience. However, the change of text size in different languages can lead to distortions in the translated web page's layout. These distortions are known as Internationalization Presentation Failures (IPFs). Debugging these IPFs can be a tedious and error-prone process. Previous research efforts to develop an automatic IPF repair technique could compromise the attractiveness and readability of the repaired web page. In this paper, we present a novel approach that can rapidly repair IPFs and maintain the readability and the attractiveness of the web page. Our approach models the correct layout of a web page as a system of constraints. The solution to the system represents the new and correct layout of the web page that resolves its IPFs. In the evaluation, we found that our approach could more quickly produce repairs that were rated as more attractive and more readable than those produced by a prior state-of-the-art technique. Abdulmajeed Alameer, Paul T. Chiou, William G. J. Halfond |
ICST | 3 |
| 2019 | A New Method for Software Test Data Generation Inspired by D-algorithmabstractTest generation for digital hardware is highly automated, scalable (in practice), and provides high test quality. In contrast, current software automatic test data generation approaches suffer from low test quality or high complexity. While mutation-oriented constraint-based test data generation for software was proposed to generate high quality test data for real program bugs, all existing approaches require symbolic analysis for the whole program, and hence are not scalable even for unit testing, i.e., testing the lowest-level software modules. We propose a new method inspired by hardware D-algorithm and divide and conquer for software test data generation. To reduce runtime complexity and improve scalability, we combine global structural analysis and a sequence of small reusable symbolic analyses of parts of the program, instead of symbolically executing each mutated version of the entire program. We also propose a multi-pass test generation system to further reduce runtime complexity and compact test data. We compare our tools with one of the best software test generation tools (EvoSuite[20], which won the SBST 2017 tool competition) and demonstrate that our approach generates higher quality unit tests in a scalable manner and provides a compact set of tests. Sandeep Gupta 0001, William G. J. Halfond |
VTS | 3 |
| 2018 | Automated repair of mobile friendly problems in web pagesabstractMobile devices have become a primary means of accessing the Internet. Unfortunately, many websites are not designed to be mobile friendly. This results in problems such as unreadable text, cluttered navigation, and content overflowing a device's viewport; all of which can lead to a frustrating and poor user experience. Existing techniques are limited in helping developers repair these mobile friendly problems. To address this limitation of prior work, we designed a novel automated approach for repairing mobile friendly problems in web pages. Our empirical evaluation showed that our approach was able to successfully resolve mobile friendly problems in 95% of the evaluation subjects. In a user study, participants preferred our repaired versions of the subjects and also considered the repaired pages to be more readable than the originals. Sonal Mahajan, Negarsadat Abolhassani, Phil McMinn, William G. J. Halfond |
ICSE | 4 |
| 2018 | Automated Repair of Internationalization Presentation Failures in Web Pages Using Style Similarity Clustering and Search-Based Techniques
Sonal Mahajan, Abdulmajeed Alameer, Phil McMinn, William G. J. Halfond |
ICST | 4 |
| 2018 | Remove RATs from your code: automated optimization of resource inefficient database writes for mobile applicationsabstractDevelopers strive to build feature-filled apps that are responsive and consume as few resources as possible. Most of these apps make use of local databases to store and access data locally. Prior work has found that local database services have become one of the major drivers of a mobile device's resource consumption. In this paper we propose an approach to reduce the energy consumption and improve runtime performance of database operations in Android apps by optimizing inefficient database writes. Our approach automatically detects database writes that happen within loops and that will trigger inefficient autocommit behaviors. Our approach then uses additional analyses to identify those that are optimizable and rewrites the code so that it is more efficient. We evaluated our approach on a set of marketplace Android apps and found it could reduce the energy and runtime of events containing the inefficient database writes by 25% to 90% and needed, on average, thirty-six seconds to analyze and transform each app. Yingjun Lyu, Ding Li 0001, William G. J. Halfond |
ISSTA | 3 |
| 2017 | An Empirical Study of Local Database Usage in Android ApplicationsabstractLocal databases have become an important component within mobile applications. Developers use local databases to provide mobile users with a responsive and secure service for data storage and access. However, using local databases comes with a cost. Studies have shown that they are one of the most energy consuming components on mobile devices and misuseof their APIs can lead to performance and security problems. In this paper, we report the results of a large scale empirical study on 1,000 top ranked apps from the Google Play app store. Our results present a detailed look into the practices, costs, and potential problems associated with local database usage in deployed apps. We distill our findings into actionable guidance for developers and motivate future areas of research related to techniques to support mobile app developers. Yingjun Lyu, Jiaping Gui, Mian Wan, William G. J. Halfond |
ICSME | 4 |
| 2017 | Automated repair of layout cross browser issues using search-based techniquesabstractA consistent cross-browser user experience is crucial for the success of a website. Layout Cross Browser Issues (XBIs) can severely undermine a website’s success by causing web pages to render incorrectly in certain browsers, thereby negatively impacting users’ impression of the quality and services that the web page delivers. Existing Cross Browser Testing (XBT) techniques can only detect XBIs in websites. Repairing them is, hitherto, a manual task that is labor intensive and requires significant expertise. Addressing this concern, our paper proposes a technique for automatically repairing layout XBIs in websites using guided search-based techniques. Our empirical evaluation showed that our approach was able to successfully fix 86% of layout XBIs reported for 15 different web pages studied, thereby improving their cross-browser consistency. Sonal Mahajan, Abdulmajeed Alameer, Phil McMinn, William G. J. Halfond |
ISSTA | 4 |
| 2017 | XFix: an automated tool for the repair of layout cross browser issuesabstractDifferences in the rendering of a website across different browsers can cause inconsistencies in its appearance and usability, resulting in Layout Cross Browser Issues (XBIs). Such XBIs can negatively impact the functionality of a website as well as users’ impressions of its trustworthiness and reliability. Existing techniques can only detect XBIs, and therefore require developers to manually perform the labor intensive task of repair. In this demo paper we introduce our tool, XFix, that automatically repairs layout XBIs in web applications. To the best of our knowledge, XFix is the first automated technique for generating XBI repairs. Sonal Mahajan, Abdulmajeed Alameer, Phil McMinn, William G. J. Halfond |
ISSTA | 4 |
| 2017 | Detecting display energy hotspots in Android appsabstractSummary The energy consumption of mobile apps has become an important consideration for developers as the underlying mobile devices are constrained by battery capacity. Display represents a significant portion of an app's energy consumption—up to 60% of an app's total energy consumption. However, developers lack techniques to identify the user interfaces in their apps for which energy needs to be improved. This paper presents a technique for detecting display energy hotspots—user interfaces of a mobile app whose energy consumption is greater than optimal. The technique leverages display power modeling and automated display transformation techniques to detect these hotspots and prioritize them for developers. The evaluation of the technique shows that it can predict display energy consumption to within 14% of the ground truth and accurately rank display energy hotspots. Furthermore, the approach found 398 display energy hotspots in a set of 962 popular Android apps, showing the pervasiveness of this problem. For these detected hotspots, the average power savings that could be realized through better user interface design was 30%. Taken together, these results indicate that the approach represents a potentially impactful technique for helping developers to detect energy related problems and reduce the energy consumption of their mobile apps. Mian Wan, Ding Li 0001, Jiaping Gui, Sonal Mahajan, William G. J. Halfond |
Softw. Test. Verification Reliab. | 6 |
| 2016 | Detecting and Localizing Visual Inconsistencies in Web ApplicationsabstractFailures in the presentation layer of a web application can negatively impact its usability and end users' perception of the application's quality. The problem of verifying the consistency of a web application's user interface across its different pages is one of the many challenges that software development teams face in testing the presentation layer. In this paper we propose a novel automated approach to detect and localize visual inconsistencies in web applications. To detect visual inconsistencies, our approach uses computer vision techniques to compare a test web page with its reference. Then to localize, our approach analyzes the structure and style of the underlying HTML elements to find the faulty elements responsible for the observed inconsistencies. Sonal Mahajan, Krupa Benhur Gadde, Anjaneyulu Pasala, William G. J. Halfond |
APSEC | 4 |
| 2016 | Automated energy optimization of HTTP requests for mobile applicationsabstractEnergy is a critical resource for apps that run on mobile devices. Among all operations, making HTTP requests is one of the most energy consuming. Previous studies have shown that bundling smaller HTTP requests into a single larger HTTP request can be an effective way to improve energy efficiency of network communication, but have not defined an automated way to detect when apps can be bundled nor to transform the apps to do this bundling. In this paper we propose an approach to reduce the energy consumption of HTTP requests in Android apps by automatically detecting and then bundling multiple HTTP requests. Our approach first detects HTTP requests that can be bundled using static analysis, then uses a proxy based technique to bundle HTTP requests at runtime. We evaluated our approach on a set of real world marketplace Android apps. In this evaluation, our approach achieved an average energy reduction of 15% for the subject apps and did not impose a significant runtime overhead on the optimized apps. Ding Li 0001, Yingjun Lyu, Jiaping Gui, William G. J. Halfond |
ICSE | 4 |
| 2016 | An Empirical Study of Internationalization Failures in the WebabstractWeb application internationalization frameworks allow businesses to more easily market and sell their products and services around the world. However, internationalization can lead to problems. Text expansion and contraction after translation may result in a distortion of the layout of the translated versions of a webpage, which can reduce their usability and aesthetics. In this paper, we investigate and report on the frequency and severity of different types of failures in webpages' user interfaces that are due to internationalization. In our study, we analyzed 449 real world internationalized webpages. Our results showed that internationalization failures occur frequently and they range significantly in terms of severity and impact on the web applications. These findings motivate and guide future work in this area. Abdulmajeed Alameer, William G. J. Halfond |
ICSME | 2 |
| 2016 | Detecting and Localizing Internationalization Presentation Failures in Web ApplicationsabstractWeb applications can be easily made available to an international audience by leveraging frameworks and tools for automatic translation and localization. However, these automated changes can distort the appearance of web applications since it is challenging for developers to design their websites to accommodate the expansion and contraction of text after it is translated to another language. Existing web testing techniques do not support developers in checking for these types of problems and manually checking every page in every language can be a labor intensive and error prone task. To address this problem, we introduce an automated technique for detecting when a web page's appearance has been distorted due to internationalization efforts and identifying the HTML elements or text responsible for the observed problem. In evaluation, our approach was able to detect internationalization problems in a set of 54 web applications with high precision and recall and was able to accurately identify the underlying elements in the web pages that led to the observed problem. Abdulmajeed Alameer, Sonal Mahajan, William G. J. Halfond |
ICST | 3 |
| 2016 | Using Visual Symptoms for Debugging Presentation Failures in Web ApplicationsabstractPresentation failures in a website can undermine its success by giving users a negative perception of the trustworthiness of the site and the quality of the services it delivers. Unfortunately, existing techniques for debugging presentation failures do not provide developers with automated and broadly applicable solutions for finding the site's faulty HTML elements and CSS properties. To address this limitation, we propose a novel automated approach for debugging web sites that is based on image processing and probabilistic techniques. Our approach first builds a model that links observable changes in the web site's appearance to faulty elements and styling properties. Then using this model, our approach predicts the elements and styling properties most likely to cause the observed failure for the page under test and reports these to the developer. In evaluation, our approach was more accurate and faster than prior techniques for identifying faulty elements in a website. Sonal Mahajan, Bailan Li, Pooyan Behnamghader, William G. J. Halfond |
ICST | 4 |
| 2016 | How does code obfuscation impact energy usage?abstractAbstract Software piracy is an important concern for application developers. Such concerns are especially relevant in mobile application development, where piracy rates can be greater than 90%. The most common approach used by mobile developers to prevent piracy is code obfuscation. However, the decision to apply such transformations is currently made without regard to the impacts of obfuscations on another area of increasing concern for mobile application developers, energy usage. Because both software piracy and battery life are important concerns, mobile application developers must strike a balance between protecting their applications and preserving the battery lives of their users' devices. To help them make such choices, we conducted an empirical study of the effects of 18 code obfuscations on the amount of energy consumed by executing a total of 21 usage scenarios spread across 11 Android applications on four different mobile phone platforms. The results of the study indicate that, while obfuscations can have a statistically significant impact on energy usage and are more likely to increase energy usage than to decrease energy usage, the magnitudes of such impacts are unlikely to be meaningful to mobile application users. Copyright © 2016 John Wiley & Sons, Ltd. Cagri Sahin, Mian Wan, Philip Tornquist, Ryan McKenna, Zachary Pearson, William G. J. Halfond, James Clause |
J. Softw. Evol. Process. | 6 |
| 2015 | Truth in Advertising: The Hidden Cost of Mobile Ads for Software DevelopersabstractThe "free app" distribution model has been extremely popular with end users and developers. Developers use mobile ads to generate revenue and cover the cost of developing these free apps. Although the apps are ostensibly free, they in fact do come with hidden costs. Our study of 21 real world Android apps shows that the use of ads leads to mobile apps that consume significantly more network data, have increased energy consumption, and require repeated changes to ad related code. We also found that complaints about these hidden costs are significant and can impact the ratings given to an app. Our results provide actionable information and guidance to software developers in weighing the tradeoffs of incorporating ads into their mobile apps. Jiaping Gui, Stuart McIlroy, Meiyappan Nagappan, William G. J. Halfond |
ICSE (1) | 4 |
| 2015 | Detection and Localization of HTML Presentation Failures Using Computer Vision-Based TechniquesabstractAn attractive and visually appealing appearance is important for the success of a website. Presentation failures in a site''s web pages can negatively impact end users'' perception of the quality of the site and the services it delivers. Debugging such failures is challenging because testers must visually inspect large web pages and analyze complex interactions among the HTML elements of a page. In this paper we propose a novel automated approach for debugging web page user interfaces. Our approach uses computer vision techniques to detect failures and can then identify HTML elements that are likely to be responsible for the failure. We evaluated our approach on a set of real-world web applications and found that the approach was able to accurately and quickly identify faulty HTML elements. Sonal Mahajan, William G. J. Halfond |
ICST | 2 |
| 2015 | WebSee: A Tool for Debugging HTML Presentation FailuresabstractPresentation failures in a website can negatively impact end users' perception of the quality of the website, the services it delivers, and the branding a company is trying to achieve. Presentation failures can occur easily in modern web applications because of the highly complex and dynamic nature of the HTML, CSS, and JavaScript that define a web page's visual appearance. Debugging such failures manually is time consuming and error-prone, and existing techniques do not provide an automated debugging solution. In this paper, we present our tool, WebSee, that provides a fully automated debugging solution for presentation failures in web applications. When run on real-world web applications, WebSee was able to accurately and quickly identify faulty HTML elements. Sonal Mahajan, William G. J. Halfond |
ICST | 2 |
| 2015 | Detecting Display Energy Hotspots in Android AppsabstractEnergy consumption of mobile apps has become an important consideration as the underlying devices are constrained by battery capacity. Display represents a significant portion of an app's energy consumption. However, developers lack techniques to identify the user interfaces in their apps for which energy needs to be improved. In this paper, we present a technique for detecting display energy hotspots - user interfaces of a mobile app whose energy consumption is greater than optimal. Our technique leverages display power modeling and automated display transformation techniques to detect these hotspots and prioritize them for developers. In an evaluation on a set of popular Android apps, our technique was very accurate in both predicting energy consumption and ranking the display energy hotspots. Our approach was also able to detect display energy hotspots in 398 Android market apps, showing its effectiveness and the pervasiveness of the problem. These results indicate that our approach represents a potentially useful technique for helping developers to detect energy related problems and reduce the energy consumption of their mobile apps. Mian Wan, Ding Li 0001, William G. J. Halfond |
ICST | 4 |
| 2015 | Identifying Inter-Component Control Flow in Web Applications
William G. J. Halfond |
ICWE | 1 |
| 2015 | String analysis for Java and Android applicationsabstractString analysis is critical for many verification techniques. However, accurately modeling string variables is a challeng- ing problem. Current approaches are generally customized for certain problem domains or have critical limitations in handling loops, providing context-sensitive inter-procedural analysis, and performing efficient analysis on complicated apps. To address these limitations, we propose a general framework, Violist, for string analysis that allows researchers to more flexibly choose how they will address each of these challenges by separating the representation and interpreta- tion of string operations. In our evaluation, we show that our approach can achieve high accuracy on both Java and Android apps in a reasonable amount of time. We also com- pared our approach with a popular and widely used string analyzer and found that our approach has higher precision and shorter execution time while maintaining the same level of recall. Ding Li 0001, Yingjun Lyu, Mian Wan, William G. J. Halfond |
ESEC/SIGSOFT FSE | 4 |
| 2015 | Nyx: a display energy optimizer for mobile web appsabstractEnergy is a critical resource for current mobile devices. In a smartphone, display is one of the most energy consuming components. Modern smartphones often use OLED screens, which consume much more energy when displaying light colors than displaying dark colors. In our previous study, we proposed a technique to reduce display energy of mo- bile web apps by changing the color scheme automatically. With this approach, we achieved a 40% reduction in display power consumption and 97% user acceptance of the new color scheme. In this tool paper, we describe Nyx, which implements our approach. Nyx is implemented as a self- contained executable file with which users can optimize en- ergy consumption of their web apps with a simple command. Ding Li 0001, Angelica Huyen Tran, William G. J. Halfond |
ESEC/SIGSOFT FSE | 3 |
| 2015 | Detecting event anomalies in event-based systemsabstractEvent-based interaction is an attractive paradigm because its use can lead to highly flexible and adaptable systems. One problem in this paradigm is that events are sent, received, and processed nondeterministically, due to the systems’ reliance on implicit invocation and implicit concurrency. This nondeterminism can lead to event anomalies, which occur when an event-based system receives multiple events that lead to the write of a shared field or memory location. Event anomalies can lead to unreliable, error-prone, and hard to debug behavior in an event-based system. To detect these anomalies, this paper presents a new static analysis technique, DEvA, for automatically detecting event anomalies. DEvA has been evaluated on a set of open-source event-based systems against a state-of-the-art technique for detecting data races in multithreaded systems, and a recent technique for solving a similar problem with event processing in Android applications. DEvA exhibited high precision with respect to manually constructed ground truths, and was able to locate event anomalies that had not been detected by the existing solutions. Gholamreza Safi, Arman Shahbazian, William G. J. Halfond, Nenad Medvidovic |
ESEC/SIGSOFT FSE | 3 |
| 2014 | Making web applications more energy efficient for OLED smartphonesabstractA smartphone’s display is one of its most energy consuming components. Modern smartphones use OLED displays that consume more energy when displaying light colors as op- posed to dark colors. This is problematic as many popular mobile web applications use large light colored backgrounds. To address this problem we developed an approach for auto- matically rewriting web applications so that they generate more energy efficient web pages. Our approach is based on program analysis of the structure of the web application im- plementation. In the evaluation of our approach we show that it can achieve a 40% reduction in display power con- sumption. A user study indicates that the transformed web pages are acceptable to users with over 60% choosing to use the transformed pages for normal usage. Ding Li 0001, Angelica Huyen Tran, William G. J. Halfond |
ICSE | 3 |
| 2014 | An Empirical Study of the Energy Consumption of Android ApplicationsabstractEnergy is a critical resource for smartphones. However, developers who create apps for these platforms lack quantitative and objective information about the behavior of apps with respect to energy consumption. In this paper, we describe the results of our source-line level energy consumption study of 405 real-world market applications. Based on our study, we discover several interesting observations. For example, we find on average apps spend 61% of their energy in idle states, network is the most energy consuming component, and only a few APIs dominate non-idle energy consumption. The results of this study provide developers with objective information about how energy is consumed by a broad sample of mobile applications and can guide them in their efforts of improving the energy efficiency of their applications. Ding Li 0001, Shuai Hao 0002, Jiaping Gui, William G. J. Halfond |
ICSME | 4 |
| 2014 | Integrated energy-directed test suite optimizationabstractIn situ testing techniques have become an important means of ensuring the reliability of embedded systems after they are deployed in the field. However, these techniques do not help testers optimize the energy consumption of their in situ test suites, which can needlessly waste the limited battery power of these systems. In this work, we extend prior techniques for test suite minimization in such a way as to allow testers to generate energy-efficient, minimized test suites with only minimal modifications to their existing work flow. We perform an extensive empirical evaluation of our approach using the test suites provided for real world applications. The results of the evaluation show that our technique is effective at generating, in less than one second, test suites that consume up to 95% less energy while maintaining coverage of the testing requirements. Ding Li 0001, Cagri Sahin, James Clause, William G. J. Halfond |
ISSTA | 5 |
| 2014 | Finding HTML presentation failures using image comparison techniquesabstractPresentation failures in web applications can negatively affect an application's usability and user experience. To find such failures, testers must visually inspect the output of a web application or exhaustively specify invariants to automatically check a page's correctness. This makes finding presentation failures labor intensive and error prone. In this paper, we present a new automated approach for detecting and localizing presentation failures in web pages. To detect presentation failures, our approach uses image processing techniques to compare a web page and its oracle. Then, to localize the failures, our approach analyzes the page with respect to its visual layout and identifies the HTML elements likely to be responsible for the failure. We evaluated our approach on a set of real-world web applications and found that the approach was able to accurately detect failures and identify the faulty HTML elements. Sonal Mahajan, William G. J. Halfond |
ASE | 2 |
| 2014 | PUMA: programmable UI-automation for large-scale dynamic analysis of mobile appsabstractMobile app ecosystems have experienced tremendous growth in the last six years. This has triggered research on dynamic analysis of performance, security, and correctness properties of the mobile apps in the ecosystem. Exploration of app execution using automated UI actions has emerged as an important tool for this research. However, existing research has largely developed analysis-specific UI automation techniques, wherein the logic for exploring app execution is intertwined with the logic for analyzing app properties. PUMA is a programmable framework that separates these two concerns. It contains a generic UI automation capability (often called a Monkey) that exposes high-level events for which users can define handlers. These handlers can flexibly direct the Monkey's exploration, and also specify app instrumentation for collecting dynamic state information or for triggering changes in the environment during app execution. Targeted towards operators of app marketplaces, PUMA incorporates mechanisms for scaling dynamic analysis to thousands of apps. We demonstrate the capabilities of PUMA by analyzing seven distinct performance, security, and correctness properties for 3,600 apps downloaded from the Google Play store. Shuai Hao 0002, Bin Liu 0004, Suman Nath, William G. J. Halfond, Ramesh Govindan |
MobiSys | 4 |
| 2014 | CARLOG: a platform for flexible and efficient automotive sensingabstractAutomotive apps can improve efficiency, safety, comfort, and longevity of vehicular use. These apps achieve their goals by continuously monitoring sensors in a vehicle, and combining them with information from cloud databases in order to detect events that are used to trigger actions (e.g., alerting a driver, turning on fog lights, screening calls). However, modern vehicles have several hundred sensors that describe the low level dynamics of vehicular subsystems, these sensors can be combined in complex ways together with cloud information. Moreover, these sensor processing algorithms may incur significant costs in acquiring sensor and cloud information. In this paper, we propose a programming framework called CARLOG to simplify the task of programming these event detection algorithms. CARLOG uses Datalog to express sensor processing algorithms, but incorporates novel query optimization methods that can be used to minimize bandwidth usage, energy or latency, without sacrificing correctness of query execution. Experimental results on a prototype show that CARLOG can reduce latency by nearly two orders of magnitude relative to an unoptimized Datalog engine. Yurong Jiang, Hang Qiu 0001, Matthew McCartney, William G. J. Halfond, Fan Bai 0002, Donald Grimm, Ramesh Govindan |
SenSys | 4 |
| 2013 | Estimating mobile application energy consumption using program analysisabstractOptimizing the energy efficiency of mobile applications can greatly increase user satisfaction. However, developers lack viable techniques for estimating the energy consumption of their applications. This paper proposes a new approach that is both lightweight in terms of its developer requirements and provides fine-grained estimates of energy consumption at the code level. It achieves this using a novel combination of program analysis and per-instruction energy modeling. In evaluation, our approach is able to estimate energy consumption to within 10% of the ground truth for a set of mobile applications from the Google Play store. Additionally, it provides useful and meaningful feedback to developers that helps them to understand application energy consumption behavior. Shuai Hao 0002, Ding Li 0001, William G. J. Halfond, Ramesh Govindan |
ICSE | 3 |
| 2013 | Calculating source line level energy information for Android applicationsabstractThe popularity of mobile apps continues to grow as developers take advantage of the sensors and data available on mobile devices. However, the increased functionality comes with a higher energy cost, which can cause a problem for users on battery constrained mobile devices. To improve the energy consumption of mobile apps, developers need detailed information about the energy consumption of their applications. Existing techniques have drawbacks that limit their usefulness or provide information at too high of a level of granularity, such as components or methods. Our approach is able to calculate source line level energy consumption information. It does this by combining hardware-based power measurements with program analysis and statistical modeling. Our empirical evaluation of the approach shows that it is fast and accurate. Ding Li 0001, Shuai Hao 0002, William G. J. Halfond, Ramesh Govindan |
ISSTA | 3 |
| 2013 | Randomizing regression tests using game theoryabstractAs software evolves, the number of test-cases in the regression test suites continues to increase, requiring testers to prioritize their execution. Usually only a subset of the test cases is executed due to limited testing resources. This subset is often known to the developers who may try to “game” the system by committing insufficiently tested code for parts of the software that will not be tested. In this new ideas paper, we propose a novel approach for randomizing regression test scheduling, based on Stackelberg games for deployment of scarce resources. We apply this approach to randomizing test cases in such a way as to maximize the testers' expected payoff when executing the test cases. Our approach accounts for resource limitations (e.g., number of testers) and provides a probabilistic distribution for scheduling test cases. We provide an example application of our approach showcasing the idea of using Stackelberg games for randomized regression test scheduling. Nupul Kukreja, William G. J. Halfond, Milind Tambe |
ASE | 2 |
| 2013 | SIF: a selective instrumentation framework for mobile applicationsabstractMobile app ecosystems have experienced tremendous growth in the last five years. As researchers and developers turn their attention to understanding the ecosystem and its different apps, instrumentation of mobile apps is a much needed emerging capability. In this paper, we explore a selective instrumentation capability that allows users to express instrumentation specifications at a high level of abstraction; these specifications are then used to automatically insert instrumentation into binaries. The challenge in our work is to develop expressive abstractions for instrumentation that can also be implemented efficiently. Designed using requirements derived from recent research that has used instrumented apps, our selective instrumentation framework, SIF, contains abstractions that allow users to compactly express precisely which parts of the app need to be instrumented. It also contains a novel path inspection capability, and provides users feedback on the approximate overhead of the instrumentation specification. Using experiments on our SIF implementation for Android, we show that SIF can be used to compactly (in 20-30 lines of code in most cases) specify instrumentation tasks previously reported in the literature. SIF's overhead is under 2% in most cases, and its instrumentation overhead feedback is within 15% in many cases. As such, we expect that SIF can accelerate studies of the mobile app ecosystem. Shuai Hao 0002, Ding Li 0001, William G. J. Halfond, Ramesh Govindan |
MobiSys | 3 |
| 2013 | Identifying message flow in distributed event-based systemsabstractDistributed event-based (DEB) systems contain highly-decoupled components that interact by exchanging messages. This enables flexible system composition and adaptation, but also makes DEB systems difficult to maintain. Most existing program analysis techniques to support maintenance are not well suited to DEB systems, while those that are tend to suffer from inaccuracy or make assumptions that limit their applicability. This paper presents Eos, a static analysis technique that identifies message information useful for maintaining a DEB system, namely, message types and message flow within a system. Eos has been evaluated on six off-the-shelf DEB systems spanning five different middleware platforms, and has exhibited excellent accuracy and efficiency. Furthermore, a case study involving a range of maintenance activities undertaken on three existing DEB systems shows that, on average, Eos enables an engineer to identify the scope and impact of required changes more accurately than existing alternatives. Joshua Garcia, Daniel Popescu 0001, Gholamreza Safi, William G. J. Halfond, Nenad Medvidovic |
ESEC/SIGSOFT FSE | 4 |
| 2012 | Automated Checking of Web Application InvocationsabstractHTTP based invocations allow web application components to communicate among themselves and build dynamic customized web pages. Invocations are widely used by web applications, but are a common source of errors. Existing techniques are only able to verify limited correctness properties of web application invocations and omit key properties, such as an argument's type and value must match its target parameter's domain. This paper presents the first approach for verifying these correctness properties of web application invocations. An empirical evaluation of the technique shows that it is able to identify, with high precision, over 30% more invocation errors than were previously identified and that the approach has a low analysis runtime cost. William G. J. Halfond |
ISSRE | 1 |
| 2011 | Domain and value checking of web application invocation argumentsabstractInvocations are widely used by many web applications, but have been found to be a common source of errors. This paper presents a new technique that can statically verify that an invocation's set of argument names, types, and request method match the constraints of a target interface. An empirical evaluation of the technique shows that it is successful at identifying previously unknown errors in web applications. William G. J. Halfond |
ASE | 1 |
| 2011 | Improving penetration testing through static and dynamic analysisabstractAbstract Penetration testing is widely used to help ensure the security of web applications. Using penetration testing, testers discover vulnerabilities by simulating attacks on a target web application. To do this efficiently, testers rely on automated techniques that gather input vector information about the target web application and analyze the application's responses to determine whether an attack was successful. Techniques for performing these steps are often incomplete, which can leave parts of the web application untested and vulnerabilities undiscovered. This paper proposes a new approach to penetration testing that addresses the limitations of current techniques. The approach incorporates two recently developed analysis techniques to improve input vector identification and detect when attacks have been successful against a web application. This paper compares the proposed approach against two popular penetration testing tools for a suite of web applications with known and unknown vulnerabilities. The evaluation results show that the proposed approach performs a more thorough penetration testing and leads to the discovery of more vulnerabilities than both the tools. Copyright © 2011 John Wiley & Sons, Ltd. William G. J. Halfond, Shauvik Roy Choudhary, Alessandro Orso |
Softw. Test. Verification Reliab. | 1 |
| 2009 | Penetration Testing with Improved Input Vector IdentificationabstractPenetration testing is widely used to help ensure the security of web applications. It discovers vulnerabilities by simulating attacks from malicious users on a target application. Identifying the input vectors of a Web application and checking the results of an attack are important parts of penetration testing, as they indicate where an attack could be introduced and whether an attempted attack was successful. Current techniques for identifying input vectors and checking attack results are typically ad-hoc and incomplete, which can cause parts of an application to be untested and leave vulnerabilities undiscovered. In this paper, we propose a new approach to penetration testing that addresses these limitations by leveraging two recently-developed analysis techniques. The first is used to identify a web application's possible input vectors, and the second is used to automatically check whether an attack resulted in an injection. To empirically evaluate our approach, we compare it against a state-of-the-art, alternative technique. Our results show that our approach performs a more thorough penetration testing and leads to the discovery of more vulnerabilities. William G. J. Halfond, Shauvik Roy Choudhary, Alessandro Orso |
ICST | 1 |
| 2009 | Precise interface identification to improve testing and analysis of web applicationsabstractAs web applications become more widespread, sophisticated, and complex, automated quality assurance techniques for such applications have grown in importance. Accurate interface identification is fundamental for many of these techniques, as the components of a web application communicate extensively via implicitly-defined interfaces to generate customized and dynamic content. However, current techniques for identifying web application interfaces can be incomplete or imprecise, which hinders the effectiveness of quality assurance techniques. To address these limitations, we present a new approach for identifying web application interfaces that is based on a specialized form of symbolic execution. In our empirical evaluation, we show that the set of interfaces identified by our approach is more accurate than those identified by other approaches. We also show that this increased accuracy leads to improvements in several important quality assurance techniques for web applications: test-input generation, penetration testing, and invocation verification. William G. J. Halfond, Saswat Anand, Alessandro Orso |
ISSTA | 1 |
| 2008 | Automated identification of parameter mismatches in web applicationsabstractQuality assurance techniques for web applications have be-come increasingly important as web applications have gained in popularity and become an essential part of our daily lives. To integrate content and data from multiple sources, the components of a web application communicate exten-sively among themselves. Unlike traditional program mod-ules, the components communicate through interfaces and invocations that are not explicitly declared. Because of this, the communication between two components can fail due to a parameter mismatch between the interface invoked by a calling component and the interface provided by the called component. Parameter mismatches can cause serious errors in the web application and are difficult to identify using tra-ditional testing and verification techniques. To address this problem, we propose a static-analysis based approach for identifying parameter mismatches. We also present an em-pirical evaluation of the approach, which we performed on a set of real web applications. The results of the evalua-tion are promising; our approach discovered 133 parameter mismatches in the subject applications. William G. J. Halfond, Alessandro Orso |
SIGSOFT FSE | 1 |
| 2008 | WASP: Protecting Web Applications Using Positive Tainting and Syntax-Aware EvaluationabstractMany software systems have evolved to include a web-based component that makes them available to the public via the Internet and can expose them to a variety of web-based attacks. One of these attacks is SQL injection, which can give attackers unrestricted access to the databases underlying web applications and has become increasingly frequent and serious. This paper presents a new, highly automated approach for protecting web applications against SQL injection that has both conceptual and practical advantages over most existing techniques. From a conceptual standpoint, the approach is based on the novel idea of positive tainting and on the concept of syntax-aware evaluation. From a practical standpoint, our technique is precise and efficient and has minimal deployment requirements. We also present an extensive empirical evaluation of our approach performed using WASP, a tool that implements our technique. In the evaluation, we used WASP to protect a wide range of web applications while subjecting them to a large and varied set of attacks and legitimate accesses. WASP was able to stop all attacks and did not generate any false positives. Our studies also show that the overhead imposed by WASP was negligible in most cases. William G. J. Halfond, Alessandro Orso, Panagiotis Manolios |
IEEE Trans. Software Eng. | 1 |
| 2007 | Improving test case generation for web applications using automated interface discoveryabstractWith the growing complexity of web applications, identifying web interfaces that can be used for testing such applications has become increasingly challenging. Many techniques that work effectively when applied to simple web applications are insufficient when used on modern, dynamic web applications, and may ultimately result in inadequate testing of the applications' functionality. To address this issue, we present a technique for automatically discovering web application interfaces based on a novel static analysis algorithm. We also report the results of an empirical evaluation in which we compare our technique against a traditional approach. The results of the comparison show that our technique can (1) discover a higher number of interfaces and (2) help generate test inputs that achieve higher coverage. William G. J. Halfond, Alessandro Orso |
ESEC/SIGSOFT FSE | 1 |
| 2006 | Preventing SQL injection attacks using AMNESIAabstractAMNESIA is a tool that detects and prevents SQL injection attacks by combining static analysis and runtime monitoring. Empirical evaluation has shown that AMNESIA is both effective and efficient against SQL injection. William G. J. Halfond, Alessandro Orso |
ICSE | 1 |
| 2006 | Command-Form Coverage for Testing Database ApplicationsabstractThe testing of database applications poses new challenges for software engineers. In particular, it is difficult to thoroughly test the interactions between an application and its underlying database, which typically occur through dynamically-generated database commands. Because traditional code-based coverage criteria focus only on the application code, they are often inadequate in exercising these commands. To address this problem, we introduce a new test adequacy criterion that is based on coverage of the database commands generated by an application and specifically focuses on the application-database interactions. We describe the criterion, an analysis that computes the corresponding testing requirements, and an efficient technique for measuring coverage of these requirements. We also present a tool that implements our approach and a preliminary study that shows the approach's potential usefulness and feasibility William G. J. Halfond, Alessandro Orso |
ASE | 1 |
| 2006 | Using positive tainting and syntax-aware evaluation to counter SQL injection attacksabstractSQL injection attacks pose a serious threat to the security of Web applications because they can give attackers unrestricted access to databases that contain sensitive information. In this paper, we propose a new, highly automated approach for protecting existing Web applications against SQL injection. Our approach has both conceptual and practical advantages over most existing techniques. From the conceptual standpoint, the approach is based on the novel idea of positive tainting and the concept of syntax-aware evaluation. From the practical standpoint, our technique is at the same time precise and efficient and has minimal deployment requirements. The paper also describes wasp, a tool that implements our technique, and a set of studies performed to evaluate our approach. In the studies, we used our tool to protect several Web applications and then subjected them to a large and varied set of attacks and legitimate accesses. The evaluation was a complete success: wasp successfully and efficiently stopped all of the attacks without generating any false positives. William G. J. Halfond, Alessandro Orso, Panagiotis Manolios |
SIGSOFT FSE | 1 |
| 2005 | AMNESIA: analysis and monitoring for NEutralizing SQL-injection attacksabstractThe use of web applications has become increasingly popular in our routine activities, such as reading the news, paying bills, and shopping on-line. As the availability of these services grows, we are witnessing an increase in the number and sophistication of attacks that target them. In particular, SQL injection, a class of code-injection attacks in which specially crafted input strings result in illegal queries to a database, has become one of the most serious threats to web applications. In this paper we present and evaluate a new technique for detecting and preventing SQL injection attacks. Our technique uses a model-based approach to detect illegal queries before they are executed on the database. In its static part, the technique uses program analysis to automatically build a model of the legitimate queries that could be generated by the application. In its dynamic part, the technique uses runtime monitoring to inspect the dynamically-generated queries and check them against the statically-built model. We developed a tool, AMNESIA, that implements our technique and used the tool to evaluate the technique on seven web applications. In the evaluation we targeted the subject applications with a large number of both legitimate and malicious inputs and measured how many attacks our technique detected and prevented. The results of the study show that our technique was able to stop all of the attempted attacks without generating any false positives. William G. J. Halfond, Alessandro Orso |
ASE | 1 |