Leandro T. C. Melo

dblp:183/1862 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
0since 2021 · last 2020
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 first-authorComputer networks · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Programming languages and type systems · 56% Program analysis · 44%

Topics — the 5 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Programming languages and type systems
type inference
0.822020
Type Inference for C: Applications to the Static Analysis of Incomplete Programs · ACM Trans. Program. Lang. Syst. 2020
Inference of static semantics for incomplete C programs · Proc. ACM Program. Lang. 2018
Program analysis › static analysis
incomplete code analysis
0.412020
Type Inference for C: Applications to the Static Analysis of Incomplete Programs · ACM Trans. Program. Lang. Syst. 2020
Program analysis
static analysis
0.412020
Type Inference for C: Applications to the Static Analysis of Incomplete Programs · ACM Trans. Program. Lang. Syst. 2020
Programming languages and type systems › language semantics
c semantics
0.312018
Inference of static semantics for incomplete C programs · Proc. ACM Program. Lang. 2018
Program analysis › static analysis
static analysis tools
0.112018
Inference of static semantics for incomplete C programs · Proc. ACM Program. Lang. 2018

Methods — techniques the papers use, named apart from their topics

unification-based inference · 0.4unification · 0.3type inference · 0.3
YearPublicationVenuePosition
2020 Type Inference for C: Applications to the Static Analysis of Incomplete Programs
abstract
Type inference is a feature that is common to a variety of programming languages. While, in the past, it has been prominently present in functional ones (e.g., ML and Haskell), today, many object-oriented/multi-paradigm languages such as C# and C++ offer, to a certain extent, such a feature. Nevertheless, type inference still is an unexplored subject in the realm of C. In particular, it remains open whether it is possible to devise a technique that encompasses the idiosyncrasies of this language. The first difficulty encountered when tackling this problem is that parsing C requires, not only syntactic, but also semantic information. Yet, greater challenges emerge due to C’s intricate type system. In this work, we present a unification-based framework that lets us infer the missing struct, union, enum, and typedef declarations in a program. As an application of our technique, we investigate the reconstruction of partial programs. Incomplete source code naturally appears in software development: during design and while evolving, testing, and analyzing programs; therefore, understanding it is a valuable asset. With a reconstructed well-typed program, one can: (i) enable static analysis tools in scenarios where components are absent; (ii) improve precision of “zero setup” static analysis tools; (iii) apply stub generators, symbolic executors, and testing tools on code snippets; and (iv) provide engineers with an assortment of compilable benchmarks for performance and correctness validation. We evaluate our technique on code from a variety of C libraries, including GNU’s Coreutils and on snippets from popular projects such as CPython, FreeBSD, and Git.
Leandro T. C. Melo, Rodrigo Geraldo Ribeiro, Breno Campos Ferreira Guimarães, Fernando Magno Quintão Pereira
ACM Trans. Program. Lang. Syst.1
2018 Inference of static semantics for incomplete C programs
abstract
Incomplete source code naturally emerges in software development: during the design phase, while evolving, testing and analyzing programs. Therefore, the ability to understand partial programs is a valuable asset. However, this problem is still unsolved in the C programming language. Difficulties stem from the fact that parsing C requires, not only syntax, but also semantic information. Furthermore, inferring types so that they respect C's type system is a challenging task. In this paper we present a technique that lets us solve these problems. We provide a unification-based type inference capable of dealing with C intricacies. The ideas we present let us reconstruct partial C programs into complete well-typed ones. Such program reconstruction has several applications: enabling static analysis tools in scenarios where software components may be absent; improving static analysis tools that do not rely on build-specifications; allowing stub-generation and testing tools to work on snippets; and assisting programmers on the extraction of reusable data-structures out of the program parts that use them. Our evaluation is performed on source code from a variety of C libraries such as GNU's Coreutils, GNULib, GNOME's GLib, and GDSL; on implementations from Sedgewick's books; and on snippets from popular open-source projects like CPython, FreeBSD, and Git.
Leandro T. C. Melo, Rodrigo Geraldo Ribeiro, Marcus R. de Araújo, Fernando Magno Quintão Pereira
Proc. ACM Program. Lang.1
2016 SMOV: Array Bound-Check and access in a single instruction
abstract
A Buffer Overflow (BOF) continues to be among the top open doors to worms and malware. Earlier in 2014, the security world was taken by surprise when researches unveiled a BOF in OpenSSL. Languages like C and C++, widely used for system development and for a large variety of applications, do not provide native Array-Bound Checks (ABC). A myriad of proposals endeavor memory protection for such languages by employing both software- and hardware-based solutions. Due to numerous reasons, none of them have yet reached the mainstream. In this work we propose a novel approach to achieve an array bound-check and a memory access (when allowed) within a single instruction. We discuss how it can be implemented on variable-length ISAs and provide a reference implementation. Our results indicate that our solution can run programs 1,79× faster than the software-based approach.
Antonio Maia, Leandro T. C. Melo, Fernando Magno Quintão Pereira, Omar P. Vilela Neto, Leonardo B. Oliveira
CCNC2
2016 NomadiKey: User authentication for smart devices based on nomadic keys
abstract
The growing importance of smart devices calls for effective user authentication mechanisms. We argue that state-of-the-art authentication mechanisms are either vulnerable to known attacks or do not meet usability needs. To address this problem we designed NomadiKey, a user-to-device authentication mechanism based on nomadic keyboard keys. NomadiKey increases security level by placing keys at different screen coordinates each time NomadiKey is activated. Besides, NomadiKey preserves usability by maintaining the traditional relative position of keys. We compare NomadiKey with other user authentication mechanisms under different attacks using statistical models and simulation. We also evaluate NomadiKey's usability with 18 users. Our results show that NomadiKey increases security compared to widely-deployed PIN authentication with limited impact on authentication times.
Leonardo Cotta, Artur Luis Fernandes, Leandro T. C. Melo, Luiz Felipe Z. Saggioro, Frederico Martins, Antonio Maia, Antonio Alfredo Ferreira Loureiro, Ítalo S. Cunha, Leonardo B. Oliveira
ICC3