Scott McPeak

dblp:37/1193 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
0since 2021 · last 2013
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 7 · 3 first-authorArtificial intelligence and machine learning · 1Theory of computation · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
4 papers
Program analysis · 62% Programming languages and type systems · 22% Compilers and program optimization · 11%
Network and information security
3 papers
Systems and software security · 100%
Theoretical computer science
1 paper
Logic in computer science · 100%

Topics — the 10 heaviest of 12, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis › static analysis
bug detection
0.212013
Scalable and incremental software bug detection · ESEC/SIGSOFT FSE 2013
Program analysis
static analysis
0.212013
Scalable and incremental software bug detection · ESEC/SIGSOFT FSE 2013
Systems and software security
memory safety
0.132005
CCured: type-safe retrofitting of legacy software · ACM Trans. Program. Lang. Syst. 2005
CCured in the real world · PLDI 2003
CCured: type-safe retrofitting of legacy code · POPL 2002
Programming languages and type systems
type inference
0.122003
CCured in the real world · PLDI 2003
CCured: type-safe retrofitting of legacy code · POPL 2002
Programming languages and type systems › type systems
type soundness
0.112005
CCured: type-safe retrofitting of legacy software · ACM Trans. Program. Lang. Syst. 2005
Logic in computer science › meta-logic
axiomatization
0.112005
Data Structure Specifications via Local Equality Axioms · CAV 2005
Program analysis › static analysis
incremental analysis
0.012013
Scalable and incremental software bug detection · ESEC/SIGSOFT FSE 2013
Compilers and program optimization › compiler security
pointer safety
0.012002
CCured: type-safe retrofitting of legacy code · POPL 2002
Program verification › dynamic verification
runtime verification
0.012002
CCured: type-safe retrofitting of legacy code · POPL 2002
Compilers and program optimization
program transformation
0.022005
CCured: type-safe retrofitting of legacy software · ACM Trans. Program. Lang. Syst. 2005
CCured in the real world · PLDI 2003

Methods — techniques the papers use, named apart from their topics

run-time type information · 0.2instrumentation · 0.2static analysis · 0.2incremental analysis · 0.2physical subtyping · 0.1type inference · 0.1runtime checking · 0.1
YearPublicationVenuePosition
2013 Scalable and incremental software bug detection
abstract
An important, but often neglected, goal of static analysis for detecting bugs is the ability to show defects to the programmer quickly. Unfortunately, existing static analysis tools scale very poorly, or are shallow and cannot find complex interprocedural defects. Previous attempts at reducing the analysis time by adding more resources (CPU, memory) or by splitting the analysis into multiple sub-analyses based on defect detection capabilities resulted in limited/negligible improvements.
Scott McPeak, Charles-Henri Gros, Murali Krishna Ramanathan
ESEC/SIGSOFT FSE1
2005 Data Structure Specifications via Local Equality Axioms
Scott McPeak, George C. Necula
CAV1
2005 CCured: type-safe retrofitting of legacy software
abstract
This article describes CCured, a program transformation system that adds type safety guarantees to existing C programs. CCured attempts to verify statically that memory errors cannot occur, and it inserts run-time checks where static verification is insufficient.CCured extends C's type system by separating pointer types according to their usage, and it uses a surprisingly simple type inference algorithm that is able to infer the appropriate pointer kinds for existing C programs. CCured uses physical subtyping to recognize and verify a large number of type casts at compile time. Additional type casts are verified using run-time type information. CCured uses two instrumentation schemes, one that is optimized for performance and one in which metadata is stored in a separate data structure whose shape mirrors that of the original user data. This latter scheme allows instrumented programs to invoke external functions directly on the program's data without the use of a wrapper function.We have used CCured on real-world security-critical network daemons to produce instrumented versions without memory-safety vulnerabilities, and we have found several bugs in these programs. The instrumented code is efficient enough to be used in day-to-day operations.
George C. Necula, Jeremy Condit, Matthew Harren, Scott McPeak, Westley Weimer
ACM Trans. Program. Lang. Syst.4
2004 Elkhound: A Fast, Practical GLR Parser Generator
Scott McPeak, George C. Necula
CC1
2003 CCured in the real world
abstract
CCured is a program transformation system that adds memory safety guarantees to C programs by verifying statically that memory errors cannot occur and by inserting run-time checks where static verification is insufficient.This paper addresses major usability issues in a previous version of CCured, in which many type casts required the use of pointers whose representation was expensive and incompatible with precompiled libraries. We have extended the CCured type inference algorithm to recognize and verify statically a large number of type casts; this goal is achieved by using physical subtyping and pointers with run-time type information to allow parametric and subtype polymorphism. In addition, we present a new instrumentation scheme that splits CCured's metadata into a separate data structure whose shape mirrors that of the original user data. This scheme allows instrumented programs to invoke external functions directly on the program's data without the use of a wrapper function.With these extensions we were able to use CCured on real-world security-critical network daemons and to produce instrumented versions without memory-safety vulnerabilities.
Jeremy Condit, Matthew Harren, Scott McPeak, George C. Necula, Westley Weimer
PLDI3
2002 CIL: Intermediate Language and Tools for Analysis and Transformation of C Programs
George C. Necula, Scott McPeak, Shree Prakash Rahul, Westley Weimer
CC2
2002 CCured: type-safe retrofitting of legacy code
abstract
In this paper we propose a scheme that combines type inference and run-time checking to make existing C programs type safe. We describe the CCured type system, which extends that of C by separating pointer types according to their usage. This type system allows both pointers whose usage can be verified statically to be type safe, and pointers whose safety must be checked at run time. We prove a type soundness result and then we present a surprisingly simple type inference algorithm that is able to infer the appropriate pointer kinds for existing C programs.Our experience with the CCured system shows that the inference is very effective for many C programs, as it is able to infer that most or all of the pointers are statically verifiable to be type safe. The remaining pointers are instrumented with efficient run-time checks to ensure that they are used safely. The resulting performance loss due to run-time checks is 0-150%, which is several times better than comparable approaches that use only dynamic checking. Using CCured we have discovered programming bugs in established C programs such as several SPECINT95 benchmarks.
George C. Necula, Scott McPeak, Westley Weimer
POPL2
2000 An Improved Adaptive Multi-Start Approach to Finding Near-Optimal Solutions to the Euclidean TSP
Dan Bonachea, Eugene Ingerman, Joshua Levy, Scott McPeak
GECCO4