Simon Holm Jensen

dblp:07/7229 · DBLP profile ↗
← Back
7ranked-venue papers
6as first author
0since 2021 · last 2015
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 7 · 6 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
4 papers
Program analysis · 26% Software testing · 24% Debugging and program repair · 14%
Network and information security
1 paper
Web and mobile security · 100%

Topics — the 9 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis
static analysis
0.322012
Remedying the eval that men do · ISSTA 2012
Modeling the HTML DOM and browser API in static analysis of JavaScript web applications · SIGSOFT FSE 2011
Operating systems › resource management
memory management
0.212015
MemInsight: platform-independent memory debugging for JavaScript · ESEC/SIGSOFT FSE 2015
Runtime systems and virtual machines › runtime memory management
object lifetime analysis
0.212015
MemInsight: platform-independent memory debugging for JavaScript · ESEC/SIGSOFT FSE 2015
Program analysis › dynamic language analysis
javascript analysis
0.112012
Remedying the eval that men do · ISSTA 2012
Programming languages and type systems
language design
0.112012
Remedying the eval that men do · ISSTA 2012
Software testing › test generation
automated test generation
0.112011
A framework for automated testing of javascript web applications · ICSE 2011
Software testing › test generation › dynamic test generation
feedback-directed test generation
0.112011
A framework for automated testing of javascript web applications · ICSE 2011
Software testing › web application testing
javascript web application testing
0.112011
A framework for automated testing of javascript web applications · ICSE 2011
Web and mobile security
web application testing
0.012011
A framework for automated testing of javascript web applications · ICSE 2011

Methods — techniques the papers use, named apart from their topics

trace analysis · 0.2source code instrumentation · 0.2static analysis · 0.1abstract interpretation · 0.1
YearPublicationVenuePosition
2015 Test Generation from Business Rules
abstract
Enterprise applications are difficult to test because their intended functionality is either not described precisely enough or described in cumbersome business rules. It takes a lot of effort on the part of a test architect to understand all the business rules and design tests that "cover" them, i.e., exercise all their constituent scenarios. Part of the problem is that it takes a complicated set up sequence to drive an application to a state in which a business rule can even fire. In this paper, we present a business rule modeling language that can be used to capture functional specification of an enterprise system. The language makes it possible to build tool support for rule authoring, so that obvious deficiencies in rules can be detected mechanically. Most importantly, we show how to mechanically generate test sequences--i.e., test steps and test data--needed to exercise these business rules. To this end, we translate the rules into logical formulae and use constraint solving to generate test sequences. One of our contributions is to overcome scalability issues in this process, and we do this by using a novel algorithm for organizing search through the space of candidate sequences to discover covering sequences. Our results on three case studies show the promise of our approach.
Simon Holm Jensen, Suresh Thummalapenta, Saurabh Sinha 0001, Satish Chandra 0001
ICST1
2015 MemInsight: platform-independent memory debugging for JavaScript
abstract
JavaScript programs often suffer from memory issues that can either hurt performance or eventually cause memory exhaustion. While existing snapshot-based profiling tools can be helpful, the information provided is limited to the coarse granularity at which snapshots can be taken. We present MemInsight, a tool that provides detailed, time-varying analysis of the memory behavior of JavaScript applications, including web applications. MemInsight is platform independent and runs on unmodified JavaScript engines. It employs tuned source-code instrumentation to generate a trace of memory allocations and accesses, and it leverages modern browser features to track precise information for DOM (document object model) objects. It also computes exact object lifetimes without any garbage collector assistance, and exposes this information in an easily-consumable manner for further analysis. We describe several client analyses built into MemInsight, including detection of possible memory leaks and opportunities for stack allocation and object inlining. An experimental evaluation showed that with no modifications to the runtime, MemInsight was able to expose memory issues in several real-world applications.
Simon Holm Jensen, Manu Sridharan, Koushik Sen, Satish Chandra 0001
ESEC/SIGSOFT FSE1
2012 Remedying the eval that men do
abstract
A range of static analysis tools and techniques have been developed in recent years with the aim of helping JavaScript web application programmers produce code that is more robust, safe, and efficient. However, as shown in a previous large-scale study, many web applications use the JavaScript eval function to dynamically construct code from text strings in ways that obstruct existing static analyses. As a consequence, the analyses either fail to reason about the web applications or produce unsound or useless results.
Simon Holm Jensen, Peter A. Jonsson, Anders Møller
ISSTA1
2011 A framework for automated testing of javascript web applications
abstract
Current practice in testing JavaScript web applications requires manual construction of test cases, which is difficult and tedious. We present a framework for feedback-directed automated test generation for JavaScript in which execution is monitored to collect information that directs the test generator towards inputs that yield increased coverage. We implemented several instantiations of the framework, corresponding to variations on feedback-directed random testing, in a tool called Artemis. Experiments on a suite of JavaScript applications demonstrate that a simple instantiation of the framework that uses event handler registrations as feedback information produces surprisingly good coverage if enough tests are generated. By also using coverage information and read-write sets as feedback information, a slightly better level of coverage can be achieved, and sometimes with many fewer tests. The generated tests can be used for detecting HTML validity problems and other programming errors.
Shay Artzi, Julian Dolby, Simon Holm Jensen, Anders Møller, Frank Tip
ICSE3
2011 Modeling the HTML DOM and browser API in static analysis of JavaScript web applications
abstract
Developers of JavaScript web applications have little tool support for catching errors early in development. In comparison, an abundance of tools exist for statically typed languages, including sophisticated integrated development environments and specialized static analyses. Transferring such technologies to the domain of JavaScript web applications is challenging. In this paper, we discuss the challenges, which include the dynamic aspects of JavaScript and the complex interactions between JavaScript, HTML, and the browser. From this, we present the first static analysis that is capable of reasoning about the flow of control and data in modern JavaScript applications that interact with the HTML DOM and browser API.
Simon Holm Jensen, Magnus Madsen, Anders Møller
SIGSOFT FSE1
2010 Interprocedural Analysis with Lazy Propagation
Simon Holm Jensen, Anders Møller, Peter Thiemann 0001
SAS1
2009 Type Analysis for JavaScript
Simon Holm Jensen, Anders Møller, Peter Thiemann 0001
SAS1