Hacker News new | past | comments | ask | show | jobs | submit login

static analysis is always going to result in a deluge of false positives

i think the future is symbolic execution, which due to a lot of factors is becoming practical




symbolic execution is very similar to static analysis in purpose, if not name (closer to verification). You are right about the false positive rate, but I don't see why you think its becoming more practical?


what do you think about klee.llvm.org?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: