• DocumentCode
    3846471
  • Title

    Finding Bugs in Web Applications Using Dynamic Test Generation and Explicit-State Model Checking

  • Author

    Shay Artzi;Adam Kiezun;Julian Dolby;Frank Tip;Daniel Dig;Amit Paradkar;Michael D. Ernst

  • Author_Institution
    Thomas J. Watson Research Center, Hawthorne
  • Volume
    36
  • Issue
    4
  • fYear
    2010
  • Firstpage
    474
  • Lastpage
    494
  • Abstract
    Web script crashes and malformed dynamically generated webpages are common errors, and they seriously impact the usability of Web applications. Current tools for webpage validation cannot handle the dynamically generated pages that are ubiquitous on today´s Internet. We present a dynamic test generation technique for the domain of dynamic Web applications. The technique utilizes both combined concrete and symbolic execution and explicit-state model checking. The technique generates tests automatically, runs the tests capturing logical constraints on inputs, and minimizes the conditions on the inputs to failing tests so that the resulting bug reports are small and useful in finding and fixing the underlying faults. Our tool Apollo implements the technique for the PHP programming language. Apollo generates test inputs for a Web application, monitors the application for crashes, and validates that the output conforms to the HTML specification. This paper presents Apollo´s algorithms and implementation, and an experimental evaluation that revealed 673 faults in six PHP Web applications.
  • Keywords
    "Computer bugs","Vehicle crash testing","Automatic testing","Logic testing","Computer crashes","Usability","Internet","Concrete","Computer languages","HTML"
  • Journal_Title
    IEEE Transactions on Software Engineering
  • Publisher
    ieee
  • ISSN
    0098-5589
  • Type

    jour

  • DOI
    10.1109/TSE.2010.31
  • Filename
    5416728