PyFlow:面向Python的过程间静态分析框架
PyFlow: An Inter-procedural Static Analysis Framework for Python
浏览论文内容
中文总结 AI 辅助
该研究提出基于IFDS的Python静态分析框架PyFlow,实现的污点分析在合成与真实基准上,较8款SAST工具取得更优的综合性能,为Python静态分析提供了有效方案。
中文摘要 AI 辅助
静态程序分析可自动推导程序属性,但精准的过程间分析仍具挑战性,而动态类型语言会加剧该难度。Python尤其存在问题:动态分派、一等函数、元编程、普遍存在的异常,以及基于描述符和属性驱动查找的对象模型,共同阻碍了精准推理。我们提出PyFlow,这是一个基于IFDS的通用Python静态分析框架。PyFlow提供多阶段中间表示流水线和由抽象域参数化的通用IFDS求解器。分析开发者仅需实现数据流语义;框架会构建超图、执行定点迭代并缓存摘要。我们在PyFlow中实现了污点分析,并针对最近ICSE '26研究中的合成与真实基准,将其与8款Python SAST工具(DevSkim、Dlint、Bandit、Bearer、CodeQL、Pysa、Semgrep和Snyk)进行评估。在合成基准上,PyFlow在所有9款工具中实现了最佳的综合召回率和F1分数;在真实基准上,它达到最高召回率和F1分数,同时保持与基于污点的引擎相当的精度。最后我们总结了为Python构建IFDS分析的经验教训。
英文摘要
Static program analysis infers program properties automatically. Yet precise interprocedural analysis remains challenging, and dynamically typed languages amplify the difficulty. Python is particularly problematic: dynamic dispatch, first-class functions, metaprogramming, pervasive exceptions, and an object model based on descriptors and attribute-driven lookup collectively impede precise reasoning. We present PyFlow, a generic IFDS-based static-analysis framework for Python. PyFlow provides a multi-stage intermediate-representation pipeline and a generic IFDS solver parameterized by abstract domains. Analysis developers implement only the dataflow semantics; the framework constructs the supergraph, performs fixed-point iteration, and caches summaries. We implement a taint analysis in \pyflow and evaluate it against eight Python SAST tools (DevSkim, Dlint, Bandit, Bearer, CodeQL, Pysa, Semgrep, and Snyk) on the synthetic and real-world benchmarks from a recent ICSE~'26 study. On the synthetic benchmark, PyFlow achieves the best aggregate recall and F1 score among all nine tools. On the real-world benchmark, it attains the highest recall and F1 score while maintaining precision competitive with taint-based engines. We conclude with lessons learned from building IFDS analyses for Python.