Affiliation:
1. Microsoft Research Cambridge & University College London, Cambridge, United Kingdom
2. New York University, New York, NY, USA
Abstract
Branching-time temporal logics (e.g. CTL, CTL*, modal mu-calculus) allow us to ask sophisticated questions about the nondeterminism that appears in systems. Applications of this type of reasoning include planning, games, security analysis, disproving, precondition synthesis, environment synthesis, etc. Unfortunately, existing automatic branching-time verification tools have limitations that have traditionally restricted their applicability (e.g. push-down systems only, universal path quantifiers only, etc).
In this paper we introduce an automation strategy that lifts many of these previous restrictions. Our method works reliably for properties with non-trivial mixtures of universal and existential modal operators. Furthermore, our approach is designed to support (possibly infinite-state) programs.
The basis of our approach is the observation that existential reasoning can be reduced to universal reasoning if the system's state-space is appropriately restricted. This restriction on the state-space must meet a constraint derived from recent work on proving non-termination. The observation leads to a new route for implementation based on existing tools. To demonstrate the practical viability of our approach, we report on the results applying our preliminary implementation to a set of benchmarks drawn from the Windows operating system, the PostgreSQL database server, SoftUpdates patching system, as well as other hand-crafted examples.
Publisher
Association for Computing Machinery (ACM)
Subject
Computer Graphics and Computer-Aided Design,Software
Reference41 articles.
1. The software model checker Blast
2. Bradley A. Manna Z. and Sipma H. The polyranking principle. Automata Languages and Programming (2005) 1349--1361. 10.1007/11523468_109 Bradley A. Manna Z. and Sipma H. The polyranking principle. Automata Languages and Programming (2005) 1349--1361. 10.1007/11523468_109
3. Burch J. Clarke E. etal Symbolic model checking: 10 20 states and beyond. Information and computation 98 2 (1992) 142--170. 10.1016/0890-5401(92)90017-A Burch J. Clarke E. et al. Symbolic model checking: 10 20 states and beyond. Information and computation 98 2 (1992) 142--170. 10.1016/0890-5401(92)90017-A
4. State/Event Software Verification for Branching-Time Specifications
Cited by
24 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献