KIT | KIT-Bibliothek | Impressum | Datenschutz

Investigating the Effects of T-Wise Interaction Sampling for Vulnerability Discovery in Highly-Configurable Software Systems

Bächle, Tim ORCID iD icon 1; Hofmayer, Erik 1; König, Christoph ORCID iD icon 1; Pett, Tobias ORCID iD icon 1; Schaefer, Ina ORCID iD icon 1
1 Institut für Informationssicherheit und Verlässlichkeit (KASTEL), Karlsruher Institut für Technologie (KIT)

Abstract (englisch):

Empirical evidence has shown that variability bugs, i.e., bugs that only manifest if certain features of a configurable software system are selected, are not only a theoretical concept. Many variability bugs involve an intricate interplay of multiple features, turning them into so-called feature-interaction bugs. The strategy of t-wise interaction sampling can be used to identify variability bugs in highly-configurable systems. In this regard, the number of findings, as well as the overall sample size, typically increase with stronger interaction sampling (i.e., higher t values). In this paper, we aim to confirm these observations for vulnerabilities. We use the static source code analysis platform Vari-Joern to analyze real-world highly-configurable software systems for the presence of vulnerability patterns using t-wise interaction sampling of varying strength and compare the number of findings and associated sample sizes. We analyze the feature configurations associated with the vulnerability warnings raised by our approach to evaluate the presence of feature interaction vulnerabilities. Our results show that stronger interaction sampling produces a greater number of findings at a higher computational cost, also for vulnerabilities. ... mehr


Verlagsausgabe §
DOI: 10.5445/IR/1000184707
Veröffentlicht am 09.09.2025
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Informationssicherheit und Verlässlichkeit (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsmonat/-jahr 09.2025
Sprache Englisch
Identifikator ISBN: 979-84-00-72024-6
KITopen-ID: 1000184707
HGF-Programm 46.23.03 (POF IV, LK 01) Engineering Security for Mobility Systems
Erschienen in Proceedings of the 29th ACM International Systems and Software Product Line Conference - Volume A. Ed.: M.R. Luaces
Veranstaltung 29th ACM International Systems and Software Product Line Conference (SPLC 2025), A Coruña, Spanien, 01.09.2025 – 05.09.2025
Verlag Association for Computing Machinery (ACM)
Seiten 45–56
Vorab online veröffentlicht am 31.08.2025
Schlagwörter Vulnerability Discovery, Software Product Lines, Combinatorial Interaction Testing, T-Wise Interaction Sampling, Static Analysis
Nachgewiesen in OpenAlex
Dimensions
Scopus
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page