public static class TaintAnalyzerResult.TaintAnalysisResult
extends java.lang.Object
TaintAnalyzerResult.getTraceReconstructionResult() for that).| Modifier and Type | Method and Description |
|---|---|
java.util.Collection<BamLocationDependentJvmMemoryLocation<SetAbstractState<JvmTaintSource>>> |
getEndpoints()
Get locations where sinks have been triggered by a valid source.
|
java.util.Map<BamLocationDependentJvmMemoryLocation<SetAbstractState<JvmTaintSource>>,java.util.List<JvmTaintSink>> |
getEndpointToTriggeredSinks()
Maps locations where sinks have been triggered by valid sources to the triggered sink.
|
ProgramLocationDependentReachedSet<JvmAbstractState<SetAbstractState<JvmTaintSource>>> |
getMainMethodReachedSet()
Returns the reached states for the entry method of the analysis.
|
BamCache<SetAbstractState<JvmTaintSource>> |
getTaintResultCache()
Returns the analysis cache, containing the analyzed taints for each reached method invocation
with unique tainted parameters.
|
public BamCache<SetAbstractState<JvmTaintSource>> getTaintResultCache()
public ProgramLocationDependentReachedSet<JvmAbstractState<SetAbstractState<JvmTaintSource>>> getMainMethodReachedSet()
public java.util.Collection<BamLocationDependentJvmMemoryLocation<SetAbstractState<JvmTaintSource>>> getEndpoints()
The endpoints are computed lazily, since it can be an expensive operation, and multiple
runs of TaintAnalyzer.analyze(MethodSignature) just update the same cache. So, if the
same TaintAnalyzer performs several runs, it's better to get the endpoints only after
all runs have been executed.
public java.util.Map<BamLocationDependentJvmMemoryLocation<SetAbstractState<JvmTaintSource>>,java.util.List<JvmTaintSink>> getEndpointToTriggeredSinks()
The endpoints are computed lazily, since it can be an expensive operation, and multiple
runs of TaintAnalyzer.analyze(MethodSignature) just update the same cache. So, if the
same TaintAnalyzer performs several runs, it's better to get the endpoints only after
all runs have been executed.