Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Static analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

LSAFE: a Lightweight Static Analysis Framework for binary Executables

Static analysis is a widely used technique for analyzing various aspects of programs. However, as programs become more complex, static analysis tools require larger resources, such as CPU time and memory, to perform the same tasks. Moreover, the source code of programs may not always be accessible, requiring static analysis to be performed on the binary executable code directly. To overcome these challenges, we propose a lightweight static analysis framework called LSAFE, which constructs control flow graphs (CFGs) and data dependency graphs (DDGs) of target programs with optimized performance in terms of CPU and memory usage. We evaluated the proposed framework using both Spec benchmark programs and real-world industrial applications, and found that it outperformed Angr, an existing state-of-the-art static analysis tool. Additionally, we demonstrate a case study that utilizes the CFG generated by LSAFE to detect memory leaks.

Qu, Guangzhi↗

MAPredict: Static Analysis Driven Memory Access Prediction Framework for Modern CPUs

Application memory access patterns are crucial in deciding how much traffic is served by the cache and forwarded to the dynamic random-access memory (DRAM). However, predicting such memory traffic is difficult because of the interplay of prefetchers, compilers, parallel execution, and innovations in manufacturer-specific micro-architectures. This research introduced MAPredict, a static analysis-driven framework that addresses these challenges to predict last-level cache (LLC)-DRAM traffic. By exploring and analyzing the behavior of modern Intel processors, MAPredict formulates cache-aware analytical models. MAPredict invokes these models to predict LLC-DRAM traffic by combining the application model, machine model, and user-provided hints to capture dynamic information. MAPredict successfully predicts LLC-DRAM traffic for different regular access patterns and provides the means to combine static and empirical observations for irregular access patterns. Evaluating 130 workloads from six applications on recent Intel micro-architectures, MAPredict yielded an average accuracy of 99% for streaming, 91% for strided, and 92% for stencil patterns. By coupling static and empirical methods, up to 97% average accuracy was obtained for random access patterns on different micro-architectures.

Monil, M. A. H.↗

MoorPy (Quasi-Static Mooring Analysis in Python)

MoorPy is a quasi-static mooring model and a suite of associated functions for mooring system analysis. The core model supports quasi-static analysis of moored floating systems including any arrangement of mooring lines and floating platforms. It solves the distributed position and tension of each mooring line segment using standard catenary equations. Floating platforms can be represented with linear hydrostatic characteristics. MoorPy automatically computes a floating system's equilibrium state and can be queried to identify a mooring system's nonlinear force-displacement relationships. Linearized stiffness matrices are efficiently computed using semi-analytic Jacobians. MoorPy also includes plotting functions and a library of mooring component property and cost coefficients. MoorPy can be used directly from Python scripts to perform mooring design and analysis tasks, or it can be coupled with other tools to compute quasi-static mooring reactions as part of a larger simulation.

Hall, Mathew↗

Software Verification Toolkit (SVT): Survey on Available Software Verification Tools and Future Direction

Writing software is difficult. However, writing complex, well tested and designed, and functionally correct software is incredibly difficult. An entire field of study is devoted to the validation and verification of software to address this problem, and in this paper we analyze the landscape of currently available third party software. We have divided our analyses into three separate subsections with regards to software validation: formal methods, static analysis, and test generation. Formal verification is the most complex method in which to validate software correctness, but also the most thorough as it truly validates the mathematical validity of the source code. Static analysis generally is relegated to abstract syntax tree traversal techniques to find errors related to faulty software such as memory leaks or stack overflow issues. Automatic test generation is similar in implementation to static analysis, but pushes a bit further in verifying the boundedness of function inputs and outputs with regards to annotated or parsed criteria. The crux of this report is to analyze and describe the software tools that implement these techniques to validate and verify software. Pros and cons related to installation, utilization, and capabilities of the frameworks are described, and reproducible examples are provided with a focus on usability. The initial survey concluded that the most interesting tools of note are Z3, Isabelle/HOL, and TLA+ with regards to formal verification; and Infer, Frama-C, and SonarQube with regards to static analysis. With these tools in mind, a final conjecture is provided that describes future avenues of utilizing these tools for developing a verification framework to assist in validating existing software at Sandia National Laboratories.

97 MATHEMATICS AND COMPUTING↗

Deciphering Discrepancies: A Comparative Analysis of Docker Image Security

As the use of microservices continues to grow and become a foundational approach to architecting software solutions, ensuring the security of microservices is paramount. Docker images have emerged as the predominant solution to containerize microservices–and thus, Docker images are becoming a large attack surface. Thus, reducing vulnerabilities in Docker images will reduce microservice cyberattacks. A common way to find vulnerabilities in Docker images employs static analysis tools like Trivy and Grype. However, these tools frequently generate disparate vulnerability reports when analyzing the same Docker image, thus causing uncertainty in tool selection. We collected 927 Docker images, analyzed them with Trivy and Grype, and compared the vulnerabilities reported in each image. Among the 865 images found to have vulnerabilities, Trivy and Grype disagreed on both the number of vulnerabilities and the vulnerability IDs found therein. Since both tools interface with external vulnerability databases, some discrepancies can be attributed to how the tools interface with these external resources. The external vulnerability databases partially overlap and frequently contradict one another, thereby creating challenges for static analysis tool developers and end users alike. This New Ideas and Emerging Results (NIER) study contains new and critical information that practitioners need for selecting and using static analysis tools–given that increases in the use of Docker technologies means increases in the size of the attack surfaces.

Boles, Brittany [Montana State University]↗

Analysis of static Wilson line correlators from lattice QCD at finite temperature with T -matrix approach

The thermodynamic T-matrix approach is used to study Wilson line correlators (WLCs) for a static quark-antiquark pair in the quark-gluon plasma (QGP). Selfconsistent results that incorporate constraints from the QGP equation of state can approximately reproduce WLCs computed in 2+1-flavor lattice-QCD (lQCD), provided the input potential exhibits less screening than in previous studies. Utilizing the updated potential to calculate pertinent heavylight T-matrices we evaluate thermal relaxation rates of heavy quarks in the QGP. We find a more pronounced temperature dependence for low-momentum quarks than in our previous results (with larger screening), which turns into a weaker temperature dependence of the (temperature-scaled) spatial diffusion coefficient, in fair agreement with the most recent lQCD data.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

T -matrix analysis of static Wilson line correlators from lattice QCD at finite temperature

Here, we utilize a previously constructed thermodynamic T -matrix approach to the quark-gluon plasma (QGP) to derive constaints on its input by using results on Wilson line correlators (WLCs) of a static quark-antiquark pair from 2 + 1-flavor lattice-QCD (lQCD) computations with realistic pion mass. The self-consistent T -matrix results, which include previous constraints from the lQCD equation of state in the light-parton sector, can describe the lQCD data for WLCs fairly well once refinements of its driving kernel are applied. In particular, the input potential requires less screening than what has been inferred from previous T-matrix analyses. Pertinent predictions for the spectral and transport properties of the QGP are discussed, including the spatial diffusion coefficient for heavy quarks; the latter turns out to have a rather weak temperature dependence, in approximate agreement with recent unquenched lQCD results.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

KBase Narrative - StRoNG Net Part 2: Genome Analysis - Student - Static

Here we continue our exploration of novel genomes discovered in module 1. We will explore different approaches for examining the genome sequence and annotation data, investigating the best approaches for answering our question: Do benthic microbes have functioning circadian clocks?

Schirmer, Aaron↗

Enabling topography-resolving structural dynamic contact simulation

Damping of structures and systems is often dominated by frictional dissipation in connections, the prediction of which remains a longstanding scientific challenge. Previous studies have shown that the actual topography of contact interfaces may have a strong effect, especially in the partial slip/liftoff regime. We recently proposed a multi-scale method, which couples finite element and boundary element modeling. The primary benefit of this approach is that it permits to analyze the effect of the actual contact topography on the dynamics of jointed structures. While this multi-scale modeling method was initially developed for quasi-static analysis, we demonstrate herein how it can be used for time step integration and Harmonic Balance analysis. We cross-verify those fully dynamic analysis methods against each other and quasi-static results, for the S4 Beam benchmark. We compare the multi-scale method against state-of-the-art full-FE analysis, in terms of numerical damping and computational performance. Some discrepancy is found to be of physical origin. Depending on the load history, it is shown that the system settles to a slightly different equilibrium. Finally, transient multi-scale simulations enable the prediction of this interesting phenomenon, for the first time, for a structure with bolted joints.

Frictional-unilateral contact↗

Enhancing Developer Productivity - L2 Milestone (Final Report)

This report documents the work done as part of the “Enhancing Developer Productivity” level 2 milestone. The team surveyed developers about impediments and successes; improved our CI pipeline monitoring and reporting; developed tools for line coverage reporting and analysis; improved compiler warning adherence in SIERRA; prototyped static analysis, AI, and mutation testing tooling in SIERRA; and developed a 3-5 year SIERRA plan document to help these initiatives continue past this milestone.

97 MATHEMATICS AND COMPUTING↗

Physical Security Timeline Analysis in Support of Advanced Reactor Demonstration and Deployment

This report presents the regulatory requirements and directions on the physical security of advanced nuclear reactors in USA. Presently, a rule is being proposed that allows for a performance-based analysis. In determining the physical security requirements for an advanced reactor, new tools may be desired to conduct a performance-based analysis. These tools should incorporate dynamic analysis methods to provide as much realism as possible. In comparison, the security requirements for existing light water reactors (LWRs) are much more prescriptive and the analysis conducted to establish the required physical security strategies were more easily performed with static analysis. In order to achieve the cost goals that advanced reactors require for adoption; the nuclear security force required should not be excessive. Dynamic physical security analysis methods and tools have been developed by the US Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) program. This report details how the dynamic risk analysis tools developed in the LWRS program using the dynamic risk modelling tool, EMRALD, may be adapted for use in analyzing the physical security designs for advanced reactors accounting for variable performance-based requirements. This report provides an example analysis of a hypothetical SFR using publicly available information and generic assumptions to demonstrate the methods and potential presentation and analysis of the results. No actual plant information is used in this example analysis. Future work in this area will create additional models that can be adapted for any advanced reactor concept and use various security features to create a physical security system that provides adequate protection from radiological theft and sabotage.

97 MATHEMATICS AND COMPUTING↗

Efficient Modeling of Floating Wind Arrays Including Current Loads and Seabed Bathymetry

Capabilities for modeling the effects of seabed bathymetry and current drag loads on a floating wind farm are now available in an open-source model for quasi-static analysis. In this model, mooring lines and dynamic cables are represented by a quasi-static solver that can quickly represent complex mooring/cabling arrangements and arrays of floating bodies. To account for seabed bathymetry, we expand the model to include a surface mesh that captures changes in water depth over a rectangular grid. We formulate modifications to the catenary equations that capture a mooring line's profile and tensions when contacting a slope seabed. To account for current drag loads on mooring lines and dynamic cables, we formulate a novel technique that rotates the reference frame so that the vector sum of the the weight and the current force are used in the catenary equations, while accounting for the seabed orientation. To complete the system, current drag loads on floating substructures are handled by inclusion of strip-theory drag calculations. These new capabilities are verified by comparing with results from the established offshore dynamics models MoorDyn and OrcaFlex in equivalent steady-state scenarios. The results show very good agreement for both sloped seabeds and current loads. With computation times of the quasi-static model typically under one second, the model additions are a useful capability toward rapidly evaluating a floating wind array's response to environmental loads under realistic site conditions.

bathymetry↗

Generalized Quasi-Static Mooring System Modeling with Analytic Jacobians

This paper presents a generalized and efficient method for quasi-static analysis of mooring systems, including complex scenarios such as when shared mooring lines interconnect multiple floating wind or wave energy devices. While quasi-static mooring models are well established, most published formulations are focused on specific applications, and no publicly available implementations provide efficient handling of large mooring system networks. The present formulation addresses these gaps by: (1) formulating solutions for edge cases not typically supported by quasi-static models; (2) creating a fully generalized model structure such that any combination of mooring lines, point masses, and floating bodies can be assembled; and (3) deriving analytic expressions for the system Jacobians (stiffness matrices) so that systems with many degrees of freedom can be solved efficiently. These techniques form the theory basis of MoorPy, an open-source mooring analysis library. The model is demonstrated on nine scenarios of increasing complexity with features of interest for offshore renewable energy applications. When compared with steady-state results from a lumped-mass dynamic model, the results show that the quasi-static formulation accurately calculates profiles and tensions and that its analytic approach provides more efficient and reliable computation of system stiffness matrices than finite-differencing methods. These results verify the accuracy of the MoorPy model.

16 TIDAL AND WAVE POWER↗

FIC Vulnerability Profile

The FIC team is engaged with Pacific Northwest National Laboratory’s (PNNL’s) Shamrock Cyber Team to provide cybersecurity analyses of the FIC software. Shamrock offers both Threat-Based Analysis services and Secure Software Development services. These services are ultimately used to understand and mitigate threats against software and to reduce vulnerabilities in software, thus improving overall cybersecurity and informing decision makers. Shamrock’s Secure Software Development services, specifically Static Analysis Security Testing (SAST) and Open-Source Analysis (OSA), produced this Vulnerability Profile.

97 MATHEMATICS AND COMPUTING↗