A First Step towards Automated Detection of Buffer Overrun Vulnerabilities
 In Network and Distributed System Security Symposium
, 2000
"... We describe a new technique for finding potential buffer overrun vulnerabilities in securitycritical C code. The key to success is to use static analysis: we formulate detection of buffer overruns as an integer range analysis problem. One major advantage of static analysis is that security bugs can ..."


Cited by 339 (10 self)
We describe a new technique for finding potential buffer overrun vulnerabilities in securitycritical C code. The key to success is to use static analysis: we formulate detection of buffer overruns as an integer range analysis problem. One major advantage of static analysis is that security bugs can be eliminated before code is deployed. We have implemented our design and used our prototype to find new remotelyexploitable vulnerabilities in a large, widely deployed software package. An earlier hand audit missed these bugs. 1.
Principles of Constraint Programming
, 2000
"... Introduction 1.1 Preliminaries Constraint programming is an alternative approach to programming in which the programming process is limited to a generation of requirements (constraints) and a solution of these requirements by means of general or domain specific methods. The general methods are us ..."


Cited by 168 (3 self)
Introduction 1.1 Preliminaries Constraint programming is an alternative approach to programming in which the programming process is limited to a generation of requirements (constraints) and a solution of these requirements by means of general or domain specific methods. The general methods are usually concerned with techniques of reducing the search space and with specific search methods. In contrast, the domain specific methods are usually provided in the form of special purpose algorithms or specialised packages, usually called constraint solvers. Typical examples of constraint solvers are: ffl a program that solves systems of linear equations, ffl a package for linear programming, ffl an implementation of the unification algorithm, a cornerstone of automated theorem proving. Problems that can be solved in a natural way by means of constraint programming are usually those for which efficient algorithms are
CLP(Intervals) Revisited
, 1994
"... The design and implementation of constraint logic programming (CLP) languages over intervals is revisited. Instead of decomposing complex constraints in terms of simple primitive constraints as in CLP(BNR), complex constraints are manipulated as a whole, enabling more sophisticated narrowing procedu ..."


Cited by 121 (18 self)
The design and implementation of constraint logic programming (CLP) languages over intervals is revisited. Instead of decomposing complex constraints in terms of simple primitive constraints as in CLP(BNR), complex constraints are manipulated as a whole, enabling more sophisticated narrowing procedures to be applied in the solver. This idea is embodied in a new CLP language Newton whose operational semantics is based on the notion of boxconsistency, an approximation of arcconsistency, and whose implementation uses Newton interval method. Experimental results indicate that Newton outperforms existing languages by an order of magnitude and is competitive with some stateoftheart tools on some standard benchmarks. Limitations of our current implementation and directions for further work are also identified.
Practical Applications of Constraint Programming
 CONSTRAINTS
, 1996
"... Constraint programming is newly flowering in industry. Several companies have recently started up to exploit the technology, and the number of industrial applications is now growing very quickly. This survey will seek, by examples, ..."


Cited by 105 (1 self)
Constraint programming is newly flowering in industry. Several companies have recently started up to exploit the technology, and the number of industrial applications is now growing very quickly. This survey will seek, by examples,
Theoretical and Numerical ConstraintHandling Techniques used with Evolutionary Algorithms: A Survey of the State of the Art
, 2002
"... This paper provides a comprehensive survey of the most popular constrainthandling techniques currently used with evolutionary algorithms. We review approaches that go from simple variations of a penalty function, to others, more sophisticated, that are biologically inspired on emulations of the imm ..."


Cited by 100 (21 self)
This paper provides a comprehensive survey of the most popular constrainthandling techniques currently used with evolutionary algorithms. We review approaches that go from simple variations of a penalty function, to others, more sophisticated, that are biologically inspired on emulations of the immune system, culture or ant colonies. Besides describing briefly each of these approaches (or groups of techniques), we provide some criticism regarding their highlights and drawbacks. A small comparative study is also conducted, in order to assess the performance of several penaltybased approaches with respect to a dominancebased technique proposed by the author, and with respect to some mathematical programming approaches. Finally, we provide some guidelines regarding how to select the most appropriate constrainthandling technique for a certain application, ad we conclude with some of the the most promising paths of future research in this area.
The Essence of Constraint Propagation
 CWI QUARTERLY VOLUME 11 (2&3) 1998, PP. 215 { 248
, 1998
"... We show that several constraint propagation algorithms (also called (local) consistency, consistency enforcing, Waltz, ltering or narrowing algorithms) are instances of algorithms that deal with chaotic iteration. To this end we propose a simple abstract framework that allows us to classify and comp ..."


Cited by 89 (6 self)
We show that several constraint propagation algorithms (also called (local) consistency, consistency enforcing, Waltz, ltering or narrowing algorithms) are instances of algorithms that deal with chaotic iteration. To this end we propose a simple abstract framework that allows us to classify and compare these algorithms and to establish in a uniform way their basic properties.
Using Incomplete Quantitative Knowledge in Qualitative Reasoning
 In Proc. of the Sixth National Conference on Artificial Intelligence
, 1988
"... Incomplete knowledge of the structure of mechanisms is an important fact of life in reasoning, commonsense or expert, about the physical world. Qualitative simulation captures an important kind of incomplete, ordinal, knowledge, and predicts the set of qualitatively possible behaviors of a mechanism ..."


Cited by 69 (16 self)
Incomplete knowledge of the structure of mechanisms is an important fact of life in reasoning, commonsense or expert, about the physical world. Qualitative simulation captures an important kind of incomplete, ordinal, knowledge, and predicts the set of qualitatively possible behaviors of a mechanism, given a qualitative description of its structure and initial state. However, one frequently has quantitative knowledge as well as qualitative, though seldom enough to specify a numerical simulation.
Local Search With Constraint Propagation and ConflictBased Heuristics
, 2002
"... Search algorithms for solving CSP (Constraint Satisfaction Problems) usually fall into one of two main families: local search algorithms and systematic algorithms. Both families have their advantages. Designing hybrid approaches seems promising since those advantages may be combined into a single ap ..."


Cited by 65 (17 self)
Search algorithms for solving CSP (Constraint Satisfaction Problems) usually fall into one of two main families: local search algorithms and systematic algorithms. Both families have their advantages. Designing hybrid approaches seems promising since those advantages may be combined into a single approach. In this paper, we present a new hybrid technique. It performs a local search over partial assignments instead of complete assignments, and uses filtering techniques and conflictbased techniques to efficiently guide the search. This new technique benefits from both classical approaches: aprioripruning of the search space from filteringbased search and possible repair of early mistakes from local search. We focus on a specific version of this technique: tabu decisionrepair.Experiments done on openshop scheduling problems show that our approach competes well with the best highly specialized algorithms. 2002 Elsevier Science B.V. All rights reserved.
Consistency Techniques for Continuous Constraints
 Constraints
, 1996
"... We consider constraint satisfaction problemswith variables in continuous,numerical domains. Contrary to most existing techniques, which focus on computing one single optimal solution, we address the problem of computing a compact representation of the space of all solutions admitted by the constrai ..."


Cited by 56 (7 self)
We consider constraint satisfaction problemswith variables in continuous,numerical domains. Contrary to most existing techniques, which focus on computing one single optimal solution, we address the problem of computing a compact representation of the space of all solutions admitted by the constraints. In particular, we show how globally consistent (also called decomposable) labelings of a constraint satisfaction problem can be computed.
Fuzzy Constraints in JobShop Scheduling
 Journal of Intelligent Manufacturing
, 1995
"... : This paper proposes an extension of the constraintbased approach to jobshop scheduling, that accounts for the flexibility of temporal constraints and the uncertainty of operation durations. The set of solutions to a problem is viewed as a fuzzy set whose membership function reflects preference. ..."


Cited by 53 (9 self)
: This paper proposes an extension of the constraintbased approach to jobshop scheduling, that accounts for the flexibility of temporal constraints and the uncertainty of operation durations. The set of solutions to a problem is viewed as a fuzzy set whose membership function reflects preference. This membership function is obtained by an egalitarist aggregation of local constraintsatisfaction levels. Uncertainty is qualitatively described is terms of possibility distributions. The paper formulates a simple mathematical model of jobshop scheduling under preference and uncertainty, relating it to the formal framework of constraintsatisfaction problems in Artificial Intelligence. A combinatorial search method that solves the problem is outlined, including fuzzy extensions of wellknown lookahead schemes. 1. Introduction There are traditionally three kinds of approaches to jobshop scheduling problems: priority rules, combinatorial optimization and constraint analysis. The first kind ...