This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Soot (software) | |
|---|---|
| Name | Soot |
| Title | Soot |
| Developer | Sable Research Group |
| Released | 1999 |
| Programming language | Java |
| Operating system | Cross-platform |
| License | LGPL |
Soot (software) is a Java analysis and transformation framework originally developed by the Sable Research Group for static analysis, optimization, and program transformation of Java bytecode. It provides intermediate representations, whole-program analysis, and plugin interfaces used in research and industry projects across static analysis, security, and compiler construction. Soot integrates with many projects and tools in the programming languages and software engineering ecosystems.
Soot traces its origins to research at the University of Edinburgh, the University of Melbourne, and the Sable Research Group, with influential contributors affiliated with McGill University, Rice University, University of California, Berkeley, Massachusetts Institute of Technology, and Princeton University. It targets the Java (programming language), Android (operating system), and bytecode produced by compilers such as Eclipse (software), NetBeans, and IntelliJ IDEA. Soot is often compared or used alongside frameworks like JVM, Dalvik (software), ART (Android Runtime), WALA, ASM (library), BCEL, and ProGuard. Notable research citing Soot intersects with projects at Microsoft Research, Google, IBM Research, Facebook (Meta Platforms, Inc.) and labs at Stanford University, Carnegie Mellon University, and University of Cambridge.
Soot’s architecture comprises multiple intermediate representations influenced by compiler research from Donald Knuth, Edsger W. Dijkstra, John Backus, and curriculum at University of Toronto. The framework implements representations such as Baf, Jimple, Shimple, and Grimp, reflecting design patterns similar to those in LLVM and GCC. Soot’s pipeline supports front-ends and back-ends that interoperate with ecosystems including Apache Software Foundation projects, Eclipse Foundation initiatives, and tools developed at National Institute of Standards and Technology (NIST). The project emphasizes modularity and extensibility, employing plugin models similar to Maven and Gradle build systems, and integrates with development environments such as Eclipse (software), Visual Studio Code, and IntelliJ IDEA.
Soot supports data-flow analysis, control-flow analysis, call-graph construction, pointer analysis, and interprocedural analyses drawing on methods from researchers at Bell Labs, AT&T Research, and universities like University of Illinois Urbana–Champaign and Cornell University. It enables null-pointer analysis, taint analysis, symbolic execution integration referencing work at University of California, San Diego, and security analyses used in studies by OWASP and CERT. Soot’s call graph and alias analysis implementations relate to algorithms from scholars such as Patrick Cousot, Thomas Reps, and Mansour Maamoun. Soot has been extended for Android-specific analyses integrating with projects at Google LLC, Xiaomi, Samsung Electronics, and research from Imperial College London.
Soot is commonly invoked via command-line interfaces and integrated into build pipelines using Apache Maven, Gradle, and continuous integration services like Jenkins, Travis CI, and GitHub Actions. Tooling around Soot includes wrappers and GUIs developed in collaboration with contributors at Oracle Corporation, Red Hat, and SAP SE, and is used in conjunction with static analyzers such as FindBugs, SpotBugs, PMD, and Checkstyle. Researchers leveraging Soot have published benchmarks at venues including PLDI, POPL, ICSE, FSE, CCS, and Usenix Security.
Soot’s performance characteristics have been evaluated in comparative studies alongside Soot competitors and frameworks such as WALA, LLVM, and GCC front-ends. It scales to large codebases from organizations like Facebook (Meta Platforms, Inc.), Google LLC, and Amazon (company), with engineering patterns borrowed from production systems at Netflix, LinkedIn, and Twitter (X) for incremental analysis and caching. Optimizations in Soot correlate with techniques from high-performance computing centers such as Lawrence Berkeley National Laboratory and Los Alamos National Laboratory for memory management and parallel processing using frameworks like Apache Spark and Hadoop.
Soot has been used in academic and industrial case studies including vulnerability discovery in applications by teams at CERT Coordination Center, malware analysis in collaborations with Kaspersky Lab and Symantec, and energy-efficient code analysis in projects at NASA and European Space Agency. It has supported research at conferences hosted by organizations such as ACM and IEEE, and has been cited in work from laboratories at MIT Lincoln Laboratory, Fraunhofer Society, and CNRS. Industry adopters and academic users have applied Soot for program slicing, refactoring, deobfuscation, and provenance analysis in settings from startups incubated at Y Combinator to enterprise groups within Siemens and Bosch.
Soot is distributed under the GNU Lesser General Public License (LGPL) and maintained by contributors across academic institutions and companies including the Sable Research Group, with code hosting and issue tracking commonly on platforms such as GitHub, GitLab, and SourceForge. The community engages through mailing lists, workshops at POPL, PLDI, and ESEC/FSE, and collaborations with organizations like ACM SIGPLAN and IEEE Computer Society. Ongoing development receives contributions from researchers affiliated with University of Waterloo, McMaster University, University of British Columbia, and industrial engineers from Intel, AMD, and Qualcomm.
Category:Static program analysis tools