kirancodes.me
To Proof Maintenance & Beyond!

CrFuzz: fuzzing multi-purpose programs through input validation

Suhwan Song, Chengyu Song, Yeongjin Jang, Byoungyoung Lee

Abstract

Fuzz testing has been proved its effectiveness in discovering software vulnerabilities. Empowered its randomness nature along with a coverage-guiding feature, fuzzing has been identified a vast number of vulnerabilities in real-world programs. This paper begins with an observation that the design of the current state-of-the-art fuzzers is not well suited for a particular (but yet important) set of software programs. Specifically, current fuzzers have limitations in fuzzing programs serving multiple purposes, where each purpose is controlled by extra options.

BibTeX
@inproceedings{Song-al:FSE20,
  author    = {Suhwan Song and
               Chengyu Song and
               Yeongjin Jang and
               Byoungyoung Lee},
  title     = {{CrFuzz:} fuzzing multi-purpose programs through input validation},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {690--700},
  publisher = {{ACM}},
  year      = {2020},
}

Related papers