Fetching the paper…
Reading the bibliography…
Fuzz testing has enjoyed great success at discovering security critical bugs in real software.
A Critique and Improvement of the CL Common Language Effect Size Statistics of McGraw and Wong
András Vargha and Harold D. Delaney. 2000 · 2000
Earlier work this paper cites.
The DaCapo Benchmarks: Java Benchmarking Development and Analysis. In ACM SIGPLAN Conference on Object-oriented Programming Systems, Languages, and Applications (OOPSLA)
Stephen M. Blackburn, Robin Garner, Chris Hoffmann, Asjad M. Khang, Kathryn S. McKinley, Rotem Bentzur, Amer Diwan, Daniel Feinberg, Daniel Frampton, Samuel Z. Guyer, Martin Hirzel, Antony Hosking, Maria Jump, Han Lee, J. Eliot B. Moss, Aashish Phansalkar, Darko Stefanović, Thomas VanDrunen, Daniel von Dincklage, and Ben Wiedermann. 2006 · 2006
Earlier work this paper cites.
Introduction to Statistical Methods and Data Analysis (with CD-ROM)
R. Lyman Ott and Micheal T. Longnecker. 2006 · 2006
Earlier work this paper cites.
Local Restarts. In International Conference on Theory and Applications of Satisfiability Testing (SAT)
Vadim Ryvchin and Ofer Strichman. 2008 · 2008
Earlier work this paper cites.
Dynamic Test Generation to Find Integer Bugs in x86 Binary Linux Programs. In USENIX Security Symposium
David Molnar, Xue Cong Li, and David A. Wagner. 2009 · 2009
Earlier work this paper cites.
Producing Wrong Data Without Doing Anything Obviously Wrong!. In International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS)
Todd Mytkowicz, Amer Diwan, Matthias Hauswirth, and Peter F. Sweeney. 2009 · 2009
Earlier work this paper cites.
A Practical Guide for Using Statistical Tests to Assess Randomized Algorithms in Software Engineering. In International Conference on Software Engineering (ICSE)
Andrea Arcuri and Lionel Briand. 2011 · 2011
Earlier work this paper cites.
Making due with what we have: use your bootstraps
Guillaume Calmettes, Gordon B. Drummond, and Sarah L. Vowler. 2012 · 2012
Earlier work this paper cites.
Unleashing Mayhem on Binary Code. In IEEE Symposium on Security and Privacy (S&P)
Sang Kil Cha, Thanassis Avgerinos, Alexandre Rebert, and David Brumley. 2012 · 2012
Earlier work this paper cites.
Different tests for a difference: how do we research?
Gordon B. Drummond and Sarah L. Vowler. 2012 · 2012
Earlier work this paper cites.
AddressSanitizer: A Fast Address Sanity Checker.. In USENIX Annual Technical Conference
Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitriy Vyukov. 2012 · 2012
Earlier work this paper cites.
Taming Compiler Fuzzers. In ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI)
Yang Chen, Alex Groce, Chaoqiang Zhang, Weng-Keen Wong, Xiaoli Fern, Eric Eide, and John Regehr. 2013 · 2013
Earlier work this paper cites.
Dowsing for Overflows: A Guided Fuzzer to Find Buffer Boundary Violations. In USENIX Security Symposium
Istvan Haller, Asia Slowinska, Matthias Neugschwandtner, and Herbert Bos. 2013 · 2013
Earlier work this paper cites.
Scheduling Black-box Mutational Fuzzing. In ACM SIGSAC Conference on Computer and Communications Security (CCS)
Maverick Woo, Sang Kil Cha, Samantha Gottlieb, and David Brumley. 2013 · 2013
Earlier work this paper cites.
Code Coverage for Suite Evaluation by Developers. In International Conference on Software Engineering (ICSE)
Rahul Gopinath, Carlos Jensen, and Alex Groce. 2014 · 2014
Earlier work this paper cites.
Coverage is Not Strongly Correlated with Test Suite Effectiveness. In International Conference on Software Engineering (ICSE)
Laura Inozemtseva and Reid Holmes. 2014 · 2014
Earlier work this paper cites.
Optimizing Seed Selection for Fuzzing. In USENIX Security Symposium
Alexandre Rebert, Sang Kil Cha, Thanassis Avgerinos, Jonathan Foote, David Warren, Gustavo Grieco, and David Brumley. 2014 · 2014
Earlier work this paper cites.
Program-Adaptive Mutational Fuzzing. In IEEE Symposium on Security and Privacy (S&P)
Sang Kil Cha, Maverick Woo, and David Brumley. 2015 · 2015
Earlier work this paper cites.
What is a bug?
Michael Hicks. 2015 · 2015
Earlier work this paper cites.
Turning Programs Against Each Other: High Coverage Fuzz-testing Using Binary-code Mutation and Dynamic Slicing. In Foundations of Software Engineering (FSE)
Ulf Kargén and Nahid Shahmehri. 2015 · 2015
Cited alongside, same era.
Code coverage and test suite effectiveness: Empirical study with real bugs in large systems. In IEEE International Conference on Software Analysis, Evolution, and Reengineering (SANER)
P. S. Kochhar, F. Thung, and D. Lo. 2015 · 2015
Cited alongside, same era.
Browser fuzzing by scheduled mutation and generation of document object models. In International Carnahan Conference on Security Technology
Ying-Dar Lin, Feng-Ze Liao, Shih-Kun Huang, and Yuan-Cheng Lai. 2015 · 2015
Cited alongside, same era.
Coverage-based Greybox Fuzzing As Markov Chain. In ACM SIGSAC Conference on Computer and Communications Security (CCS)
Marcel Böhme, Van-Thuan Pham, and Abhik Roychoudhury. 2016 · 2016
Cited alongside, same era.
Static Program Analysis as a Fuzzing Aid. In Research in Attacks, Intrusions, and Defenses (RAID)
Bhargava Shastry, Markus Leutner, Tobias Fiebig, Kashyap Thimmaraju, Fabian Yamaguchi, Konrad Rieck, Stefan Schmid, Jean-Pierre Seifert, and Anja Feldmann. 2017 · 2017
Later among the works it cites.
Skyfire: Data-Driven Seed Generation for Fuzzing. In IEEE Symposium on Security and Privacy (S&P)
Junjie Wang, Bihuan Chen, Lei Wei, and Yang Liu. 2017 · 2017
Later among the works it cites.
Designing New Operating Primitives to Improve Fuzzing Performance. In ACM SIGSAC Conference on Computer and Communications Security (CCS)
Wen Xu, Sanidhya Kashyap, Changwoo Min, and Taesoo Kim. 2017 · 2017
Later among the works it cites.
S2F: Discover Hard-to-Reach Vulnerabilities by Semi-Symbolic Fuzz Testing. In International Conference on Computational Intelligence and Security
Bin Zhang, Jiaxi Ye, Chao Feng, and Chaojing Tang. 2017 · 2017
Later among the works it cites.
A hybrid symbolic execution assisted fuzzing method. In IEEE Region 10 Conference (TENCON)
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Brendan Dolan-Gavitt, Patrick Hulin, Engin Kirda, Tim Leek, Andrea Mambretti, William K. Robertson, Frederick Ulrich, and Ryan Whelan. 2016 · 2016
Cited alongside, same era.
QuickFuzz: an automatic random fuzzer for common file formats. In International Symposium on Haskell
Gustavo Grieco, Martín Ceresa, and Pablo Buiras. 2016 · 2016
Cited alongside, same era.
Driller: Augmenting Fuzzing Through Selective Symbolic Execution.. In Network and Distributed System Security Symposium (NDSS)
Nick Stephens, John Grosen, Christopher Salls, Andrew Dutcher, Ruoyu Wang, Jacopo Corbetta, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2016 · 2016
Cited alongside, same era.
SeededFuzz: Selecting and Generating Seeds for Directed Fuzzing. In International Symposium on Theoretical Aspects of Software Engineering (TASE)
Weiguang Wang, Hao Sun, and Qingkai Zeng. 2016 · 2016
Cited alongside, same era.
Grammar-based adaptive fuzzing: Evaluation on SCADA modbus protocol. In IEEE International Conference on Smart Grid Communications
Hyunguk Yoo and Taeshik Shon. 2016 · 2016
Cited alongside, same era.
Directed Greybox Fuzzing. In ACM SIGSAC Conference on Computer and Communications Security (CCS)
Marcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, and Abhik Roychoudhury. 2017 · 2017
Cited alongside, same era.
DIFUZE: Interface Aware Fuzzing for Kernel Drivers. In ACM SIGSAC Conference on Computer and Communications Security (CCS)
Jake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili, Shuang Hao, Christopher Kruegel, and Giovanni Vigna. 2017 · 2017
Cited alongside, same era.
QuickFuzz Testing for Fun and Profit
Gustavo Grieco, Martn Ceresa, Agustn Mista, and Pablo Buiras. 2017 · 2017
Cited alongside, same era.
L. Zhang and V. L. L. Thing. 2017 · 2017
Later among the works it cites.
American Fuzzing Lop (AFL)
AFL 2018 · 2018
Closest in time.
CERT Basic Fuzzing Framework (BFF)
BFF 2018 · 2018
Closest in time.
Angora: Efficient Fuzzing by Principled Search. In IEEE Symposium on Security and Privacy (S&P)
Peng Chen and Hao Chen. 2018 · 2018
Closest in time.
Confidence Intervals for a Median
ConfIntv 2018 · 2018
Closest in time.
Darpa Cyber Grand Challenge (CGC) Binaries
DARPA CGC 2018 · 2018
Closest in time.
Of Bugs and Baselines
Brendan Dolan-Gavitt. 2018 · 2018
Closest in time.
Fuzzer Test Suite
FuzzerTestSuite 2018 · 2018
Closest in time.
Enhancing Memory Error Detection for Large-Scale Applications and Fuzz Testing. In Network and Distributed System Security Symposium (NDSS)
Wookhyun Han, Byunggill Joe, Byoungyoung Lee, Chengyu Song, and Insik Shin. 2018 · 2018
Closest in time.
AFL quick start guide
lcamtuf. 2018 · 2018
Closest in time.
FairFuzz: A Targeted Mutation Strategy for Increasing Greybox Fuzz Testing Coverage
Caroline Lemieux and Koushik Sen. 2018 · 2018
Closest in time.
libFuzzer
libFuzzer 2018 · 2018
Closest in time.
T-Fuzz: fuzzing by program transformation. In IEEE Symposium on Security and Privacy (S&P)
Hui Peng, Yan Shoshitaishvili, and Mathias Payer. 2018 · 2018
Closest in time.
Semantic Crash Bucketing. In IEEE International Conference on Automated Software Engineering (ASE)
Rijnard van Tonder, John Kotheimer, and Claire Le Goues. 2018 · 2018
Closest in time.