Fetching the paper…
Reading the bibliography…
Continuous fuzzing is an increasingly popular technique for automated quality and security assurance.
N. E.-S. J. Gould and N. Eldredge, “Punctuated equilibria: An alternative to phyletic gradualism,” Essential readings in evolutionary biology , pp. 82–115, 1972
1972
Earlier work this paper cites.
J. H. Saltzer and M. D. Schroeder, “The protection of information in computer systems,” Proceedings of the IEEE , vol. 63, no. 9, pp. 1278–1308, 1975
1975
Earlier work this paper cites.
B. P. Miller, L. Fredriksen, and B. So, “An empirical study of the reliability of UNIX utilities,” Communications of the ACM , vol. 33, no. 12, pp. 32–44, 1990
1990
Earlier work this paper cites.
M. D. Vose and G. E. Liepins, “Punctuated equilibria in genetic search,” Complex Systems , vol. 5, no. 1, pp. 31–44, 1991
1991
Earlier work this paper cites.
A. I. Antón and C. Potts, “Functional paleontology: System evolution as the user sees it,” in International Conference on Software Engineering. , ser. ICSE ’01, 2001
2001
Earlier work this paper cites.
A. Gorshenev and Y. M. Pis’mak, “Punctuated equilibrium in software evolution,” Physical Review E , vol. 70, no. 6, p. 067103, 2004
2004
Earlier work this paper cites.
P. Oehlert, “Violating assumptions with fuzzing,” IEEE Security & Privacy , vol. 3, no. 2, pp. 58–62, 2005
2005
Earlier work this paper cites.
M. Sutton and A. Greene, “The art of file format fuzzing,” in Blackhat USA , 2005
2005
Earlier work this paper cites.
J. Wu, “Open source software evolution and its dynamics,” Ph.D. dissertation, University of Waterloo, 2006
2006
Earlier work this paper cites.
Z. Li, L. Tan, X. Wang, S. Lu, Y. Zhou, and C. Zhai, “Have things changed now? An empirical study of bug characteristics in modern open source software,” in Workshop on Architectural and System Support for Improving Software Dependability , ser. ASID ’06, 2006
2006
Earlier work this paper cites.
S. Frei, M. May, U. Fiedler, and B. Plattner, “Large-scale vulnerability analysis,” in Workshop on Large-scale Attack Defense , ser. LSAD ’06, 2006
2006
Earlier work this paper cites.
S. Christey and R. A. Martin, “Vulnerability type distributions in CVE,” https://cwe.mitre.org/documents/vuln-trends/vuln-trends.pdf , MITRE, Tech. Rep., 2007
2007
Earlier work this paper cites.
K. Serebryany and T. Iskhodzhanov, “ThreadSanitizer: data race detection in practice,” in Workshop on Binary Instrumentation and Applications , ser. WBIA ’09, 2009
2009
Earlier work this paper cites.
P. J. Guo, T. Zimmermann, N. Nagappan, and B. Murphy, “Characterizing and predicting which bugs get fixed: An empirical study of Microsoft Windows,” in International Conference on Software Engineering , ser. ICSE ’10, 2010
2010
Earlier work this paper cites.
S. Neuhaus and T. Zimmermann, “Security trend analysis with CVE topic models,” in International Symposium on Software Reliability Engineering , ser. ISSRE ’10, 2010
2010
Earlier work this paper cites.
——, “Security versus performance bugs: A case study on Firefox,” in Conference on Mining Software Repositories , ser. MSR ’11, 2011
2011
Earlier work this paper cites.
K. Serebryany, D. Bruening, A. Potapenko, and D. Vyukov, “AddressSanitizer: A fast address sanity checker,” in USENIX Annual Technical Conference , ser. USENIX ATC ’12, 2012
2012
Earlier work this paper cites.
B. Liu, L. Shi, Z. Cai, and M. Li, “Software vulnerability discovery techniques: A survey,” in International Conference on Multimedia Information Networking and Security , ser. ICMINS ’12. IEEE, 2012
2012
Earlier work this paper cites.
M. Shahzad, M. Z. Shafiq, and A. X. Liu, “A large scale exploratory analysis of software vulnerability life cycles,” in International Conference on Software Engineering , ser. ICSE ’12, 2012
2012
Earlier work this paper cites.
F. Zhang, F. Khomh, Y. Zou, and A. E. Hassan, “An empirical study on factors impacting bug fixing time,” in Working Conference on Reverse Engineering , ser. WCRE ’12, 2012
2012
Earlier work this paper cites.
C. Holler, K. Herzig, and A. Zeller, “Fuzzing with code fragments,” in USENIX Security Symposium , 2012
2012
Earlier work this paper cites.
S. Zaman, B. Adams, and A. E. Hassan, “A qualitative study on performance bugs,” in Conference on Mining Software Repositories , ser. MSR ’12, 2012
2012
Earlier work this paper cites.
I. Haller, A. Slowinska, M. Neugschwandtner, and H. Bos, “Dowser: A guided fuzzer to find buffer overflow vulnerabilities,” in USENIX Security Symposium , 2013
2013
Earlier work this paper cites.
M. Carvalho, J. DeMott, R. Ford, and D. A. Wheeler, “Heartbleed 101,” IEEE Security & Privacy , vol. 12, no. 4, pp. 63–67, 2014
2014
Earlier work this paper cites.
M. E. Joorabchi, M. Mirzaaghaei, and A. Mesbah, “Works for me! Characterizing non-reproducible bug reports,” in Mining Software Repositories , ser. MSR ’14, 2014
2014
Earlier work this paper cites.
Q. Luo, F. Hariri, L. Eloussi, and D. Marinov, “An empirical analysis of flaky tests,” in Symposium on Foundations of Software Engineering , ser. FSE ’14, 2014
2014
Earlier work this paper cites.
R. K. Saha, S. Khurshid, and D. E. Perry, “An empirical study of long lived bugs,” in Conference on Software Maintenance, Reengineering, and Reverse Engineering , ser. CSMR-WCRE ’14, 2014
2014
Earlier work this paper cites.
T.-H. Chen, M. Nagappan, E. Shihab, and A. E. Hassan, “An empirical study of dormant bugs,” in Mining Software Repositories , ser. MSR ’14, 2014
2014
Earlier work this paper cites.
E. Stepanov and K. Serebryany, “MemorySanitizer: fast detector of uninitialized memory use in C++,” in International Symposium on Code Generation and Optimization , ser. CGO ’15, 2015
2015
Earlier work this paper cites.
C. Evans, B. Hawkes, H. Adkins, M. Moore, M. Zalewski, and G. Eschelbeck, “Feedback and data-driven updates to Google’s disclosure policy,” https://googleprojectzero.blogspot.com/2015/02/feedback-and-data-driven-updates-to.html , 2015
2015
Earlier work this paper cites.
S. Sidiroglou-Douskos, E. Lahtinen, N. Rittenhouse, P. Piselli, F. Long, D. Kim, and M. Rinard, “Targeted automatic integer overflow discovery using goal-directed conditional branch enforcement,” in International Conference on Architectural Support for Programming Languages and Operating Systems , ser. ASPLOS ’15, 2015
2015
Earlier work this paper cites.
Z. Sialveras and N. Naziridis, “Introducing Choronzon: An approach at knowledge-based evolutionary fuzzing,” in ZeroNights , 2015
2015
Earlier work this paper cites.
M. Mouzarani, B. Sadeghiyan, and M. Zolfaghari, “Smart fuzzing method for detecting stack-based buffer overflow in binary codes,” IET Software , vol. 10, no. 4, pp. 96–107, 2016
2016
Cited alongside, same era.
K. Serebryany, “OSS-Fuzz — Google’s continuous fuzzing service for open source software,” in USENIX Security Symposium , 2017
2017
Cited alongside, same era.
F. Li and V. Paxson, “A large scale empirical study of security patches,” in Conference on Computer and Communications Security , ser. CCS ’17, 2017
2017
Cited alongside, same era.
T. Petsios, J. Zhao, A. D. Keromytis, and S. Jana, “SlowFuzz: Automated domain-independent detection of algorithmic complexity vulnerabilities,” in Conference on Computer and Communications Security , ser. CCS ’17, 2017
2017
Cited alongside, same era.
X. Jia, C. Zhang, P. Su, Y. Yang, H. Huang, and D. Feng, “Towards efficient heap overflow discovery,” in USENIX Security Symposium , 2017
K. Serebryany, D. Drysdale, C. Lopez, and M. Moroz, “Why fuzz?” https://github.com/google/fuzzing/blob/c4458cc2afa4c23f42190611f2172e0211171bbf/docs/why-fuzz.md , 2020
2020
Later among the works it cites.
P. Godefroid, “Fuzzing: Hack, art, and science,” Communications of the ACM , vol. 63, no. 2, pp. 70–76, 2020
2020
Later among the works it cites.
A. Zeller, R. Gopinath, M. Böhme, G. Fraser, and C. Holler, “Fuzzing: Breaking things with random inputs,” in The Fuzzing Book . Saarland University, 2020
2020
Later among the works it cites.
B. Liu, G. Meng, W. Zou, Q. Gong, F. Li, M. Lin, D. Sun, W. Huo, and C. Zhang, “A large-scale empirical study on vulnerability distribution within projects and the lessons learned,” in International Conference on Software Engineering , ser. ICSE ’20, 2020
2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2017
Cited alongside, same era.
O. Bastani, R. Sharma, A. Aiken, and P. Liang, “Synthesizing program input grammars,” in Conference on Programming Language Design and Implementation , ser. PLDI ’17, 2017
2017
Cited alongside, same era.
S. Schumilo, C. Aschermann, R. Gawlik, S. Schinzel, and T. Holz, “kAFL: Hardware-assisted feedback fuzzing for OS kernels,” in USENIX Security Symposium , 2017
2017
Cited alongside, same era.
A. Takanen, J. D. Demott, C. Miller, and A. Kettunen, Fuzzing for software security testing and quality assurance . Artech House, 2018
2018
Cited alongside, same era.
J. Li, B. Zhao, and C. Zhang, “Fuzzing: A survey,” Cybersecurity , vol. 1, no. 1, p. 6, 2018
2018
Cited alongside, same era.
C. Lemieux, R. Padhye, K. Sen, and D. Song, “PerfFuzz: Automatically generating pathological inputs,” in International Symposium on Software Testing and Analysis , ser. ISSTA ’18, 2018
2018
Cited alongside, same era.
S. Gan, C. Zhang, X. Qin, X. Tu, K. Li, Z. Pei, and Z. Chen, “CollAFL: Path sensitive fuzzing,” in Symposium on Security and Privacy , ser. S&P ’18, 2018
2018
Cited alongside, same era.
P. Chen and H. Chen, “Angora: Efficient fuzzing by principled search,” in Symposium on Security and Privacy , ser. S&P ’18, 2018
2018
Cited alongside, same era.
W. Blair, A. Mambretti, S. Arshad, M. Weissbacher, W. Robertson, E. Kirda, and M. Egele, “Hotfuzz: Discovering algorithmic denial-of-service vulnerabilities through guided micro-fuzzing,” in Network and Distributed Systems Security , ser. NDSS ’20, 2020
2020
Later among the works it cites.
C. Wen, H. Wang, Y. Li, S. Qin, Y. Liu, Z. Xu, H. Chen, X. Xie, G. Pu, and T. Liu, “Memlock: Memory usage guided fuzzing,” in International Conference on Software Engineering , ser. ICSE ’20, 2020
2020
Later among the works it cites.
A. Fioraldi, D. Daniele Cono, and L. Querzoni, “Fuzzing binaries for memory safety errors with QASan,” in Secure Development Conference , ser. SecDev ’20, 2020
2020
Later among the works it cites.
C. Holler, “The human component in bug finding,” in FuzzCon Europe , 2020
2020
Later among the works it cites.
https://github.com/google/clusterfuzz/blob/0b5c023eca9e3aac41faba17da8f341c0ca2ddc7/src/appengine/handlers/cron/cleanup.py , 2020
2020
Later among the works it cites.
“Z3Prover/z3 issue no. 4461,” https://github.com/Z3Prover/z3/issues/4461 , accessed December, 2020
2020
Later among the works it cites.
https://cve.mitre.org/data/downloads/allitems.csv , accessed October, 2020
2020
Later among the works it cites.
M. Morehouse and M. Kaplan, “libFuzzer tutorial,” https://github.com/google/fuzzing/blob/aeaafab3dd557ed050a0c1c659b7caa6899e89dc/tutorial/libFuzzerTutorial.md , 2020
2020
Later among the works it cites.
M. Böhme and B. Falk, “Fuzzing: On the exponential cost of vulnerability discovery,” in Joint Meeting of the European Software Engineering Conference and Symposium on the Foundations of Software Engineering , ser. ESEC/FSE ’20, 2020
2020
Later among the works it cites.
D. She, R. Krishna, L. Yan, S. Jana, and B. Ray, “MTFuzz: Fuzzing with a multi-task neural network,” in Joint Meeting of the European Software Engineering Conference and the Symposium on the Foundations of Software Engineering , ser. ESEC/FSE ’20, 2020
2020
Later among the works it cites.
X. Zhu, X. Feng, X. Meng, S. Wen, S. Camtepe, Y. Xiang, and K. Ren, “CSI-Fuzz: Full-speed edge tracing using coverage sensitive instrumentation,” IEEE Transactions on Dependable and Secure Computing (to appear) , 2020
2020
Later among the works it cites.
M. Böhme, V. J. Manès, and S. K. Cha, “Boosting fuzzer efficiency: An information theoretic perspective,” in Joint Meeting of the European Software Engineering Conference and Symposium on the Foundations of Software Engineering , ser. ESEC/FSE ’20, 2020
2020
Later among the works it cites.
S. Song, C. Song, Y. Jang, and B. Lee, “CrFuzz: Fuzzing multi-purpose programs through input validation,” in Joint Meeting of the European Software Engineering Conference and Symposium on the Foundations of Software Engineering , ser. ESEC/FSE ’20, 2020
2020
Later among the works it cites.
S. Gan, C. Zhang, P. Chen, B. Zhao, X. Qin, D. Wu, and Z. Chen, “Greyone: Data flow sensitive fuzzing,” in USENIX Security Symposium , 2020
2020
Later among the works it cites.
M. Verdi, A. Sami, J. Akhondali, F. Khomh, G. Uddin, and A. K. Motlagh, “An empirical study of C++ vulnerabilities in crowd-sourced code examples,” IEEE Transactions on Software Engineering (to appear) , 2020
2020
Later among the works it cites.
W. Lam, K. Muşlu, H. Sajnani, and S. Thummalapenta, “A study on the lifecycle of flaky tests,” in International Conference on Software Engineering , ser. ICSE ’20, 2020
2020
Later among the works it cites.
“ClusterFuzz,” google.github.io/clusterfuzz , accessed January, 2021
2021
Closest in time.
“Mayhem,” www.forallsecure.com/mayhem , accessed January, 2021
2021
Closest in time.
“american fuzzy lop,” https://github.com/google/AFL , accessed January, 2021
2021
Closest in time.
“libFuzzer — a library for coverage-guided fuzz testing,” https://www.llvm.org/docs/LibFuzzer.html , accessed January, 2021
2021
Closest in time.
“honggfuzz,” https://honggfuzz.dev , accessed January, 2021
2021
Closest in time.
“Bug disclosure guidelines,” https://google.github.io/oss-fuzz/getting-started/bug-disclosure-guidelines/#bug-disclosure-guidelines , accessed January, 2021
2021
Closest in time.
“SeleniumHQ browser automation,” https://www.selenium.dev/ , accessed January, 2021
2021
Closest in time.
“robots.txt,” https://bugs.chromium.org/robots.txt , accessed January, 2021
2021
Closest in time.
“Common vulnerabilities and exposures,” https://cve.mitre.org/ , MITRE, accessed January, 2021
2021
Closest in time.
“Fixing a bug,” https://google.github.io/clusterfuzz/using-clusterfuzz/workflows/fixing-a-bug/ , accessed January, 2021
2021
Closest in time.
“2020 CWE top 25 most dangerous software weaknesses,” https://cwe.mitre.org/top25/archive/2020/2020_cwe_top25.html , 2020, accessed January, 2021
2021
Closest in time.