IEEE Transactions on Software Engineering · 2019 · 72 citations · 166 references
EngineeringSoftware SystemsSoftware EngineeringSimulationSource Code AnalysisSoftware AnalysisModel FuzzerReliability EngineeringSystems EngineeringBinary AnalysisFuzzingCompilersTest GenerationProgramming LanguagesStatic AnalysisComputer EngineeringComputer ScienceStatic Program AnalysisProgram AnalysisSoftware TestingTechniques Available TodayFault InjectionCurrent Fuzzing Literature
Among the many software testing techniques available today, <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">fuzzing</i> has remained highly popular due to its conceptual simplicity, its low barrier to deployment, and its vast amount of empirical evidence in discovering real-world software vulnerabilities. At a high level, fuzzing refers to a process of repeatedly running a program with generated inputs that may be syntactically or semantically malformed. While researchers and practitioners alike have invested a large and diverse effort towards improving fuzzing in recent years, this surge of work has also made it difficult to gain a comprehensive and coherent view of fuzzing. To help preserve and bring coherence to the vast literature of fuzzing, this paper presents a unified, general-purpose model of fuzzing together with a taxonomy of the current fuzzing literature. We methodically explore the design decisions at every stage of our model fuzzer by surveying the related literature and innovations in the art, science, and engineering that make modern-day fuzzers effective.
166
Chi-Keung Luk, Robert Cohn, Robert Muth et al. · ACM SIGPLAN Notices · 2005 · 3.2K citations
Engineering, Computer Architecture, Software Engineering +16
Symbolic execution and program testing
James C. King · Communications of the ACM · 1976 · 2.9K citations · Full text
Chi-Keung Luk, Robert Cohn, Robert Muth et al. · 2005 · 2.3K citations
Engineering, Computer Architecture, Software Engineering +16