Publication | Open Access
Evocatio
16
Citations
29
References
2022
Year
Software MaintenanceEngineeringRoot CauseSoftware EngineeringSource Code AnalysisSoftware AnalysisHardware SecuritySystems EngineeringFuzzingComputer EngineeringComputer ScienceDebuggerStatic Program AnalysisAutomated RepairSoftware DesignProgram AnalysisSoftware TestingSecurity-critical BugsCoverage-guided Greybox FuzzersSystem Software
The popularity of coverage-guided greybox fuzzers has led to a tsunami of security-critical bugs that developers must prioritize and fix. Knowing the capabilities a bug exposes (e.g., type of vulnerability, number of bytes read/written) enables prioritization of bug fixes. Unfortunately, understanding a bug's capabilities is a time consuming process, requiring (a) an understanding of the bug's root cause, (b) an understanding how an attacker may exploit the bug, and (c) the development of a patch mitigating these threats. This is a mostly-manual process that is qualitative and arbitrary, potentially leading to a misunderstanding of the bug's capabilities.
| Year | Citations | |
|---|---|---|
Page 1
Page 1