The Fuzzing Hype-Train: How Random Testing Triggers Thousands of Crashes

Mathias Payer · IEEE Security & Privacy · 2019

Software contains bugs, and some bugs are exploitable. Mitigations protect our systems in the presence of these vulnerabilities, often stopping the program once a security violation has been detected. The alternative is to discover bugs during development and fix them in the code. The task of finding and reproducing bugs is difficult; however, fuzzing is an efficient way to find security-critical bugs by triggering exceptions, such as crashes, memory corruption, or assertion failures automatically (or with a little help). Furthermore, fuzzing comes with a witness (proof of the vulnerability) that enables developers to reproduce the bug and fix it.

Read the paper · More papers on PaperTik