A Review of Fuzz Testing for Configuration-Sensitive Software

Lang Chu, Minhuan Huang, Xiang Li, Yuanping Nie · 2024

In the real world, many software systems come with numerous configuration options, which play a crucial role in their operation. These configurations not only provide flexibility and customization to the software's functionality but also largely determine the security boundaries during actual runtime. Many security vulnerabilities only manifest in specific configuration environments. Fuzz testing, a widely recognized security testing approach, has revealed numerous security vulnerabilities in various software systems, demonstrating its practical value in vulnerability detection. In the practice of fuzz testing, comprehensive consideration of the diversity of software configurations is essential for expanding test coverage and uncovering deep-seated vulnerabilities triggered only under specific configurations. This is a key strategy for enhancing the effectiveness of fuzz testing. This paper reviews the techniques for handling software configurations in fuzz testing research. Firstly, we introduce the relevant work on software configurations and software security testing. Then, we summarize several representative tools and frameworks capable of fuzzing both configurations and inputs simultaneously, analyzing their strengths and limitations. Finally, we discuss the challenges and future directions in fuzz testing concerning configuration handling.

Read the paper · More papers on PaperTik