Matches in SemOpenAlex for { <https://semopenalex.org/work/W157156687> ?p ?o ?g. }
- W157156687 abstract "Fuzz testing is an effective technique for finding security vulnerabilities in software. Traditionally, fuzz testing tools apply random mutations to well-formed inputs of a program and test the resulting values. We present an alternative whitebox fuzz testing approach inspired by recent advances in symbolic execution and dynamic test generation. Our approach records an actual run of the program under test on a well-formed input, symbolically evaluates the recorded trace, and gathers constraints on inputs capturing how the program uses these. The collected constraints are then negated one by one and solved with a constraint solver, producing new inputs that exercise different control paths in the program. This process is repeated with the help of a code-coverage maximizing heuristic designed to find defects as fast as possible. We have implemented this algorithm in SAGE (Scalable, Automated, Guided Execution), a new tool employing x86 instruction-level tracing and emulation for whitebox fuzzing of arbitrary file-reading Windows applications. We describe key optimizations needed to make dynamic test generation scale to large input files and long execution traces with hundreds of millions of instructions. We then present detailed experiments with several Windows applications. Notably, without any format-specific knowledge, SAGE detects the MS07-017 ANI vulnerability, which was missed by extensive blackbox fuzzing and static analysis tools. Furthermore, while still in an early stage of development, SAGE has already discovered 30+ new bugs in large shipped Windows applications including image processors, media players, and file decoders. Several of these bugs are potentially exploitable memory access violations." @default.
- W157156687 created "2016-06-24" @default.
- W157156687 creator A5004549231 @default.
- W157156687 creator A5069392259 @default.
- W157156687 creator A5074105893 @default.
- W157156687 date "2008-11-01" @default.
- W157156687 modified "2023-10-03" @default.
- W157156687 title "Automated Whitebox Fuzz Testing." @default.
- W157156687 cites W108689914 @default.
- W157156687 cites W1512013758 @default.
- W157156687 cites W1536898727 @default.
- W157156687 cites W1550112417 @default.
- W157156687 cites W1582456956 @default.
- W157156687 cites W175329226 @default.
- W157156687 cites W1972429847 @default.
- W157156687 cites W200765967 @default.
- W157156687 cites W2009007001 @default.
- W157156687 cites W2009489720 @default.
- W157156687 cites W2096449544 @default.
- W157156687 cites W2098115125 @default.
- W157156687 cites W2101512909 @default.
- W157156687 cites W2104993088 @default.
- W157156687 cites W2107794009 @default.
- W157156687 cites W2117058582 @default.
- W157156687 cites W2118915305 @default.
- W157156687 cites W2132897303 @default.
- W157156687 cites W2133612077 @default.
- W157156687 cites W2135023759 @default.
- W157156687 cites W2138721431 @default.
- W157156687 cites W2146280225 @default.
- W157156687 cites W2156858199 @default.
- W157156687 cites W2165100126 @default.
- W157156687 cites W82260615 @default.
- W157156687 hasPublicationYear "2008" @default.
- W157156687 type Work @default.
- W157156687 sameAs 157156687 @default.
- W157156687 citedByCount "395" @default.
- W157156687 countsByYear W1571566872012 @default.
- W157156687 countsByYear W1571566872013 @default.
- W157156687 countsByYear W1571566872014 @default.
- W157156687 countsByYear W1571566872015 @default.
- W157156687 countsByYear W1571566872016 @default.
- W157156687 countsByYear W1571566872017 @default.
- W157156687 countsByYear W1571566872018 @default.
- W157156687 countsByYear W1571566872019 @default.
- W157156687 countsByYear W1571566872020 @default.
- W157156687 countsByYear W1571566872021 @default.
- W157156687 countsByYear W1571566872022 @default.
- W157156687 countsByYear W1571566872023 @default.
- W157156687 crossrefType "proceedings-article" @default.
- W157156687 hasAuthorship W157156687A5004549231 @default.
- W157156687 hasAuthorship W157156687A5069392259 @default.
- W157156687 hasAuthorship W157156687A5074105893 @default.
- W157156687 hasConcept C1009929 @default.
- W157156687 hasConcept C111065885 @default.
- W157156687 hasConcept C11219265 @default.
- W157156687 hasConcept C149810388 @default.
- W157156687 hasConcept C162324750 @default.
- W157156687 hasConcept C170723468 @default.
- W157156687 hasConcept C199360897 @default.
- W157156687 hasConcept C2777904410 @default.
- W157156687 hasConcept C2779639559 @default.
- W157156687 hasConcept C41008148 @default.
- W157156687 hasConcept C50522688 @default.
- W157156687 hasConcept C53942775 @default.
- W157156687 hasConcept C97686452 @default.
- W157156687 hasConceptScore W157156687C1009929 @default.
- W157156687 hasConceptScore W157156687C111065885 @default.
- W157156687 hasConceptScore W157156687C11219265 @default.
- W157156687 hasConceptScore W157156687C149810388 @default.
- W157156687 hasConceptScore W157156687C162324750 @default.
- W157156687 hasConceptScore W157156687C170723468 @default.
- W157156687 hasConceptScore W157156687C199360897 @default.
- W157156687 hasConceptScore W157156687C2777904410 @default.
- W157156687 hasConceptScore W157156687C2779639559 @default.
- W157156687 hasConceptScore W157156687C41008148 @default.
- W157156687 hasConceptScore W157156687C50522688 @default.
- W157156687 hasConceptScore W157156687C53942775 @default.
- W157156687 hasConceptScore W157156687C97686452 @default.
- W157156687 hasLocation W1571566871 @default.
- W157156687 hasOpenAccess W157156687 @default.
- W157156687 hasPrimaryLocation W1571566871 @default.
- W157156687 hasRelatedWork W1480909796 @default.
- W157156687 hasRelatedWork W1497028280 @default.
- W157156687 hasRelatedWork W1710734607 @default.
- W157156687 hasRelatedWork W2002934700 @default.
- W157156687 hasRelatedWork W2009489720 @default.
- W157156687 hasRelatedWork W2065948900 @default.
- W157156687 hasRelatedWork W2096449544 @default.
- W157156687 hasRelatedWork W2101512909 @default.
- W157156687 hasRelatedWork W2104993088 @default.
- W157156687 hasRelatedWork W2107147876 @default.
- W157156687 hasRelatedWork W2110311336 @default.
- W157156687 hasRelatedWork W2119251836 @default.
- W157156687 hasRelatedWork W2129487583 @default.
- W157156687 hasRelatedWork W2132897303 @default.
- W157156687 hasRelatedWork W2133612077 @default.
- W157156687 hasRelatedWork W2134633067 @default.
- W157156687 hasRelatedWork W2137530017 @default.
- W157156687 hasRelatedWork W2156858199 @default.