Åpne denne publikasjonen i ny fane eller vindu >>2025 (engelsk)Rapport (Annet vitenskapelig)
Abstract [en]
Fuzz testing has become the de facto standard for vulnerability discovery. State-of-the-art fuzzers employ a so-called gray-box approach,where coverage information is fed back to the fuzzer after each generated test case, thereby allowing it to effectivize its generationstrategy over time to find bugs deep within the code. Despite research efforts in recent years, networked applications have proven tobe notoriously difficult to fuzz efficiently and thoroughly. Modern fuzzers struggle with the complex environmental interactions andstatefulness associated with networked systems and subsequently, shortcuts are taken to ensure at least some degree of hardening.
In this paper we study 32 prominent protocol implementations that have been continuously fuzzed by OSS-Fuzz. We define metricsto measure fuzzing activity within a project and correlate our measurements with registered CVEs for discovered vulnerabilities. Our analysis show a strong correlation between fuzzing activity and registered CVEs within a project. However, by using the CWE-1000 analys framework, we show that the correlation is only strong for certain classes of vulnerabilities. From those observations, we areable to draw conclusions about what current fuzzing practices are lacking and where fuzzing research efforts need to be spent in thefuture.
This technical report is an extension of doi:10.1145/3672608.3707730, which has been published with ACM in the SAC 2025 conference proceedings.
sted, utgiver, år, opplag, sider
Stockholm: KTH Royal Institute of Technology, 2025. s. 13
Serie
TRITA-EECS-RP ; 2025:3
Emneord
Computer network, protocol, testing, fuzz testing
HSV kategori
Forskningsprogram
Elektro- och systemteknik; Datalogi
Identifikatorer
urn:nbn:se:kth:diva-372022 (URN)
Merknad
This technical report is an extension of doi:10.1145/3672608.3707730, which has been published with ACM in the SAC 2025 conference proceedings.
QC 20251029
2025-10-232025-10-232026-02-18bibliografisk kontrollert