Open this publication in new window or tab >>2025 (English)Report (Other academic)
Abstract [en]
Fuzz testing has become the de facto standard for vulnerability discovery. State-of-the-art fuzzers employ a so-called gray-box approach,where coverage information is fed back to the fuzzer after each generated test case, thereby allowing it to effectivize its generationstrategy over time to find bugs deep within the code. Despite research efforts in recent years, networked applications have proven tobe notoriously difficult to fuzz efficiently and thoroughly. Modern fuzzers struggle with the complex environmental interactions andstatefulness associated with networked systems and subsequently, shortcuts are taken to ensure at least some degree of hardening.
In this paper we study 32 prominent protocol implementations that have been continuously fuzzed by OSS-Fuzz. We define metricsto measure fuzzing activity within a project and correlate our measurements with registered CVEs for discovered vulnerabilities. Our analysis show a strong correlation between fuzzing activity and registered CVEs within a project. However, by using the CWE-1000 analys framework, we show that the correlation is only strong for certain classes of vulnerabilities. From those observations, we areable to draw conclusions about what current fuzzing practices are lacking and where fuzzing research efforts need to be spent in thefuture.
This technical report is an extension of doi:10.1145/3672608.3707730, which has been published with ACM in the SAC 2025 conference proceedings.
Place, publisher, year, edition, pages
Stockholm: KTH Royal Institute of Technology, 2025. p. 13
Series
TRITA-EECS-RP ; 2025:3
Keywords
Computer network, protocol, testing, fuzz testing
National Category
Communication Systems Telecommunications Computer Sciences Computer Engineering Security, Privacy and Cryptography
Research subject
Electrical Engineering; Computer Science
Identifiers
urn:nbn:se:kth:diva-372022 (URN)
Note
This technical report is an extension of doi:10.1145/3672608.3707730, which has been published with ACM in the SAC 2025 conference proceedings.
QC 20251029
2025-10-232025-10-232026-02-18Bibliographically approved