4 papers · 1 filter
Rust and Go directed fuzzing with LibAFL-DiFuzz
Timofey Mezhuev, Darya Parygina, Daniil Kuts
In modern SSDLC, program analysis and automated testing are essential for minimizing vulnerabilities before software release, with fuzzing being a fast and widely used dynamic test…
Hybrid Approach to Directed Fuzzing
Darya Parygina, Timofey Mezhuev, Daniil Kuts
Program analysis and automated testing have recently become an essential part of SSDLC. Directed greybox fuzzing is one of the most popular automated testing methods that focuses o…
LibAFL-DiFuzz: Advanced Architecture Enabling Directed Fuzzing
Darya Parygina, Timofey Mezhuev, Daniil Kuts
Directed fuzzing performs best for targeted program testing via estimating the impact of each input in reaching predefined program points. But due to insufficient analysis of the p…
Numeric Truncation Security Predicate
Timofey Mezhuev, Ilay Kobrin, Alexey Vishnyakov +1
Numeric truncation is a widely spread error in software written in languages with static data typing, such as C/C++ or Java. It occurs when the significant bits of the value with a…