POWER: Program Option-Aware Fuzzer for High Bug Detection Ability

Cited 3 time in webofscience Cited 0 time in scopus
  • Hit : 61
  • Download : 0
DC FieldValueLanguage
dc.contributor.authorLee, Ahcheongko
dc.contributor.authorAriq, Irfanko
dc.contributor.authorKim, Yunhoko
dc.contributor.authorKim, Moonzooko
dc.date.accessioned2022-11-15T05:02:30Z-
dc.date.available2022-11-15T05:02:30Z-
dc.date.created2022-09-27-
dc.date.created2022-09-27-
dc.date.created2022-09-27-
dc.date.created2022-09-27-
dc.date.issued2022-04-06-
dc.identifier.citationIEEE International Conference on Software Testing, Verification and Validation (ICST), pp.220 - 231-
dc.identifier.urihttp://hdl.handle.net/10203/299631-
dc.description.abstractMost programs with command-line interface (CLI) have dozens of command-line options (e.g.,-l,-F,-R for ls) to alternate the operation of the programs. Thus, depending on the option configurations (i.e., a list of options like-l-F and-F-R) applied during fuzzing, the test coverage and crash detection results can vary significantly. In this paper, we propose a novel fuzzing technique POWER that detects more crashes than the cutting-edge fuzzers by actively constructing and carefully selecting various program option configurations. The salient idea of POWER is to enforce diverse executions of a target program by selecting a set of the option configurations each of which is far 'different/distant' from the others in the set. Another core idea of POWER is to apply different fuzzing strategies to different input domains (i.e., option configurations and input files) to increase testing effectiveness within limited time budget. The experiment results on the 30 real-world programs show that POWER detects significantly more crash bugs than the state-of-the-art fuzzing techniques.-
dc.languageEnglish-
dc.publisherInstitute of Electrical and Electronics Engineers Inc.-
dc.titlePOWER: Program Option-Aware Fuzzer for High Bug Detection Ability-
dc.typeConference-
dc.identifier.wosid000850246600020-
dc.identifier.scopusid2-s2.0-85133305202-
dc.type.rimsCONF-
dc.citation.beginningpage220-
dc.citation.endingpage231-
dc.citation.publicationnameIEEE International Conference on Software Testing, Verification and Validation (ICST)-
dc.identifier.conferencecountrySP-
dc.identifier.conferencelocationVirtual-
dc.identifier.doi10.1109/ICST53961.2022.00032-
dc.contributor.localauthorKim, Moonzoo-
dc.contributor.nonIdAuthorKim, Yunho-
Appears in Collection
CS-Conference Papers(학술회의논문)
Files in This Item
There are no files associated with this item.
This item is cited by other documents in WoS
⊙ Detail Information in WoSⓡ Click to see webofscience_button
⊙ Cited 3 items in WoS Click to see citing articles in records_button

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0