Projects per year
Abstract
As researchers, we already understand how to make testing more effective and efficient at finding bugs. However, as fuzzing (i.e., automated testing) becomes more widely adopted in practice, practitioners are asking: Which assurances does a fuzzing campaign provide that exposes no bugs? When is it safe to stop the fuzzer with a reasonable residual risk? How much longer should the fuzzer be run to achieve sufficient coverage? It is time for us to move beyond the innovation of increasingly sophisticated testing techniques, to build a body of knowledge around the explication and quantification of the testing process, and to develop sound methodologies to estimate and extrapolate these quantities with measurable accuracy. In our vision of the future practitioners leverage a rich statistical toolset to assess residual risk, to obtain statistical guarantees, and to analyze the cost-benefit trade-off for ongoing fuzzing campaigns. We propose a general framework as a first starting point to tackle this fundamental challenge and discuss a large number of concrete opportunities for future research.
Original language | English |
---|---|
Title of host publication | Proceedings - 2019 IEEE/ACM 41st International Conference on Software Engineering |
Subtitle of host publication | New Ideas and Emerging Results, ICSE-NIER 2019 |
Editors | Anita Sarma, Leonarado Murta |
Place of Publication | Piscataway NJ USA |
Publisher | IEEE, Institute of Electrical and Electronics Engineers |
Pages | 5-8 |
Number of pages | 4 |
ISBN (Electronic) | 9781728117584 |
ISBN (Print) | 9781728117591 |
DOIs | |
Publication status | Published - 2019 |
Event | International Conference on Software Engineering 2019: New Ideas and Emerging Results - Fairmont The Queen Elizabeth Hotel, Montreal, Canada Duration: 25 May 2019 → 31 May 2019 Conference number: 41st https://ieeexplore.ieee.org/xpl/conhome/8790673/proceeding (Proceedings) |
Conference
Conference | International Conference on Software Engineering 2019 |
---|---|
Abbreviated title | ICSE-NIER 2019 |
Country/Territory | Canada |
City | Montreal |
Period | 25/05/19 → 31/05/19 |
Other | Track within the International Conference on Software Engineering |
Internet address |
Keywords
- Cost benefit tradeoff
- Guarantees
- Residual risk
- Statistics
Projects
- 1 Finished
-
Fortifying Our Digital Economy: Advanced Automated Vulnerability Discovery
Boehme, M. (Primary Chief Investigator (PCI))
Australian Research Council (ARC)
1/03/19 → 31/08/21
Project: Research