FuzzTastic: A Fine-grained, Fuzzer-agnostic Coverage Analyzer
Performing sound and fair fuzzer evaluations can be challenging, not only because of the randomness involved in fuzzing, but also due to the large number of fuzz tests generated. Existing evaluations use code coverage as a proxy measure for fuzzing effectiveness. Yet, instead of considering coverage of all generated fuzz inputs, they only consider the inputs stored in the fuzzer queue. However, as we show in this paper, this approach can lead to biased assessments due to path collisions. Therefore, we developed FuzzTastic, a fuzzer-agnostic coverage analyzer that allows practitioners and researchers to perform uniform fuzzer evaluations that are not affected by such collisions. In addition, its time-stamped, coverage-probing approach enables frequency-based coverage analysis to identify barely tested source code and to visualize fuzzing progress over time and across code. To foster further studies in this field, we make FuzzTastic, together with a benchmark dataset worth ~12 CPU-years of fuzzing, publicly available; the demo video can be found at https://youtu.be/Lm-eBx0aePA
Wed 11 MayDisplayed time zone: Eastern Time (US & Canada) change
04:00 - 05:00 | Software Testing 2DEMO - Demonstrations at ICSE Demo room 1 Chair(s): Jiajun Jiang Tianjin University | ||
04:00 15mDemonstration | QuSBT: Search-Based Testing of Quantum Programs DEMO - Demonstrations Xinyi Wang Nanjing University of Aeronautics and Astronautics, Paolo Arcaini National Institute of Informatics
, Tao Yue Simula Research Laboratory, Norway, Shaukat Ali Simula Research Laboratory, Norway DOI Pre-print Media Attached | ||
04:15 15mDemonstration | MASS: A tool for Mutation Analysis for Space CPS DEMO - Demonstrations Oscar Cornejo SnT Centre, University of Luxembourg, Fabrizio Pastore University of Luxembourg, Lionel Briand University of Luxembourg; University of Ottawa Pre-print Media Attached | ||
04:30 15mDemonstration | TestKnight: An Interactive Assistant to Stimulate Test Engineering DEMO - Demonstrations Cristian-Alexandru Botocan Delft University of Technology, Piyush Deshmukh Delft University of Technology, Pavlos Makridis Delft University of Technology, Jorge Romeu Huidobro Delft University of Technology, Mathanrajan Sundarrajan Delft University of Technology, Maurício Aniche Delft University of Technology, Andy Zaidman Delft University of Technology Pre-print Media Attached | ||
04:45 15mDemonstration | FuzzTastic: A Fine-grained, Fuzzer-agnostic Coverage Analyzer DEMO - Demonstrations Stephan Lipp Technical University of Munich, Daniel Elsner TU Munich, Thomas Hutzelmann Technical University of Munich, Sebastian Banescu Technical University of Munich, Alexander Pretschner TU Munich, Marcel Böhme MPI-SP, Germany and Monash University, Australia DOI Pre-print Media Attached |