ISSTA 2025
Wed 25 - Sat 28 June 2025 Trondheim, Norway
Sat 28 Jun 2025 15:12 - 15:30 at Cosmos 3C - Afternoon 1

In recent years, fuzzing has gained attention as a primary means for the early detection of vulnerabilities. Although coverage-based greybox fuzzing utilizes internal coverage information to achieve high exploration efficiency, it remains difficult to employ the fuzzing framework in some restricted environments where we cannot instrument the program, such as firmware or smartphone applications. In contrast, blackbox fuzzing does not require runtime information and is thus more widely applicable, but suffers from lower efficiency because coverage cannot be measured. To address this issue, there is a growing demand for methods that can approximate coverage in blackbox environments to optimize fuzzing. One existing study proposes estimating coverage based on the relationship between program responses and strings embedded in its binary. However, this approach faces challenges with ambiguous matching algorithms and the non-uniqueness that occurs when a single string is shared by multiple basic blocks, leading to frequent misestimations. In this research, we propose a new coverage inference method, Shepherd, which combines high-precision string matching with context analysis to resolve these problems. Experimental results show that Shepherd significantly improves estimation accuracy compared to the existing approach.

Sat 28 Jun

Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change

14:00 - 15:30
Afternoon 1FUZZING at Cosmos 3C
14:00
18m
Talk
On the Applicability of Benford’s Law to Detect Saturation in Fuzzing
FUZZING
Jungwoo Lee KAIST, Haeun Lee KAIST, Sangjun Park KAIST, Sang Kil Cha KAIST
14:18
18m
Talk
Trailblazer: Practical End-to-end Web API Fuzzing
FUZZING
Lianglu Pan University of Melbourne, Shaanan Cohney University of Melbourne, Toby Murray University of Melbourne, Thuan Pham University of Melbourne
14:36
18m
Talk
Revisiting the Combination of Static Analysis Error Traces and Dynamic Symbolic Execution: A Potential Approach for True Positive Confirmation
FUZZING
Yihua Xu East China Normal University, Chengyu Zhang Loughborough University, Geguang Pu East China Normal University, China
14:54
18m
Talk
MQueez: Specification-Driven Fuzzing for MQTT Broker
FUZZING
Xinpeng Liu Zhejiang University, Qinying Wang Zhejiang University, Peiyu Liu Zhejiang University, Wenhai Wang Zhejiang University, Shouling Ji Zhejiang University
15:12
18m
Talk
Shepherd: High-Precision Coverage Inference for Response-guided Blackbox Fuzzing
FUZZING
Takuya Shimizu Ricerca Security, Inc., Ryuichi Yoshizawa Ricerca Security, Inc., Kaoru Otsuka Ricerca Security, Inc., Yudai Fujiwara Ricerca Security, Inc., Yuichi Sugiyama Ricerca Security, Inc.

Information for Participants
Sat 28 Jun 2025 14:00 - 15:30 at Cosmos 3C - Afternoon 1
Info for room Cosmos 3C:

Cosmos 3C is the third room in the Cosmos 3 wing.

When facing the main Cosmos Hall, access to the Cosmos 3 wing is on the left, close to the stairs. The area is accessed through a large door with the number “3”, which will stay open during the event.