ISSTA/ECOOP 2024
Mon 16 - Fri 20 September 2024 Vienna, Austria
Mon 16 Sep 2024 11:30 - 11:45 at EI 9 Hlawka - Strauss Session

Greybox fuzzing is used extensively in research and practice. There are umpteen improvements proposed in the literature to improve greybox fuzzing. However, to what extent do these improvements affect the internal components (or internals) of a given fuzzer is not yet understood as the improvements are mostly evaluated in terms of code coverage and bug finding capability. Such an evaluation is insufficient to understand the effect of improvements on the internals of fuzzer. Some of the literature developed tools to visualize the outcomes of the fuzzing to enhance the understanding. However, they only focus on high-level information and no previous research on visualization has been dedicated to understanding fuzzing internals.

To close this gap, we propose the first step towards the development of a fuzzing-specific visualization framework: a taxonomy of visualization analysis tasks that fuzzing experts desire to help them understand the internals of fuzzing. Our approach involves conducting semi-structured interviews with fuzzing experts and using qualitative data analysis to systematically extract the task taxonomy from the interview data. We also evaluate the support of existing visualization tools for fuzzing through the lens of our taxonomy. In our pilot study, we conducted interviews with six fuzzing experts and extracted a preliminary taxonomy. We aim to conduct another 20 interviews to gain more insights and make the taxonomy more robust at Phase 2.

Mon 16 Sep

Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change

10:30 - 12:00
Strauss SessionFUZZING at EI 9 Hlawka
10:30
15m
Talk
Directed or Undirected: Investigating Fuzzing Strategies in a CI/CD Setup
FUZZING
Madonna Huang University of British Columbia, Caroline Lemieux University of British Columbia
10:45
15m
Talk
Effective Fuzzing within CI/CD Pipelines
FUZZING
Arindam Sharma Imperial College London, UK, Cristian Cadar Imperial College London, Jonathan Metzman Google
11:00
15m
Talk
Automated Feature Testing of Verilog Parsers using Fuzzing
FUZZING
Quentin Corradi Imperial College London, John Wickerson Imperial College London, George A. Constantinides Imperial College London, UK
11:15
15m
Talk
WebAssembly as a Fuzzing Compilation Target
FUZZING
Florian Bauckholt CISPA Helmholtz Center for Information Security, Thorsten Holz CISPA Helmholtz Center for Information Security
11:30
15m
Talk
Visualization Task Taxonomy to Understand the Fuzzing Internals
FUZZING
Sriteja Kummita Fraunhofer IEM, Miao Miao The University of Texas at Dallas, Eric Bodden Heinz Nixdorf Institut, Paderborn University and Fraunhofer IEM, Shiyi Wei University of Texas at Dallas

Information for Participants
Mon 16 Sep 2024 10:30 - 12:00 at EI 9 Hlawka - Strauss Session
Info for room EI 9 Hlawka:

Map: https://tuw-maps.tuwien.ac.at/?q=CAEG17

Room tech: https://raumkatalog.tiss.tuwien.ac.at/room/13939