{"id":"https://openalex.org/W4404193542","doi":"https://doi.org/10.1007/s10664-024-10556-3","title":"Hyperfuzzing: black-box security hypertesting with a grey-box fuzzer","display_name":"Hyperfuzzing: black-box security hypertesting with a grey-box fuzzer","publication_year":2024,"publication_date":"2024-11-08","ids":{"openalex":"https://openalex.org/W4404193542","doi":"https://doi.org/10.1007/s10664-024-10556-3"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10664-024-10556-3","pdf_url":null,"source":{"id":"https://openalex.org/S109852484","display_name":"Empirical Software Engineering","issn_l":"1382-3256","issn":["1382-3256","1573-7616"],"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":true,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319965","https://openalex.org/P4310319900"],"host_organization_lineage_names":["Springer Nature","Springer Science+Business Media"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"journal-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://doi.org/10.1007/s10664-024-10556-3","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5058734486","display_name":"Daniel Blackwell","orcid":"https://orcid.org/0000-0001-7320-9057"},"institutions":[{"id":"https://openalex.org/I45129253","display_name":"University College London","ror":"https://ror.org/02jx3x895","country_code":"GB","type":"funder","lineage":["https://openalex.org/I124357947","https://openalex.org/I45129253"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Daniel Blackwell","raw_affiliation_strings":["University College London, London, United Kingdom"],"affiliations":[{"raw_affiliation_string":"University College London, London, United Kingdom","institution_ids":["https://openalex.org/I45129253"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036272832","display_name":"Ingolf Becker","orcid":"https://orcid.org/0000-0002-3963-4743"},"institutions":[{"id":"https://openalex.org/I45129253","display_name":"University College London","ror":"https://ror.org/02jx3x895","country_code":"GB","type":"funder","lineage":["https://openalex.org/I124357947","https://openalex.org/I45129253"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Ingolf Becker","raw_affiliation_strings":["University College London, London, United Kingdom"],"affiliations":[{"raw_affiliation_string":"University College London, London, United Kingdom","institution_ids":["https://openalex.org/I45129253"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101473569","display_name":"David Clark","orcid":"https://orcid.org/0000-0002-8882-9205"},"institutions":[{"id":"https://openalex.org/I45129253","display_name":"University College London","ror":"https://ror.org/02jx3x895","country_code":"GB","type":"funder","lineage":["https://openalex.org/I124357947","https://openalex.org/I45129253"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"David Clark","raw_affiliation_strings":["University College London, London, United Kingdom"],"affiliations":[{"raw_affiliation_string":"University College London, London, United Kingdom","institution_ids":["https://openalex.org/I45129253"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":["https://openalex.org/A5058734486"],"corresponding_institution_ids":["https://openalex.org/I45129253"],"apc_list":{"value":2290,"currency":"EUR","value_usd":2890},"apc_paid":{"value":2290,"currency":"EUR","value_usd":2890},"fwci":2.039,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.785868,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":88,"max":92},"biblio":{"volume":"30","issue":"1","first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9911,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.7375868},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.7165124},{"id":"https://openalex.org/keywords/s-box","display_name":"S-box","score":0.60351336}],"concepts":[{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.7375868},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.7165124},{"id":"https://openalex.org/C45737032","wikidata":"https://www.wikidata.org/wiki/Q748364","display_name":"S-box","level":4,"score":0.60351336},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5390434},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.29259318},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.20335367},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.17368585},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.15822297},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.129989},{"id":"https://openalex.org/C106544461","wikidata":"https://www.wikidata.org/wiki/Q543151","display_name":"Block cipher","level":3,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10664-024-10556-3","pdf_url":null,"source":{"id":"https://openalex.org/S109852484","display_name":"Empirical Software Engineering","issn_l":"1382-3256","issn":["1382-3256","1573-7616"],"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":true,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319965","https://openalex.org/P4310319900"],"host_organization_lineage_names":["Springer Nature","Springer Science+Business Media"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1007/s10664-024-10556-3","pdf_url":null,"source":{"id":"https://openalex.org/S109852484","display_name":"Empirical Software Engineering","issn_l":"1382-3256","issn":["1382-3256","1573-7616"],"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":true,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319965","https://openalex.org/P4310319900"],"host_organization_lineage_names":["Springer Nature","Springer Science+Business Media"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.76,"display_name":"Peace, justice, and strong institutions"}],"grants":[{"funder":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council","award_id":"EP/S022503/1"}],"datasets":[],"versions":[],"referenced_works_count":24,"referenced_works":["https://openalex.org/W1138977110","https://openalex.org/W1878475345","https://openalex.org/W1977764760","https://openalex.org/W2002934700","https://openalex.org/W2042033151","https://openalex.org/W2094873755","https://openalex.org/W2101171610","https://openalex.org/W2104658241","https://openalex.org/W2122049982","https://openalex.org/W2147436337","https://openalex.org/W2156585713","https://openalex.org/W2162022335","https://openalex.org/W2204772115","https://openalex.org/W2780206242","https://openalex.org/W2899478507","https://openalex.org/W2963804422","https://openalex.org/W2964241064","https://openalex.org/W3048076421","https://openalex.org/W3089358079","https://openalex.org/W3166104887","https://openalex.org/W3194771370","https://openalex.org/W3196404481","https://openalex.org/W4243284147","https://openalex.org/W4313549794"],"related_works":["https://openalex.org/W4400374418","https://openalex.org/W4397049040","https://openalex.org/W4287626382","https://openalex.org/W4206598047","https://openalex.org/W3105637246","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2094644515","https://openalex.org/W2011644400","https://openalex.org/W1984273188"],"abstract_inverted_index":{"Abstract":[0],"Despite":[1],"being":[2,102],"a":[3,29,119,136,178],"severe":[4],"error":[5,180],"where":[6],"programs":[7],"inadvertently":[8],"reveal":[9],"confidential":[10,150],"information,":[11],"insecure":[12,47,193],"flows":[13,48,194],"rarely":[14],"receive":[15],"explicit":[16],"attention":[17],"during":[18],"software":[19],"testing.":[20],"LeakFuzzer":[21,59,134,187],"uses":[22],"an":[23],"input-output":[24],"non-interference":[25,57],"property,":[26],"specialised":[27],"via":[28],"security":[30],"flow":[31,110],"policy":[32],"for":[33,52,126],"the":[34,40,43,55,61,64,67,92,127,130,192,196,202],"program":[35],"under":[36],"test,":[37],"to":[38,104,152,161],"advance":[39,121],"state":[41,65,128],"of":[42,54,63,66,95,107,129,139,165,168,191],"art.":[44,131],"It":[45,88],"detects":[46],"by":[49],"using":[50,201],"hypertesting":[51],"violations":[53,106],"program\u2019s":[56],"property.":[58],"extends":[60],"capabilities":[62],"art":[68],"fuzzer,":[69],"AFL++,":[70,98],"and":[71,84,124,142,177,206],"thus":[72,90],"inherits":[73],"its":[74],"advantages":[75],"such":[76],"as":[77,97,99,101],"scalability,":[78],"automated":[79],"input":[80],"generation,":[81],"high":[82],"coverage":[83],"low":[85],"developer":[86],"intervention.":[87],"can":[89,188,212],"detect":[91,105],"same":[93],"set":[94,138],"errors":[96],"well":[100],"able":[103],"secure":[108],"information":[109,151],"policies":[111],"at":[112,216],"small":[113],"additional":[114],"performance":[115],"costs.":[116],"This":[117],"offers":[118],"significant":[120],"in":[122,156,181,195],"scalability":[123],"automation":[125],"We":[132],"evaluated":[133],"on":[135],"diverse":[137],"12":[140],"C":[141],"C++":[143],"benchmarks":[144],"containing":[145],"known":[146],"bugs":[147],"that":[148],"cause":[149],"be":[153],"disclosed,":[154],"ranging":[155],"size":[157],"from":[158,172],"just":[159],"80":[160],"over":[162],"900k":[163],"lines":[164],"code.":[166],"Nine":[167],"these":[169],"are":[170],"taken":[171],"real-world":[173],"CVEs":[174],"including":[175],"Heartbleed":[176],"recent":[179],"PostgreSQL.":[182],"Given":[183],"20":[184],"24-hour":[185],"runs,":[186],"find":[189,214],"100%":[190],"SUTs":[197],"whereas":[198],"existing":[199],"techniques":[200],"CBMC":[203],"model":[204],"checker":[205],"AFL++":[207],"augmented":[208],"with":[209],"different":[210],"sanitizers":[211],"only":[213],"40%":[215],"best.":[217]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4404193542","counts_by_year":[{"year":2024,"cited_by_count":2}],"updated_date":"2025-04-22T06:51:21.895134","created_date":"2024-11-09"}