{"id":"https://openalex.org/W4386043258","doi":"https://doi.org/10.48550/arxiv.2308.09081","title":"Hyperfuzzing: black-box security hypertesting with a grey-box fuzzer","display_name":"Hyperfuzzing: black-box security hypertesting with a grey-box fuzzer","publication_year":2023,"publication_date":"2023-01-01","ids":{"openalex":"https://openalex.org/W4386043258","doi":"https://doi.org/10.48550/arxiv.2308.09081"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2308.09081","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"posted-content","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/abs/2308.09081","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5016149616","display_name":"Daniel J. Blackwell","orcid":"https://orcid.org/0000-0001-6619-1792"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Blackwell, Daniel","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036272832","display_name":"Ingolf Becker","orcid":"https://orcid.org/0000-0002-3963-4743"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Becker, Ingolf","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5013673413","display_name":"David Clark","orcid":"https://orcid.org/0000-0002-7004-934X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Clark, David","raw_affiliation_strings":[],"affiliations":[]}],"institution_assertions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":65},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9996,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9996,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9991,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9974,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/information-leakage","display_name":"Information leakage","score":0.6232774},{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.59925866},{"id":"https://openalex.org/keywords/ranging","display_name":"Ranging","score":0.43398076}],"concepts":[{"id":"https://openalex.org/C55166926","wikidata":"https://www.wikidata.org/wiki/Q2892946","display_name":"Oracle","level":2,"score":0.7236731},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.71138567},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.6712961},{"id":"https://openalex.org/C2779201187","wikidata":"https://www.wikidata.org/wiki/Q2775060","display_name":"Information leakage","level":2,"score":0.6232774},{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.59925866},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.47575304},{"id":"https://openalex.org/C115051666","wikidata":"https://www.wikidata.org/wiki/Q6522493","display_name":"Ranging","level":2,"score":0.43398076},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4156142},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.30822867},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.2566287},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2308.09081","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2308.09081","pdf_url":"http://arxiv.org/pdf/2308.09081","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":false,"landing_page_url":"https://api.datacite.org/dois/10.48550/arxiv.2308.09081","pdf_url":null,"source":{"id":"https://openalex.org/S4393179698","display_name":"DataCite API","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I4210145204","host_organization_name":"DataCite","host_organization_lineage":["https://openalex.org/I4210145204"],"host_organization_lineage_names":["DataCite"],"type":"metadata"},"license":null,"license_id":null,"version":null}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2308.09081","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[{"score":0.73,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, justice, and strong institutions"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4385301282","https://openalex.org/W4288084466","https://openalex.org/W4248424560","https://openalex.org/W4210660460","https://openalex.org/W3203597304","https://openalex.org/W3120811337","https://openalex.org/W3023977444","https://openalex.org/W2990186179","https://openalex.org/W2912724380","https://openalex.org/W2511770387"],"abstract_inverted_index":{"Information":[0],"leakage":[1],"is":[2,18],"a":[3,36,42,88,111,147],"class":[4],"of":[5,31,55,64,85,96,102,114,134,137,160],"error":[6,149],"that":[7,87],"can":[8,80,91,157,182],"lead":[9],"to":[10,99,130],"severe":[11],"consequences.":[12],"However":[13],"unlike":[14],"other":[15],"errors,":[16],"it":[17],"rarely":[19],"explicitly":[20],"considered":[21],"during":[22],"the":[23,29,32,50,53,56,62,82,94,161,164,172],"software":[24],"testing":[25],"process.":[26],"LeakFuzzer":[27,60,109,156],"advances":[28],"state":[30,54],"art":[33,57],"by":[34],"using":[35,169],"noninterference":[37],"security":[38,43],"property":[39],"together":[40],"with":[41,93,179],"flow":[44,105],"policy":[45],"as":[46,67,171],"an":[47],"oracle.":[48],"As":[49],"tool":[51,79],"extends":[52],"fuzzer,":[58],"AFL++,":[59],"inherits":[61],"advantages":[63],"AFL++":[65,177],"such":[66,170],"scalability,":[68],"automated":[69],"input":[70],"generation,":[71],"high":[72],"coverage":[73],"and":[74,117,146,176],"low":[75],"developer":[76],"intervention.":[77],"The":[78],"detect":[81,100],"same":[83],"set":[84,113],"errors":[86],"normal":[89],"fuzzer":[90],"detect,":[92],"addition":[95],"being":[97],"able":[98],"violations":[101],"secure":[103],"information":[104,122],"policies.":[106],"We":[107],"evaluated":[108],"on":[110],"diverse":[112],"10":[115],"C":[116],"C++":[118],"benchmarks":[119],"containing":[120],"known":[121],"leaks,":[123],"ranging":[124],"in":[125,150,163],"size":[126],"from":[127,141],"just":[128],"80":[129],"over":[131],"900k":[132],"lines":[133],"code.":[135],"Seven":[136],"these":[138],"are":[139],"taken":[140],"real-world":[142],"CVEs":[143],"including":[144],"Heartbleed":[145],"recent":[148],"PostgreSQL.":[151],"Given":[152],"20":[153],"24-hour":[154],"runs,":[155],"find":[158,184],"100%":[159],"leaks":[162],"SUTs":[165],"whereas":[166],"existing":[167],"techniques":[168],"CBMC":[173],"model":[174],"checker":[175],"augmented":[178],"different":[180],"sanitizers":[181],"only":[183],"40%":[185],"at":[186],"best.":[187]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4386043258","counts_by_year":[],"updated_date":"2025-04-14T13:40:33.800278","created_date":"2023-08-22"}