Fuzzing & Concolic Testing
Olaf Maas (@olafmaas)
Michael The (@michael-the1)
Willem Vaandrager (@wvaandrager)
- Cadar, Cristian, and Koushik Sen. "Symbolic execution for software testing: three decades later." Communications of the ACM 56.2 (2013): 82-90.
- Yan Shoshitaishvili, Ruoyu Wang, Christophe Hauser, Christopher Kruegel, and Giovanni Vigna. 2015. Firmalice - Automatic Detection of Authentication Bypass Vulnerabilities in Binary Firmware. In Proceedings 2015 Network and Distributed System Security Symposium. Reston, VA: Internet Society.
- Holler, Christian, Kim Herzig, and Andreas Zeller. "Fuzzing with Code Fragments." USENIX Security Symposium. 2012.
- Yang Chen, Alex Groce, Chaoqiang Zhang, Weng-Keen Wong, Xiaoli Fern, Eric Eide, and John Regehr. 2013. Taming compiler fuzzers. In Proceedings of the 34th ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI '13). ACM, New York, NY, USA, 197-208. DOI=http://dx.doi.org/10.1145/2491956.2462173