{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T08:32:07Z","timestamp":1742977927537,"version":"3.40.3"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030808242"},{"type":"electronic","value":"9783030808259"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-80825-9_6","type":"book-chapter","created":{"date-parts":[[2021,7,8]],"date-time":"2021-07-08T23:38:40Z","timestamp":1625787520000},"page":"106-129","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Refined Grey-Box Fuzzing with Sivo"],"prefix":"10.1007","author":[{"given":"Ivica","family":"Nikoli\u0107","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Radu","family":"Mantu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shiqi","family":"Shen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Prateek","family":"Saxena","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,7,9]]},"reference":[{"key":"6_CR1","unstructured":"Circumventing fuzzing roadblocks with compiler transformations (2016). https:\/\/lafintel.wordpress.com\/"},{"key":"6_CR2","first-page":"1","volume":"19","author":"C Aschermann","year":"2019","unstructured":"Aschermann, C., Schumilo, S., Blazytko, T., Gawlik, R., Holz, T.: Redqueen: fuzzing with input-to-state correspondence. NDSS. 19, 1\u201315 (2019)","journal-title":"NDSS."},{"key":"6_CR3","doi-asserted-by":"crossref","unstructured":"B\u00f6hme, M., Pham, V.T., Nguyen, M.D., Roychoudhury, A.: Directed greybox fuzzing. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 2329\u20132344 (2017)","DOI":"10.1145\/3133956.3134020"},{"issue":"5","key":"6_CR4","doi-asserted-by":"publisher","first-page":"489","DOI":"10.1109\/TSE.2017.2785841","volume":"45","author":"M B\u00f6hme","year":"2017","unstructured":"B\u00f6hme, M., Pham, V.T., Roychoudhury, A.: Coverage-based greybox fuzzing as Markov chain. IEEE Trans. Softw. Eng. 45(5), 489\u2013506 (2017)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"6_CR5","first-page":"209","volume":"8","author":"C Cadar","year":"2008","unstructured":"Cadar, C., Dunbar, D., Engler, D.R., et al.: Klee: unassisted and automatic generation of high-coverage tests for complex systems programs. OSDI 8, 209\u2013224 (2008)","journal-title":"OSDI"},{"key":"6_CR6","doi-asserted-by":"crossref","unstructured":"Chen, P., Chen, H.: Angora: efficient fuzzing by principled search. In: 2018 IEEE Symposium on Security and Privacy (SP), pp. 711\u2013725. IEEE (2018)","DOI":"10.1109\/SP.2018.00046"},{"key":"6_CR7","doi-asserted-by":"crossref","unstructured":"Chen, P., Liu, J., Chen, H.: Matryoshka: fuzzing deeply nested branches. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (2019)","DOI":"10.1145\/3319535.3363225"},{"key":"6_CR8","doi-asserted-by":"crossref","unstructured":"Choi, J., Jang, J., Han, C., Cha, S.K.: Grey-box concolic testing on binary code. In: 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE), pp. 736\u2013747. IEEE (2019)","DOI":"10.1109\/ICSE.2019.00082"},{"key":"6_CR9","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., et al.: Lava: large-scale automated vulnerability addition. In: S&P (2016)","DOI":"10.1109\/SP.2016.15"},{"key":"6_CR10","doi-asserted-by":"crossref","unstructured":"Du, D., Hwang, F.K., Hwang, F.: Combinatorial group testing and its applications, vol. 12. World Scientific (2000)","DOI":"10.1142\/4252"},{"key":"6_CR11","unstructured":"Fioraldi, A., Maier, D., Ei\u00dffeldt, H., Heuse, M.: Afl++: combining incremental steps of fuzzing research. In: 14th USENIX Workshop on Offensive Technologies WOOT) (2020)"},{"key":"6_CR12","unstructured":"Gan, S., et al.: Greyone: data flow sensitive fuzzing. In: 29th USENIX Security Symposium (USENIX Security 20). USENIX Association, Boston, MA (2020). https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/gan"},{"key":"6_CR13","doi-asserted-by":"crossref","unstructured":"Gan, S., et al.: CollAFL: path sensitive fuzzing. In: 2018 IEEE Symposium on Security and Privacy (SP), pp. 679\u2013696. IEEE (2018)","DOI":"10.1109\/SP.2018.00040"},{"key":"6_CR14","doi-asserted-by":"crossref","unstructured":"Ganesh, V., Leek, T., Rinard, M.: Taint-based directed whitebox fuzzing. In: 2009 IEEE 31st International Conference on Software Engineering, pp. 474\u2013484. IEEE (2009)","DOI":"10.1109\/ICSE.2009.5070546"},{"key":"6_CR15","unstructured":"Google: OSS-Fuzz - continuous fuzzing of open source software (2020). https:\/\/github.com\/google\/oss-fuzz"},{"key":"6_CR16","doi-asserted-by":"crossref","unstructured":"Huang, H., Yao, P., Wu, R., Shi, Q., Zhang, C.: Pangolin: incremental hybrid fuzzing with polyhedral path abstraction. In: 2020 IEEE Symposium on Security and Privacy (SP), pp. 1613\u20131627. IEEE (2020)","DOI":"10.1109\/SP40000.2020.00063"},{"key":"6_CR17","doi-asserted-by":"crossref","unstructured":"Inozemtseva, L., Holmes, R.: Coverage is not strongly correlated with test suite effectiveness. In: Proceedings of the 36th International Conference on Software Engineering, pp. 435\u2013445 (2014)","DOI":"10.1145\/2568225.2568271"},{"key":"6_CR18","doi-asserted-by":"crossref","unstructured":"Klees, G., Ruef, A., Cooper, B., Wei, S., Hicks, M.: Evaluating fuzz testing. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pp. 2123\u20132138 (2018)","DOI":"10.1145\/3243734.3243804"},{"key":"6_CR19","unstructured":"Kocsis, L., Szepesv\u00e1ri, C.: Discounted UCB. In: 2nd PASCAL Challenges Workshop, vol. 2 (2006)"},{"key":"6_CR20","doi-asserted-by":"crossref","unstructured":"Lemieux, C., Sen, K.: Fairfuzz: a targeted mutation strategy for increasing greybox fuzz testing coverage. In: Proceedings of the 33rd ACM\/IEEE International Conference on Automated Software Engineering, pp. 475\u2013485 (2018)","DOI":"10.1145\/3238147.3238176"},{"key":"6_CR21","doi-asserted-by":"crossref","unstructured":"Li, Y., Chen, B., Chandramohan, M., Lin, S.W., Liu, Y., Tiu, A.: Steelix: program-state based binary fuzzing. In: Proceedings of the 2017 11th Joint Meeting on Foundations of Software Engineering, pp. 627\u2013637 (2017)","DOI":"10.1145\/3106237.3106295"},{"key":"6_CR22","unstructured":"Lyu, C., Ji, S., Zhang, C., Li, Y., Lee, W.H., Song, Y., Beyah, R.: MOPT: optimized mutation scheduling for fuzzers. In: 28th USENIX Security Symposium (USENIX Security 2019), pp. 1949\u20131966 (2019)"},{"key":"6_CR23","doi-asserted-by":"crossref","unstructured":"Man\u00e8s, V.J., Kim, S., Cha, S.K.: Ankou: guiding grey-box fuzzing towards combinatorial difference. In: Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering, pp. 1024\u20131036 (2020)","DOI":"10.1145\/3377811.3380421"},{"key":"6_CR24","doi-asserted-by":"crossref","unstructured":"Nethercote, N., Seward, J.: Valgrind: a framework for heavyweight dynamic binary instrumentation. In: PLDI (2007)","DOI":"10.1145\/1250734.1250746"},{"key":"6_CR25","unstructured":"Nikolic, I., Mantu, R.: Sivo: Refined gray-box fuzzer. https:\/\/github.com\/ivicanikolicsg\/SivoFuzzer"},{"key":"6_CR26","first-page":"1","volume":"17","author":"S Rawat","year":"2017","unstructured":"Rawat, S., Jain, V., Kumar, A., Cojocar, L., Giuffrida, C., Bos, H.: Vuzzer: application-aware evolutionary fuzzing. NDSS 17, 1\u201314 (2017)","journal-title":"NDSS"},{"key":"6_CR27","unstructured":"Ryabinin, A.: Ubsan: run-time undefined behavior sanity checker (2014). https:\/\/lwn.net\/Articles\/617364\/"},{"key":"6_CR28","unstructured":"Serebryany, K., Bruening, D., Potapenko, A., Vyukov, D.: Addresssanitizer: a fast address sanity checker. In: USENIX ATC (2012)"},{"key":"6_CR29","doi-asserted-by":"crossref","unstructured":"Serebryany, K.: Continuous fuzzing with libfuzzer and addresssanitizer. In: 2016 IEEE Cybersecurity Development (SecDev), pp. 157\u2013157. IEEE (2016)","DOI":"10.1109\/SecDev.2016.043"},{"key":"6_CR30","doi-asserted-by":"crossref","unstructured":"She, D., Krishna, R., Yan, L., Jana, S., Ray, B.: Mtfuzz: fuzzing with a multi-task neural network. In: FSE (2020)","DOI":"10.1145\/3410251"},{"key":"6_CR31","first-page":"1","volume":"16","author":"N Stephens","year":"2016","unstructured":"Stephens, N., et al.: Driller: augmenting fuzzing through selective symbolic execution. NDSS 16, 1\u201316 (2016)","journal-title":"NDSS"},{"key":"6_CR32","unstructured":"Swiecki, R.: Honggfuzz: Security oriented software fuzzer. supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based) (2020). https:\/\/honggfuzz.dev\/"},{"key":"6_CR33","doi-asserted-by":"crossref","unstructured":"Wang, Y., et al.: Not all coverage measurements are equal: fuzzing by coverage accounting for input prioritization. NDSS (2020)","DOI":"10.14722\/ndss.2020.24422"},{"key":"6_CR34","doi-asserted-by":"crossref","unstructured":"You, W., et al.: Profuzzer: On-the-fly input type probing for better zero-day vulnerability discovery. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 769\u2013786. IEEE (2019)","DOI":"10.1109\/SP.2019.00057"},{"key":"6_CR35","unstructured":"Yue, T., et al.: Ecofuzz: adaptive energy-saving greybox fuzzing as a variant of the adversarial multi-armed bandit. In: 29th USENIX Security Symposium (USENIX Security 20) (2020)"},{"key":"6_CR36","unstructured":"Yun, I., Lee, S., Xu, M., Jang, Y., Kim, T.: QSYM: a practical concolic execution engine tailored for hybrid fuzzing. In: 27th USENIX Security Symposium (USENIX Security 2018), pp. 745\u2013761 (2018)"},{"key":"6_CR37","unstructured":"Zalewski, M.: American fuzzy lop (2.52b) (2019). https:\/\/lcamtuf.coredump.cx\/afl\/"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-80825-9_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,8,5]],"date-time":"2021-08-05T09:10:50Z","timestamp":1628154650000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-80825-9_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030808242","9783030808259"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-80825-9_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"9 July 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 July 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 July 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dimva2021.campus.ciencias.ulisboa.pt\/cfp.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"65","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"18","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}