{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,13]],"date-time":"2025-06-13T20:45:25Z","timestamp":1749847525476,"version":"3.40.3"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031293702"},{"type":"electronic","value":"9783031293719"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-29371-9_7","type":"book-chapter","created":{"date-parts":[[2023,3,30]],"date-time":"2023-03-30T13:24:05Z","timestamp":1680182645000},"page":"124-144","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Differential Testing of Cryptographic Libraries with Hybrid Fuzzing"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0305-3605","authenticated-orcid":false,"given":"Hoyong","family":"Jin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dohyeon","family":"An","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5513-0836","authenticated-orcid":false,"given":"Taekyoung","family":"Kwon","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,3,31]]},"reference":[{"key":"7_CR1","doi-asserted-by":"publisher","unstructured":"Babi\u0107, D., et al.: Fudge: fuzz driver generation at scale. In: Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC\/FSE 19), pp. 975\u2013985 (2019). https:\/\/doi.org\/10.1145\/3338906.3340456","DOI":"10.1145\/3338906.3340456"},{"key":"7_CR2","unstructured":"Blessing, J., Specter, MA., Weitzner, DJ.: You Really Shouldn\u2019t Roll Your Own Crypto: An Empirical Study of Vulnerabilities in Cryptographic Libraries. In: arXiv preprint arXiv:2107.04940 (2021)"},{"issue":"2","key":"7_CR3","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1145\/2408776.2408795","volume":"56","author":"C Cadar","year":"2013","unstructured":"Cadar, C., Sen, K.: Symbolic execution for software testing: three decades later. Commun. ACM 56(2), 82\u201390 (2013)","journal-title":"Commun. ACM"},{"key":"7_CR4","doi-asserted-by":"publisher","unstructured":"Cho, M., Kim, S., Kwon, T.: Intriguer: Field-level constraint solving for hybrid fuzzing. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS 19), pp. 515\u2013530 (2019). https:\/\/doi.org\/10.1145\/3319535.3354249","DOI":"10.1145\/3319535.3354249"},{"key":"7_CR5","unstructured":"Cryptofuzz. https:\/\/github.com\/guidovranken\/cryptofuzz. 2019 (2022)"},{"key":"7_CR6","unstructured":"Cryptofuzz\u2019s Matator. https:\/\/github.com\/guidovranken\/cryptofuzz\/blob\/master\/mutator.cpp. (2022)"},{"key":"7_CR7","unstructured":"CVE-2022-1343. https:\/\/access.redhat.com\/security\/cve\/cve-2022-1343. (2022)"},{"key":"7_CR8","unstructured":"Fioraldi, A., Maier, D., Ei\u00dffeldt, H., Heuse, M.: AFL++: Combining Incremental Steps of Fuzzing Research. In: 14th USENIX Workshop on Offensive Technologies (WOOT 20) (2020)"},{"key":"7_CR9","unstructured":"Google.AFL. https:\/\/github.com\/google\/AFL. 2013 (2022)"},{"key":"7_CR10","unstructured":"Google.AFL Persistent mode demo. https:\/\/github.com\/google\/AFL\/tree\/master\/experimental\/persistent_demo. (2022)"},{"key":"7_CR11","unstructured":"Google.FuzzBench report. https:\/\/www.fuzzbench.com\/reports\/2021-06-02\/index.html_openssl_x509-summary (2022)"},{"key":"7_CR12","unstructured":"Google.Syzkaller. https:\/\/github.com\/google\/syzkaller. (2022)"},{"key":"7_CR13","unstructured":"Ispoglou, K., Austin, D., Mohan, V., Payer, M.: FuzzGen: Automatic Fuzzer Generation. In: 29th USENIX Security Symposium (USENIX Security 20), pp. 2271\u20132287 (2020)"},{"key":"7_CR14","doi-asserted-by":"crossref","unstructured":"Jung, J., Tong, S., Hu, H., Lim, J., Jin, Y., Kim, T.: Winnie: Fuzzing windows applications with harness synthesis and fast cloning. In: The Network and Distributed System Security Symposium (NDSS 2021), pp. 1\u201317 (2021)","DOI":"10.14722\/ndss.2021.24334"},{"key":"7_CR15","doi-asserted-by":"crossref","unstructured":"Kim, K., Jeong, DR., Kim, CH., Jang, Y., Shin, I., Lee, B.: HFL: Hybrid Fuzzing on the Linux Kernel. In: The Network and Distributed System Security Symposium (NDSS 2020), pp. 1\u201317 (2020)","DOI":"10.14722\/ndss.2020.24018"},{"key":"7_CR16","doi-asserted-by":"publisher","unstructured":"Klees, G., Ruef, A., Cooper, B., Wei, S., Hicks, M.: Evaluating fuzz testing. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (CCS 18), pp. 2123\u20132138 (2018). https:\/\/doi.org\/10.1145\/3243734.3243804","DOI":"10.1145\/3243734.3243804"},{"key":"7_CR17","unstructured":"LibFuzzer Docs. https:\/\/llvm.org\/docs\/LibFuzzer.html. (2022)"},{"key":"7_CR18","unstructured":"LibFuzzer Standalone. https:\/\/github.com\/llvm\/llvm-project\/tree\/main\/compiler-rt\/lib\/fuzzer\/standalone. (2022)"},{"key":"7_CR19","unstructured":"LLVM Project. https:\/\/github.com\/llvm\/llvm-project. (2022)"},{"key":"7_CR20","doi-asserted-by":"publisher","unstructured":"Mera, A., Feng, B., Lu, L., Kirda, E.: DICE: Automatic emulation of dma input channels for dynamic firmware analysis. In: 2021 IEEE Symposium on Security and Privacy (SP), pp. 1938\u20131954 (2021). https:\/\/doi.org\/10.1109\/SP40001.2021.00018","DOI":"10.1109\/SP40001.2021.00018"},{"key":"7_CR21","doi-asserted-by":"publisher","unstructured":"Nilizadeh, S., Noller, Y., Pasareanu, CS. Pasareanu.: DifFuzz: differential fuzzing for side-channel analysis. In:2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE), pp. 176\u2013187 (2019). https:\/\/doi.org\/10.1109\/ICSE.2019.00034","DOI":"10.1109\/ICSE.2019.00034"},{"key":"7_CR22","doi-asserted-by":"crossref","unstructured":"Noller, Y., P\u01ces\u01cereanu, CS., B\u00f6hme, M., Sun, Y., Nguyen, HL., Grunske, L.: HyDiff: Hybrid differential software analysis. In: 2020 IEEE\/ACM 42nd International Conference on Software Engineering (ICSE), pp. 1273\u20131285 (2020)","DOI":"10.1145\/3377811.3380363"},{"key":"7_CR23","unstructured":"OpenSSL 1-day bug: BN_mod_exp2_mont NULL pointer dereference. https:\/\/github.com\/openssl\/openssl\/issues\/17648. (2022)"},{"key":"7_CR24","unstructured":"OpenSSL\u2019s Github Issue labeled triaged:bug. https:\/\/github.com\/openssl\/openssl\/issues?q=is:issue+is:open+label: triaged:+bug (2022)"},{"key":"7_CR25","unstructured":"Serebryany, K.: OSS-Fuzz: Google\u2019s continuous fuzzing service for open source software. https:\/\/github.com\/google\/oss-fuzz. (2017). (2022)"},{"key":"7_CR26","doi-asserted-by":"publisher","unstructured":"She, D., Pei, K., Epstein, D., Yang, J., Ray, B., Jana, S.: Neuzz: efficient fuzzing with neural program smoothing. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 803\u2013817 (2019). https:\/\/doi.org\/10.1109\/SP.2019.00052","DOI":"10.1109\/SP.2019.00052"},{"key":"7_CR27","doi-asserted-by":"crossref","unstructured":"Stephens, N., et al.: Augmenting fuzzing through selective symbolic execution. In: the Network and Distributed System Security Symposium (NDSS 2016), pp. 1\u201316 (2016)","DOI":"10.14722\/ndss.2016.23368"},{"key":"7_CR28","unstructured":"Wang, D., Zhang, Z., Zhang, H., Qian, Z., Krishnamurthy, SV., Abu-Ghazaleh, N.: SyzVegas: Beating Kernel Fuzzing Odds with Reinforcement Learning. In: 30th USENIX Security Symposium (USENIX Security 21), pp. 2741\u20132758 (2021)"},{"key":"7_CR29","doi-asserted-by":"publisher","unstructured":"Yang, X., Chen, Y., Eide, E., Regehr, J.: Finding and understanding bugs in C compilers. In: Proceedings of the 32nd ACM SIGPLAN conference on Programming language design and implementation (PLDI 11), pp. 283\u2013194 (2011). https:\/\/doi.org\/10.1145\/1993498.1993532","DOI":"10.1145\/1993498.1993532"},{"key":"7_CR30","unstructured":"Yang, Y., Kim, T., Chun, BG.: Finding consensus bugs in ethereum via multi-transaction differential fuzzing. In: 15th USENIX Symposium on Operating Systems Design and Implementation (OSDI 21), pp. 349\u2013365 (2021)"},{"key":"7_CR31","unstructured":"Yue, T., et al.: EcoFuzz: Adaptive Energy-Saving Greybox Fuzzing as a Variant of the Adversarial Multi-Armed Bandit. In: 29th USENIX Security Symposium (USENIX Security 20), pp. 2307\u20132324 (2020)"},{"key":"7_CR32","unstructured":"Yun, I., Lee, S., Xu, M., Jang, Y., Kim, T.: QSYM: a practical concolic execution engine tailored for hybrid fuzzing. In: 27th USENIX Security Symposium (USENIX Security 18), pp. 745\u2013761 (2018)"}],"container-title":["Lecture Notes in Computer Science","Information Security and Cryptology \u2013 ICISC 2022"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-29371-9_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,3,30]],"date-time":"2023-03-30T13:25:08Z","timestamp":1680182708000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-29371-9_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031293702","9783031293719"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-29371-9_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"31 March 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICISC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information Security and Cryptology","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Seoul","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 November 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 December 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icisc2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.icisc.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"69","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"24","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}