{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T07:04:11Z","timestamp":1751267051567,"version":"3.37.3"},"reference-count":37,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2024,11,8]],"date-time":"2024-11-08T00:00:00Z","timestamp":1731024000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,11,8]],"date-time":"2024-11-08T00:00:00Z","timestamp":1731024000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["EP\/S022503\/1"],"award-info":[{"award-number":["EP\/S022503\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2025,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Despite being a severe error where programs inadvertently reveal confidential information, insecure flows rarely receive explicit attention during software testing. LeakFuzzer uses an input-output non-interference property, specialised via a security flow policy for the program under test, to advance the state of the art. It detects insecure flows by using hypertesting for violations of the program\u2019s non-interference property. LeakFuzzer extends the capabilities of the state of the art fuzzer, AFL++, and thus inherits its advantages such as scalability, automated input generation, high coverage and low developer intervention. It can thus detect the same set of errors as AFL++, as well as being able to detect violations of secure information flow policies at small additional performance costs. This offers a significant advance in scalability and automation for the state of the art. We evaluated LeakFuzzer on a diverse set of 12 C and C++ benchmarks containing known bugs that cause confidential information to be disclosed, ranging in size from just 80 to over 900k lines of code. Nine of these are taken from real-world CVEs including Heartbleed and a recent error in PostgreSQL. Given 20 24-hour runs, LeakFuzzer can find 100% of the insecure flows in the SUTs whereas existing techniques using the CBMC model checker and AFL++ augmented with different sanitizers can only find 40% at best.<\/jats:p>","DOI":"10.1007\/s10664-024-10556-3","type":"journal-article","created":{"date-parts":[[2024,11,8]],"date-time":"2024-11-08T07:15:51Z","timestamp":1731050151000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Hyperfuzzing: black-box security hypertesting with a grey-box fuzzer"],"prefix":"10.1007","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7320-9057","authenticated-orcid":false,"given":"Daniel","family":"Blackwell","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ingolf","family":"Becker","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Clark","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,11,8]]},"reference":[{"key":"10556_CR1","unstructured":"(h1994st) SH (2020) Grammar Mutator - AFL++. https:\/\/github.com\/AFLplusplus\/Grammar-Mutator"},{"key":"10556_CR2","unstructured":"4973 C (2014) xxHash. https:\/\/github.com\/Cyan4973\/xxHash"},{"issue":"6","key":"10556_CR3","doi-asserted-by":"publisher","first-page":"1207","DOI":"10.1017\/S0960129511000193","volume":"21","author":"G Barthe","year":"2011","unstructured":"Barthe G, D\u2019argenio PR, Rezk T (2011) Secure information flow by self-composition. Math Struct Comput Sci 21(6):1207\u20131252","journal-title":"Math Struct Comput Sci"},{"key":"10556_CR4","volume-title":"Secure computer systems: mathematical foundations","author":"DE Bell","year":"1973","unstructured":"Bell DE, LaPadula LJ (1973) Secure computer systems: mathematical foundations. Technical report, MITRE CORP BEDFORD MA"},{"key":"10556_CR5","unstructured":"Bellard F (2005) Qemu, a fast and portable dynamic translator. In: USENIX annual technical conference, FREENIX track, vol 41. Califor-nia, USA, pp 10\u20135555"},{"key":"10556_CR6","doi-asserted-by":"crossref","unstructured":"Biondi F, Enescu MA, Heuser A, Legay A, Meel KS, Quilbeuf J (2018) Scalable approximation of quantitative information flow in programs. In: International conference on verification, model checking, and abstract interpretation. Springer, pp 71\u201393","DOI":"10.1007\/978-3-319-73721-8_4"},{"key":"10556_CR7","doi-asserted-by":"crossref","unstructured":"Brennan T, Saha S, Bultan T (2020) Jvm fuzzing for jit-induced side-channel detection. In: Proceedings of the ACM\/IEEE 42nd international conference on software engineering, pp 1011\u20131023","DOI":"10.1145\/3377811.3380432"},{"key":"10556_CR8","doi-asserted-by":"publisher","first-page":"690","DOI":"10.1007\/978-3-642-39799-8_47","volume-title":"Computer aided verification","author":"T Chothia","year":"2013","unstructured":"Chothia T, Kawamoto Y, Novakovic C (2013) A tool for estimating information leakage. In: Sharygina N, Veith H (eds) Computer aided verification. Springer, Berlin, Heidelberg, pp 690\u2013695"},{"key":"10556_CR9","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1007\/978-3-319-11212-1_13","volume-title":"Computer Security - ESORICS 2014","author":"T Chothia","year":"2014","unstructured":"Chothia T, Kawamoto Y, Novakovic C (2014) Leakwatch: estimating information leakage from java programs. In: Kuty\u0142owski M, Vaidya J (eds) Computer Security - ESORICS 2014. Springer, Cham, pp 219\u2013236"},{"issue":"3","key":"10556_CR10","doi-asserted-by":"publisher","first-page":"321","DOI":"10.3233\/JCS-2007-15302","volume":"15","author":"D Clark","year":"2007","unstructured":"Clark D, Hunt S, Malacaria P (2007) A static analysis for quantifying information flow in a simple imperative language. J Comput Secur 15(3):321\u2013371","journal-title":"J Comput Secur"},{"key":"10556_CR11","doi-asserted-by":"crossref","unstructured":"Clarkson MR, Schneider FB (2008) Hyperproperties. In: 21st IEEE Computer security foundations symposium","DOI":"10.1109\/CSF.2008.7"},{"issue":"5","key":"10556_CR12","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1145\/360051.360056","volume":"19","author":"DE Denning","year":"1976","unstructured":"Denning DE (1976) A lattice model of secure information flow. Commun ACM 19(5):236\u2013243","journal-title":"Commun ACM"},{"key":"10556_CR13","unstructured":"Fioraldi A, Maier D, Ei\u00dffeldt H, Heuse M (2020) $$\\{$$AFL++$$\\}$$: combining incremental steps of fuzzing research. In: 14th USENIX workshop on offensive technologies (WOOT 20)"},{"issue":"3","key":"10556_CR14","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1145\/2093548.2093564","volume":"55","author":"P Godefroid","year":"2012","unstructured":"Godefroid P, Levin MY, Molnar D (2012) Sage: whitebox fuzzing for security testing. Commun ACM 55(3):40\u201344","journal-title":"Commun ACM"},{"key":"10556_CR15","doi-asserted-by":"publisher","unstructured":"Goguen JA, Meseguer J (1982) Security policies and security models. In: 1982 IEEE symposium on security and privacy, pp 11\u201311. https:\/\/doi.org\/10.1109\/SP.1982.10014","DOI":"10.1109\/SP.1982.10014"},{"key":"10556_CR16","unstructured":"Google (2011) sanitizers. https:\/\/github.com\/google\/sanitizers"},{"key":"10556_CR17","unstructured":"Google (2016) fuzzer-test-suite. https:\/\/github.com\/google\/fuzzer-test-suite"},{"key":"10556_CR18","unstructured":"Google (2019) afl-based-fuzzers-overview.md. https:\/\/github.com\/google\/fuzzing\/blob\/master\/docs\/afl-based-fuzzers-overview.md"},{"key":"10556_CR19","doi-asserted-by":"crossref","unstructured":"Hamann T, Herda M, Mantel H, Mohr M, Schneider D, Tasch M (2018) A uniform information-flow security benchmark suite for source code and bytecode. In: Nordic conference on secure IT systems. Springer, pp 437\u2013453","DOI":"10.1007\/978-3-030-03638-6_27"},{"key":"10556_CR20","doi-asserted-by":"crossref","unstructured":"He S, Emmi M, Ciocarlie G (2020) ct-fuzz: fuzzing for timing leaks. In: 2020 IEEE 13th International Conference on Software Testing, Validation and Verification (ICST). IEEE, pp 466\u2013471","DOI":"10.1109\/ICST46399.2020.00063"},{"key":"10556_CR21","doi-asserted-by":"crossref","unstructured":"Heusser J, Malacaria P (2010) Quantifying information leaks in software. In: Proceedings of the 26th annual computer security applications conference, pp 261\u2013269","DOI":"10.1145\/1920261.1920300"},{"key":"10556_CR22","unstructured":"Hocevar S (2007) zzuf - multi-purpose fuzzer. http:\/\/caca.zoy.org\/wiki\/zzuf"},{"key":"10556_CR23","unstructured":"Kinder J (2015) Hypertesting: the case for automated testing of hyperproperties. In: 3rd Workshop on hot issues in security principles and trust (HotSpot)"},{"key":"10556_CR24","doi-asserted-by":"crossref","unstructured":"Klebanov V, Manthey N, Muise C (2013) Sat-based analysis and quantification of information flow in programs. In: Quantitative evaluation of systems: 10th international conference, QEST 2013, Buenos Aires, Argentina, August 27-30, 2013. Proceedings 10. Springer, pp 177\u2013192","DOI":"10.1007\/978-3-642-40196-1_16"},{"key":"10556_CR25","doi-asserted-by":"crossref","unstructured":"Klees G, Ruef A, Cooper B, Wei S, Hicks M (2018) Evaluating fuzz testing. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, pp 2123\u20132138","DOI":"10.1145\/3243734.3243804"},{"key":"10556_CR26","doi-asserted-by":"crossref","unstructured":"Mesecan I, Blackwell D, Clark D, Cohen MB, Petke J (2021) Hypergi: automated detection and repair of information flow leakage. In: 36th IEEE\/ACM International conference on Automated Software Engineering (ASE)","DOI":"10.1109\/ASE51524.2021.9678758"},{"key":"10556_CR27","doi-asserted-by":"crossref","unstructured":"Mesecan I, Blackwell D, Clark D, Cohen MB, Petke J (2022) Keeping secrets: multi-objective genetic improvement for detecting and reducing information leakage. In: 37th IEEE\/ACM international conference on automated software engineering, ASE","DOI":"10.1145\/3551349.3556947"},{"key":"10556_CR28","doi-asserted-by":"crossref","unstructured":"Metzman J, Szekeres L, Simon L, Sprabery R, Arya A (2021) Fuzzbench: an open fuzzer benchmarking platform and service. In: Proceedings of the 29th ACM joint meeting on european software engineering conference and symposium on the foundations of software engineering, pp 1393\u20131403","DOI":"10.1145\/3468264.3473932"},{"issue":"12","key":"10556_CR29","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1145\/96267.96279","volume":"33","author":"BP Miller","year":"1990","unstructured":"Miller BP, Fredriksen L, So B (1990) An empirical study of the reliability of unix utilities. Commun ACM 33(12):32\u201344","journal-title":"Commun ACM"},{"key":"10556_CR30","unstructured":"Moroz M (2019) google\/AFL. https:\/\/github.com\/google\/AFL\/blob\/master\/docs\/status_screen.txt"},{"key":"10556_CR31","doi-asserted-by":"crossref","unstructured":"Nilizadeh S, Noller Y, P\u0103s\u0103reanu CS (2019) Diffuzz: differential fuzzing for side-channel analysis. In: 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE). IEEE, pp 176\u2013187","DOI":"10.1109\/ICSE.2019.00034"},{"key":"10556_CR32","doi-asserted-by":"crossref","unstructured":"Noller Y, Tizpaz-Niari S (2021) Qfuzz: quantitative fuzzing for side channels. In: Proceedings of the 30th ACM SIGSOFT international symposium on software testing and analysis, pp 257\u2013269","DOI":"10.1145\/3460319.3464817"},{"issue":"6","key":"10556_CR33","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2382756.2382791","volume":"37","author":"Q-S Phan","year":"2012","unstructured":"Phan Q-S, Malacaria P, Tkachuk O, P\u0103s\u0103reanu CS (2012) Symbolic quantitative information flow. ACM SIGSOFT Softw Eng Notes 37(6):1\u20135","journal-title":"ACM SIGSOFT Softw Eng Notes"},{"issue":"1","key":"10556_CR34","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/JSAC.2002.806121","volume":"21","author":"A Sabelfeld","year":"2003","unstructured":"Sabelfeld A, Myers AC (2003) Language-based information-flow security. Sel Areas Commun 21(1):5\u201319","journal-title":"Sel Areas Commun"},{"key":"10556_CR35","unstructured":"Shen Z, Roongta R, Dolan-Gavitt B (2024) Drifuzz: harvesting bugs in device drivers from golden seeds"},{"key":"10556_CR36","unstructured":"tegansb, Schwartz-Narbonne D (2020) github.com - diffblue\/cbmc - Parsing Errors when compiling C++ #5489. https:\/\/github.com\/diffblue\/cbmc\/issues\/5489"},{"key":"10556_CR37","unstructured":"Zalewski M (2014) american fuzzy lop (2.52b). http:\/\/lcamtuf.coredump.cx\/afl\/"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-024-10556-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-024-10556-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-024-10556-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,7]],"date-time":"2025-01-07T14:12:19Z","timestamp":1736259139000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-024-10556-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,8]]},"references-count":37,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1]]}},"alternative-id":["10556"],"URL":"https:\/\/doi.org\/10.1007\/s10664-024-10556-3","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"type":"print","value":"1382-3256"},{"type":"electronic","value":"1573-7616"}],"subject":[],"published":{"date-parts":[[2024,11,8]]},"assertion":[{"value":"23 September 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 November 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declared that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of interest"}}],"article-number":"22"}}