{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T02:43:53Z","timestamp":1769913833036,"version":"3.49.0"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2021,9,30]],"date-time":"2021-09-30T00:00:00Z","timestamp":1632960000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,9,30]],"date-time":"2021-09-30T00:00:00Z","timestamp":1632960000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J. Comput. Sci. Technol."],"published-print":{"date-parts":[[2021,10]]},"DOI":"10.1007\/s11390-021-1196-0","type":"journal-article","created":{"date-parts":[[2021,10,27]],"date-time":"2021-10-27T14:02:58Z","timestamp":1635343378000},"page":"1212-1228","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Vulnerable Region-Aware Greybox Fuzzing"],"prefix":"10.1007","volume":"36","author":[{"given":"Ling-Yun","family":"Situ","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhi-Qiang","family":"Zuo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Le","family":"Guan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lin-Zhang","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuan-Dong","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jin","family":"Shi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,9,30]]},"reference":[{"issue":"12","key":"1196_CR1","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1145\/96267.96279","volume":"33","author":"BP Miller","year":"1990","unstructured":"Miller B P, Fredriksen L, So B. An empirical study of the reliability of UNIX utilities. Communications of the ACM, 1990, 33(12): 32-44. DOI: https:\/\/doi.org\/10.1145\/96267.96279.","journal-title":"Communications of the ACM"},{"key":"1196_CR2","doi-asserted-by":"crossref","unstructured":"Li J, Zhao B, Zhang C. Fuzzing: A survey. Cybersecurity, 2018, 1(1): Article No. 6. DOI: 10.1186\/s42400-018-0002-y.","DOI":"10.1186\/s42400-018-0002-y"},{"key":"1196_CR3","unstructured":"Sutton M, Greene A, Amini P. Fuzzing: Brute Force Vulnerability Discovery (1st edition). Addison-Wesley Professional, 2007."},{"key":"1196_CR4","doi-asserted-by":"publisher","first-page":"118","DOI":"10.1016\/j.cose.2018.02.002","volume":"75","author":"C Chen","year":"2018","unstructured":"Chen C, Cui B, Ma J, Wu R, Guo J, Liu W. A systematic review of fuzzing techniques. Computers & Security, 2018, 75: 118-137. DOI: https:\/\/doi.org\/10.1016\/j.cose.2018.02.002.","journal-title":"Computers & Security"},{"key":"1196_CR5","doi-asserted-by":"publisher","unstructured":"Man\u00e8s V J M, Han H S, Han C, Cha S K, Egele M, Schwartz E J, Woo M. The art, science, and engineering of fuzzing: A survey. IEEE Trans. Software Engineering. DOI: https:\/\/doi.org\/10.1109\/TSE.2019.2946563.","DOI":"10.1109\/TSE.2019.2946563"},{"key":"1196_CR6","unstructured":"Devarajan G. Unraveling SCADA protocols: Using sulley fuzzer. In Proc. the DEF CON 15 Hacking Conf., August 2007."},{"key":"1196_CR7","doi-asserted-by":"publisher","unstructured":"Gascon H, Wressnegger C, Yamaguchi F, Arp D, Rieck K. Pulsar: Stateful black-box fuzzing of proprietary network protocols. In Proc. the 11th International Conference on Security and Privacy in Communication Networks, October 2015, pp.330-347. DOI: https:\/\/doi.org\/10.1007\/978-3-319-28865-918.","DOI":"10.1007\/978-3-319-28865-918"},{"key":"1196_CR8","doi-asserted-by":"publisher","unstructured":"Ganesh V, Leek T, Rinard M. Taint-based directed white-box fuzzing. In Proc. the 31st Int. Software Engineering, May 2009, pp.474-484. DOI: https:\/\/doi.org\/10.1109\/ICSE.2009.5070546.","DOI":"10.1109\/ICSE.2009.5070546"},{"key":"1196_CR9","doi-asserted-by":"publisher","unstructured":"Wang T, Wei T, Gu G, Zou W. TaintScope: A checksumaware directed fuzzing tool for automatic software vulnerability detection. In Proc. the 2010 IEEE Symposium on Security and Privacy, May 2010, pp.497-512. DOI: https:\/\/doi.org\/10.1109\/SP.2010.37.","DOI":"10.1109\/SP.2010.37"},{"key":"1196_CR10","doi-asserted-by":"crossref","unstructured":"Stephens N, Grosen J, Salls C, Dutcher A, Wang R, Corbetta J, Shoshitaishvili Y, Kruegel C, Vingna G. Driller: Augmenting fuzzing through selective symbolic execution. In Proc. the 23rd Annual Network and Dis- tributed System Security Symposium, February 2016. DOI: 10.14722\/ndss.2016.23368.","DOI":"10.14722\/ndss.2016.23368"},{"issue":"3","key":"1196_CR11","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1145\/2093548.2093564","volume":"55","author":"P Godefroid","year":"2012","unstructured":"Godefroid P, Levin M Y, Molnar D. SAGE: Whitebox fuzzing for security testing. Communications of the ACM, 2012, 55(3): 40-44. DOI: https:\/\/doi.org\/10.1145\/2093548.2093564.","journal-title":"Communications of the ACM"},{"key":"1196_CR12","doi-asserted-by":"publisher","unstructured":"Situ L, Wang L, Li X, Guan L, Zhang W, Liu P. Energy distribution matters in greybox fuzzing. In Proc. the 41st Int. Software Engineering: Companion Proceedings, May 2019, pp.270-271. DOI: https:\/\/doi.org\/10.1109\/ICSE-Companion.2019.00109.","DOI":"10.1109\/ICSE-Companion.2019.00109"},{"issue":"5","key":"1196_CR13","doi-asserted-by":"publisher","first-page":"489","DOI":"10.1109\/TSE.2017.2785841","volume":"45","author":"M B\u00f6hme","year":"2017","unstructured":"B\u00f6hme M, Pham V T, Roychoudhury A. Coveragebased greybox fuzzing as Markov chain. IEEE Trans. Software Engineering, 2017, 45(5): 489-506. DOI: https:\/\/doi.org\/10.1109\/TSE.2017.2785841.","journal-title":"IEEE Trans. Software Engineering"},{"key":"1196_CR14","doi-asserted-by":"publisher","unstructured":"Pham V T, B\u00f6hme M, Santosa A E, Caciulescu A R, Roychoudhury A. Smart greybox fuzzing. IEEE Transactions on Software Engineering. DOI: https:\/\/doi.org\/10.1109\/TSE.2019.2941681.","DOI":"10.1109\/TSE.2019.2941681"},{"key":"1196_CR15","doi-asserted-by":"publisher","unstructured":"Du X, Chen B, Li Y, Guo J, Zhou Y, Liu Y, Jiang Y. Leopard: Identifying vulnerable code for vulnerability assessment through program metrics. In Proc. the 41st Int. Software Engineering, May 2019, pp.60-71. DOI: https:\/\/doi.org\/10.1109\/ICSE.2019.00024.","DOI":"10.1109\/ICSE.2019.00024"},{"issue":"10","key":"1196_CR16","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1145\/2544173.2509553","volume":"48","author":"Y Li","year":"2013","unstructured":"Li Y, Su Z, Wang L, Li L. Steering symbolic execution to less traveled paths. ACM SIGPLAN Notices, 2013, 48(10): 19-32. DOI: https:\/\/doi.org\/10.1145\/2544173.2509553.","journal-title":"ACM SIGPLAN Notices"},{"key":"1196_CR17","doi-asserted-by":"publisher","unstructured":"Wang X, Sun J, Chen Z, Zhang P, Wang J, Lin Y. Towards optimal concolic testing. In Proc. the 40th Int. Conf. Software Engineering, May 2018, pp.291-302. DOI: https:\/\/doi.org\/10.1145\/3180155.3180177.","DOI":"10.1145\/3180155.3180177"},{"key":"1196_CR18","doi-asserted-by":"publisher","unstructured":"Inozemtseva L, Holmes R. Coverage is not strongly correlated with test suite effectiveness. In Proc. the 36th Int. Conf. Software Engineering, May 2014, pp.435-445. DOI: https:\/\/doi.org\/10.1145\/2568225.2568271.","DOI":"10.1145\/2568225.2568271"},{"key":"1196_CR19","doi-asserted-by":"publisher","unstructured":"Petsios T, Zhao J, Keromytis A D, Jana S. Slow- Fuzz: Automated domain-independent detection of algorithmic complexity vulnerabilities. In Proc. the 2017 ACM SIGSAC Conference on Computer and Communications Security, October 2017, pp.2155-2168. DOI: https:\/\/doi.org\/10.1145\/3133956.3134073.","DOI":"10.1145\/3133956.3134073"},{"key":"1196_CR20","doi-asserted-by":"publisher","unstructured":"Lemieux C, Sen K. FairFuzz: A targeted mutation strategy for increasing greybox fuzz testing coverage. In Proc. the 33rd ACM\/IEEE Int. Automated Soft- ware Engineering, September 2018, pp.475-485. DOI: https:\/\/doi.org\/10.1145\/3238147.3238176.","DOI":"10.1145\/3238147.3238176"},{"key":"1196_CR21","doi-asserted-by":"publisher","unstructured":"B\u00f6hme M, Pham V T, Nguyen M D, Roychoudhury A. Directed greybox fuzzing. In Proc. the 2017 ACM SIGSAC Conference on Computer and Communications Security, October 2017, pp.2329-2344. DOI: https:\/\/doi.org\/10.1145\/3133956.3134020.","DOI":"10.1145\/3133956.3134020"},{"key":"1196_CR22","doi-asserted-by":"publisher","unstructured":"Gan S, Zhang C, Qin X, Tu X, Li K, Pei Z, Chen Z. CollAFL: Path sensitive fuzzing. In Proc. the 2018 IEEE Symposium on Security and Privacy, May 2018, pp.679-696. DOI: https:\/\/doi.org\/10.1109\/SP.2018.00040.","DOI":"10.1109\/SP.2018.00040"},{"key":"1196_CR23","doi-asserted-by":"publisher","unstructured":"Chen P, Chen H. Angora: Efficient fuzzing by principled search. In Proc. the 2018 IEEE Symposium on Security and Privacy, May 2018, pp.711-725. DOI: https:\/\/doi.org\/10.1109\/SP.2018.00046.","DOI":"10.1109\/SP.2018.00046"},{"key":"1196_CR24","doi-asserted-by":"publisher","unstructured":"Dolan-Gavitt B, Hulin P, Kirda E, Lee T, Mambretti A, Robertson W, Ulrich F, Whelan R. LAVA: Large-scale automated vulnerability addition. In Proc. the 2016 IEEE Symposium on Security and Privacy, May 2016, pp.110- 121. DOI: https:\/\/doi.org\/10.1109\/SP.2016.15.","DOI":"10.1109\/SP.2016.15"},{"key":"1196_CR25","doi-asserted-by":"publisher","unstructured":"Woo M, Cha S K, Gottlieb S, Brumley D. Scheduling blackbox mutational fuzzing. In Proc. the 2013 ACM SIGSAC Conference on Computer & Communications Security, November 2013, pp.511-522. DOI: https:\/\/doi.org\/10.1145\/2508859.2516736.","DOI":"10.1145\/2508859.2516736"},{"key":"1196_CR26","doi-asserted-by":"publisher","unstructured":"B\u00f6hme M. STADS: Software testing as species discovery. ACM Transactions on Software Engineering and Method- ology, 2018, 27(2): Article No. 7. DOI: https:\/\/doi.org\/10.1145\/3210309.","DOI":"10.1145\/3210309"},{"issue":"5","key":"1196_CR27","doi-asserted-by":"publisher","first-page":"972","DOI":"10.1007\/s11390-019-1955-3","volume":"34","author":"LY Situ","year":"2019","unstructured":"Situ L Y, Wang L Z, Liu Y, Mao B, Li X. Automatic detection and repair recommendation for missing checks. Journal of Computer Science and Technology, 2019, 34(5): 972-992. DOI: https:\/\/doi.org\/10.1007\/s11390-019-1955-3.","journal-title":"Journal of Computer Science and Technology"},{"key":"1196_CR28","doi-asserted-by":"publisher","unstructured":"Rawat S, Jain V, Kumar A, Cojocar L, Giuffrida C, Bos H. VUzzer: Application-aware evolutionary fuzzing. In Proc. the 24th Annual Network and Distributed System Security Symposium, February 26-March 1, 2017. DOI: https:\/\/doi.org\/10.14722\/ndss.2017.23404.","DOI":"10.14722\/ndss.2017.23404"},{"key":"1196_CR29","doi-asserted-by":"publisher","unstructured":"Klees G, Ruef A, Cooper B, Wei S, Hichk M. Evaluating fuzz testing. In Proc. the 2018 ACM SIGSAC Conference on Computer and Communications Security, October 2018, pp.2123-2138. DOI: https:\/\/doi.org\/10.1145\/3243734.3243804.","DOI":"10.1145\/3243734.3243804"},{"key":"1196_CR30","doi-asserted-by":"publisher","unstructured":"Wang Y, Jia X, Liu Y, Zeng K, Bao T, Wu D, Su P. Not all coverage measurements are equal: Fuzzing by coverage accounting for input prioritization. In Proc. the 27th Annual Network and Distributed System Security Symposium, February 2020. DOI: https:\/\/doi.org\/10.14722\/ndss.2020.24422.","DOI":"10.14722\/ndss.2020.24422"},{"key":"1196_CR31","doi-asserted-by":"publisher","unstructured":"Chen H, Xue Y, Li Y, Chen B, Xie X, Wu X, Liu Y. Hawkeye: Towards a desired directed grey-box fuzzer. In Proc. the 2018 ACM SIGSAC Conference on Computer and Communications Security, October 2018, pp.2095- 2108. DOI: https:\/\/doi.org\/10.1145\/3243734.3243849.","DOI":"10.1145\/3243734.3243849"},{"issue":"2","key":"1196_CR32","doi-asserted-by":"publisher","first-page":"101","DOI":"10.3102\/10769986025002101","volume":"25","author":"A Vargha","year":"2000","unstructured":"Vargha A, Delaney H D. A critique and improvement of the CL common language effect size statistics of McGraw and Wong. Journal of Educational and Behavioral Statistics, 2000, 25(2): 101-132. DOI: https:\/\/doi.org\/10.3102\/10769986025002101.","journal-title":"Journal of Educational and Behavioral Statistics"},{"issue":"3","key":"1196_CR33","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1002\/stvr.1486","volume":"24","author":"A Arcuri","year":"2014","unstructured":"Arcuri A, Briand L. A hitchhiker's guide to statistical tests for assessing randomized algorithms in software engineering. Software Testing, Verification and Reliability, 2014, 24(3): 219-250. DOI: https:\/\/doi.org\/10.1002\/stvr.1486.","journal-title":"Software Testing, Verification and Reliability"},{"key":"1196_CR34","doi-asserted-by":"publisher","unstructured":"Li Y, Chen B, Chandramohan M, Lin S W, Liu Y, Tiu A. Steelix: Program-state based binary fuzzing. In Proc. the 11th Joint Meeting on Foundations of Software Engineering, August 2017, pp.627-637. DOI: https:\/\/doi.org\/10.1145\/3106237.3106295.","DOI":"10.1145\/3106237.3106295"},{"key":"1196_CR35","unstructured":"Serebryany K, Bruening D, Potapenko A, Vyukov D. AddressSanitizer: A fast address sanity checker. In Proc. the 2012 USENIX Annual Technical Conference, June 2012, pp.309-318."},{"key":"1196_CR36","doi-asserted-by":"publisher","unstructured":"Stepanov E, Serebryany K. MemorySanitizer: Fast detector of uninitialized memory use in C++. In Proc. the 13th Annual IEEE\/ACM International Symposium on Code Gene- ration and Optimization, February 2015, pp.46-55. DOI: https:\/\/doi.org\/10.1109\/CGO.2015.7054186.","DOI":"10.1109\/CGO.2015.7054186"},{"key":"1196_CR37","doi-asserted-by":"publisher","unstructured":"Serebryany K, Iskhodzhanov T. ThreadSanitizer: Data race detection in practice. In Proc. the Workshop on Binary Instrumentation and Applications, December 2009, pp.62-71. DOI: https:\/\/doi.org\/10.1145\/1791194.1791203.","DOI":"10.1145\/1791194.1791203"},{"key":"1196_CR38","doi-asserted-by":"publisher","unstructured":"Li Y, Xue Y, Chen H, Wu, X, Zhang C, Xie X, Wang H, Liu Y. Cerebro: Context-aware adaptive fuzzing for effective vulnerability detection. In Proc. the 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, August 2019, pp.533-544. DOI: https:\/\/doi.org\/10.1145\/3338906.3338975.","DOI":"10.1145\/3338906.3338975"}],"container-title":["Journal of Computer Science and Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11390-021-1196-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11390-021-1196-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11390-021-1196-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,27]],"date-time":"2021-10-27T15:15:01Z","timestamp":1635347701000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11390-021-1196-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,30]]},"references-count":38,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2021,10]]}},"alternative-id":["1196"],"URL":"https:\/\/doi.org\/10.1007\/s11390-021-1196-0","relation":{},"ISSN":["1000-9000","1860-4749"],"issn-type":[{"value":"1000-9000","type":"print"},{"value":"1860-4749","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,30]]},"assertion":[{"value":"3 December 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 May 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 September 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}