{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:43:07Z","timestamp":1785512587227,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":84,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,6,27]],"date-time":"2020-06-27T00:00:00Z","timestamp":1593216000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Ant Financial Research Program"},{"name":"National Natural Science Foundation of China","award":["61772347, 61836005, 61972260, 61772408, 61721002"],"award-info":[{"award-number":["61772347, 61836005, 61972260, 61772408, 61721002"]}]},{"name":"Guangdong Basic and Applied Basic Research Foundation","award":["2019A1515011577"],"award-info":[{"award-number":["2019A1515011577"]}]},{"name":"National Key R&D Program of China","award":["2018YFB0803501"],"award-info":[{"award-number":["2018YFB0803501"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,6,27]]},"DOI":"10.1145\/3377811.3380396","type":"proceedings-article","created":{"date-parts":[[2020,10,1]],"date-time":"2020-10-01T18:25:34Z","timestamp":1601576734000},"page":"765-777","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":109,"title":["MemLock"],"prefix":"10.1145","author":[{"given":"Cheng","family":"Wen","sequence":"first","affiliation":[{"name":"Shenzhen University, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haijun","family":"Wang","sequence":"additional","affiliation":[{"name":"Shenzhen University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuekang","family":"Li","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shengchao","family":"Qin","sequence":"additional","affiliation":[{"name":"Teesside University, UK and Shenzhen University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhiwu","family":"Xu","sequence":"additional","affiliation":[{"name":"Shenzhen University, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongxu","family":"Chen","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaofei","family":"Xie","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Geguang","family":"Pu","sequence":"additional","affiliation":[{"name":"East China Normal University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ting","family":"Liu","sequence":"additional","affiliation":[{"name":"Xi'an Jiaotong University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,10]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2512989.2513000"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1985793.1985795"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23371"},{"key":"e_1_3_2_1_4_1","volume-title":"Full-featured MP4 format and MPEG DASH library and tools","unstructured":"Bento4. 2019. Full-featured MP4 format and MPEG DASH library and tools. http:\/\/www.bento4.com. accessed: 2019-08-01."},{"key":"e_1_3_2_1_5_1","unstructured":"GNU binutils. 2019. a collection of binary tools. https:\/\/www.gnu.org\/software\/binutils\/. accessed: 2019-08-01."},{"key":"e_1_3_2_1_6_1","volume-title":"GRIMOIRE: Synthesizing Structure while Fuzzing.","author":"Blazytko Tim","year":"2019","unstructured":"Tim Blazytko, Cornelius Aschermann, Moritz Schl\u00f6gel, Ali Abbasi, Sergej Schumilo, Simon W\u00f6rner, and Thorsten Holz. 2019. GRIMOIRE: Synthesizing Structure while Fuzzing. (2019)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134020"},{"key":"e_1_3_2_1_8_1","volume-title":"Coverage-based greybox fuzzing as markov chain","author":"B\u00f6hme Marcel","year":"2017","unstructured":"Marcel B\u00f6hme, Van-Thuan Pham, and Abhik Roychoudhury. 2017. Coverage-based greybox fuzzing as markov chain. IEEE Transactions on Software Engineering (2017)."},{"key":"e_1_3_2_1_9_1","unstructured":"Maintained by Google. 2018. honggfuzz. http:\/\/honggfuzz.com\/."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666356.2594301"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243849"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00046"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1375634.1375656"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/11547662_7"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2980930.2907955"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2019.00015"},{"key":"e_1_3_2_1_17_1","unstructured":"CVE-2017-9804. 2017. Available from MITRE. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-9804."},{"key":"e_1_3_2_1_18_1","unstructured":"CVE-2018-17985. 2018. Available from MITRE. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-17985."},{"key":"e_1_3_2_1_19_1","unstructured":"CVE-2018-4868. 2019. Available from MITRE. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-4868."},{"key":"e_1_3_2_1_20_1","unstructured":"CVE-2019-6291. 2019. Available from MITRE. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-6291."},{"key":"e_1_3_2_1_21_1","unstructured":"CVE-2019-6292. 2019. Available from MITRE. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-6292."},{"key":"e_1_3_2_1_22_1","unstructured":"CVE-2019-7704. 2019. Available from MITRE. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-7704."},{"key":"e_1_3_2_1_23_1","volume-title":"accessed","author":"Details CVE","year":"2019","unstructured":"CVE Details. accessed: 2019. The list of Vulnerabilities according to CWE-400: Uncontrolled Resource Consumption. https:\/\/www.cvedetails.com\/cwe-details\/400\/Uncontrolled-Resource-Consumption-039-Resource-Exhaustion.html."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2017.02.043"},{"key":"e_1_3_2_1_25_1","volume-title":"Image metadata library and tools","unstructured":"Exiv2. 2019. Image metadata library and tools. http:\/\/www.exiv2.org\/. accessed: 2019-08-01."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00025"},{"key":"e_1_3_2_1_27_1","unstructured":"Flex. 2019. The Fast Lexical Analyzer - scanner generator for lexing in C and C++. https:\/\/github.com\/westes\/flex. accessed: 2019-08-01."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00040"},{"key":"e_1_3_2_1_29_1","unstructured":"Google. 2018. The list of common sanitizer options. https:\/\/github.com\/google\/sanitizers\/wiki\/SanitizerCommonFlags."},{"key":"e_1_3_2_1_30_1","unstructured":"Google. 2019. ClusterFuzz. https:\/\/google.github.io\/clusterfuzz\/."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04761-9_14"},{"key":"e_1_3_2_1_32_1","unstructured":"Jasper. 2019. Image Processing\/Coding Tool Kit. https:\/\/www.ece.uvic.ca\/~frodo\/jasper\/. accessed: 2019-08-01."},{"key":"e_1_3_2_1_33_1","volume-title":"26th USENIX Security Symposium. 989--1006","author":"Jia Xiangkun","year":"2017","unstructured":"Xiangkun Jia, Chao Zhang, Purui Su, Yi Yang, Huafeng Huang, and Dengguo Feng. 2017. Towards efficient heap overflow discovery. In 26th USENIX Security Symposium. 989--1006."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10506-2_14"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.5555\/977395.977673"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3213846.3213874"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238176"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-018-0002-y"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106295"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2018.2834476"},{"key":"e_1_3_2_1_42_1","volume-title":"A library for generating Macromedia Flash files","unstructured":"Libming. 2019. A library for generating Macromedia Flash files. http:\/\/www.libming.org\/. accessed: 2019-08-01."},{"key":"e_1_3_2_1_43_1","unstructured":"Libsass. 2019. A C\/C++ implementation of a Sass compiler. https:\/\/github.com\/sass\/libsass. accessed: 2019-08-01."},{"key":"e_1_3_2_1_44_1","volume-title":"CAFA: A Checksum-Aware Fuzzing Assistant Tool for Coverage Improvement. Security and Communication Networks","author":"Liu Xiaolong","year":"2018","unstructured":"Xiaolong Liu, Qiang Wei, Qingxian Wang, Zheng Zhao, and Zhongxu Yin. 2018. CAFA: A Checksum-Aware Fuzzing Assistant Tool for Coverage Improvement. Security and Communication Networks (2018)."},{"key":"e_1_3_2_1_45_1","unstructured":"LLVM-Documentation. 2018. libFuzzer - a library for coverage-guided fuzz testing. http:\/\/llvm.org\/docs\/LibFuzzer.html."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/TASE.2018.00027"},{"key":"e_1_3_2_1_47_1","volume-title":"Manuel Egele, Edward J Schwartz, and Maverick Woo.","author":"Manes Valentin JM","year":"2018","unstructured":"Valentin JM Manes, HyungSeok Han, Choongwoo Han, Sang Kil Cha, Manuel Egele, Edward J Schwartz, and Maverick Woo. 2018. Fuzzing: Art, Science, and Engineering. arXiv preprint arXiv:1812.00140 (2018)."},{"key":"e_1_3_2_1_48_1","unstructured":"MemLock. accessed: 2020-01-01. MemLock's Home Page. https:\/\/icse2020-memlock.github.io\/."},{"key":"e_1_3_2_1_49_1","volume-title":"accessed","author":"MITRE.","year":"2019","unstructured":"MITRE. accessed: 2019. CWE-400: Uncontrolled Resource Consumption. https:\/\/cwe.mitre.org\/data\/definitions\/400.html."},{"key":"e_1_3_2_1_50_1","volume-title":"accessed","author":"MITRE.","year":"2019","unstructured":"MITRE. accessed: 2019. CWE-401: Missing Release of Memory after Effective Lifetime. https:\/\/cwe.mitre.org\/data\/definitions\/401.html."},{"key":"e_1_3_2_1_51_1","volume-title":"accessed","author":"MITRE.","year":"2019","unstructured":"MITRE. accessed: 2019. CWE-674: Uncontrolled Recursion. https:\/\/cwe.mitre.org\/data\/definitions\/674.html."},{"key":"e_1_3_2_1_52_1","volume-title":"accessed","author":"MITRE.","year":"2019","unstructured":"MITRE. accessed: 2019. CWE-789: Uncontrolled Memory Allocation. https:\/\/cwe.mitre.org\/data\/definitions\/789.html."},{"key":"e_1_3_2_1_53_1","unstructured":"mjs. 2019. mjs: Restricted JavaScript engine. https:\/\/github.com\/cesanta\/mjs. accessed: 2019-08-01."},{"key":"e_1_3_2_1_54_1","unstructured":"Nasm. 2019. The Netwide Assembler. https:\/\/www.nasm.us. accessed: 2019-08-01."},{"key":"e_1_3_2_1_55_1","unstructured":"Openjpeg. 2019. An open-source JPEG 2000 codec written in C language. https:\/\/github.com\/uclouvain\/openjpeg. accessed: 2019-08-01."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3293882.3330576"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00056"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134073"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23404"},{"key":"e_1_3_2_1_60_1","unstructured":"Alexey Samsonov and Kostya Serebryany. 2013. New features in addresssanitizer. (2013)."},{"key":"e_1_3_2_1_61_1","unstructured":"Kostya Serebryany. 2017. OSS-Fuzz-Google's continuous fuzzing service for open source software. (2017)."},{"key":"e_1_3_2_1_62_1","unstructured":"Konstantin Serebryany Derek Bruening Alexander Potapenko and Dmitriy Vyukov. 2012. AddressSanitizer: A fast address sanity checker. In Presented as part of the 2012 USENIX Annual Technical Conference. 309--318."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238159"},{"key":"e_1_3_2_1_64_1","first-page":"1","article-title":"Driller: Augmenting Fuzzing Through Selective Symbolic Execution","volume":"16","author":"Stephens Nick","year":"2016","unstructured":"Nick Stephens, John Grosen, Christopher Salls, Andrew Dutcher, Ruoyu Wang, Jacopo Corbetta, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2016. Driller: Augmenting Fuzzing Through Selective Symbolic Execution.. In NDSS, Vol. 16. 1--16.","journal-title":"NDSS"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.13"},{"key":"e_1_3_2_1_66_1","volume-title":"Fuzzing for software security testing and quality assurance","author":"Takanen Ari","unstructured":"Ari Takanen, Jared D Demott, Charles Miller, and Atte Kettunen. 2018. Fuzzing for software security testing and quality assurance. Artech House."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33338-5_5"},{"key":"e_1_3_2_1_68_1","first-page":"101","article-title":"A critique and improvement of the CL common language effect size statistics of McGraw and Wong","volume":"25","author":"Vargha Andr\u00e1s","year":"2000","unstructured":"Andr\u00e1s Vargha and Harold D Delaney. 2000. A critique and improvement of the CL common language effect size statistics of McGraw and Wong. Journal of Educational and Behavioral Statistics 25, 2 (2000), 101--132.","journal-title":"Journal of Educational and Behavioral Statistics"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3192366.3192376"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3290326"},{"key":"e_1_3_2_1_71_1","volume-title":"Qinghua Zheng, and Ting Liu.","author":"Wang Haijun","year":"2019","unstructured":"Haijun Wang, Yun Lin, Zijiang Yang, Jun Sun, Yang Liu, Jin Song Dong, Qinghua Zheng, and Ting Liu. 2019. Explaining Regressions via Alignment Slicing and Mending. IEEE Transactions on Software Engineering (2019), 1--1."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2016.2584063"},{"key":"e_1_3_2_1_73_1","volume-title":"Typestate-Guided Fuzzer for Discovering Use-after-Free Vulnerabilities. In 2020 IEEE\/ACM 42nd International Conference on Software Engineering","author":"Wang Haijun","year":"2020","unstructured":"Haijun Wang, Xiaofei Xie, Yi Li, Cheng Wen, Yang Liu, Shengchao Qin, Hongxu Chen, and Yulei. Sui. 2020. Typestate-Guided Fuzzer for Discovering Use-after-Free Vulnerabilities. In 2020 IEEE\/ACM 42nd International Conference on Software Engineering. Seoul, South Korea."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338966"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00081"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183440.3183494"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236039"},{"key":"e_1_3_2_1_78_1","volume-title":"american fuzzy lop","author":"Technical","unstructured":"Technical whitepaper for afl fuzz. 2019. american fuzzy lop. http:\/\/lcamtuf.coredump.cx\/afl\/technical_details.txt. accessed: 2019-08-01."},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.scico.2017.06.010"},{"key":"e_1_3_2_1_80_1","unstructured":"yaml cpp. 2019. A YAML parser and emitter in C++. https:\/\/github.com\/jbeder\/yaml-cpp. accessed: 2019-08-01."},{"key":"e_1_3_2_1_81_1","volume-title":"The pattern matching swiss knife for malware researchers","unstructured":"Yara. 2019. The pattern matching swiss knife for malware researchers. http:\/\/virustotal.github.io\/yara\/. accessed: 2019-08-01."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00057"},{"key":"e_1_3_2_1_83_1","volume-title":"QSYM: A Practical Concolic Execution Engine Tailored for Hybrid Fuzzing. In 27th USENIX Security Symposium. 745--761","author":"Yun Insu","year":"2018","unstructured":"Insu Yun, Sangho Lee, Meng Xu, Yeongjin Jang, and Taesoo Kim. 2018. QSYM: A Practical Concolic Execution Engine Tailored for Hybrid Fuzzing. In 27th USENIX Security Symposium. 745--761."},{"key":"e_1_3_2_1_84_1","unstructured":"Michal Zalewski. 2017. American Fuzzy Lop 2.52b. http:\/\/lcamtuf.coredump.cx\/afl\/."}],"event":{"name":"ICSE '20: 42nd International Conference on Software Engineering","location":"Seoul South Korea","acronym":"ICSE '20","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","KIISE Korean Institute of Information Scientists and Engineers","IEEE CS"]},"container-title":["Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3377811.3380396","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3377811.3380396","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:41:39Z","timestamp":1750200099000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3377811.3380396"}},"subtitle":["memory usage guided fuzzing"],"short-title":[],"issued":{"date-parts":[[2020,6,27]]},"references-count":84,"alternative-id":["10.1145\/3377811.3380396","10.1145\/3377811"],"URL":"https:\/\/doi.org\/10.1145\/3377811.3380396","relation":{},"subject":[],"published":{"date-parts":[[2020,6,27]]},"assertion":[{"value":"2020-10-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}