{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:04:39Z","timestamp":1777806279494,"version":"3.51.4"},"reference-count":76,"publisher":"SAGE Publications","issue":"5","license":[{"start":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:00:00Z","timestamp":1750291200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2025,9]]},"abstract":"<jats:p>Testing a program\u2019s capability to effectively handle errors is a significant challenge, given that program errors are relatively uncommon. To address this, software fault injection (SFI)-based fuzzing combines SFI with traditional fuzzing to inject faults and trigger errors, enabling the testing of (error handling) code. However, current SFI-based fuzzing approaches have overlooked the correlation between paths housing error points. In fact, the execution paths of error points often share common paths. As a result, fuzzers usually generate test cases repeatedly to explore these common paths. This practice can compromise the efficiency of the fuzzer(s). To address this issue, this paper introduces HuntFUZZ, a novel SFI-based fuzzing framework designed to minimize redundant exploration of error points with correlated paths. HuntFUZZ achieves this by clustering these correlated error points and using concolic execution to resolve the path constraints necessary for approaching or reaching these clusters. This approach provides the fuzzer with optimized test cases, allowing it to efficiently explore error points within the cluster while minimizing redundancy. We evaluate HuntFUZZ on a diverse set of 42 applications, and HuntFUZZ successfully reveals 162 known bugs, with 62 of them being related to error handling. Additionally, due to its efficient error point detection method, HuntFUZZ discovers seven unique zero-day bugs, which are all missed by existing fuzzers. Furthermore, we compare HuntFUZZ with four existing fuzzing approaches, including AFL, AFL++, AFLGo, and EH-FUZZ. Our evaluation confirms that HuntFUZZ can cover a broader range of error points, and it exhibits better performance in terms of bug-finding speed.<\/jats:p>","DOI":"10.1177\/0926227x251343867","type":"journal-article","created":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T03:23:09Z","timestamp":1750303389000},"page":"334-359","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":0,"title":["HuntFUZZ: Enhancing error handling testing through clustering based fuzzing"],"prefix":"10.1177","volume":"33","author":[{"given":"Jin","family":"Wei","sequence":"first","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"},{"name":"Institute of BigsData, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8517-0580","authenticated-orcid":false,"given":"Ping","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of BigsData, Fudan University, Shanghai, China"},{"name":"Purple Mountain Laboratories, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Dai","sequence":"additional","affiliation":[{"name":"Worcester Polytechnic Institute, Massachusetts, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoyan","family":"Sun","sequence":"additional","affiliation":[{"name":"Worcester Polytechnic Institute, Massachusetts, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhihao","family":"Zhang","sequence":"additional","affiliation":[{"name":"Worcester Polytechnic Institute, Massachusetts, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chang","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yi","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of BigsData, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2025,6,19]]},"reference":[{"key":"e_1_3_3_2_2","unstructured":"Gunawi HS Rubio-Gonz\u00e1lez C Arpaci-Dusseau AC et al. Eio: Error handling is occasionally correct. In: 6th USENIX Conference on File and Storage Technologies FAST\u201908 San Jose California February 26\u201329 2008 USENIX Association 2560 Ninth St. Suite 215 Berkeley CA United States."},{"key":"e_1_3_3_3_2","doi-asserted-by":"crossref","unstructured":"Saha S Lozi JP Thomas G et al. Hector: Detecting resource-release omission faults in error-handling code for systems software. In: 2013 43rd annual IEEE\/IFIP international conference on dependable systems and networks (DSN) Budapest Hungary 24\u201327 June 2013 pp.1\u201312. IEEE.","DOI":"10.1109\/DSN.2013.6575307"},{"key":"e_1_3_3_4_2","doi-asserted-by":"crossref","unstructured":"Weimer W Necula GC. Finding and preventing run-time error handling mistakes. In: Proceedings of the 19th annual ACM SIGPLAN conference on object-oriented programming systems languages and applicationss (OOPSLA \u201904) Vancouver British Columbia Canada Oct. 2004 pp.419\u2013431 Association for Computing Machinery New York United States.","DOI":"10.1145\/1028976.1029011"},{"key":"e_1_3_3_5_2","doi-asserted-by":"crossref","unstructured":"Cabral B Marques P. Exception handling: a field study in java and. net. In: ECOOP 2007\u2013object-oriented programming: 21st European conference Berlin Germany July 30\u2013August 3 2007. Proceedings 21 2007 pp.151\u2013175. Springer Berlin Heidelberg.","DOI":"10.1007\/978-3-540-73589-2_8"},{"key":"e_1_3_3_6_2","doi-asserted-by":"crossref","unstructured":"Ebert F Castor F. A study on developers\u2019 perceptions about exception handling bugs. In: 2013 IEEE international conference on software maintenance Eindhoven Netherlands 22\u201328 September 2013 Eindhoven Netherlands pp.448\u2013451. IEEE NW Washington DC United States.","DOI":"10.1109\/ICSM.2013.69"},{"key":"e_1_3_3_7_2","doi-asserted-by":"crossref","unstructured":"Kery MB Le Goues C Myers BA. Examining programmer practices for locally handling exceptions. In: Proceedings of the 13th international conference on mining software repositories (MSR) Austin Texas May 14\u201322 2016 pp.484\u2013487 Association for Computing Machinery New York United States.","DOI":"10.1145\/2901739.2903497"},{"key":"e_1_3_3_8_2","doi-asserted-by":"crossref","unstructured":"Shah H G\u00f6rg C Harrold MJ. Why do developers neglect exception handling? In: Proceedings of the 4th international workshop on Exception handling (WEN) \u00a0Atlanta Georgia November 14 \u00a02008 pp.62\u201368 \u00a0Association for Computing Machinery New York United States.","DOI":"10.1145\/1454268.1454277"},{"key":"e_1_3_3_9_2","doi-asserted-by":"crossref","unstructured":"Fu C Ryder BG Milanova A et al. Testing of Java web services for robustness. In: Proceedings of the 2004 ACM SIGSOFT international symposium on Software testing and analysis Boston Massachusetts USA July 2004 pp.23\u201334 Association for Computing Machinery New York United States.","DOI":"10.1145\/1007512.1007516"},{"key":"e_1_3_3_10_2","doi-asserted-by":"crossref","unstructured":"Askarov A Sabelfeld A. Catch me if you can: permissive yet secure error handling. In: Proceedings of the ACM SIGPLAN fourth workshop on programming languages and analysis for security Dublin Ireland June 15\u201321 2009 pp.45\u201357 Association for Computing Machinery New York United States.","DOI":"10.1145\/1554339.1554346"},{"key":"e_1_3_3_11_2","unstructured":"Jana S Kang YJ Roth S et al. Automatically detecting error handling bugs using error specifications. In: 25th USENIX security symposium (USENIX Security 16) Austin TX Aug. 2016 pp.345\u2013362 \u00a0USENIX Association 2560 Ninth St. Suite 215 Berkeley CA United States."},{"key":"e_1_3_3_12_2","doi-asserted-by":"crossref","unstructured":"Lawall J Laurie B Hansen RR et al. Finding error handling bugs in OpenSSL using Coccinelle. In: 2010 European dependable computing conference Valencia Spain 28\u201330 April 2010 pp.191\u2013196. IEEE.","DOI":"10.1109\/EDCC.2010.31"},{"key":"e_1_3_3_13_2","doi-asserted-by":"crossref","unstructured":"Zuo C Wu J Guo S. Automatically detecting ssl error-handling vulnerabilities in hybrid mobile web apps. In: Proceedings of the 10th ACM symposium on information computer and communications security Singapore Republic of Singapore April 14\u201317 2015 pp.591\u2013596 Association for Computing Machinery New York United States.","DOI":"10.1145\/2714576.2714583"},{"key":"e_1_3_3_14_2","unstructured":"M. CORPORATION. Cve-2019-7846 2019. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-7846."},{"key":"e_1_3_3_15_2","unstructured":"M. CORPORATION. Cve-2019-2240 2019. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-2240."},{"key":"e_1_3_3_16_2","unstructured":"M. CORPORATION. Cve-2019-1750 2019. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-1750."},{"key":"e_1_3_3_17_2","doi-asserted-by":"crossref","unstructured":"M. CORPORATION. Cve-2019-1785 2019. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-1785.","DOI":"10.1007\/978-3-662-48986-4_312809"},{"key":"e_1_3_3_18_2","unstructured":"Patrick-Evans J Cavallaro L Kinder J. {POTUS}: Probing {Off\u2212The\u2212Shelf}{USB} drivers with symbolic fault injection. In: 11th USENIX workshop on offensive technologies (WOOT 17) Vancouver BC Canada August 14\u201315 2017 USENIX Association 2560 Ninth St. Suite 215 Berkeley CA United States."},{"key":"e_1_3_3_19_2","doi-asserted-by":"crossref","unstructured":"Jiang ZM Bai JJ Lawall J et al. Fuzzing error handling code in device drivers based on software fault injection. In: software reliability 2019 IEEE 30th International symposium on engineering (ISSRE) Berlin Germany 27\u201330 Oct 2019 pp.128\u2013138. IEEE.","DOI":"10.1109\/ISSRE.2019.00022"},{"key":"e_1_3_3_20_2","unstructured":"Jiang ZM Bai JJ Lu K et al. Fuzzing error handling code using {Context-Sensitive} software fault injection. In: 29th USENIX security symposium (USENIX Security 20) August 12\u201314 2020 pp.2595\u20132612 USENIX Association 2560 Ninth St. Suite 215 Berkeley CA United States."},{"key":"e_1_3_3_21_2","doi-asserted-by":"crossref","unstructured":"Liu P Ji S Zhang X et al. Ifizz: Deep-state and efficient fault-scenario generation to test IoT firmware. In: 2021 36th IEEE\/ACM International conference on automated software engineering (ASE) Melbourne Australia November 15\u201319 2021 pp.805\u2013816. IEEE.","DOI":"10.1109\/ASE51524.2021.9678785"},{"key":"e_1_3_3_22_2","article-title":"Testing error handling code with software fault injection and error-coverage-guided fuzzing","author":"Bai JJ","year":"2023","unstructured":"Bai JJ, Fu ZX, Xie KT, et al. Testing error handling code with software fault injection and error-coverage-guided fuzzing. IEEE Trans Dependable Secure Comput 2023, vol. 21, pp.1724\u20131739.","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"e_1_3_3_23_2","doi-asserted-by":"crossref","unstructured":"Rosenberg HA Shin KG. Software fault injection and its application in distributed systems. In: FTCS-23 the twenty-third international symposium on fault-tolerant computing Toulouse France June 22\u201324 1993 pp.208\u2013217. IEEE.","DOI":"10.1109\/FTCS.1993.627324"},{"key":"e_1_3_3_24_2","doi-asserted-by":"crossref","unstructured":"Yang X Chen Y Eide E et al. Finding and understanding bugs in c compilers. In: Proceedings of the 32nd ACM SIGPLAN conference on Programming language design and implementation San Jose California USA June 4\u20138 2011 pp.283\u2013294 Association for Computing Machinery New York United States.","DOI":"10.1145\/1993498.1993532"},{"key":"e_1_3_3_25_2","doi-asserted-by":"crossref","unstructured":"Chen Y Groce A Zhang C et al. Taming compiler fuzzers. In: Proceedings of the 34th ACM SIGPLAN conference on Programming language design and implementation Seattle Washington USA June 16\u201319 2013 pp.197\u2013208 Association for Computing Machinery New York United States.","DOI":"10.1145\/2491956.2462173"},{"key":"e_1_3_3_26_2","doi-asserted-by":"crossref","unstructured":"Godefroid P Kiezun A Levin MY. Grammar-based whitebox fuzzing. In: Proceedings of the 29th ACM SIGPLAN conference on programming language design and implementation Tucson AZ USA June 7\u201313 2008 pp.206\u2013215 Association for Computing Machinery New York United States.","DOI":"10.1145\/1375581.1375607"},{"key":"e_1_3_3_27_2","doi-asserted-by":"crossref","unstructured":"Wang J Chen B Wei L et al. Skyfire: Data-driven seed generation for fuzzing. In: 2017 IEEE symposium on security and privacy (SP) San Jose CA USA May 22\u201326 2017 pp.579\u2013594. IEEE.","DOI":"10.1109\/SP.2017.23"},{"key":"e_1_3_3_28_2","doi-asserted-by":"crossref","unstructured":"Rawat S Jain V Kumar A et al. Vuzzer: Application-aware evolutionary fuzzing. In: NDSS Vol. 17 2017 pp.1\u201314.","DOI":"10.14722\/ndss.2017.23404"},{"key":"e_1_3_3_29_2","unstructured":"Holler C Herzig K Zeller A. Fuzzing with code fragments. In: 21st USENIX Security Symposium (USENIX Security 12) Bellevue WA August 8\u201310 2012 pp.445\u2013458 USENIX Association 2560 Ninth St. Suite 215 Berkeley CA United States."},{"key":"e_1_3_3_30_2","doi-asserted-by":"crossref","unstructured":"Lemieux C Sen K. Fairfuzz: A targeted mutation strategy for increasing greybox fuzz testing coverage. In: Proceedings of the 33rd ACM\/IEEE international conference on automated software engineering Montpellier France September 3\u20137 2018 pp.475\u2013485 Association for Computing Machinery New York United States.","DOI":"10.1145\/3238147.3238176"},{"key":"e_1_3_3_31_2","first-page":"1980","article-title":"Smart greybox fuzzing","volume":"47","author":"Pham VT","year":"2019","unstructured":"Pham VT, B\u00f6hme M, Santosa AE, et\u00a0al. Smart greybox fuzzing. IEEE Trans Softw Eng 2019; 47: 1980\u20131997.","journal-title":"IEEE Trans Softw Eng"},{"key":"e_1_3_3_32_2","doi-asserted-by":"crossref","unstructured":"Aschermann C Frassetto T Holz T et\u00a0al. Nautilus: fishing for deep bugs with grammars. In: NDSS 2019.","DOI":"10.14722\/ndss.2019.23412"},{"key":"e_1_3_3_33_2","doi-asserted-by":"crossref","unstructured":"Padhye R Lemieux C Sen K et al. Semantic fuzzing with zest. In: Proceedings of the 28th ACM SIGSOFT international symposium on software testing and analysis Beijing China July 15\u201319 2019 pp.329\u2013340 Association for Computing Machinery New York United States.","DOI":"10.1145\/3293882.3330576"},{"key":"e_1_3_3_34_2","doi-asserted-by":"crossref","unstructured":"Wang J Chen B Wei L et al. Superion: Grammar-aware greybox fuzzing. In: 2019 IEEE\/ACM 41st international conference on software engineering (ICSE) Montreal Quebec Canada 27 May 2019 pp.724\u2013735. IEEE.","DOI":"10.1109\/ICSE.2019.00081"},{"key":"e_1_3_3_35_2","unstructured":"Zalewski M. American fuzzy lop 2023. https:\/\/github.com\/google\/AFL."},{"key":"e_1_3_3_36_2","unstructured":"Google. Honggfuzz 2023. https:\/\/google.github.io\/honggfuzz\/."},{"key":"e_1_3_3_37_2","doi-asserted-by":"crossref","unstructured":"B\u00f6hme M Pham VT Roychoudhury A. Coverage-based greybox fuzzing as Markov chain. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security Vienna Austria October 24\u201328 2016 pp.1032\u20131043 Association for Computing Machinery New York United States.","DOI":"10.1145\/2976749.2978428"},{"key":"e_1_3_3_38_2","doi-asserted-by":"crossref","unstructured":"Gan S Zhang C Qin X et al. Collafl: Path sensitive fuzzing. In: 2018 IEEE symposium on security and privacy (SP) San Francisco CA May 21\u201323 2018 pp.679\u2013696. IEEE.","DOI":"10.1109\/SP.2018.00040"},{"key":"e_1_3_3_39_2","unstructured":"Yun I Lee S Xu M et al. Qsym: a practical concolic execution engine tailored for hybrid fuzzing. In: Proceedings of the 27th USENIX security symposium (USENIX Security 18) Baltimore MD USA August 15\u201317 2018 pp.745\u2013761 USENIX Association 2560 Ninth St. Suite 215 Berkeley CA United States."},{"key":"e_1_3_3_40_2","doi-asserted-by":"crossref","unstructured":"Aschermann C Schumilo S Blazytko T et al. Redqueen: Fuzzing with input-to-state correspondence. In: Proceedings of the 26th Annual network and distributed system security symposium (NDSS) vol. 19 San Diego CA February 24\u201327 2019 pp.1\u201315.","DOI":"10.14722\/ndss.2019.23371"},{"key":"e_1_3_3_41_2","unstructured":"M. CORPORATION. Cve-2019-4332 2019. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-4332."},{"key":"e_1_3_3_42_2","unstructured":"Li Y Ji S Chen Y et al. {UNIFUZZ}: A holistic and pragmatic {Metrics-Driven} platform for evaluating fuzzers. In: 30th USENIX security symposium (USENIX Security 21) Vancouver B.C. Canada August 11\u201313 2021 pp.2777\u20132794."},{"key":"e_1_3_3_43_2","unstructured":"Fioraldi A Maier D Ei\u00dffeldt H et al. {AFL++}: Combining incremental steps of fuzzing research. In: 14th USENIX workshop on offensive technologies (WOOT 20) 11 August 2020 pp.10\u201321 USENIX Association 2560 Ninth St. Suite 215 Berkeley CA United States."},{"key":"e_1_3_3_44_2","doi-asserted-by":"crossref","unstructured":"B\u00f6hme M et al. Directed greybox fuzzing. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security Dallas Texas USA 30 October\u20133 November 2017 Association for Computing Machinery New York United States.","DOI":"10.1145\/3133956.3134020"},{"key":"e_1_3_3_45_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2016.01.018"},{"key":"e_1_3_3_46_2","doi-asserted-by":"crossref","unstructured":"Banabic R Candea G. Fast black-box testing of system recovery code. In: Proceedings of the 7th ACM European conference on computer systems Bern Switzerland April 10\u201313 2012 pp.281\u2013294 Association for Computing Machinery New York United States.","DOI":"10.1145\/2168836.2168865"},{"key":"e_1_3_3_47_2","doi-asserted-by":"crossref","unstructured":"Cong K Lei L Yang Z et al. Automatic fault injection for driver robustness testing. In: Proceedings of the 2015 international symposium on software testing and analysis Baltimore MD USA July 13\u201317 2015 pp.361\u2013372 Association for Computing Machinery New York United States.","DOI":"10.1145\/2771783.2771811"},{"key":"e_1_3_3_48_2","doi-asserted-by":"crossref","unstructured":"Marinescu PD Candea G. Lfi: a practical and general library-level fault injector. In: 2009 IEEE\/IFIP International Conference on Dependable Systems & Networks storil\/Lisbon Portugal 2009 pp.379\u2013388. IEEE.","DOI":"10.1109\/DSN.2009.5270313"},{"key":"e_1_3_3_49_2","doi-asserted-by":"crossref","unstructured":"Mendonca M Neves N. Robustness testing of the Windows DDK. In: 37th annual IEEE\/IFIP international conference on dependable systems and networks (DSN\u201907) June 25\u201328 2007 pp.554\u2013564. IEEE NW Washington DC United States.","DOI":"10.1109\/DSN.2007.85"},{"key":"e_1_3_3_50_2","doi-asserted-by":"crossref","unstructured":"Susskraut M Fetzer C. Automatically finding and patching bad error handling. In: 2006 Sixth European dependable computing conference Coimbra Oct. 18\u201320 2006 pp.13\u201322. IEEE.","DOI":"10.1109\/EDCC.2006.3"},{"key":"e_1_3_3_51_2","doi-asserted-by":"crossref","unstructured":"Zhang P Elbaum S. Amplifying tests to validate exception handling code. In: 2012 34th International conference on software engineering (ICSE) Zurich Switzerland June 2\u20139 2012 pp.595\u2013605. IEEE.","DOI":"10.1109\/ICSE.2012.6227157"},{"key":"e_1_3_3_52_2","article-title":"Sage: Whitebox fuzzing for security testing","volume":"10","author":"Fuzzing IW","year":"2012","unstructured":"Fuzzing IW. Sage: Whitebox fuzzing for security testing. SAGE 2012; 10:1, pp.20\u201327.","journal-title":"SAGE"},{"key":"e_1_3_3_53_2","doi-asserted-by":"crossref","unstructured":"Stephens N Grosen J Salls C et al. Driller: augmenting fuzzing through selective symbolic execution. In: NDSS Vol. 16 2016 pp.1\u201316.","DOI":"10.14722\/ndss.2016.23368"},{"key":"e_1_3_3_54_2","unstructured":"Cadar C Dunbar D Engler DR et al. Klee: Unassisted and automatic generation of high-coverage tests for complex systems programs. In: OSDI vol. 8 2008 pp.209\u2013224 \u00a0USENIX Association 2560 Ninth St. Suite 215 Berkeley CA United States."},{"key":"e_1_3_3_55_2","doi-asserted-by":"crossref","unstructured":"Cha SK Avgerinos T Rebert A et al. Unleashing mayhem on binary code. In: 2012 IEEE symposium on security and privacy San Francisco CA USA May 20\u201323 2012 pp.380\u2013394. IEEE.","DOI":"10.1109\/SP.2012.31"},{"key":"e_1_3_3_56_2","doi-asserted-by":"crossref","unstructured":"Shoshitaishvili Y Wang R Salls C et al. Sok:(state of) the art of war: Offensive techniques in binary analysis. In: 2016 IEEE symposium on security and privacy (SP) San Jose CA USA May 22\u201326 2016 pp.138-157. IEEE.","DOI":"10.1109\/SP.2016.17"},{"key":"e_1_3_3_57_2","article-title":"Hybrid fuzz testing: discovering software bugs via fuzzing and symbolic execution","author":"Pak BS","year":"2012","unstructured":"Pak BS. Hybrid fuzz testing: discovering software bugs via fuzzing and symbolic execution. Master\u2019s thesis, School Comput Sci Carneg Mellon Univ 2012.","journal-title":"Master\u2019s thesis, School Comput Sci Carneg Mellon Univ"},{"key":"e_1_3_3_58_2","doi-asserted-by":"crossref","unstructured":"Majumdar R Sen K. Hybrid concolic testing. In: 29th international conference on software engineering (ICSE\u201907) Minneapolis MN May 20\u201326 2007 pp.416\u2013426. IEEE.","DOI":"10.1109\/ICSE.2007.41"},{"key":"e_1_3_3_59_2","unstructured":"Poeplau S Francillon A. Symbolic execution with {SymCC}: Don\u2019t interpret compile! In: 29th USENIX security symposium (USENIX security 20) August 12\u201314 2020 pp.181\u2013198 USENIX Association 2560 Ninth St. Suite 215 Berkeley CA United States."},{"key":"e_1_3_3_60_2","unstructured":"Python. https:\/\/www.python.org\/."},{"key":"e_1_3_3_61_2","unstructured":"Z3 time out issue. https:\/\/github.com\/Z3Prover\/z3\/issues\/419."},{"key":"e_1_3_3_62_2","doi-asserted-by":"crossref","unstructured":"Jiang ZM Bai JJ Lawall J et al. Fuzzing error handling code in device drivers based on software fault injection. In: 2019 IEEE 30th international symposium on software reliability engineering (ISSRE) Berlin Germany Oct. 28\u201331 2019 pp.128\u2013138. IEEE.","DOI":"10.1109\/ISSRE.2019.00022"},{"key":"e_1_3_3_63_2","unstructured":"LLVM pass. https:\/\/llvm.org\/docs\/WritingAnLLVMPass.html."},{"key":"e_1_3_3_64_2","unstructured":"Serebryany K Bruening D Potapenko A et al. {AddressSanitizer}: A fast address sanity checker. In: 2012 USENIX annual technical conference (USENIX ATC 12) Boston MA June 13\u20131 2012 pp.309\u2013318 USENIX Association 2560 Ninth St. Suite 215 Berkeley CA United States."},{"key":"e_1_3_3_65_2","unstructured":"Msan: memory sanitizer 2019. http:\/\/github.com\/google\/sanitizers\/wiki\/MemorySanitizer."},{"key":"e_1_3_3_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/1064978.1065034"},{"key":"e_1_3_3_67_2","unstructured":"Research M. https:\/\/github.com\/Z3Prover\/z3."},{"key":"e_1_3_3_68_2","unstructured":"man db. https:\/\/gitlab.com\/man-db\/man-db\/-\/tree\/2.12.0?ref_type=tags."},{"key":"e_1_3_3_69_2","unstructured":"woff2. https:\/\/github.com\/google\/woff2."},{"key":"e_1_3_3_70_2","unstructured":"gzip. https:\/\/ftp.gnu.org\/gnu\/gzip\/."},{"key":"e_1_3_3_71_2","unstructured":"bzip2. https:\/\/github.com\/vim\/vim\/tree\/v9.0.1343."},{"key":"e_1_3_3_72_2","unstructured":"sassc. https:\/\/github.com\/sass\/sassc."},{"key":"e_1_3_3_73_2","unstructured":"tidy. https:\/\/github.com\/htacg\/tidy-html5."},{"key":"e_1_3_3_74_2","unstructured":"jqlang. https:\/\/github.com\/jqlang\/jq."},{"key":"e_1_3_3_75_2","unstructured":"bash. https:\/\/ftp.gnu.org\/gnu\/bash\/bash-5.2.21.tar.gz."},{"key":"e_1_3_3_76_2","unstructured":"mksh. http:\/\/www.mirbsd.org\/MirOS\/dist\/mir\/mksh\/mksh-R59c.tgz."},{"key":"e_1_3_3_77_2","unstructured":"K S. OSS-Fuzz-google\u2019s continuous fuzzing service for open source software."}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X251343867","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/0926227X251343867","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0926227X251343867","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:54Z","timestamp":1777495554000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0926227X251343867"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,19]]},"references-count":76,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2025,9]]}},"alternative-id":["10.1177\/0926227X251343867"],"URL":"https:\/\/doi.org\/10.1177\/0926227x251343867","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,19]]}}}