{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:16:27Z","timestamp":1781108187123,"version":"3.54.1"},"reference-count":27,"publisher":"IGI Global Scientific Publishing","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010,7]]},"abstract":"<jats:p>Many software security vulnerabilities only reveal themselves under certain conditions, that is, particular configurations and inputs together with a certain runtime environment. One approach to detecting these vulnerabilities is fuzz testing. However, typical fuzz testing makes no guarantees regarding the syntactic and semantic validity of the input, or of how much of the input space will be explored. To address these problems, the authors present a new testing methodology called Configuration Fuzzing. Configuration Fuzzing is a technique whereby the configuration of the running application is mutated at certain execution points to check for vulnerabilities that only arise in certain conditions. As the application runs in the deployment environment, this testing technique continuously fuzzes the configuration and checks \u201csecurity invariants\u2019\u2019 that, if violated, indicate vulnerability. This paper discusses the approach and introduces a prototype framework called ConFu (CONfiguration FUzzing testing framework) for implementation. Additionally, the results of case studies that demonstrate the approach\u2019s feasibility are presented along with performance evaluations.<\/jats:p>","DOI":"10.4018\/jsse.2010070103","type":"journal-article","created":{"date-parts":[[2010,9,7]],"date-time":"2010-09-07T22:46:58Z","timestamp":1283899618000},"page":"41-55","source":"Crossref","is-referenced-by-count":8,"title":["CONFU"],"prefix":"10.4018","volume":"1","author":[{"given":"Huning","family":"Dai","sequence":"first","affiliation":[{"name":"Columbia University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christian","family":"Murphy","sequence":"additional","affiliation":[{"name":"Columbia University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gail","family":"Kaiser","sequence":"additional","affiliation":[{"name":"Columbia University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2010070103-0","doi-asserted-by":"publisher","DOI":"10.1109\/TIM.2003.817144"},{"key":"jsse.2010070103-1","author":"J.Biskup","year":"2009","journal-title":"Security in computing systems challenges, approaches, and solutions"},{"key":"jsse.2010070103-2","doi-asserted-by":"crossref","unstructured":"Chu, M., Murphy, C., & Kaiser, G. (2008). Distributed in vivo testing of software applications. In Proceedings of the First International Conference on Software Testing, Verification and Validation (pp. 509-512).","DOI":"10.1109\/ICST.2008.13"},{"key":"jsse.2010070103-3","unstructured":"Clarke, T. (2009). Fuzzing for software vulnerability discovery (Tech. Rep. No. RHUL-MA-2009-4). London: University of London, Department of Mathematics."},{"key":"jsse.2010070103-4","unstructured":"Du, W., & Mathur, A. P. (2000). Testing for software vulnerability using environment perturbation. In Proceedings of the International Conference on Dependable Systems and Networks (p. 603)."},{"key":"jsse.2010070103-5","unstructured":"Fouch\u00e9, S., Cohen, M. B., & Porter, A. (2009). Incremental covering array failure characterization in large configuration spaces. In Proceedings of the Eighteenth International Symposium on Software Testing and Analysis (ISSTA \u201909) (pp. 177-188). New York: ACM."},{"key":"jsse.2010070103-6","doi-asserted-by":"crossref","unstructured":"Ganesh, V., Leek, T., & Rinard, M. (2009). Taint-based directed whitebox fuzzing. In Proceedings of the 2009 IEEE 31st International Conference on Software Engineering (ICSE \u201909) (pp. 474-484). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/ICSE.2009.5070546"},{"key":"jsse.2010070103-7","unstructured":"Godefroid, P., Levin, M. Y., & Molnar, D. A. (2008). Automated whitebox fuzz testing. In Proceedings of the Network Distributed Security Symposium (NDSS)."},{"key":"jsse.2010070103-8","doi-asserted-by":"crossref","unstructured":"Gross, K. C., Urmanov, A., Votta, L. G., McMaster, S., & Porter, A. (2006). Towards dependability in everyday software using software telemetry. In Proceedings of the Third IEEE International Workshop on Engineering of Autonomic & Autonomous Systems (EASE \u201906) (pp. 9-18). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/EASE.2006.21"},{"key":"jsse.2010070103-9","doi-asserted-by":"crossref","unstructured":"Hangal, S., & Lam, M. S. (2002). Tracking down software bugs using automatic anomaly detection. In Proceedings of the 2002 International Conference on Software Engineering (pp. 291-301).","DOI":"10.1145\/581376.581377"},{"key":"jsse.2010070103-10","doi-asserted-by":"publisher","DOI":"10.1007\/0-387-25036-0_10"},{"key":"jsse.2010070103-11","unstructured":"Hayhurst, K. J., Veerhusen, D. S., Chilenski, J. J., & Rierson, L. K. (2001). A practical tutorial on modified condition\/decision coverage (Tech. Rep. No. NASA\/TM-2001-210876). Houston, TX: NASA."},{"key":"jsse.2010070103-12","doi-asserted-by":"publisher","DOI":"10.1109\/2.585157"},{"key":"jsse.2010070103-13","unstructured":"Jurani, L. (2006). Using fuzzing to detect security vulnerabilities (Tech. Rep. NO. INFIGO-TD-01-04-2006). Richmond, BC, Canada: INFIGO."},{"key":"jsse.2010070103-14","unstructured":"Kr\u00fcgel, C., Toth, T., & Kirda, E. (2002). Service specific anomaly detection for network intrusion detection. In Proceedings of the 2002 ACM Symposium on Applied Computing (SAC \u201902) (pp. 201-208). New York: ACM."},{"key":"jsse.2010070103-15","unstructured":"Locasto, M. E., Sidiroglou, S., & Keromytis, A. D. (2006). Software self-healing using collaborative application communities. In Proceedings of the Internet Society (ISOC) Symposium on Network and Distributed Systems Security (NDSS 2006) (pp. 95-106)."},{"key":"jsse.2010070103-16","doi-asserted-by":"crossref","unstructured":"Memon, A., et al. (2004). Skoll: distributed continuous quality assurance. In Proceedings of the 26th International Conference on Software Engineering (ICSE) (pp. 459-468).","DOI":"10.1109\/ICSE.2004.1317468"},{"key":"jsse.2010070103-17","doi-asserted-by":"crossref","unstructured":"Murphy, C., Kaiser, G., Vo, I., & Chu, M. (2009). Quality assurance of software applications using the in vivo testing approach. In Proceedings of the Second IEEE International Conference on Software Testing, Verification and Validation (ICST) (pp. 111-120).","DOI":"10.1109\/ICST.2009.18"},{"key":"jsse.2010070103-18","doi-asserted-by":"crossref","unstructured":"Osman, S., Subhraveti, D., Su, G., & Nieh, J. (2002). The design and implementation of Zap: A system for migrating computing environments. In Proceedings of the Fifth Symposium on Operating Systems Design and Implementation (OSDI) (pp. 361-376).","DOI":"10.1145\/1060289.1060323"},{"key":"jsse.2010070103-19","unstructured":"Osterweil, L. (1996). Perpetually testing software. In Proceedings of the Ninth International Software Quality Week."},{"key":"jsse.2010070103-20","doi-asserted-by":"crossref","first-page":"189","DOI":"10.3233\/JCS-2002-101-209","article-title":"Model-based analysis of configuration vulnerabilities.","volume":"10","author":"C.Ramakrishnan","year":"2002","journal-title":"Journal of Computer Security"},{"key":"jsse.2010070103-21","unstructured":"Rubenstein, D., Osterweil, L., & Zilberstein, S. (1997). An anytime approach to analyzing software systems. In Proceedings of the 10th FLAIRS (pp. 386-391)."},{"key":"jsse.2010070103-22","author":"M.Sutton","year":"2007","journal-title":"Fuzzing: Brute Force Vulnerability Discovery"},{"key":"jsse.2010070103-23","doi-asserted-by":"crossref","unstructured":"Thompson, H. H., Whittaker, J. A., & Mottay, F. E. (2002). Software security vulnerability testing in hostile environments. In Proceedings of the 2002 ACM Symposium on Applied Computing (pp. 260-264). New York: ACM.","DOI":"10.1145\/508791.508844"},{"issue":"4","key":"jsse.2010070103-24","doi-asserted-by":"crossref","first-page":"465","DOI":"10.1093\/comjnl\/25.4.465","article-title":"On testing non-testable programs.","volume":"25","author":"E. J.Weyuker","year":"1982","journal-title":"The Computer Journal"},{"key":"jsse.2010070103-25","doi-asserted-by":"crossref","unstructured":"Yoon, I.-C., Sussman, A., Memon, A., & Porter, A. (2008). Effective and scalable software compatibility testing. In Proceedings of the 2008 International Symposium on Software Testing and Analysis (ISSTA \u201908) (pp. 63-74). New York: ACM.","DOI":"10.1145\/1390630.1390640"},{"key":"jsse.2010070103-26","doi-asserted-by":"publisher","DOI":"10.1145\/267580.267590"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=46151","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,2,5]],"date-time":"2019-02-05T14:53:31Z","timestamp":1549378411000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2010070103"}},"subtitle":["Configuration Fuzzing Testing Framework for Software Vulnerability Detection"],"short-title":[],"issued":{"date-parts":[[2010,7]]},"references-count":27,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2010070103","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010,7]]}}}