SlideShare a Scribd company logo
whoami
Proving absence of bugs.
Showing presence of bugs.
Maximising Fuzzing
Effectiveness & Efficiency
More Challenges
in Fuzzing
Fundamental Limitation:
Exponential Cost
Assurances in
Software Security
Future Directions
• Fuzzing for Automatic Vulnerability Discovery

• Making machines attack other machines.

• Focus on scalability, efficiency, and effectiveness.

• Foundations of Software Security

• Assurances in Software Security

• Fundamental limitations of existing approaches

• Drawing from multiple disciplines (information theory, biostatistics)

whoami
Marcel Böhme
ARC DECRA Fellow

Senior Lecturer (A/Prof)

Monash University, Australia
fuzzing
more in The Fuzzing Book @ fuzzingbook.org
efficiency
scalability
1 2 4 8 16 32 64 128 256 512
machines
new bugs 1 2 3 4 5 6 7 8 9
24 hrs
continuous fuzzing
when to stop?

More Related Content

PDF
Foundations Of Software Testing
PDF
Fuzzing: Challenges and Reflections
PDF
The Curious Case of Fuzzing for Automated Software Testing
PDF
Ensuring Security through Continuous Testing
PDF
Security vulnerabilities for grown ups - GOTOcon 2012
PDF
Sigma Open Tech Week: Bitter Truth About Software Security
PPTX
2014 abic-talk
PDF
A taste of Exploratory Testing
Foundations Of Software Testing
Fuzzing: Challenges and Reflections
The Curious Case of Fuzzing for Automated Software Testing
Ensuring Security through Continuous Testing
Security vulnerabilities for grown ups - GOTOcon 2012
Sigma Open Tech Week: Bitter Truth About Software Security
2014 abic-talk
A taste of Exploratory Testing

Similar to DS3 Fuzzing Panel (M. Boehme) (20)

PPT
Fuzzing101 - webinar on Fuzzing Performance
PPTX
Fault Models and Fuzzing
PPT
Fuzzing 101 Webinar on Zero Day Management
PPT
Perform fuzz on appplications web interface
PPTX
Fuzzing101: Unknown vulnerability management for Telecommunications
PDF
Fighting Software Inefficiency Through Automated Bug Detection
PDF
Масштабируемый и эффективный фаззинг Google Chrome
PDF
Fuzzing underestimated method of finding hidden bugs
PDF
Shorter Version of BbWorld 09 Forensics Presentation
PDF
Increasing DevSecOps Maturity Level in 2021
PDF
Az4301280282
PDF
bug-advocacy
PDF
0-knowledge fuzzing white paper
PDF
0-knowledge fuzzing white paper
PPTX
Blaze Information Security: Slaying bugs and improving software security thro...
PPT
msutton-fuzzing.ppt
PDF
FUZZING & SOFTWARE SECURITY TESTING
PDF
Fuzz-testing: A hacker's approach to making your code more secure | Pascal Ze...
PPTX
How to fix bug or defects in software
PDF
[Wroclaw #4] Fuzzing - underestimated method of finding hidden bugs
Fuzzing101 - webinar on Fuzzing Performance
Fault Models and Fuzzing
Fuzzing 101 Webinar on Zero Day Management
Perform fuzz on appplications web interface
Fuzzing101: Unknown vulnerability management for Telecommunications
Fighting Software Inefficiency Through Automated Bug Detection
Масштабируемый и эффективный фаззинг Google Chrome
Fuzzing underestimated method of finding hidden bugs
Shorter Version of BbWorld 09 Forensics Presentation
Increasing DevSecOps Maturity Level in 2021
Az4301280282
bug-advocacy
0-knowledge fuzzing white paper
0-knowledge fuzzing white paper
Blaze Information Security: Slaying bugs and improving software security thro...
msutton-fuzzing.ppt
FUZZING & SOFTWARE SECURITY TESTING
Fuzz-testing: A hacker's approach to making your code more secure | Pascal Ze...
How to fix bug or defects in software
[Wroclaw #4] Fuzzing - underestimated method of finding hidden bugs
Ad

More from mboehme (9)

PDF
[Keynote @ RAID'24] How to solve cybersecurity once and for all
PDF
An Implementation of Preregistration
PDF
On the Reliability of Coverage-based Fuzzer Benchmarking
PDF
Statistical Reasoning About Programs
PDF
On the Surprising Efficiency and Exponential Cost of Fuzzing
PDF
Fuzzing: On the Exponential Cost of Vulnerability Discovery
PDF
Boosting Fuzzer Efficiency: An Information Theoretic Perspective
PDF
AFLGo: Directed Greybox Fuzzing
KEY
NUS SoC Graduate Outreach @ TU Dresden
[Keynote @ RAID'24] How to solve cybersecurity once and for all
An Implementation of Preregistration
On the Reliability of Coverage-based Fuzzer Benchmarking
Statistical Reasoning About Programs
On the Surprising Efficiency and Exponential Cost of Fuzzing
Fuzzing: On the Exponential Cost of Vulnerability Discovery
Boosting Fuzzer Efficiency: An Information Theoretic Perspective
AFLGo: Directed Greybox Fuzzing
NUS SoC Graduate Outreach @ TU Dresden
Ad

Recently uploaded (20)

PDF
How AI/LLM recommend to you ? GDG meetup 16 Aug by Fariman Guliev
PDF
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
PPTX
assetexplorer- product-overview - presentation
PDF
AutoCAD Professional Crack 2025 With License Key
PPTX
AMADEUS TRAVEL AGENT SOFTWARE | AMADEUS TICKETING SYSTEM
PDF
Tally Prime Crack Download New Version 5.1 [2025] (License Key Free
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PPTX
history of c programming in notes for students .pptx
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PDF
Cost to Outsource Software Development in 2025
PDF
iTop VPN 6.5.0 Crack + License Key 2025 (Premium Version)
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
How to Make Money in the Metaverse_ Top Strategies for Beginners.pdf
PPTX
Operating system designcfffgfgggggggvggggggggg
PPTX
Monitoring Stack: Grafana, Loki & Promtail
PDF
CapCut Video Editor 6.8.1 Crack for PC Latest Download (Fully Activated) 2025
PDF
Nekopoi APK 2025 free lastest update
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
Website Design Services for Small Businesses.pdf
How AI/LLM recommend to you ? GDG meetup 16 Aug by Fariman Guliev
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
assetexplorer- product-overview - presentation
AutoCAD Professional Crack 2025 With License Key
AMADEUS TRAVEL AGENT SOFTWARE | AMADEUS TICKETING SYSTEM
Tally Prime Crack Download New Version 5.1 [2025] (License Key Free
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
history of c programming in notes for students .pptx
wealthsignaloriginal-com-DS-text-... (1).pdf
Cost to Outsource Software Development in 2025
iTop VPN 6.5.0 Crack + License Key 2025 (Premium Version)
Design an Analysis of Algorithms II-SECS-1021-03
Design an Analysis of Algorithms I-SECS-1021-03
How to Make Money in the Metaverse_ Top Strategies for Beginners.pdf
Operating system designcfffgfgggggggvggggggggg
Monitoring Stack: Grafana, Loki & Promtail
CapCut Video Editor 6.8.1 Crack for PC Latest Download (Fully Activated) 2025
Nekopoi APK 2025 free lastest update
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Website Design Services for Small Businesses.pdf

DS3 Fuzzing Panel (M. Boehme)

  • 1. whoami Proving absence of bugs. Showing presence of bugs. Maximising Fuzzing Effectiveness & Efficiency More Challenges in Fuzzing Fundamental Limitation: Exponential Cost Assurances in Software Security Future Directions • Fuzzing for Automatic Vulnerability Discovery • Making machines attack other machines. • Focus on scalability, efficiency, and effectiveness. • Foundations of Software Security • Assurances in Software Security • Fundamental limitations of existing approaches • Drawing from multiple disciplines (information theory, biostatistics) whoami Marcel Böhme ARC DECRA Fellow Senior Lecturer (A/Prof) Monash University, Australia
  • 2. fuzzing more in The Fuzzing Book @ fuzzingbook.org
  • 4. scalability 1 2 4 8 16 32 64 128 256 512 machines new bugs 1 2 3 4 5 6 7 8 9 24 hrs