All Stories

  1. CrossFit: Demystifying VM Callback Bugs in Interpreters
  2. Subscription Bombing: Email under Attack
  3. CLower: Detecting Compiler Pessimization Bugs through Redundant Memory Accesses
  4. eBPF Misbehavior Detection: Fuzzing with a Specification-Based Oracle
  5. Liberating Libraries through Automated Fuzz Driver Generation: Striking a Balance without Consumer Code
  6. MendelFuzz: The Return of the Deterministic Stage
  7. Top of the Heap: Efficient Memory Error Protection of Safe Heap Objects
  8. Fuzzing JavaScript Engines with a Graph-based IR
  9. Gradient: Gradual Compartmentalization via Object Capabilities Tracked in Types
  10. Tango: Extracting Higher-Order Feedback through State Inference
  11. SyzRisk: A Change-Pattern-Based Continuous Kernel Regression Fuzzer
  12. TuneFuzz: Adaptively Exploring Target Programs
  13. Crystallizer: A Hybrid Path Analysis Framework to Aid in Uncovering Deserialization Vulnerabilities
  14. DatAFLow : Toward a Data-Flow-Guided Fuzzer
  15. DatAFLow : Toward a Data-flow-guided Fuzzer
  16. Fuzzing binaries using dynamic control flow analysis
  17. Creating Trust by Abolishing Hierarchies
  18. Imprecise Store Exceptions
  19. One Fuzz Doesn’t Fit All: Optimizing Directed Fuzzing via Target-tailored Program State Restriction
  20. Designing a Provenance Analysis for SGX Enclaves
  21. PACMem
  22. Minerva: browser API fuzzing with dynamic mod-ref analysis
  23. Evocatio
  24. Automatically deduplicating program crashes by test case simplification and root-cause clustering
  25. μSCOPE: A Methodology for Analyzing Least-Privilege Compartmentalization in Large Software Artifacts
  26. Seed selection for successful fuzzing
  27. Gramatron: effective grammar-aware fuzzing
  28. Magma: A Ground-Truth Fuzzing Benchmark
  29. Rebooting Virtual Memory with Midgard
  30. Magma: A Ground-Truth Fuzzing Benchmark
  31. Too Quiet in the Library: An Empirical Study of Security Updates in Android Apps' Native Code
  32. Too Quiet in the Library: An Empirical Study of Security Updates in Android Apps’ Native Code
  33. Code Specialization through Dynamic Feature Observation
  34. Enclosure: language-based restriction of untrusted libraries
  35. Magma
  36. SMoTherSpectre
  37. PoLPer
  38. Milkomeda
  39. Block Oriented Programming
  40. HexType
  41. Enforcing Least Privilege Memory Views for Multithreaded Applications
  42. TypeSan