All You Ever Wanted to Know About Dynamic Taint Analysis and Forward Symbolic Execution
Automated Whitebox Fuzz Testing
Angora: Efficient Fuzzing by Principled Search
Full-speed Fuzzing: Reducing Fuzzing Overhead through Coverage-guided Tracing
Magma: A Ground-Truth Fuzzing Benchmark
Hawkeye: Towards a Desired Directed Grey-box Fuzzer
ParmeSan: Sanitizer-guided Greybox Fuzzing
WindRanger: A Directed Greybox Fuzzer driven by Deviation Basic Blocks
Binary-level Directed Fuzzing for Use-After-Free Vulnerabilities
MC2: Rigorous and Effeicient Directed Greybox Fuzzing
DAFL: Directed Grey-box Fuzzing Guided by Data Dependency
SELECTFUZZ: Efficient Directed Fuzzing withSelective Path Exploration
Guiding Directed Fuzzing with Feasibility
Predecessor-aware Directed Greybox Fuzzing
BEACON : Directed Grey-Box Fuzzing with Provable Path Pruning
One Fuzz Doesn’t Fit All: Optimizing Directed Fuzzing via Target-tailored Program State
Constraint-guided Directed Greybox Fuzzing
Sound Input Filter Generation for Integer Overflow Errors
Smartian: Enhancing Smart Contract Fuzzing with Static and Dynamic Data-Flow Analyses