As we move to memory safe language, pointer arithmetic no longer is the main
source of bugs, instead API misuse becomes a key issue. Complex code is hidden
behind API abstractions and developers may make mistakes in how they use these
APIs. While API mining has been an active field …
Scripting languages are an essential part of many software environments. Common
languages like Python, Ruby, or PHP power large parts of the modern web but bugs
in their runtime environments allow attackers to break memory safety and
sandboxing guarantees. A common bug class is callback bugs which happen when
user-defined …
Fuzzing has become the dominant dynamic testing approach to find bugs in
software. For complex software like Chrome, we observed that fuzzing only
reaches around 30% of coverage, i.e., 70% of code is not executed and therefore
not tested. While not all code will be reachable in practice, there's …