How to evaluate fuzzers?
For an academic, "I prefer to use coverage, but reviewers want to see CVEs." Can't reasonably fix bugs as part of a PhD.
Measurements are broken. Incentives are misaligned. #36c3
Replying to @MayaKaczorowski
There was incredible research on this topic in “Evaluating Fuzz Testing”, published at SIGSAC 2018. It offers a historical critique and path forward for measuring fuzzers. @trailofbits wrote a summary on our blog:https://blog.trailofbits.com/2018/10/05/how-to-spot-good-fuzzing-research/ …
0 replies
0 retweets
7 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.