Going Beyond Coverage-Guided Fuzzing with Structured Fuzzing

Black Hat USA 2019

Presented by: Jonathan Metzman
Date: Wednesday August 07, 2019
Time: 17:05 - 17:30
Location: Lagoon GHI

Coverage-guided fuzzers like AFL and libFuzzer have led to a "fuzzing renaissance". This is because they made it possible for security researchers to write effective fuzzers for formats without knowing about the format's structure. However, structure-aware (aka structured) fuzzing is far from dead. In fact, the combination of structured and coverage-guided (aka coverage) fuzzing has quietly become the state of the art in automated vulnerability discovery.This talk will:

The talk will ultimately benefit anyone who is interested in fuzzing. In particular, it will benefit security researchers trying to go beyond coverage fuzzing to find vulnerabilities in real code.

Jonathan Metzman

Jonathan Metzman works on the Chrome security team where he writes fuzzers and infrastructure for running fuzzers (ClusterFuzz and OSS-Fuzz).


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats