QSYM: a practical concolic execution engine tailored for hybrid fuzzing
QSYM: a practical concolic execution engine tailored for hybrid fuzzing Yun et al., USENIX Security 2018
There are two main approaches to automated test case generated for uncovering bugs and vulnerabilities: fuzzing and concolic execution. Fuzzing is good at quickly exploring the input space, but can get stuck when trying to get past more complex conditional causes (i.e., when randomly generated inputs are unlikely to satisfy them). Concolic execution, which we saw in action earlier in the week, uses symbolic execution to uncover constraints and pass them to a solver. It can handle complex branch conditions, but it’s much slower. Hybrid fuzzers combine both coverage-guided fuzzing and concolic execution, bringing in the big guns (concolic) when the fuzzer gets stuck. In non-trivial real-world applications though, even the hybrid approach has been too slow. Until now.
For me, the attention grabbing paragraph in this paper is to be found on page 8 (752) in section 5.1. Google’s OSS-Fuzz was previously used to test a number of important real-world applications and libraries including libjpeg, libpng, libtiff, lepton, openjpge, tcpdump, file, libarchive, audiofile, ffmpeg, and binutils.
It is worth noting that Google’s OSS-Fuzz generated 10 trillion test inputs Continue reading
“If you asked me five years ago if I would be talking about open source I would have said you were crazy,” said Amy Wheelus, VP of Network Cloud at AT&T.
When it launches, the operator will be the first service provider globally to commercially launch 5G. However, it is using its own proprietary pre-standard 5G gear.
The third release has a more equitable feature set provided by AT&T, the other founding carrier members, and more recent additions.
For Airship, the most pressing issue is minimizing the impact on network operations during more frequent update cycles.
SDxCentral's latest research brief is aimed at providing enterprises contemplating purchasing SD-WAN solutions with a concrete five-step process and a set of core considerations critical to success.
Thao Nyugen works for Packet as director of hardware platforms. Coming from Facebook, he led the development and deployment of over 1 million Open Compute Project servers in the last eight years.
Traditional routing fails to differentiate between application and user requirements. SD-WAN is changing that with identity awareness.
The four new labs, alongside its existing lab in New York City, will rely on local partnerships to test and refine new 5G use cases.
NetSpeed’s technology helps architects optimize system-on-chip performance before manufacturing the chips.
This is T-Mobile's second 5G equipment deal in two months. Ericsson is a long-time partner to T-Mobile and supplied some of the operator's LTE network equipment.