Clement Poncelet

dblp:337/0824 · DBLP profile ↗
← Back
1ranked-venue papers
1as first author
1since 2021 · last 2022
0000-0002-3165-634XORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 100%
Software engineering, system software, and programming languages
1 paper
Software testing · 100%
Computer networks
1 paper
Internet architecture and protocols · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › vulnerability discovery
fuzzing
0.612022
So Many Fuzzers, So Little Time✱: Experience from Evaluating Fuzzers on the Contiki-NG Network (Hay)Stack · ASE 2022
Systems and software security
vulnerability discovery
0.612022
So Many Fuzzers, So Little Time✱: Experience from Evaluating Fuzzers on the Contiki-NG Network (Hay)Stack · ASE 2022
Software testing › fuzzing
fuzzer benchmarking
0.612022
So Many Fuzzers, So Little Time✱: Experience from Evaluating Fuzzers on the Contiki-NG Network (Hay)Stack · ASE 2022
Software testing
fuzzing
0.612022
So Many Fuzzers, So Little Time✱: Experience from Evaluating Fuzzers on the Contiki-NG Network (Hay)Stack · ASE 2022
Internet architecture and protocols › network architecture design › layered architecture › protocol layering
network stack
0.212022
So Many Fuzzers, So Little Time✱: Experience from Evaluating Fuzzers on the Contiki-NG Network (Hay)Stack · ASE 2022

Methods — techniques the papers use, named apart from their topics

sanitizers · 1.7mutation-based fuzzing · 1.7hybrid fuzzing · 1.7
YearPublicationVenuePosition
2022 So Many Fuzzers, So Little Time✱: Experience from Evaluating Fuzzers on the Contiki-NG Network (Hay)Stack
abstract
Fuzz testing (“fuzzing”) is a widely-used and effective dynamic technique to discover crashes and security vulnerabilities in software, supported by numerous tools, which keep improving in terms of their detection capabilities and speed of execution. In this paper, we report our findings from using state-of-the-art mutation-based and hybrid fuzzers (AFL, Angora, Honggfuzz, Intriguer, MOpt-AFL, QSym, and SymCC) on a non-trivial code base, that of Contiki-NG, to expose and fix serious vulnerabilities in various layers of its network stack, during a period of more than three years. As a by-product, we provide a Git-based platform which allowed us to create and apply a new, quite challenging, open-source bug suite for evaluating fuzzers on real-world software vulnerabilities. Using this bug suite, we present an impartial and extensive evaluation of the effectiveness of these fuzzers, and measure the impact that sanitizers have on it. Finally, we offer our experiences and opinions on how fuzzing tools should be used and evaluated in the future.
Clement Poncelet, Konstantinos Sagonas, Nicolas Tsiftes
ASE1