Generalized Method for Comparative Analysis of Fuzz-Testing Tools
摘要
Abstract
A systematic analysis of methods for evaluating the effectiveness of fuzzers is conducted. A minimal but complete set of metrics is identified: branch coverage, number of unique crashes, and time to first crash. A normalized integral indicator is proposed that allows post hoc comparison of the results of different tools without reruns.