Mix Assertion, Logging, Unit Testing and Fuzzing with ZeroErr
Mix Assertion, Logging, Unit Testing and Fuzzing with ZeroErr Build Safer Modern C++ Application Speaker: Xiaofan Sun Date: Sep 19, 2024Self-Introduction • Got my Ph.D. from UC, Riverside capture additional context information if needed • Make sure specific path is takenStructure-Aware Fuzzing Generation-based fuzzers usually target a single input type - string. All input is reading from running the test.Benefits of Integration • Fuzzing test case can use all those features • Fuzzing do not need additional assertion implementation • Writing fuzzing test case as well as unit test case so0 码力 | 54 页 | 961.46 KB | 5 月前32020: The Year of Sanitizers?
Want to unleash the memory vulnerability beast? Put your test units on steroids, by spinning fuzzing jobs with ASan in Azure, leveraging the power of the Cloud from the comfort of your Visual Studio manager static analyzer dynamic analyzer (runtime) automated refactoring tools build system + fuzzing code reviews platform12 17 year old code base under active development 3.5 million lines of C++ coverage for the runtime analysis (all possible scenarios) the biggest impact when combined with fuzzing46 2020 Victor Ciura | @ciura_victor - 2020: The Year of Sanitizers? 0 false positives! Dynamic0 码力 | 135 页 | 27.77 MB | 5 月前3Embracing an Adversarial Mindset for Cpp Security
SIDE ACTIVITIESDay in the Life: Vulnerability Research ● Looking at code 75% ● Instrumenting fuzzing harnesses 5% ● Making POC when needed 1% ● Tackling cross-org issues to combat a whole bug class system attempts to extend a metadata block. ● Could have been easily discovered with the help of fuzzing ● Driver had extensive use of try/catch blocks to catch exceptions. ● Access violation exceptions dependencies up to date • Use static code analysis tools built into your CICD pipeline • Use fuzzing in your CICD pipelineStrategies for Secure C++ DevelopmentExploit Mitigation Timeline 2003 SAFESEH0 码力 | 92 页 | 3.67 MB | 5 月前3Lifetime Safety in C++: Past, Present and Future
safetySpatial safety Temporal safetySpatial safety • BufferCheck (soon), SAL • ASAN, GWP-ASAN, HWASAN + Fuzzing • Bounds-checked data structures • Checked C, Deputy • -fbounds-safety, buffer hardening Temporal Temporal safetySpatial safety • BufferCheck (soon), SAL • ASAN, GWP-ASAN, HWASAN + Fuzzing • Bounds-checked data structures • Checked C, Deputy • -fbounds-safety, buffer hardening Temporal safety safety MSpatial safety • BufferCheck (soon), SAL • ASAN, GWP-ASAN, HWASAN + Fuzzing • Bounds-checked data structures • Checked C, Deputy • -fbounds-safety, buffer hardening Temporal safety p0 码力 | 124 页 | 2.03 MB | 5 月前3A New Decade of Visual Studio: C++20, Open STL and More
of Sanitizers? Victor Ciura – Fuzzing/Testing venue Fri 9/18 12:00 – 13:00 Introducing Microsoft’s New Open Source Fuzzing Platform Justin Campbell, Michael Walker – Fuzzing/Testing venue Visit https://aka Development with Codespaces – Nick Uhlenhuth Friday 18th • Introducing Microsoft’s New Open Source Fuzzing Platform – Justin Campbell & Michael Walker0 码力 | 37 页 | 2.67 MB | 5 月前3whats new in visual studio
Announcing today Experimental libFuzzer Support • An in-process, coverage-guided, evolutionary fuzzing engine • Available in Visual Studio 2022 • Under /fsanitize=fuzzer Visit https://aka.ms/cpp/libfuzzer Analysis https://aka.ms/cpp/ca/bg ⚡ Dynamic Analysis • Address Sanitizer https://aka.ms/asan • Fuzzing with libFuzzer https://aka.ms/cpp/libfuzzer Visual Studio Agenda 1. Conformance 2. Code0 码力 | 42 页 | 19.02 MB | 5 月前3Back to Basics Unit Testing
Hard Tests Easy (Robotics Track) Xiaofan Sun (Thursday): Mix Assertion, Logging, Unit Testing and Fuzzing Pete Muldoon (Wednesday) Dependency Injection in C++ "Accelerated TDD" by Phil Nash just finished test library" (Lightning Talk) https://youtu.be/nnlEQwQlHQg Other Testing 2020: Barnabás Bágyi "Fuzzing Class Interfaces for Generating and Running Tests with libFuzzer" https://youtu.be/TtPXYPJ5_eE0 码力 | 109 页 | 4.13 MB | 5 月前3CMake Configuration for Demo Project
Build this if you start getting messages like: # profiling: ..../cmake-build-debug/..../2019_11_18_fuzzing_gilded_rose.dir/GildedRoseApprovalTe sts.cc.gcda: # cannot merge previous GCDA file: corrupt arc0 码力 | 1 页 | 1.23 KB | 5 月前3CROSS PLATFORM PITFALLS AND HOW TO AVOID THEM
Development with Codespaces – Nick Uhlenhuth Friday 18th • Introducing Microsoft’s New Open Source Fuzzing Platform – Justin Campbell & Michael Walker Our Sessions0 码力 | 67 页 | 360.44 KB | 5 月前3Building Safe and Reliable Surgical Robotics with C++
Shift left: Stress test the SW Simulation testing SQA testing Performance testing HW testing Fuzzing Fault injection testing Stress testing Reliability testing Regression testing Testing0 码力 | 71 页 | 4.02 MB | 5 月前3
共 25 条
- 1
- 2
- 3
相关搜索词
MixAssertionLoggingUnitTestingandFuzzingwithZeroErr2020TheYearofSanitizersEmbracinganAdversarialMindsetforCppSecurityLifetimeSafetyinC++PastPresentFutureNewDecadeVisualStudio20OpenSTLMorewhatsnewvisualstudioBacktoBasicsCMakeConfigurationDemoProjectCROSSPLATFORMPITFALLSANDHOWTOAVOIDTHEMBuildingSafeReliableSurgicalRobotics