For any errorless fuzzing campaign, no matter how long, there is always some residual risk that a software error would be discovered if only the campaign was run for just a bit longer. Recently, greybox fuzzing tools have found widespread adoption. Yet, practitioners can only guess when the residual risk of a greybox fuzzing campaign falls below a specific, maximum allowable threshold.
No takes yet. Share an insight, caveat, or question.
Böhme et al. (2021) studied this question.
Synapse has enriched 4 closely related papers on similar clinical questions. Consider them for comparative context: