Microsoft introduces Project OpenFuzz to reduce the complexity of fuzz testing

Spread the love

Microsoft is releasing a new open-source tool to help developers find and fix bugs at scale. Project OpenFuzz is a fuzz testing framework for Azure.
According to Microsoft, fuzz testing is an effective method for improving code quality, and is a gold standard for finding and removing exploitable security vulnerabilities. Although it is effective, it’s also often complicated to use, execute, and extract information from. With OpenFuzz, the company hopes to eliminate some of that complexity. 
Developers can use OpenFuzz to launch a fuzzing job from just a single command line. 
Key capabilities of Project OneFuzz include

composable fuzzing workflows,
built-in ensemble fuzzing,
programmatic triage and result deduplication,
on-demand live-debugging of found crashes,
introspection at every stage,
the ability to fuzz on Windows and Linux,
and crash reporting notification callbacks.

The project is currently available on GitHub and is being updated by Microsoft Research & Security Groups. The company plans to continue maintaining and expanding the project. 
“Microsoft’s goal of enabling developers to easily and continuously fuzz test their code prior to release is core to our mission of empowerment. The global release of Project OneFuzz is intended to help harden the platforms and tools that power our daily work and personal lives to make an attacker’s job more difficult,” Justin Campbell, principal security software engineering lead at Microsoft Security, and Mike Walker, special projects management at Microsoft Security, wrote in a post. 
The post Microsoft introduces Project OpenFuzz to reduce the complexity of fuzz testing appeared first on SD Times.

X ITM Cloud News


Leave a Reply

Next Post

Signals & Threads - Interview with Andrey Mokhov on build systems (a la carte)

Wed Sep 16 , 2020
Spread the love           submitted by /u/yminsky [link] [comments] X ITM Cloud News

Cloud Computing – Consultancy – Development – Hosting – APIs – Legacy Systems

X-ITM Technology helps our customers across the entire enterprise technology stack with differentiated industry solutions. We modernize IT, optimize data architectures, and make everything secure, scalable and orchestrated across public, private and hybrid clouds.

This image has an empty alt attribute; its file name is x-itmdc.jpg

The enterprise technology stack includes ITO; Cloud and Security Services; Applications and Industry IP; Data, Analytics and Engineering Services; and Advisory.

Watch an animation of  X-ITM‘s Enterprise Technology Stack

We combine years of experience running mission-critical systems with the latest digital innovations to deliver better business outcomes and new levels of performance, competitiveness and experiences for our customers and their stakeholders.

X-ITM invests in three key drivers of growth: People, Customers and Operational Execution.

The company’s global scale, talent and innovation platforms serve 6,000 private and public-sector clients in 70 countries.

X-ITM’s extensive partner network helps drive collaboration and leverage technology independence. The company has established more than 200 industry-leading global Partner Network relationships, including 15 strategic partners: Amazon Web Services, AT&T, Dell Technologies, Google Cloud, HCL, HP, HPE, IBM, Micro Focus, Microsoft, Oracle, PwC, SAP, ServiceNow and VMware