2020•Lecture notes in computer scienceOpen access

Legion: Best-First Concolic Testing (Competition Contribution)

Dongge Liu, Gidon Ernst, Toby Murray, Benjamin I. P. Rubinstein

Open full text 11 citations

Abstract

Legion is a grey-box coverage-based concolic tool that aims to balance the complementary nature of fuzzing and symbolic execution to achieve the best of both worlds. It proposes a variation of Monte Carlo tree search (MCTS) that formulates program exploration as sequential decision-making under uncertainty guided by the best-first search strategy. It relies on approximate path-preserving fuzzing , a novel instance of constrained random testing, which quickly generates many diverse inputs that likely target program parts of interest. In Test-Comp 2020 [ 1 ], the prototype performed within 90% of the best score in 9 of 22 categories.

Open-access reader

About this research paper

What this paper is about

Legion is a grey-box coverage-based concolic tool that aims to balance the complementary nature of fuzzing and symbolic execution to achieve the best of both worlds. It proposes a variation of Monte Carlo tree search (MCTS) that formulates program exploration as sequential decision-making under uncertainty guided by the best-first search strategy. It relies on approximate path-preserving fuzzing , a novel instance of constrained random testing, which quickly generates many diverse inputs that likely target program parts of interest. In Test-Comp 2020 [ 1 ], the prototype performed within 90% of the best score in 9 of 22 categories.

Why it matters

OpenAlex reports 11 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Legion is a grey-box coverage-based concolic tool that aims to balance the complementary nature of fuzzing and symbolic execution to achieve the best of both worlds. It proposes a variation of Monte Carlo tree search (MCTS) that formulates program exploration as sequential decision-making under uncertainty guided by the best-first search strategy. It relies on approximate path-preserving fuzzing , a novel instance of constrained random testing, which quickly generates many diverse inputs that likely target program parts of interest. In Test-Comp 2020 [ 1 ], the prototype performed within 90% of the best score in 9 of 22 categories.

Key concepts: Fuzz testing, Concolic testing, Computer science, Symbolic execution, Random testing, Code coverage, Path (computing), Tree (set theory)

Related papers

Back to paper searchBrowse research topicsOriginal source
Legion: Best-First Concolic Testing (Competition Contribution) — Research Paper | ScholarLens