100万件超のファジング実行ログを分析し ソフトウェアのバグ検出実態を解明 ~継続的ファジングの効果を実証、より安全な オープンソースソフトウェア開発へ指針を提示~

2026-07-28 奈良先端科学技術大学院大学

奈良先端科学技術大学院大学を中心とする研究グループは、Googleが運用するオープンソースソフトウェア(OSS)向け継続的ファジングサービス「OSS-Fuzz」の約112万件の実行ログを分析し、継続的ファジングによるバグ検出の実態を定量的に明らかにした。878のOSSプロジェクトを対象に、ファジング実行履歴、検出されたバグ、コードカバレッジの推移を解析した結果、約36%のプロジェクトで導入直後の初回実行時にバグが発見される一方、継続的な実施によりコードカバレッジが向上し、新たなバグの発見につながることを確認した。また、コードカバレッジの変動がバグ検出と強く相関し、開発者が準備するシードコーパス(初期入力データ)が長期的なバグ発見性能を高めることも示された。本研究は、OSS開発者に対し、ファジングを早期導入し継続運用する重要性を実証的に示すとともに、安全性・信頼性の高いソフトウェア開発やサイバーセキュリティ強化に向けた実践的な指針を提供する成果である。

100万件超のファジング実行ログを分析し ソフトウェアのバグ検出実態を解明 ~継続的ファジングの効果を実証、より安全な オープンソースソフトウェア開発へ指針を提示~

<関連情報>

連続ファジングの大規模実証分析:100万回のファジングセッションから得られた知見 Large-Scale Empirical Analysis of Continuous Fuzzing: Insights From 1 Million Fuzzing Sessions

Tatsuya Shirai; Olivier Nourry; Yutaro Kashiwa; Kenji Fujiwara; Yasutaka Kamei; Hajimu Iida
IEEE Transactions on Software Engineering  Published: 13 April 2026
DOI:https://doi.org/10.1109/TSE.2026.3683879

Abstract

Software vulnerabilities are constantly being reported and exploited in software products, causing significant impacts on society. In recent years, the main approach to vulnerability detection, fuzzing, has been integrated into the continuous integration process to run in short and frequent cycles. This continuous fuzzing allows for fast identification and remediation of vulnerabilities during the development process. Despite adoption by thousands of projects, however, it is unclear how continuous fuzzing contributes to vulnerability detection. This study aims to elucidate the role of continuous fuzzing in vulnerability detection. Specifically, we investigate the coverage and the total number of fuzzing sessions when fuzzing bugs are discovered. We collect issue reports, coverage reports, and fuzzing logs from OSS-Fuzz, an online service provided by Google that performs fuzzing during continuous integration. Through an empirical study of a total of approximately 1.12 million fuzzing sessions from 878 projects participating in OSS-Fuzz, we reveal that (i) a substantial number of fuzzing bugs exist prior to the integration of continuous fuzzing, leading to a high detection rate in the early stages; (ii) code coverage continues to increase as continuous fuzzing progresses; (iii) changes in coverage contribute to the detection of fuzzing bugs; and (iv) developer-provided seed corpus exhibit long-term effectiveness. This study provides empirical insights into how continuous fuzzing contributes to fuzzing bug detection, offering practical implications for future strategies and tool development in continuous fuzzing.

1602ソフトウェア工学
ad
ad
Follow
ad
タイトルとURLをコピーしました