Fuzzing

Turkish equivalent: Fuzz testiDomain: Cybersecurity

An automated testing technique that feeds malformed, unexpected, or generated inputs to software to discover crashes and security defects.

Security Context

Fuzzing exercises software with malformed, unexpected, mutated, or generated inputs. It is especially effective for file parsers, protocol decoders, and native code where memory-safety failures and unusual edge cases may be triggered automatically. Corpus quality, mutation strategy, coverage feedback, and sanitizers strongly influence yield.

Assurance Boundary

Fuzzing is not formal verification. A path that has not been reached by the fuzzer is not thereby shown to be safe, and the absence of crashes is not proof of correctness.

Related technical publications

Publications whose title or summary directly references this concept.