What if the most dangerous bugs in your software are hiding behind inputs nobody thought to test?
Modern software can pass unit tests, code reviews, static analysis, and QA—and still fail when confronted with the right unexpected input.
A malformed file. A strange API request. An unexpected sequence of bytes. A deeply nested document. A state transition no developer anticipated.
Fuzzing is designed to find those failures.
Fuzzing Engineering: A Practical Guide to Automated Vulnerability Discovery, Coverage-Guided Testing, and Secure Software Development takes you beyond the idea of simply throwing random data at a program. It presents fuzzing as a practical engineering discipline built around automated input generation, feedback, code coverage, instrumentation, crash detection, analysis, and continuous testing.
Inside this book, you'll learn how to:
• Understand the foundations and purpose of modern fuzzing
• Choose between black-box, white-box, and grey-box approaches
• Apply mutation-based, generation-based, grammar-based, stateful, and hybrid techniques
• Design effective fuzzing harnesses for real software targets
• Use instrumentation, sanitizers, and runtime monitoring to expose failures
• Build and manage seed corpora and coverage-guided fuzzing campaigns
• Fuzz REST APIs, GraphQL, network protocols, web applications, and file formats
• Discover parsing, validation, memory-safety, and unexpected-state failures
• Investigate crashes and distinguish meaningful findings from testing noise
• Reproduce, triage, deduplicate, and analyze discovered failures
• Understand buffer overflows, use-after-free, and out-of-bounds errors
• Explore fuzzing for embedded, IoT, and mobile systems
• Apply AI-assisted techniques to input generation, crash analysis, and test optimization
• Integrate fuzzing into CI/CD and DevSecOps workflows
• Build continuous fuzzing campaigns and measure their effectiveness
Who Is This Book For?
This book is written for software developers, security engineers, penetration testers, QA engineers, application security professionals, DevSecOps practitioners, and software architects who want a practical understanding of automated software testing and vulnerability discovery.
You don't need to be a compiler researcher or formal-methods expert to get started. If you already know how to program and understand the basics of software security, this book provides a practical path from your first fuzzing harness to more sophisticated, continuous fuzzing workflows.
Effective fuzzing is not about generating the largest number of crashes. It is about reaching meaningful code, discovering previously unknown behavior, understanding why failures occur, and turning those discoveries into fixes and permanent regression tests.
You'll learn the complete fuzzing lifecycle—from target preparation and instrumentation through execution, mutation, crash triage, remediation, and regression testing.
The book also emphasizes an important reality: fuzzing is not a replacement for every other security technique. It works alongside code review, threat modeling, static analysis, traditional testing, and manual security assessment to expose weaknesses that other approaches may miss.
Build Software That Survives the Unexpected.
Every application makes assumptions about the inputs it will receive. Fuzzing systematically challenges those assumptions at a scale that human testers cannot match.
Whether you're securing a parser, testing an API, hardening native software, improving software quality, or building a continuous security-testing pipeline, Fuzzing Engineering gives you the concepts, techniques, and engineering mindset needed to make fuzzing a practical part of modern software development.
Die Inhaltsangabe kann sich auf eine andere Ausgabe dieses Titels beziehen.
Anbieter: PBShop.store US, Wood Dale, IL, USA
PAP. Zustand: New. New Book. Shipped from UK. Established seller since 2000. Bestandsnummer des Verkäufers L2-9798177201436
Anzahl: Mehr als 20 verfügbar
Anbieter: PBShop.store UK, Fairford, GLOS, Vereinigtes Königreich
PAP. Zustand: New. New Book. Shipped from UK. Established seller since 2000. Bestandsnummer des Verkäufers L2-9798177201436
Anzahl: Mehr als 20 verfügbar
Anbieter: AHA-BUCH GmbH, Einbeck, Deutschland
Taschenbuch. Zustand: Neu. Neuware. Bestandsnummer des Verkäufers 9798177201436
Anzahl: 2 verfügbar