YoVDO

Fuzz Testing of Envoy - Ensuring Security and Correctness

Offered By: CNCF [Cloud Native Computing Foundation] via YouTube

Tags

Fuzz Testing Courses Software Security Courses Automated testing Courses Envoy Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore fuzz testing techniques for Envoy in this 28-minute conference talk by Google engineers Adi Peleg and Teju Nareddy. Gain insights into ensuring the correctness and safety of Envoy parsers and state machines against untrusted or adversarial inputs. Learn about automated software testing methods that use randomized inputs to uncover complex edge cases and potential vulnerabilities. Discover various fuzzers used in Envoy, the OSS-Fuzz infrastructure, and real-world examples of bugs discovered through fuzz testing. Delve into the creation of specific fuzz tests for ESF components in Envoy, and understand the different levels of fuzzing, their tradeoffs, and the development workflow. Get an overview of what to fuzz in Envoy, who can write fuzz tests, and how the community can contribute to this crucial aspect of software security.

Syllabus

Intro
How does fuzzing work?
Fuzz Test Goals
Library Under Test
Fuzz Schema
Initial Corpus
Example Mutation
Development Workflow
What to Fuzz in Envoy?
Levels of Fuzzing in Envoy
Fuzzer Tradeoffs
Who Can Write Fuzz Tests?
Community Help
Future Work


Taught by

CNCF [Cloud Native Computing Foundation]

Related Courses

Desarrollo de aplicaciones profesionales para Android
Galileo University via edX
Engineering Maintainable Android Apps
Vanderbilt University via Coursera
Técnicas Avançadas para Projeto de Software
Instituto Tecnológico de Aeronáutica via Coursera
Accelerate Software Delivery using DevOps
Microsoft via edX
Continuous Integration and Deployment
Udacity