Clusterfuzz
Scalable fuzzing infrastructure.
ClusterFuzz is a scalable [fuzzing](https://en.wikipedia.org/wiki/Fuzzing) infrastructure that finds security and stability issues in software. The project is written primarily in Python, distributed under the Apache License 2.0 license, first published in 2019. It has gained significant community traction with 5,573 stars and 617 forks on GitHub. Key topics include: fuzzing, security, stability, vulnerabilities.
ClusterFuzz
<p align="center"> <img src="docs/images/logo.png" width="400"> </p>ClusterFuzz is a scalable fuzzing
infrastructure that finds security and stability issues in software.
Google uses ClusterFuzz to fuzz all Google products and as the fuzzing
backend for OSS-Fuzz.
ClusterFuzz provides many features which help seamlessly integrate fuzzing into
a software project's development process:
- Highly scalable. Can run on any size cluster (e.g. OSS-Fuzz instance runs on
100,000 VMs). - Accurate deduplication of crashes.
- Fully automatic bug filing, triage and closing for various issue trackers
(e.g. Monorail, Jira). - Supports multiple coverage guided fuzzing engines
(libFuzzer, AFL, AFL++ and Honggfuzz)
for optimal results (with ensemble fuzzing and fuzzing strategies). - Support for blackbox fuzzing.
- Testcase minimization.
- Regression finding through bisection.
- Statistics for analyzing fuzzer performance, and crash rates.
- Easy to use web interface for management and viewing crashes.
- Support for various authentication providers using Firebase.
Overview
<p align="center"> <img src="docs/images/overview.png"> </p>Documentation
You can find detailed documentation here.
Trophies
As of February 2023, ClusterFuzz has found ~27,000 bugs in Google (e.g. Chrome). Additionally, ClusterFuzz has helped identify and fix over 8,900 vulnerabilities and 28,000 bugs across 850 projects integrated with OSS-Fuzz.
Getting Help
You can file an issue to ask
questions, request features, or ask for help.
Staying Up to Date
We will use clusterfuzz-announce(#)googlegroups.com to make announcements about ClusterFuzz.
ClusterFuzzLite
For a more lightweight version of ClusterFuzz that runs on CI/CD
systems, check out ClusterFuzzLite.
Contributors
Showing top 12 contributors by commit count.
