is there a paper on the relationship between number of fuzzing cycles and number or bugs found? i feel like i remember this being a thing, but can’t find it.
@buherator@infosec.place @aDot@social.treehouse.systems exponential cost of vulnerabilities from Böhme and co should cover that
@buherator@infosec.place @aDot@social.treehouse.systems ah, yep, slightly misremembered the name: https://mboehme.github.io/paper/FSE20.EmpiricalLaw.pdf