Instrumented Fuzz Testing Using AIR Integers (Whitepaper)
• SEI Report
Publisher
Software Engineering Institute
Topic or Tag
Abstract
Integers represent a growing and underestimated source of vulnerabilities in C and C++ programs. In this paper, we present the as-if infinitely ranged (AIR) integer model, which provides a largely automated mechanism for eliminating integer overflow, truncation, and other integral exceptional conditions. The AIR integer model either produces a value equivalent to one that would have been obtained using infinitely ranged integers or results in a runtime-constraint violation. Instrumented fuzz testing of libraries that have been compiled using a prototype AIR integer compiler has been effective in discovering vulnerabilities in software with low false positive and false negative rates. Furthermore, the runtime overhead of the AIR integer model is low enough for typical applications to enable this feature in deployed systems for additional runtime protection
Integers represent a growing and underestimated source of vulnerabilities in C and C++ programs. In this paper, we present the as-if infinitely ranged (AIR) integer model, which provides a largely automated mechanism for eliminating integer overflow, truncation, and other integral exceptional conditions. The AIR integer model either produces a value equivalent to one that would have been obtained using infinitely ranged integers or results in a runtime-constraint violation. Instrumented fuzz testing of libraries that have been compiled using a prototype AIR integer compiler has been effective in discovering vulnerabilities in software with low false positive and false negative rates. Furthermore, the runtime overhead of the AIR integer model is low enough for typical applications to enable this feature in deployed systems for additional runtime protection
Cite This SEI Report
Dannenberg, R., Dormann, W., Keaton, D., Seacord, R., Wilson, T., & Plum, T. (2010, February 1). Instrumented Fuzz Testing Using AIR Integers (Whitepaper). Retrieved August 16, 2026, from https://www.sei.cmu.edu/library/instrumented-fuzz-testing-using-air-integers-whitepaper/.
@techreport{dannenberg_2010,
author={Dannenberg, Roger and Dormann, William and Keaton, David and Seacord, Robert and Wilson, Timothy and Plum, Thomas},
title={Instrumented Fuzz Testing Using AIR Integers (Whitepaper)},
month={Feb},
year={2010},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/instrumented-fuzz-testing-using-air-integers-whitepaper/},
note={Accessed: 2026-Aug-16}
}
Dannenberg, Roger, William Dormann, David Keaton, Robert Seacord, Timothy Wilson, and Thomas Plum. "Instrumented Fuzz Testing Using AIR Integers (Whitepaper)." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, February 1, 2010. https://www.sei.cmu.edu/library/instrumented-fuzz-testing-using-air-integers-whitepaper/.
R. Dannenberg, W. Dormann, D. Keaton, R. Seacord, T. Wilson, and T. Plum, "Instrumented Fuzz Testing Using AIR Integers (Whitepaper)," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 1-Feb-2010 [Online]. Available: https://www.sei.cmu.edu/library/instrumented-fuzz-testing-using-air-integers-whitepaper/. [Accessed: 16-Aug-2026].
Dannenberg, Roger, William Dormann, David Keaton, Robert Seacord, Timothy Wilson, and Thomas Plum. "Instrumented Fuzz Testing Using AIR Integers (Whitepaper)." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 Feb. 2010. https://www.sei.cmu.edu/library/instrumented-fuzz-testing-using-air-integers-whitepaper/. Accessed 16 Aug. 2026.
Dannenberg, Roger; Dormann, William; Keaton, David; Seacord, Robert; Wilson, Timothy; & Plum, Thomas. Instrumented Fuzz Testing Using AIR Integers (Whitepaper). Software Engineering Institute. 2010. https://www.sei.cmu.edu/library/instrumented-fuzz-testing-using-air-integers-whitepaper/