Fuzzing

Fuzzing throws malformed and unexpected input at a program until something breaks.

It is very good at finding the cases nobody thought to test, because it is not constrained by anybody's idea of reasonable input. It works best on things that parse: file formats, protocols, decoders. It is under-used outside security-critical software largely because it is unglamorous and needs somewhere to run.

Checked against the primary source.

More on Application security