Fuzzing For Microsoft SDL
Black Box Fuzz Testing is a requirement of the software security testing phase of the SDL, the industry-leading software security assurance process that was created by Microsoft and proven effective since 2004.
Given diligent application of required security activities in the Design and Implementation phases, fuzzing done at the Verification phase confirms that attack surface reduction and threat modeling were complete and that resulting code was well written from a security standpoint. We recommend that beSTORM is used for this.
For paper, see: beSTORM and the SDL