Automated Black-Box Testing of Mass Assignment Vulnerabilities in RESTful APIs
Davide Corradini, Michele Pasqua, Mariano Ceccato
摘要
Mass assignment is one of the most prominent vulnerabilities in RESTful APIs that originates from a misconfiguration in common web frameworks. This allows attackers to exploit naming convention and automatic binding to craft malicious requests that (massively) override data supposed to be read-only. In this paper, we adopt a black-box testing perspective to automatically detect mass assignment vulnerabilities in RESTful APIs. Indeed, execution scenarios are generated purely based on the OpenAPI specification, that lists the available operations and their message format. Clustering is used to group similar operations and reveal read-only fields, the latter are candidates for mass assignment. Then, test interaction sequences are automatically generated by instantiating abstract testing templates, with the aim of trying to use the found read-only fields to carry out a mass assignment attack. Test interactions are run, and their execution is assessed by a specific oracle, in order to reveal whether the vulnerability could be successfully exploited. The proposed novel approach has been implemented and evaluated on a set of case studies written in different programming languages. The evaluation highlights that the approach is quite effective in detecting seeded vulnerabilities, with a remarkably high accuracy.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- AGORA: Automated Generation of Test Oracles for REST APIsJuan C. Alonso, Sergio Segura, Antonio Ruiz-CortésISSTA 2023 · 被引用 15 次
- A Multi-Agent Approach for REST API Testing with Semantic Graphs and LLM-Driven InputsMyeongsoo Kim, Tyler Stennett, Saurabh Sinha, Alessandro OrsoICSE 2025 · 被引用 4 次
- Effective Directed Fuzzing with Hierarchical Scheduling for Web Vulnerability DetectionZihan Lin, Yuan Zhang, Jiarun Dai, Xinyou Huang 等USENIX Security 2025
它引用的顶会 Paper1
相关 Paper
- NAUTILUS: Automated RESTful API Vulnerability DetectionGelei Deng, Zhiyi Zhang, Yuekang Li, Yi Liu 等USENIX Security 2023
- Effective REST APIs Testing with Error Message AnalysisLixin Xu, Huayao Wu, Zhenyu Pan, Tongtong Xu 等ISSTA 2025 · 被引用 1 次
- Combinatorial Testing of RESTful APIsHuayao Wu, Lixin Xu, Xintao Niu, Changhai NieICSE 2022 · 被引用 47 次
- Morest: Model-based RESTful API Testing with Execution FeedbackYi Liu, Yuekang Li, Gelei Deng, Yang Liu 等ICSE 2022 · 被引用 52 次
- RESTGuardian: Automated Black-Box Fuzzing for RESTful API via Efficient Dependency Inference and Deep Vulnerability DetectionYifan Guo, Na Wang, Yunjia Wang, Zhenyu Chen 等CCS 2026
