EDEFuzz: A Web API Fuzzer for Excessive Data Exposures
Lianglu Pan, Shaanan Cohney, Toby Murray, Van-Thuan Pham
摘要
APIs often transmit far more data to client applications than they need, and in the context of web applications, often do so over public channels. This issue, termed Excessive Data Exposure (EDE), was OWASP's third most significant API vulnerability of 2019. However, there are few automated tools-either in research or industry-to effectively find and remediate such issues. This is unsurprising as the problem lacks an explicit test oracle: the vulnerability does not manifest through explicit abnormal behaviours (e.g., program crashes or memory access violations). In this work, we develop a metamorphic relation to tackle that challenge and build the first fuzzing tool-that we call EDEFuzz-to systematically detect EDEs. EDEFuzz can significantly reduce false negatives that occur during manual inspection and ad-hoc text-matching techniques, the current most-used approaches. We tested EDEFuzz against the sixty-nine applicable targets from the Alexa Top-200 and found 33,365 potential leaks-illustrating our tool's broad applicability and scalability. In a more-tightly controlled experiment of eight popular websites in Australia, EDEFuzz achieved a high true positive rate of 98.65% with minimal configuration, illustrating our tool's accuracy and efficiency.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Anota: Identifying Business Logic Vulnerabilities via Annotation-Based SanitizationMeng Wang, Philipp Görz, Joschua Schilling, Keno Hassler 等NDSS 2026 · 被引用 4 次
- Are Your Requests Your True Needs? Checking Excessive Data Collection in VPA AppFuman Xie, Chuan Yan, Mark Huasong Meng, Shao-Ming Teng 等ICSE 2024 · 被引用 4 次
- SATORI: Static Test Oracle Generation for REST APIsJuan C. Alonso, Alberto Martin-Lopez, Sergio Segura, Gabriele Bavota 等ASE 2025 · 被引用 2 次
- Peeling Off the Cocoon: Unveiling Suppressed Golden Seeds for Mutational Greybox FuzzingRuixiang Qian, Chunrong Fang, Zengxu Chen, Youxin Fu 等OOPSLA 2026
- The Tragedy of Convenience: Cascading User-Data Leakage from SMS-delivered URLsMuhammad Danish, Enrique Sobrados, Priya Kaushik, Bhupendra Acharya 等CCS 2026
它引用的顶会 Paper5
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 被引用 150 次
- Nyx-net: network fuzzing with incremental snapshotsSergej Schumilo, Cornelius Aschermann, Andrea Jemmett, Ali Abbasi 等EuroSys 2022 · 被引用 76 次
- Testing Machine Translation via Referential TransparencyPinjia He, Clara Meister, Zhendong SuICSE 2021 · 被引用 50 次
- WebEvo: taming web application evolution via detecting semantic structure changesFei Shao, Rui Xu, Wasif Arman Haque, Jingwei Xu 等ISSTA 2021 · 被引用 11 次
- Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection VulnerabilitiesErik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel 等S&P 2023
相关 Paper
- Mockingbird: Efficient Excessive Data Exposures Detection via Dynamic Code InstrumentationChenxiao Xia, Jiazheng Sun, Jun Zheng, Yu-an Tan 等ASE 2025
- Minerva: browser API fuzzing with dynamic mod-ref analysisChijin Zhou, Quan Zhang, Mingzhe Wang, Lihua Guo 等FSE 2022 · 被引用 20 次
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
- Auspex: Unveiling Inconsistency Bugs of Transaction Fee Mechanism in BlockchainZheyuan He, Zihao Li, Jiahao Luo, Feng Luo 等USENIX Security 2025
- No Harness, No Problem: Oracle-guided Harnessing for Auto-generating C API Fuzzing HarnessesGabriel Sherman, Stefan NagyICSE 2025 · 被引用 1 次
