Vulnerability-oriented Testing for RESTful APIs
Wenlong Du, Jian Li, Yanhao Wang, Libo Chen, Ruijie Zhao, Junmin Zhu, Zhengguang Han, Yijun Wang, Zhi Xue
摘要
With the increasing popularity of APIs, ensuring their security has become a crucial concern. However, existing security testing methods for RESTful APIs usually lack targeted approaches to identify and detect security vulnerabilities. In this paper, we propose VOAPI 2 , a vulnerability-oriented API inspection framework designed to directly expose vulnerabilities in RESTful APIs, based on our observation that the type of vulnerability hidden in an API interface is strongly associated with its functionality. By leveraging this insight, we first track commonly used strings as keywords to identify APIs' functionality. Then, we generate a stateful and suitable request sequence to inspect the candidate API function within a targeted payload. Finally, we verify whether vulnerabilities exist or not through feedback-based testing. Our experiments on real-world APIs demonstrate the effectiveness of our approach, with significant improvements in vulnerability detection compared to state-of-the-art methods. VOAPI 2 discovered 7 zero-day and 19 disclosed bugs on seven real-world RESTful APIs, and 23 of them have been assigned CVE IDs. Our findings highlight the importance of considering APIs' functionality when discovering their bugs, and our method provides a practical and efficient solution for securing RESTful APIs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- When Specifications Meet Reality: Uncovering API Inconsistencies in Ethereum InfrastructureJie Ma, Ningyu He, Jinwen Xi, Mingzhe Xing 等OOPSLA 2026
- SQLiFuzz: Uncovering SQL Injection in Any Web ApplicationsI Putu Arya Dharmaadi, Van-Thuan Pham, Fadi Mohsen, Fatih TurkmenFSE 2026
- Test Suites Guided Vulnerability Validation for Node.js ApplicationsChanghua Luo, Penghui Li, Wei Meng, Chao ZhangCCS 2024
- A Systematic Threat Analysis and Practical Attacks on Automated Frequency Coordination SystemsYilu Dong, Tianchang Yang, Arupjyoti Bhuyan, Syed Rafiul HussainNSDI 2026
- MINES: Explainable Anomaly Detection through Web API Invariant InferenceWenjie Zhang, Yun Lin, Chun Fung Amos Kwok, Xiwen Teoh 等ICSE 2026
它引用的顶会 Paper4
- Differential regression testing for REST APIsPatrice Godefroid, Daniel Lehmann, Marina PolishchukISSTA 2020 · 被引用 52 次
- Combinatorial Testing of RESTful APIsHuayao Wu, Lixin Xu, Xintao Niu, Changhai NieICSE 2022 · 被引用 47 次
- MINER: A Hybrid Data-Driven Approach for REST API FuzzingChenyang Lyu, Jiacheng Xu, Shouling Ji, Xuhong Zhang 等USENIX Security 2023
- NAUTILUS: Automated RESTful API Vulnerability DetectionGelei Deng, Zhiyi Zhang, Yuekang Li, Yi Liu 等USENIX Security 2023
相关 Paper
- Automated Black-Box Testing of Mass Assignment Vulnerabilities in RESTful APIsDavide Corradini, Michele Pasqua, Mariano CeccatoICSE 2023 · 被引用 12 次
- APIRL: Deep Reinforcement Learning for REST API FuzzingMyles Foley, Sergio MaffeisAAAI 2025 · 被引用 6 次
- Effective REST APIs Testing with Error Message AnalysisLixin Xu, Huayao Wu, Zhenyu Pan, Tongtong Xu 等ISSTA 2025 · 被引用 1 次
- Morest: Model-based RESTful API Testing with Execution FeedbackYi Liu, Yuekang Li, Gelei Deng, Yang Liu 等ICSE 2022 · 被引用 52 次
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
