NAUTILUS: Automated RESTful API Vulnerability Detection
Gelei Deng, Zhiyi Zhang, Yuekang Li, Yi Liu, Tianwei Zhang, Yang Liu, Guo Yu, Dongjin Wang
摘要
RESTful APIs have become arguably the most prevalent endpoint for accessing web services. Blackbox vulnerability scanners are a popular choice for detecting vulnerabilities in web services automatically. Unfortunately, they suffer from a number of limitations in RESTful API testing. Particularly, existing tools cannot effectively obtain the relations between API operations, and they lack the awareness of the correct sequence of API operations during testing. These drawbacks hinder the tools from requesting the API operations properly to detect potential vulnerabilities. To address this challenge, we propose NAUTILUS, which includes a novel specification annotation strategy to uncover RESTful API vulnerabilities. The annotations encode the proper operation relations and parameter generation strategies for the RESTful service, which assist NAUTILUS to generate meaningful operation sequences and thus uncover vulnerabilities that require the execution of multiple API operations in the correct sequence. We experimentally compare NAUTILUS with four state-of-art vulnerability scanners and RESTful API testing tools on six RESTful services. Evaluation results demonstrate that NAUTILUS can successfully detect an average of 141% more vulnerabilities, and cover 104% more API operations. We also apply NAUTILUS to nine real-world RESTful services, and detected 23 unique 0-day vulnerabilities with 12 CVE numbers, including one remote code execution vulnerability in Atlassian Confluence, and three high-risk vulnerabilities in Microsoft Azure, which can affect millions of users.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- PentestGPT: Evaluating and Harnessing Large Language Models for Automated Penetration TestingGelei Deng, Yi Liu, Víctor Mayoral Vilches, Peng Liu 等USENIX Security 2024 · 被引用 186 次
- Vulnerability-oriented Testing for RESTful APIsWenlong Du, Jian Li, Yanhao Wang, Libo Chen 等USENIX Security 2024 · 被引用 17 次
- BunnyFinder: Finding Incentive Flaws for Ethereum ConsensusRujia Li, Mingfei Zhang, Xueqian Lu, Wenbo Xu 等NDSS 2026 · 被引用 5 次
- MASTERKEY: Automated Jailbreaking of Large Language Model ChatbotsGelei Deng, Yi Liu, Yuekang Li, Kailong Wang 等NDSS 2024
- SQLiFuzz: Uncovering SQL Injection in Any Web ApplicationsI Putu Arya Dharmaadi, Van-Thuan Pham, Fadi Mohsen, Fatih TurkmenFSE 2026
它引用的顶会 Paper4
- Ijon: Exploring Deep State Spaces via FuzzingCornelius Aschermann, Sergej Schumilo, Ali Abbasi, Thorsten HolzS&P 2020 · 被引用 146 次
- Automatic Web Testing Using Curiosity-Driven Reinforcement LearningYan Zheng, Yi Liu, Xiaofei Xie, Yepang Liu 等ICSE 2021 · 被引用 75 次
- Rise of the HaCRS: Augmenting Autonomous Cyber Reasoning Systems with Human AssistanceYan Shoshitaishvili, Michael Weissbacher, Lukas Dresel, Christopher Salls 等CCS 2017 · 被引用 57 次
- Morest: Model-based RESTful API Testing with Execution FeedbackYi Liu, Yuekang Li, Gelei Deng, Yang Liu 等ICSE 2022 · 被引用 52 次
相关 Paper
- Automated Black-Box Testing of Mass Assignment Vulnerabilities in RESTful APIsDavide Corradini, Michele Pasqua, Mariano CeccatoICSE 2023 · 被引用 12 次
- Combinatorial Testing of RESTful APIsHuayao Wu, Lixin Xu, Xintao Niu, Changhai NieICSE 2022 · 被引用 47 次
- RESTGuardian: Automated Black-Box Fuzzing for RESTful API via Efficient Dependency Inference and Deep Vulnerability DetectionYifan Guo, Na Wang, Yunjia Wang, Zhenyu Chen 等CCS 2026
- DeepREST: Automated Test Case Generation for REST APIs Exploiting Deep Reinforcement LearningDavide Corradini, Zeno Montolli, Michele Pasqua, Mariano CeccatoASE 2024 · 被引用 13 次
- Effective REST APIs Testing with Error Message AnalysisLixin Xu, Huayao Wu, Zhenyu Pan, Tongtong Xu 等ISSTA 2025 · 被引用 1 次
