Taint Analysis for Graph APIs Focusing on Broken Access Control
Fuente:
arXiv
Saved in:
| Main Authors: | Lambers, Leen, Sakizloglou, Lucas, Khakharova, Taisiya, Orejas, Fernando |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Exploring a Graph-based Approach to Offline Reinforcement Learning for Sepsis Treatment
by: Khakharova, Taisiya, et al.
Published: (2025)
by: Khakharova, Taisiya, et al.
Published: (2025)
Formal Model Guided Conformance Testing for Blockchains
by: Drobnjakovic, Filip, et al.
Published: (2025)
by: Drobnjakovic, Filip, et al.
Published: (2025)
Uma Prova de Conceito para a Verificação Formal de Contratos Inteligentes
by: Neves, Murilo de Souza, et al.
Published: (2026)
by: Neves, Murilo de Souza, et al.
Published: (2026)
Optimal Circuit Synthesis of Linear Codes for Error Detection and Correction
by: Yang, Xi, et al.
Published: (2026)
by: Yang, Xi, et al.
Published: (2026)
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
by: Corradini, Davide, et al.
Published: (2025)
by: Corradini, Davide, et al.
Published: (2025)
Proceedings 16th International Workshop on Graph Computation Models
by: Lambers, Leen, et al.
Published: (2026)
by: Lambers, Leen, et al.
Published: (2026)
Harnessing the Power of LLM to Support Binary Taint Analysis
by: Liu, Puzhuo, et al.
Published: (2023)
by: Liu, Puzhuo, et al.
Published: (2023)
BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
by: Dharmaadi, I Putu Arya, et al.
Published: (2025)
by: Dharmaadi, I Putu Arya, et al.
Published: (2025)
HardTaint: Production-Run Dynamic Taint Analysis via Selective Hardware Tracing
by: Zhang, Yiyu, et al.
Published: (2024)
by: Zhang, Yiyu, et al.
Published: (2024)
Evaluating Implicit Regulatory Compliance in LLM Tool Invocation via Logic-Guided Synthesis
by: Song, Da, et al.
Published: (2026)
by: Song, Da, et al.
Published: (2026)
Multi-Agent Taint Specification Extraction for Vulnerability Detection
by: Ghebremichael, Jonah, et al.
Published: (2026)
by: Ghebremichael, Jonah, et al.
Published: (2026)
BacAlarm: Mining and Simulating Composite API Traffic to Prevent Broken Access Control Violations
by: Yang, Yanjing, et al.
Published: (2025)
by: Yang, Yanjing, et al.
Published: (2025)
PrediQL: Automated Testing of GraphQL APIs with LLMs
by: Liu, Shaolun, et al.
Published: (2025)
by: Liu, Shaolun, et al.
Published: (2025)
LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
by: Xiang, Jiahui, et al.
Published: (2024)
by: Xiang, Jiahui, et al.
Published: (2024)
ZTaint-Havoc: From Havoc Mode to Zero-Execution Fuzzing-Driven Taint Inference
by: Xie, Yuchong, et al.
Published: (2025)
by: Xie, Yuchong, et al.
Published: (2025)
Detecting Misuse of Security APIs: A Systematic Review
by: Mousavi, Zahra, et al.
Published: (2023)
by: Mousavi, Zahra, et al.
Published: (2023)
Security Testing of RESTful APIs With Test Case Mutation
by: Salva, Sebastien, et al.
Published: (2024)
by: Salva, Sebastien, et al.
Published: (2024)
YASA: Scalable Multi-Language Taint Analysis on the Unified AST at Ant Group
by: Wang, Yayi, et al.
Published: (2026)
by: Wang, Yayi, et al.
Published: (2026)
Learning to Triage Taint Flows Reported by Dynamic Program Analysis in Node.js Packages
by: Ni, Ronghao, et al.
Published: (2025)
by: Ni, Ronghao, et al.
Published: (2025)
When Security Meets Usability: An Empirical Investigation of Post-Quantum Cryptography APIs
by: Toruan, Marthin, et al.
Published: (2026)
by: Toruan, Marthin, et al.
Published: (2026)
Dynamic Taint Tracking using Partial Instrumentation for Java Applications
by: Thakur, Manoj RameshChandra
Published: (2024)
by: Thakur, Manoj RameshChandra
Published: (2024)
Verification of Robust Properties for Access Control Policies
by: Gheorghiu, Alexander V.
Published: (2026)
by: Gheorghiu, Alexander V.
Published: (2026)
MirrorFuzz: Leveraging LLM and Shared Bugs for Deep Learning Framework APIs Fuzzing
by: Ou, Shiwen, et al.
Published: (2025)
by: Ou, Shiwen, et al.
Published: (2025)
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
by: Ni, Ronghao, et al.
Published: (2026)
by: Ni, Ronghao, et al.
Published: (2026)
Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-Procedural Path-Sensitive Taint Analysis
by: Ji, Yuchen, et al.
Published: (2025)
by: Ji, Yuchen, et al.
Published: (2025)
R+R: Reassessing Java Security API Misuse in Current LLMs: A Replication on JCA and JSSE APIs with External Security Knowledge
by: Lu, Tianhe, et al.
Published: (2026)
by: Lu, Tianhe, et al.
Published: (2026)
Profile of Vulnerability Remediations in Dependencies Using Graph Analysis
by: Vera, Fernando, et al.
Published: (2024)
by: Vera, Fernando, et al.
Published: (2024)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
by: Montaruli, Biagio, et al.
Published: (2025)
by: Montaruli, Biagio, et al.
Published: (2025)
Fine-grained Data Access Control for Collaborative Process Execution on Blockchain
by: Marangone, Edoardo, et al.
Published: (2022)
by: Marangone, Edoardo, et al.
Published: (2022)
Real Money, Fake Models: Deceptive Model Claims in Shadow APIs
by: Zhang, Yage, et al.
Published: (2026)
by: Zhang, Yage, et al.
Published: (2026)
ACFIX: Guiding LLMs with Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts
by: Zhang, Lyuye, et al.
Published: (2024)
by: Zhang, Lyuye, et al.
Published: (2024)
ModZoo: A Large-Scale Study of Modded Android Apps and their Markets
by: Saavedra, Luis A., et al.
Published: (2024)
by: Saavedra, Luis A., et al.
Published: (2024)
LLM Based Input Space Partitioning Testing for Library APIs
by: Li, Jiageng, et al.
Published: (2024)
by: Li, Jiageng, et al.
Published: (2024)
Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis
by: Pecka, Nicholas, et al.
Published: (2025)
by: Pecka, Nicholas, et al.
Published: (2025)
Building Privacy-and-Security-Focused Federated Learning Infrastructure for Global Multi-Centre Healthcare Research
by: Zhang, Fan, et al.
Published: (2026)
by: Zhang, Fan, et al.
Published: (2026)
Access Hoare Logic
by: Beckmann, Arnold, et al.
Published: (2025)
by: Beckmann, Arnold, et al.
Published: (2025)
ORCAS: Obfuscation-Resilient Binary Code Similarity Analysis using Dominance Enhanced Semantic Graph
by: Wang, Yufeng, et al.
Published: (2025)
by: Wang, Yufeng, et al.
Published: (2025)
Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD
by: Avirneni, Surya Teja
Published: (2025)
by: Avirneni, Surya Teja
Published: (2025)
Enhancing REST API Fuzzing with Access Policy Violation Checks and Injection Attacks
by: Sahin, Omur, et al.
Published: (2026)
by: Sahin, Omur, et al.
Published: (2026)
Failure Analysis of Safety Controllers in Autonomous Vehicles Under Object-Based LiDAR Attacks
by: Ganiuly, Daniyal, et al.
Published: (2025)
by: Ganiuly, Daniyal, et al.
Published: (2025)
Similar Items
-
Exploring a Graph-based Approach to Offline Reinforcement Learning for Sepsis Treatment
by: Khakharova, Taisiya, et al.
Published: (2025) -
Formal Model Guided Conformance Testing for Blockchains
by: Drobnjakovic, Filip, et al.
Published: (2025) -
Uma Prova de Conceito para a Verificação Formal de Contratos Inteligentes
by: Neves, Murilo de Souza, et al.
Published: (2026) -
Optimal Circuit Synthesis of Linear Codes for Error Detection and Correction
by: Yang, Xi, et al.
Published: (2026) -
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
by: Corradini, Davide, et al.
Published: (2025)