Testing Access-Control Configuration Changes for Web Applications
Fuente:
arXiv
Saved in:
| Main Authors: | Xiang, Chengcheng, Zhong, Li, Mugnier, Eric, Nguyen, Nathaniel, Zhou, Yuanyuan, Xu, Tianyin |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Designing Robust API Monitoring Solutions
by: D'Elia, Daniele Cono, et al.
Published: (2020)
by: D'Elia, Daniele Cono, et al.
Published: (2020)
A Survey of Fuzzing Open-Source Operating Systems
by: Hu, Kun, et al.
Published: (2025)
by: Hu, Kun, et al.
Published: (2025)
Threadbox: Sandboxing for Modular Security
by: Alhindi, Maysara, et al.
Published: (2025)
by: Alhindi, Maysara, et al.
Published: (2025)
Bomfather: An eBPF-based Kernel-level Monitoring Framework for Accurate Identification of Unknown, Unused, and Dynamically Loaded Dependencies in Modern Software Supply Chains
by: Srinivasan, Naveen, et al.
Published: (2025)
by: Srinivasan, Naveen, et al.
Published: (2025)
SyzRetrospector: A Large-Scale Retrospective Study of Syzbot
by: Bursey, Joseph, et al.
Published: (2024)
by: Bursey, Joseph, et al.
Published: (2024)
KNighter: Transforming Static Analysis with LLM-Synthesized Checkers
by: Yang, Chenyuan, et al.
Published: (2025)
by: Yang, Chenyuan, et al.
Published: (2025)
Configuration Validation with Large Language Models
by: Lian, Xinyu, et al.
Published: (2023)
by: Lian, Xinyu, et al.
Published: (2023)
BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
by: Dharmaadi, I Putu Arya, et al.
Published: (2025)
by: Dharmaadi, I Putu Arya, et al.
Published: (2025)
LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
by: Xiang, Jiahui, et al.
Published: (2024)
by: Xiang, Jiahui, et al.
Published: (2024)
TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
by: Yang, Guan-Yan, et al.
Published: (2025)
by: Yang, Guan-Yan, et al.
Published: (2025)
A Patient-Centric Blockchain Framework for Secure Electronic Health Record Management: Decoupling Data Storage from Access Control
by: Romel, Tanzim Hossain, et al.
Published: (2025)
by: Romel, Tanzim Hossain, et al.
Published: (2025)
OAMAC: Origin-Aware Mandatory Access Control for Practical Post-Compromise Attack Surface Reduction
by: Mohammed, Omer Abdelmajeed Idris, et al.
Published: (2026)
by: Mohammed, Omer Abdelmajeed Idris, et al.
Published: (2026)
A Survey of Web Application Security Tutorials
by: Chembakottu, Bhagya, et al.
Published: (2026)
by: Chembakottu, Bhagya, et al.
Published: (2026)
WebAssembly Based Portable and Secure Sensor Interface for Internet of Things
by: Ou, Botong, et al.
Published: (2026)
by: Ou, Botong, et al.
Published: (2026)
Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems
by: Zhou, Jinmeng, et al.
Published: (2024)
by: Zhou, Jinmeng, et al.
Published: (2024)
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
by: Corradini, Davide, et al.
Published: (2025)
by: Corradini, Davide, et al.
Published: (2025)
Access Control Threatened by Quantum Entanglement
by: Zhang, Zhicheng, et al.
Published: (2025)
by: Zhang, Zhicheng, et al.
Published: (2025)
Blindfold: Confidential Memory Management by Untrusted Operating System
by: Li, Caihua, et al.
Published: (2024)
by: Li, Caihua, et al.
Published: (2024)
RAN Tester UE: An Automated Declarative UE Centric Security Testing Platform
by: Ueltschey, Charles Marion, et al.
Published: (2025)
by: Ueltschey, Charles Marion, et al.
Published: (2025)
Empowering WebAssembly with Thin Kernel Interfaces
by: Ramesh, Arjun, et al.
Published: (2023)
by: Ramesh, Arjun, et al.
Published: (2023)
Fuzzing Frameworks for Server-side Web Applications: A Survey
by: Dharmaadi, I Putu Arya, et al.
Published: (2024)
by: Dharmaadi, I Putu Arya, et al.
Published: (2024)
Unlocking User-oriented Pages: Intention-driven Black-box Scanner for Real-world Web Applications
by: Wang, Weizhe, et al.
Published: (2025)
by: Wang, Weizhe, et al.
Published: (2025)
Secure and Efficient Access Control for Computer-Use Agents via Context Space
by: Gong, Haochen, et al.
Published: (2025)
by: Gong, Haochen, et al.
Published: (2025)
BacAlarm: Mining and Simulating Composite API Traffic to Prevent Broken Access Control Violations
by: Yang, Yanjing, et al.
Published: (2025)
by: Yang, Yanjing, et al.
Published: (2025)
Fine-grained Data Access Control for Collaborative Process Execution on Blockchain
by: Marangone, Edoardo, et al.
Published: (2022)
by: Marangone, Edoardo, et al.
Published: (2022)
Scalable and Accurate Application-Level Crash-Consistency Testing via Representative Testing
by: Gu, Yile, et al.
Published: (2025)
by: Gu, Yile, et al.
Published: (2025)
Version-level Third-Party Library Detection in Android Applications via Class Structural Similarity
by: Zhou, Bolin, et al.
Published: (2025)
by: Zhou, Bolin, et al.
Published: (2025)
Ringmaster: How to juggle high-throughput host OS system calls from TrustZone TEEs
by: Habeeb, Richard, et al.
Published: (2026)
by: Habeeb, Richard, et al.
Published: (2026)
Safe Sharing of Fast Kernel-Bypass I/O Among Nontrusting Applications
by: Beadle, Alan, et al.
Published: (2025)
by: Beadle, Alan, et al.
Published: (2025)
ACFIX: Guiding LLMs with Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts
by: Zhang, Lyuye, et al.
Published: (2024)
by: Zhang, Lyuye, et al.
Published: (2024)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)
by: Liu, Bin, et al.
Published: (2025)
Visualizing Privacy-Relevant Data Flows in Android Applications
by: Khedkar, Mugdha, et al.
Published: (2025)
by: Khedkar, Mugdha, et al.
Published: (2025)
DeLog: An Efficient Log Compression Framework with Pattern Signature Synthesis
by: Yu, Siyu, et al.
Published: (2026)
by: Yu, Siyu, et al.
Published: (2026)
BinPRE: Enhancing Field Inference in Binary Analysis Based Protocol Reverse Engineering
by: Jiang, Jiayi, et al.
Published: (2024)
by: Jiang, Jiayi, et al.
Published: (2024)
Comparing Effectiveness and Efficiency of Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP) Tools in a Large Java-based System
by: Seth, Aishwarya, et al.
Published: (2023)
by: Seth, Aishwarya, et al.
Published: (2023)
Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves
by: Dhanraj, Vijay, et al.
Published: (2025)
by: Dhanraj, Vijay, et al.
Published: (2025)
Securing Cloud File Systems with Trusted Execution
by: Burke, Quinn, et al.
Published: (2023)
by: Burke, Quinn, et al.
Published: (2023)
QASecClaw: A Multi-Agent LLM Approach for False Positive Reduction in Static Application Security Testing
by: Ameen, Mohd Ruhul, et al.
Published: (2026)
by: Ameen, Mohd Ruhul, et al.
Published: (2026)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
PentestGPT: An LLM-empowered Automatic Penetration Testing Tool
by: Deng, Gelei, et al.
Published: (2023)
by: Deng, Gelei, et al.
Published: (2023)
Similar Items
-
Designing Robust API Monitoring Solutions
by: D'Elia, Daniele Cono, et al.
Published: (2020) -
A Survey of Fuzzing Open-Source Operating Systems
by: Hu, Kun, et al.
Published: (2025) -
Threadbox: Sandboxing for Modular Security
by: Alhindi, Maysara, et al.
Published: (2025) -
Bomfather: An eBPF-based Kernel-level Monitoring Framework for Accurate Identification of Unknown, Unused, and Dynamically Loaded Dependencies in Modern Software Supply Chains
by: Srinivasan, Naveen, et al.
Published: (2025) -
SyzRetrospector: A Large-Scale Retrospective Study of Syzbot
by: Bursey, Joseph, et al.
Published: (2024)