Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
Fuente:
arXiv
Saved in:
| Main Authors: | Corradini, Davide, Ceccato, Mariano, Ghafari, Mohammad |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Mining REST APIs for Potential Mass Assignment Vulnerabilities
by: Mazidi, Arash, et al.
Published: (2024)
by: Mazidi, Arash, et al.
Published: (2024)
DeepREST: Automated Test Case Generation for REST APIs Exploiting Deep Reinforcement Learning
by: Corradini, Davide, et al.
Published: (2024)
by: Corradini, Davide, et al.
Published: (2024)
PrediQL: Automated Testing of GraphQL APIs with LLMs
by: Liu, Shaolun, et al.
Published: (2025)
by: Liu, Shaolun, et al.
Published: (2025)
BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
by: Dharmaadi, I Putu Arya, et al.
Published: (2025)
by: Dharmaadi, I Putu Arya, et al.
Published: (2025)
Think Broad, Act Narrow: CWE Identification with Multi-Agent Large Language Models
by: Sayagh, Mohammed, et al.
Published: (2025)
by: Sayagh, Mohammed, et al.
Published: (2025)
Security Testing of RESTful APIs With Test Case Mutation
by: Salva, Sebastien, et al.
Published: (2024)
by: Salva, Sebastien, et al.
Published: (2024)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)
by: Liu, Bin, et al.
Published: (2025)
Gameful Introduction to Cryptography for Dyslexic Students
by: Rahartomo, Argianto, et al.
Published: (2024)
by: Rahartomo, Argianto, et al.
Published: (2024)
Taint Analysis for Graph APIs Focusing on Broken Access Control
by: Lambers, Leen, et al.
Published: (2025)
by: Lambers, Leen, et al.
Published: (2025)
TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
by: Yang, Guan-Yan, et al.
Published: (2025)
by: Yang, Guan-Yan, et al.
Published: (2025)
From Struggle to Simplicity with a Usable and Secure API for Encryption in Java
by: Firouzi, Ehsan, et al.
Published: (2024)
by: Firouzi, Ehsan, et al.
Published: (2024)
LLM Security Guard for Code
by: Kavian, Arya, et al.
Published: (2024)
by: Kavian, Arya, et al.
Published: (2024)
The Auth Shim: A Lightweight Architectural Pattern for Integrating Enterprise SSO with Standalone Open-Source Applications
by: Agrawal, Yuvraj
Published: (2025)
by: Agrawal, Yuvraj
Published: (2025)
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
by: Ruan, Bonan, et al.
Published: (2024)
by: Ruan, Bonan, et al.
Published: (2024)
Detecting Misuse of Security APIs: A Systematic Review
by: Mousavi, Zahra, et al.
Published: (2023)
by: Mousavi, Zahra, et al.
Published: (2023)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
by: Montaruli, Biagio, et al.
Published: (2025)
by: Montaruli, Biagio, et al.
Published: (2025)
LLM4CVE: Enabling Iterative Automated Vulnerability Repair with Large Language Models
by: Fakih, Mohamad, et al.
Published: (2025)
by: Fakih, Mohamad, et al.
Published: (2025)
Root-Cause-Driven Automated Vulnerability Repair
by: Wang, Hulin, et al.
Published: (2026)
by: Wang, Hulin, et al.
Published: (2026)
Enhancing REST API Fuzzing with Access Policy Violation Checks and Injection Attacks
by: Sahin, Omur, et al.
Published: (2026)
by: Sahin, Omur, et al.
Published: (2026)
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
by: Zhang, Fangyuan, et al.
Published: (2024)
by: Zhang, Fangyuan, et al.
Published: (2024)
When Security Meets Usability: An Empirical Investigation of Post-Quantum Cryptography APIs
by: Toruan, Marthin, et al.
Published: (2026)
by: Toruan, Marthin, et al.
Published: (2026)
A Faceted Classification of Authenticator-Centric Authentication Techniques
by: Mattukat, Alex R., et al.
Published: (2026)
by: Mattukat, Alex R., et al.
Published: (2026)
Execution-State-Aware LLM Reasoning for Automated Proof-of-Vulnerability Generation
by: Li, Haoyu, et al.
Published: (2026)
by: Li, Haoyu, et al.
Published: (2026)
MirrorFuzz: Leveraging LLM and Shared Bugs for Deep Learning Framework APIs Fuzzing
by: Ou, Shiwen, et al.
Published: (2025)
by: Ou, Shiwen, et al.
Published: (2025)
VulKey: Automated Vulnerability Repair Guided by Domain-Specific Repair Patterns
by: Li, Jia, et al.
Published: (2026)
by: Li, Jia, et al.
Published: (2026)
Benchmarking Prompt Engineering Techniques for Secure Code Generation with GPT Models
by: Bruni, Marc, et al.
Published: (2025)
by: Bruni, Marc, et al.
Published: (2025)
Broken by Default: A Formal Verification Study of Security Vulnerabilities in AI-Generated Code
by: Blain, Dominik, et al.
Published: (2026)
by: Blain, Dominik, et al.
Published: (2026)
Generating Proof-of-Vulnerability Tests to Help Enhance the Security of Complex Software
by: Kanchi, Shravya, et al.
Published: (2026)
by: Kanchi, Shravya, et al.
Published: (2026)
Automated Penetration Testing: Formalization and Realization
by: Skandylas, Charilaos, et al.
Published: (2024)
by: Skandylas, Charilaos, et al.
Published: (2024)
LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
by: Xiang, Jiahui, et al.
Published: (2024)
by: Xiang, Jiahui, et al.
Published: (2024)
LLM Based Input Space Partitioning Testing for Library APIs
by: Li, Jiageng, et al.
Published: (2024)
by: Li, Jiageng, et al.
Published: (2024)
APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching
by: Nong, Yu, et al.
Published: (2024)
by: Nong, Yu, et al.
Published: (2024)
AutoVulnPHP: LLM-Powered Two-Stage PHP Vulnerability Detection and Automated Localization
by: Wang, Zhiqiang, et al.
Published: (2026)
by: Wang, Zhiqiang, et al.
Published: (2026)
CodeHacker: Automated Test Case Generation for Detecting Vulnerabilities in Competitive Programming Solutions
by: Shi, Jingwei, et al.
Published: (2026)
by: Shi, Jingwei, et al.
Published: (2026)
FuzzingBrain V2: A Multi-Agent LLM System for Automated Vulnerability Discovery and Reproduction
by: Sheng, Ze, et al.
Published: (2026)
by: Sheng, Ze, et al.
Published: (2026)
HYDRA: A Hybrid Heuristic-Guided Deep Representation Architecture for Predicting Latent Zero-Day Vulnerabilities in Patched Functions
by: Farhad, Mohammad, et al.
Published: (2025)
by: Farhad, Mohammad, et al.
Published: (2025)
AIM: Automated Input Set Minimization for Metamorphic Security Testing
by: Chaleshtari, Nazanin Bayati, et al.
Published: (2024)
by: Chaleshtari, Nazanin Bayati, et al.
Published: (2024)
R+R: Reassessing Java Security API Misuse in Current LLMs: A Replication on JCA and JSSE APIs with External Security Knowledge
by: Lu, Tianhe, et al.
Published: (2026)
by: Lu, Tianhe, et al.
Published: (2026)
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
by: Li, Zhen, et al.
Published: (2024)
by: Li, Zhen, et al.
Published: (2024)
Enhancing Fuzz Testing Efficiency through Automated Fuzz Target Generation
by: Tran, Chi Thien
Published: (2026)
by: Tran, Chi Thien
Published: (2026)
Similar Items
-
Mining REST APIs for Potential Mass Assignment Vulnerabilities
by: Mazidi, Arash, et al.
Published: (2024) -
DeepREST: Automated Test Case Generation for REST APIs Exploiting Deep Reinforcement Learning
by: Corradini, Davide, et al.
Published: (2024) -
PrediQL: Automated Testing of GraphQL APIs with LLMs
by: Liu, Shaolun, et al.
Published: (2025) -
BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
by: Dharmaadi, I Putu Arya, et al.
Published: (2025) -
Think Broad, Act Narrow: CWE Identification with Multi-Agent Large Language Models
by: Sayagh, Mohammed, et al.
Published: (2025)