BacAlarm: Mining and Simulating Composite API Traffic to Prevent Broken Access Control Violations
Fuente:
arXiv
Saved in:
| Main Authors: | Yang, Yanjing, Zhang, He, Liu, Bohan, Xu, Jinwei, Hu, Jinghao, Dong, Liming, Mao, Zhewen, Pan, Dongxue |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Enhancing REST API Fuzzing with Access Policy Violation Checks and Injection Attacks
by: Sahin, Omur, et al.
Published: (2026)
by: Sahin, Omur, et al.
Published: (2026)
DLAP: A Deep Learning Augmented Large Language Model Prompting Framework for Software Vulnerability Detection
by: Yang, Yanjing, et al.
Published: (2024)
by: Yang, Yanjing, et al.
Published: (2024)
BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
by: Dharmaadi, I Putu Arya, et al.
Published: (2025)
by: Dharmaadi, I Putu Arya, et al.
Published: (2025)
Generating API Parameter Security Rules with LLM for API Misuse Detection
by: Liu, Jinghua, et al.
Published: (2024)
by: Liu, Jinghua, et al.
Published: (2024)
Taint Analysis for Graph APIs Focusing on Broken Access Control
by: Lambers, Leen, et al.
Published: (2025)
by: Lambers, Leen, et al.
Published: (2025)
Mutation-based Evaluation of Cryptographic API Misuse Detectors
by: Ami, Amit Seal, et al.
Published: (2021)
by: Ami, Amit Seal, et al.
Published: (2021)
ACFIX: Guiding LLMs with Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts
by: Zhang, Lyuye, et al.
Published: (2024)
by: Zhang, Lyuye, et al.
Published: (2024)
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
by: Corradini, Davide, et al.
Published: (2025)
by: Corradini, Davide, et al.
Published: (2025)
When Specifications Meet Reality: Uncovering API Inconsistencies in Ethereum Infrastructure
by: Ma, Jie, et al.
Published: (2026)
by: Ma, Jie, et al.
Published: (2026)
From Struggle to Simplicity with a Usable and Secure API for Encryption in Java
by: Firouzi, Ehsan, et al.
Published: (2024)
by: Firouzi, Ehsan, et al.
Published: (2024)
GraphQLer: Enhancing GraphQL Security with Context-Aware API Testing
by: Tsai, Omar, et al.
Published: (2025)
by: Tsai, Omar, et al.
Published: (2025)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024)
by: Rahman, Imranur, et al.
Published: (2024)
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
by: Zhang, Fangyuan, et al.
Published: (2024)
by: Zhang, Fangyuan, et al.
Published: (2024)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
by: Montaruli, Biagio, et al.
Published: (2025)
by: Montaruli, Biagio, et al.
Published: (2025)
SCRUTINEER: Detecting Logic-Level Usage Violations of Reusable Components in Smart Contracts
by: Lin, Xingshuang, et al.
Published: (2025)
by: Lin, Xingshuang, et al.
Published: (2025)
Designing Robust API Monitoring Solutions
by: D'Elia, Daniele Cono, et al.
Published: (2020)
by: D'Elia, Daniele Cono, et al.
Published: (2020)
Train in Vain: Functionality-Preserving Poisoning to Prevent Unauthorized Use of Code Datasets
by: Xiao, Yuan, et al.
Published: (2026)
by: Xiao, Yuan, et al.
Published: (2026)
Broken Quantum: A Systematic Formal Verification Study of Security Vulnerabilities Across the Open-Source Quantum Computing Simulator Ecosystem
by: Blain, Dominik
Published: (2026)
by: Blain, Dominik
Published: (2026)
R+R: Reassessing Java Security API Misuse in Current LLMs: A Replication on JCA and JSSE APIs with External Security Knowledge
by: Lu, Tianhe, et al.
Published: (2026)
by: Lu, Tianhe, et al.
Published: (2026)
Privacy Bills of Materials: A Transparent Privacy Information Inventory for Collaborative Privacy Notice Generation in Mobile App Development
by: Tao, Zhen, et al.
Published: (2025)
by: Tao, Zhen, et al.
Published: (2025)
A Study of Malware Prevention in Linux Distributions
by: Vu, Duc-Ly, et al.
Published: (2024)
by: Vu, Duc-Ly, et al.
Published: (2024)
A Data-Mining Based Study of Security Vulnerability Types and Their Mitigation in Different Languages
by: Antal, Gábor, et al.
Published: (2024)
by: Antal, Gábor, et al.
Published: (2024)
Mining the YARA Ecosystem: From Ad-Hoc Sharing to Data-Driven Threat Intelligence
by: Esteban, Dectot--Le Monnier de Gouville, et al.
Published: (2026)
by: Esteban, Dectot--Le Monnier de Gouville, et al.
Published: (2026)
MINES: Explainable Anomaly Detection through Web API Invariant Inference
by: Zhang, Wenjie, et al.
Published: (2025)
by: Zhang, Wenjie, et al.
Published: (2025)
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
SCAFFOLD-CEGIS: Preventing Latent Security Degradation in LLM-Driven Iterative Code Refinement
by: Chen, Yi, et al.
Published: (2026)
by: Chen, Yi, et al.
Published: (2026)
OMLog: Online Log Anomaly Detection for Evolving System with Meta-learning
by: Tian, Jiyu, et al.
Published: (2024)
by: Tian, Jiyu, et al.
Published: (2024)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
by: Rahman, Md Nafiu, et al.
Published: (2026)
by: Rahman, Md Nafiu, et al.
Published: (2026)
Broken by Default: A Formal Verification Study of Security Vulnerabilities in AI-Generated Code
by: Blain, Dominik, et al.
Published: (2026)
by: Blain, Dominik, et al.
Published: (2026)
Fine-grained Data Access Control for Collaborative Process Execution on Blockchain
by: Marangone, Edoardo, et al.
Published: (2022)
by: Marangone, Edoardo, et al.
Published: (2022)
Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD
by: Avirneni, Surya Teja
Published: (2025)
by: Avirneni, Surya Teja
Published: (2025)
LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
by: Xiang, Jiahui, et al.
Published: (2024)
by: Xiang, Jiahui, et al.
Published: (2024)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
by: Li, Zhihao, et al.
Published: (2025)
by: Li, Zhihao, et al.
Published: (2025)
DyMA-Fuzz: Dynamic Direct Memory Access Abstraction for Re-hosted Monolithic Firmware Fuzzing
by: Farrelly, Guy, et al.
Published: (2026)
by: Farrelly, Guy, et al.
Published: (2026)
An Empirical Analysis of EOS Blockchain: Architecture, Contract, and Security
by: Liu, Haiyang, et al.
Published: (2025)
by: Liu, Haiyang, et al.
Published: (2025)
iblock: Accurate and Scalable Bitcoin Simulations with OMNeT++
by: Scatena, Niccolò, et al.
Published: (2025)
by: Scatena, Niccolò, et al.
Published: (2025)
Compositional Jailbreaking: An Empirical Analysis of Mutator Chain Interactions in Aligned LLMs
by: Bugnot, Reinelle Jan, et al.
Published: (2026)
by: Bugnot, Reinelle Jan, et al.
Published: (2026)
Preserving Privacy in Software Composition Analysis: A Study of Technical Solutions and Enhancements
by: Wang, Huaijin, et al.
Published: (2024)
by: Wang, Huaijin, et al.
Published: (2024)
Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation
by: Lin, Bo, et al.
Published: (2025)
by: Lin, Bo, et al.
Published: (2025)
Hybrid Privacy Policy-Code Consistency Check using Knowledge Graphs and LLMs
by: Mao, Zhenyu, et al.
Published: (2025)
by: Mao, Zhenyu, et al.
Published: (2025)
Similar Items
-
Enhancing REST API Fuzzing with Access Policy Violation Checks and Injection Attacks
by: Sahin, Omur, et al.
Published: (2026) -
DLAP: A Deep Learning Augmented Large Language Model Prompting Framework for Software Vulnerability Detection
by: Yang, Yanjing, et al.
Published: (2024) -
BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
by: Dharmaadi, I Putu Arya, et al.
Published: (2025) -
Generating API Parameter Security Rules with LLM for API Misuse Detection
by: Liu, Jinghua, et al.
Published: (2024) -
Taint Analysis for Graph APIs Focusing on Broken Access Control
by: Lambers, Leen, et al.
Published: (2025)