Increasing Reliability of Programming Interfaces Based on Fuzz Testing

被引:0
|
作者
Khortiuk, Yaroslav [1 ]
Kondratenko, Galyna [1 ]
Sidenko, Ievgen [1 ]
Kondratenko, Yuriy [1 ]
机构
[1] Petro Mohyla Black Sea Natl Univ, Intelligent Informat Syst Dept, Mykolaiv, Ukraine
来源
2020 IEEE 11TH INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS, SERVICES AND TECHNOLOGIES (DESSERT): IOT, BIG DATA AND AI FOR A SAFE & SECURE WORLD AND INDUSTRY 4.0 | 2020年
关键词
fuzzing; fuzz testing; automation; quality assurance; REST API;
D O I
10.1109/dessert50317.2020.9125060
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Over the last decade, there has been a significant growth in web applications for data processing and output, most of them working through the REST API to communicate with third-party applications. Tools for automatically testing web services through their REST API and verifying the reliability and security of these services are still in their infancy. The most sophisticated testing tools currently available for the REST API scan all API traffic in real-time and then analyze, modify, and reproduce it. Many of these tools were born as extensions of more established web site testing and crawling tools. As these REST API testing tools are all recent and not widely used, it is unknown at this time how effective they are in finding errors and how important they are for security. In this paper, using the latest researches in the field, several methods and approaches for fuzzing web interfaces are analyzed. Their comparative analysis of existing techniques allows to see the current state, performance, and appliance to real-world web application and widely used REST API architecture in general.
引用
收藏
页码:272 / 277
页数:6
相关论文
共 50 条
  • [31] DeltaFuzz: Historical Version Information Guided Fuzz Testing
    Zhang, Jia-Ming
    Cui, Zhan-Qi
    Chen, Xiang
    Wu, Huan-Huan
    Zheng, Li-Wei
    Liu, Jian-Bin
    JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2022, 37 (01) : 29 - 49
  • [32] Fuzz: Genetic Algorithm-based Fuzzing for Stress Testing Congestion Control Algorithms.
    Ray, Devdeep
    Seshan, Srinivasan
    THE 21ST ACM WORKSHOP ON HOT TOPICS IN NETWORKS, HOTNETS 2022, 2022, : 31 - 37
  • [33] L2Fuzz: Discovering Bluetooth L2CAP Vulnerabilities Using Stateful Fuzz Testing
    Park, Haram
    Nkuba, Carlos Kayembe
    Woo, Seunghoon
    Lee, Heejo
    2022 52ND ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN 2022), 2022, : 343 - 354
  • [34] IDENTIFYING VULNERABILITIES IN SCADA SYSTEMS VIA FUZZ-TESTING
    Shapiro, Rebecca
    Bratus, Sergey
    Rogers, Edmond
    Smith, Sean
    CRITICAL INFRASTRUCTURE PROTECTION V, 2011, 367 : 57 - +
  • [35] Polar: Function Code Aware Fuzz Testing of ICS Protocol
    Luo, Zhengxiong
    Zuo, Feilong
    Jiang, Yu
    Gao, Jian
    Jiao, Xun
    Sun, Jiaguang
    ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2019, 18 (05)
  • [36] A Control Flow Graph Optimization Method for Enhancing Fuzz Testing
    He, Yuan
    Xue, Bo
    Zhang, Lina
    Lu, Chengyang
    IEEE ACCESS, 2024, 12 : 169370 - 169378
  • [37] Efficient Fuzz Testing for Apache Spark Using Framework Abstraction
    Zhang, Qian
    Wang, Jiyuan
    Gulzar, Muhammad Ali
    Padhye, Rohan
    Kim, Miryung
    2021 IEEE/ACM 43RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS (ICSE-COMPANION 2021), 2021, : 61 - 64
  • [38] Adversarial generation method for smart contract fuzz testing seeds guided by chain-based LLM
    Sun, Jiaze
    Yin, Zhiqiang
    Zhang, Hengshan
    Chen, Xiang
    Zheng, Wei
    AUTOMATED SOFTWARE ENGINEERING, 2025, 32 (01)
  • [39] A Negative Input Space Complexity Metric as Selection Criterion for Fuzz Testing
    Schneider, Martin A.
    Wendland, Marc-Florian
    Hoffmann, Andreas
    TESTING SOFTWARE AND SYSTEMS, ICTSS 2015, 2015, 9447 : 257 - 262
  • [40] Network protocol fuzz testing for information systems and applications: a survey and taxonomy
    Munea, Tewodros Legesse
    Lim, Hyunwoo
    Shon, Taeshik
    MULTIMEDIA TOOLS AND APPLICATIONS, 2016, 75 (22) : 14745 - 14757