paper-with-me

홈 › Papers

FuzzTheREST: An Intelligent Automated Black-box RESTful API Fuzzer

2024-07-19 · Tiago Dias, Eva Maia, Isabel Praça

Software's pervasive impact and increasing reliance in the era of digital transformation raise concerns about vulnerabilities, emphasizing the need for software security. Fuzzy testing is a dynamic analysis software testing technique that consists of feeding faulty input data to a System Under Test (SUT) and observing its behavior. Specifically regarding black-box RESTful API testing, recent literature has attempted to automate this technique using heuristics to perform the input search and using the HTTP response status codes for classification. However, most approaches do not keep track of code coverage, which is important to validate the solution. This work introduces a black-box RESTful API fuzzy testing tool that employs Reinforcement Learning (RL) for vulnerability detection. The fuzzer operates via the OpenAPI Specification (OAS) file and a scenarios file, which includes information to communicate with the SUT and the sequences of functionalities to test, respectively. To evaluate its effectiveness, the tool was tested on the Petstore API. The tool found a total of six unique vulnerabilities and achieved 55\% code coverage.

📄 PDF Abstract BibTeX arXiv:2407.14361

Code (0)

등록된 구현이 없습니다.

Tasks

Reinforcement Learning (RL)software testingVulnerability Detection

Similar Papers 제목 키워드 기반

BertRLFuzzer: A BERT and Reinforcement Learning Based Fuzzer

2023-05-21 · Piyush Jha, Joseph Scott, Jaya Sriram Ganeshna, Mudit Singh 외

We present a novel tool BertRLFuzzer, a BERT and Reinforcement Learning (RL) based fuzzer aimed at finding security vulnerabilities for Web applications. BertRLFuzzer works as follows: given a set of seed inputs, the fuz…

16kreinforcement-learningReinforcement LearningReinforcement Learning (RL)

Fuzz-Testing Meets LLM-Based Agents: An Automated and Efficient Framework for Jailbreaking Text-To-Image Generation Models

2024-08-01 · Yingkai Dong, Xiangtao Meng, Ning Yu, Zheng Li 외

Text-to-image (T2I) generative models have revolutionized content creation by transforming textual descriptions into high-quality images. However, these models are vulnerable to jailbreaking attacks, where carefully craf…

Image GenerationIn-Context LearningLanguage ModellingLarge Language Model+2

Beware the evolving 'intelligent' web service! An integration architecture tactic to guard AI-first components

2020-05-27 · Alex Cummaudo, Scott Barnett, Rajesh Vasa, John Grundy 외

Intelligent services provide the power of AI to developers via simple RESTful API endpoints, abstracting away many complexities of machine learning. However, most of these intelligent services-such as computer vision-con…

Leveraging Textual Specifications for Grammar-based Fuzzing of Network Protocols

2018-10-10 · Samuel Jero, Maria Leonor Pacheco, Dan Goldwasser, Cristina Nita-Rotaru

Grammar-based fuzzing is a technique used to find software vulnerabilities by injecting well-formed inputs generated following rules that encode application semantics. Most grammar-based fuzzers for network protocols rel…

JBFuzz: Jailbreaking LLMs Efficiently and Effectively Using Fuzzing

2025-03-12 · Vasudev Gohil

Large language models (LLMs) have shown great promise as language understanding and decision making tools, and they have permeated various aspects of our everyday life. However, their widespread availability also comes w…

Red TeamingSafety Alignment