Fuzzing Frameworks for Server-side Web Applications: A Survey

I Dharmaadi, E Athanasopoulos, F Turkmen - arXiv preprint arXiv …, 2024 - arxiv.org
There are around 5.3 billion Internet users, amounting to 65.7% of the global population,
and web technology is the backbone of the services delivered via the Internet. To ensure …

Are Your Requests Your True Needs? Checking Excessive Data Collection in VPA App

F Xie, C Yan, MH Meng, S Teng, Y Zhang… - Proceedings of the IEEE …, 2024 - dl.acm.org
Virtual personal assistants (VPA) services encompass a large number of third-party
applications (or apps) to enrich their functionalities. These apps have been well examined to …

Beyond the Coverage Plateau: A Comprehensive Study of Fuzz Blockers (Registered Report)

W Gao, VT Pham, D Liu, O Chang, T Murray… - Proceedings of the 2nd …, 2023 - dl.acm.org
Fuzzing and particularly code coverage-guided greybox fuzzing is highly successful in
automated vulnerability discovery, as evidenced by the multitude of vulnerabilities …

Revealing inputs causing web API performance latency using response-time-guided genetic algorithm fuzzing

YT Huang, SJ Lee - Artificial Life and Robotics, 2024 - Springer
Web APIs are integral to modern web development, enabling service integration and
automation. Ensuring their performance and functionality is critical, yet performance testing …

KubeFuzzer: Automating RESTful API Vulnerability Detection in Kubernetes.

T Zheng, R Tang, X Chen… - Computers, Materials & …, 2024 - search.ebscohost.com
RESTful API fuzzing is a promising method for automated vulnerability detection in
Kubernetes platforms. Existing tools struggle with generating lengthy, high-semantic request …

AFLSmart++: Smarter Greybox Fuzzing

VT Pham - 2023 IEEE/ACM International Workshop on Search …, 2023 - ieeexplore.ieee.org
Model/grammar-based greybox fuzzing has gained attention from both industry and
academia due to its capability of discovering bugs/vulnerabilities in programs taking highly …

Static Analysis Of Client-Side JavaScript Code To Detect Server-Side Business Logic Vulnerabilities

F van der Windt - 2023 - diva-portal.org
In the real world, web applications are crucial in various domains, from e-commerce to
finance and healthcare. However, these applications are not immune to vulnerabilities …