Checking Security Properties of Cloud Service REST APIs

2020 IEEE 13th International Conference on Software Testing, Validation and Verification (ICST)(2020)

引用 43|浏览29
暂无评分
摘要
Most modern cloud and web services are programmatically accessed through REST APIs. This paper discusses how an attacker might compromise a service by exploiting vulnerabilities in its REST API. We introduce four security rules that capture desirable properties of REST APIs and services. We then show how a stateful REST API fuzzer can be extended with active property checkers that automatically test and detect violations of these rules. We discuss how to implement such checkers in a modular and efficient way. Using these checkers, we found new bugs in several deployed production Azure and Office365 cloud services, and we discuss their security implications. All these bugs have been fixed.
更多
查看译文
关键词
Test generation,Security,Cloud and Web services,REST APIs
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要