AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (1.3 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Article | Open Access

A REST API Fuzz Testing Framework Based on GUI Interaction and Specification Completion

Zonglin Li#,1Xu Zhao#,2Yan Cao2( )Yazhe Li3Yihong Zhang1
School of Cyber Science and Engineering, Zhengzhou University, Zhengzhou, 450002, China
Key Laboratory of Cyberspace Security, Ministry of Education, Information Engineering University, Zhengzhou, 450001, China
School of Business and Commerce, Zhengzhou Business Technicians Institude, Zhengzhou, 450100, China

#These authors contributed equally to this work

Show Author Information

Abstract

With the rapid development of Internet technology, REST APIs (Representational State Transfer Application Programming Interfaces) have become the primary communication standard in modern microservice architectures, raising increasing concerns about their security. Existing fuzz testing methods include random or dictionary-based input generation, which often fail to ensure both syntactic and semantic correctness, and OpenAPI-based approaches, which offer better accuracy but typically lack detailed descriptions of endpoints, parameters, or data formats. To address these issues, this paper proposes the APIDocX fuzz testing framework. It introduces a crawler tailored for dynamic web pages that automatically simulates user interactions to trigger APIs, capturing and extracting parameter information from communication packets. A multi-endpoint parameter adaptation method based on improved Jaccard similarity is then used to generalize these parameters to other potential API endpoints, filling in gaps in OpenAPI specifications. Experimental results demonstrate that the extracted parameters can be generalized with 79.61% accuracy. Fuzz testing using the enriched OpenAPI documents leads to improvements in test coverage, the number of valid test cases generated, and fault detection capabilities. This approach offers an effective enhancement to automated REST API security testing.

References

【1】
【1】
 
 
Computers, Materials & Continua
Article number: 95

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Li Z, Zhao X, Cao Y, et al. A REST API Fuzz Testing Framework Based on GUI Interaction and Specification Completion. Computers, Materials & Continua, 2026, 86(3): 95. https://doi.org/10.32604/cmc.2025.071511

7

Views

0

Downloads

0

Crossref

0

Web of Science

0

Scopus

Received: 06 August 2025
Accepted: 10 November 2025
Published: 12 January 2026
© The Author 2025.

This work is licensed under a Creative Commons Attribution 4.0 International License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.