Vulnerability-oriented Testing for RESTful APIs

Wenlong Du, Jian Li, Yanhao Wang, Libo Chen, Zhengguang Han, Yijun Wang, Zhi Xue

33rd USENIX Security Symposium · Day 1 · USENIX Security '24 · USENIX Security '24

Overview

RESTful APIs have become the backbone of modern software architecture, powering everything from cloud services and enterprise applications to IoT devices. Their widespread adoption, however, has unfortunately been accompanied by a surge in security vulnerabilities, leading to significant incidents like the Facebook API bug that reportedly affected millions of users. Addressing this escalating threat requires robust and efficient methods for discovering API security weaknesses. This talk introduces V-API, a novel inspection framework designed to tackle this challenge by employing a vulnerability-oriented strategy.

Watch on YouTube

Visual summary for Vulnerability-oriented Testing for RESTful APIs by Wenlong Du, Jian Li, Yanhao Wang, Libo Chen, Zhengguang Han, Yijun Wang, Zhi Xue
Visual summary for Vulnerability-oriented Testing for RESTful APIs by Wenlong Du, Jian Li, Yanhao Wang, Libo Chen, Zhengguang Han, Yijun Wang, Zhi Xue

Key moments

  1. 0:00 Introduction: The growing problem of API security
  2. 1:00 The core insight: Connecting API function to vulnerability
  3. 2:45 Verifying the insight: SSRF prevalence in remote APIs
  4. 4:10 Integrating the idea: Challenges for a new testing method
  5. 5:00 V-API Architecture: How the tool works
  6. 6:50 Test sequence construction using producer-consumer relationships
  7. 8:40 Evaluation results: V-API's superior vulnerability discovery
  8. 9:50 Conclusion: Summary of V-API's effectiveness and findings

Vulnerability-oriented Testing for RESTful APIs

Speakers: Wenlong Du, Jian Li, Yanhao Wang, Libo Chen, Zhengguang Han, Yijun Wang, Zhi Xue

Conference: USENIX Security '24

YouTube: https://www.youtube.com/watch?v=PZUu7nHJhEo

Overview

RESTful APIs have become the backbone of modern software architecture, powering everything from cloud services and enterprise applications to IoT devices. Their widespread adoption, however, has unfortunately been accompanied by a surge in security vulnerabilities, leading to significant incidents like the Facebook API bug that reportedly affected millions of users. Addressing this escalating threat requires robust and efficient methods for discovering API security weaknesses. This talk introduces V-API, a novel inspection framework designed to tackle this challenge by employing a vulnerability-oriented strategy.

The core insight behind V-API is that the type of vulnerability hidden within an API is often closely related to its specific function. By leveraging this correlation, V-API aims to move beyond generic API testing approaches to provide a more targeted and effective mechanism for identifying critical security flaws. The framework promises to not only improve the efficacy of vulnerability discovery but also to enhance the efficiency of the testing process, offering a significant advancement in the realm of API security.

This article delves into the technical underpinnings of V-API, exploring its architecture, methodologies, and the compelling results achieved in real-world API testing. It highlights how V-API’s unique approach can uncover previously unknown vulnerabilities and provides crucial insights for developers and security professionals seeking to fortify their API ecosystems against persistent threats.

Background

▶ Watch: Introduction: The growing problem of API security (0:00)

The landscape of API security testing is complex, with numerous tools and methodologies available. However, many existing solutions, while effective for general API functionality and robustness testing, often fall short when it comes to identifying specific, high-impact security vulnerabilities. A popular tool like "R," for instance, excels at creating complex test cases and uncovering issues such as server errors, resource leaks, and general error problems. Yet, its efficacy diminishes significantly when confronted with specific security flaws like Server-Side Request Forgery (SSRF) or Cross-Site Scripting (XSS). Furthermore, comprehensive testing with such tools can be prohibitively time-consuming, especially when dealing with applications that expose hundreds of API endpoints.

The challenge, as highlighted by the speakers, can be framed by imagining the thought process of an experienced hacker. When tasked with finding an SSRF vulnerability in a large application like Jira, a hacker wouldn't randomly probe every single endpoint. Instead, they would intuitively focus on endpoints that, based on their function, are more likely to exhibit such a weakness. For example, if an API documentation describes an endpoint like /image/remote that is designed for "getting a remote image," and it accepts a parameter named imageURL, an attacker would immediately consider the possibility of manipulating imageURL to point to an internal resource. Sending a request with an SSRF payload to this specific endpoint could then reveal an internal service, leading to a successful SSRF discovery.

This intuitive approach by attackers underscores a fundamental disconnect in traditional API testing: the lack of a strong, explicit link between an API's perceived function and the types of security vulnerabilities it might harbor. Without this insight, testing becomes a broad, inefficient exercise. The problem, therefore, is to systematically identify which API endpoints and parameters should be targeted for specific vulnerability types, moving beyond brute-force or generic fuzzing to a more intelligent, vulnerability-oriented strategy. This foundational problem is what V-API seeks to address by formalizing the attacker's intuition into a systematic framework.

Key Findings

▶ Watch: Verifying the insight: SSRF prevalence in remote APIs (2:45)

The central premise of V-API, and its most significant finding, is the existence of a distinguishing connection between specific API security vulnerabilities and API functions. This means that certain types of API functionalities are inherently more prone to particular security flaws. For instance, APIs designed to request remote resources are often susceptible to SSRF, while those handling file operations might be vulnerable to unrestricted file uploads. This insight, which mirrors an attacker’s intuitive targeting, forms the bedrock of V-API’s efficiency and effectiveness.

To verify this hypothesis, the researchers undertook a meticulous analysis of six common CWE (Common Weakness Enumeration) types. They manually summarized the sub-functions of APIs corresponding to each vulnerability type. This analysis involved deriving insights from publicly available API documentations, examining source code where feasible, and scrutinizing detailed vulnerability descriptions from various sources.

A concrete example illustrates this correlation: a CVE related to an API endpoint named API_GET_JSON. By checking its specification, the researchers understood that this endpoint was designed for "loading a file based on a URL." This functional description immediately flags it as a potential candidate for SSRF vulnerabilities due to its interaction with external or specified URLs.

The results of this extensive analysis were striking:

  • SSRF Prevalence: The study revealed that SSRF vulnerabilities are highly prevalent in APIs that request remote resources. Keywords associated with such functions often include "remote," "proxy," and "URL." The hit rate for SSRF in these specific functional contexts was remarkably high, at approximately 81%. This strong correlation provides a clear signal for targeted testing.
  • General Correlation: Beyond SSRF, other vulnerabilities also exhibited similar patterns. On average, 37% of API interfaces found to be infected by a specific type of bug belonged to the same function narrative. While not as high as SSRF's 81%, this still represents a significant statistical advantage over random testing, indicating that understanding an API's function can substantially narrow down the search space for specific vulnerabilities.

These findings validate the core idea that a vulnerability-oriented strategy can dramatically improve the efficiency and accuracy of API security testing. By focusing testing efforts on API functions known to correlate with specific vulnerability types, V-API can identify weaknesses more effectively than general-purpose testing tools.

Technical Deep Dive

▶ Watch: V-API Architecture: How the tool works (5:00)

Integrating the insight that API function correlates with vulnerability type into a practical testing method required addressing three key challenges:

  1. Efficiently identifying API functions and pinpointing potentially vulnerable ones.
  2. Creating valid test sequences that respect protocol states and target identified vulnerable interfaces.
  3. Generating effective fuzz test cases tailored to different API functions and their associated security vulnerabilities.

V-API's architecture is meticulously designed to address these challenges, comprising several interconnected modules:

V-API Architecture

The overall architecture of V-API operates as follows:

  • API Specification Parser: The process begins by parsing the API specification (e.g., OpenAPI/Swagger). This module is crucial for understanding the structural layout and intended functionality of the APIs, extracting endpoint paths, parameters, HTTP methods, and data schemas.
  • Function-Vulnerability Mapper: The parsed data is then fed into this mapper. This module is built upon a database of path keywords and parameter keywords derived from extensive analysis of CVE databases and expert security insights. By cross-referencing these keywords with the API specification, the mapper deduces the likely function of each API endpoint and, crucially, maps these functions to potential vulnerability types. This process identifies initial "candidate APIs" that might be vulnerable.
  • Test Sequence Generator: Not all API calls can be made in isolation; many require prior actions (e.g., authentication, resource creation). This module is responsible for creating valid request sequences. It constructs sequences that respect API dependencies and protocol states, ensuring that the target vulnerable interfaces are reached in a valid operational context. This involves identifying producer-consumer relationships and generating appropriate parameter values to navigate the API workflow.
  • Test Case Generator: Once a valid sequence is established, this module produces specific test cases. These are not generic fuzzing inputs but are carefully crafted payloads designed to exploit the specific vulnerability types identified by the Function-Vulnerability Mapper for the given API function.
  • Vulnerability Verifier: The generated test cases are sent to the API application under test via this module. The verifier monitors the application's responses, analyzing them for indicators of vulnerability. This might involve checking for specific error messages, unexpected data leakage, or changes in application state.
  • Proof of Concept (PoC) Generation: If a vulnerability is detected by the verifier, V-API automatically generates a Proof of Concept (PoC) to demonstrate the flaw, providing actionable evidence for remediation.

Semantic Keyword Collection

A cornerstone of the Function-Vulnerability Mapper is its ability to deduce API function from keywords. This capability is built through a rigorous process of semantic keyword collection:

  • The researchers analyzed a vast corpus of CVEs (Common Vulnerabilities and Exposures) and NVDs (National Vulnerability Database) to conduct word frequency analysis. This helped identify terms commonly associated with specific vulnerability types and API functionalities.
  • Expert experience was then leveraged to refine and augment these keyword lists, ensuring that the identified keywords accurately reflect API functions and their security implications. These keywords (e.g., "remote," "proxy," "URL" for SSRF; "upload," "file," "document" for file upload vulnerabilities) are critical for the mapper to make informed deductions.

Candidate Interface Extraction

In this module, the API specification parser extracts details like API paths, HTTP methods, and parameter names. The Function-Vulnerability Mapper then uses the collected path and parameter keywords to deduce the function of these APIs. For example, an API with a path containing "upload" and a parameter named "file" would be identified as a file upload function. This functional deduction then allows the system to map potential vulnerability types (e.g., unrestricted file upload) to this specific interface.

Reverse Sequence Construction

Many vulnerabilities require a specific sequence of operations to be triggered. V-API employs reverse sequence construction to ensure valid testing contexts. This involves:

  • Producer-Consumer Relationships: Identifying how data generated by one API endpoint (a "producer") is consumed by another (a "consumer"). For example, creating a resource (producer) might generate an ID that is then used to access or modify that resource (consumer).
  • CRUD Semantics: Leveraging the standard Create, Read, Update, Delete (CRUD) operations to understand typical API workflows and dependencies.
  • Resource Hierarchy: Understanding how resources are structured and related within the API (e.g., a document belonging to a collection).

An example provided illustrates this: if an API endpoint has two consumers, collection ID and document ID, the system identifies potential producers. If two producers show the same path but one uses POST and the other GET, V-API's rules prioritize POST requests for resource creation over GET requests, leading to the removal of the less relevant producer for sequence construction. This intelligent prioritization ensures that the generated sequences are not only valid but also more likely to lead to a vulnerable state.

Test Case Center and Validation Server

The Test Case Center is responsible for orchestrating the actual requests. It sends requests augmented with specific payloads (e.g., SSRF payloads, XSS scripts) to the API application. The application's response is then captured by the Validation Server. If a vulnerability like SSRF is detected (e.g., by observing an unexpected external request from the server or specific error messages), the Validation Server provides feedback to the Test Case Center. This feedback loop allows for dynamic adjustment of test cases and efficient generation of a Proof of Concept (PoC). Different payloads are used for different API types and vulnerability classes, ensuring comprehensive and targeted testing.

Demo / Proof of Concept

▶ Watch: Test sequence construction using producer-consumer relationships (6:50)

While the talk did not provide an extensive live demonstration of V-API in action with specific step-by-step walkthroughs of exploiting a vulnerability, the speakers indicated that "samples in our testing class" were used, employing "different payloads for different API types." This suggests that the framework includes a suite of pre-defined and dynamically generated test payloads tailored to the identified vulnerability-function correlations. The Test Case Center and Validation Server components are designed precisely for this purpose: the former crafts and dispatches these specific payloads, and the latter interprets the API’s responses to confirm the presence of a vulnerability and generate a PoC. This implies that the demonstration focused more on the efficacy of the overall system through its evaluation results rather than a detailed live hack.

Defensive Implications

▶ Watch: Conclusion: Summary of V-API's effectiveness and findings (9:50)

The findings and methodology presented by V-API carry profound implications for API security defenders, offering actionable insights and a powerful new toolset. The core message is clear: understanding the functional purpose of an API endpoint is paramount for effective security testing and defense.

  1. Prioritize Vulnerability-Oriented Testing: The most significant implication is the validation of the vulnerability-oriented strategy. The finding that 81% of SSRF vulnerabilities correlate with APIs requesting remote resources, and an average of 37% for other bug types, strongly suggests that security teams should move beyond generic fuzzing. Instead, they should prioritize testing efforts by first identifying API functions and then applying targeted tests for the vulnerabilities most likely associated with those functions. This makes testing more efficient and significantly increases the likelihood of finding critical flaws.
  1. Focus on Functional Analysis: Defenders should invest in tools and processes that can parse API specifications (like OpenAPI/Swagger) and automatically deduce the function of each endpoint. This functional understanding, combined with a knowledge base of function-vulnerability correlations (similar to V-API's semantic keyword collection), can guide security assessments. For example, any API endpoint that accepts URLs or handles file uploads should immediately be flagged for deep scrutiny regarding SSRF and file upload vulnerabilities, respectively.
  1. Adopt V-API or Similar Methodologies: The evaluation results for V-API are compelling:
  • Superior Vulnerability Discovery: V-API discovered a total of 70 vulnerabilities in seven real-world RESTful API applications. Crucially, 26 of these were previously unknown (day-0 vulnerabilities), and 7 were subsequently assigned CVE numbers. In stark contrast, other general-purpose API testing tools and vulnerability scanners identified only a few vulnerabilities, highlighting V-API's superior effectiveness for security-specific flaws. This performance gap indicates that V-API, or tools employing similar vulnerability-oriented strategies, are essential for comprehensive API security.
  • Efficiency Validation: The experiment comparing V-API with its "minus V" variant (where the vulnerability-oriented strategy was removed) further solidified its value. V-API minus V found no new vulnerabilities and was significantly slower. This unequivocally proves that the intelligent, targeted approach is not just effective but also highly efficient, saving valuable time and resources in the testing lifecycle.
  • Comparable Coverage: Despite its targeted approach, V-API's test sequence generator module achieved comparable code coverage to other API testing tools. This indicates that the focused testing doesn't compromise the breadth of the areas explored, ensuring that critical paths are still exercised.
  1. Leverage Published Resources: The speakers explicitly stated that their code is published. This provides an invaluable resource for security researchers and development teams to explore, adapt, and integrate V-API's methodologies into their own security pipelines. Open-sourcing such tools accelerates community-wide improvements in API security.

In essence, V-API provides a blueprint for a more intelligent, attacker-centric approach to API security testing. Defenders who embrace these principles—prioritizing functional analysis, adopting targeted testing methodologies, and leveraging advanced tools like V-API—will be significantly better equipped to identify and mitigate the growing threat landscape associated with RESTful APIs. The high number of discovered day-0 vulnerabilities underscores the urgent need for such sophisticated testing frameworks in modern software development.

Key Takeaways

  • API Function Correlates with Vulnerability Type: The core insight is that specific API functions (e.g., requesting remote resources, handling file uploads) are strongly associated with particular security vulnerabilities (e.g., SSRF, unrestricted file upload). This correlation enables more targeted and efficient testing.
  • V-API Outperforms Generic Tools: V-API, a novel inspection framework, significantly outperforms traditional API testing tools and vulnerability scanners in discovering specific security flaws, uncovering 70 vulnerabilities in real-world APIs, including 26 previously unknown (day-0) bugs with 7 CVEs assigned.
  • Targeted Strategy is Efficient and Effective: The vulnerability-oriented strategy employed by V-API is crucial for its success. Removing this strategy (V-API minus V) resulted in no new vulnerability discoveries and significantly slower testing, validating the approach's efficiency and efficacy.
  • Comprehensive Architecture for API Security: V-API utilizes a multi-stage architecture including an API Specification Parser, Function-Vulnerability Mapper, Test Sequence Generator, Test Case Generator, and Vulnerability Verifier to systematically identify, sequence, and exploit API weaknesses.
  • Actionable Insights for Defenders: Security teams should prioritize understanding API functions, leverage tools that map functions to potential vulnerabilities, and adopt targeted testing methodologies to improve the efficiency and effectiveness of their API security assessments.
  • Code Availability: The researchers have published their code, providing a valuable resource for the security community to implement and build upon this vulnerability-oriented testing approach.

About the Speaker(s)

The talk was presented by Jian Li. The research paper, "Vulnerability-oriented Testing for RESTful APIs," was a collaborative effort by Wenlong Du, Jian Li, Yanhao Wang, Libo Chen, Zhengguang Han, Yijun Wang, and Zhi Xue. Their affiliations and specific roles (e.g., student, professor, industry researcher) were not detailed in the provided transcript or metadata, but their collective work highlights a strong academic and research focus on advancing API security testing methodologies.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research presents a highly effective, novel framework for API vulnerability discovery by formalizing the attacker's intuition: linking API function to specific vulnerability types. V-API significantly outperforms generic testing tools, identifying 26 previously unknown vulnerabilities and securing 7 CVEs in real-world applications. This is a critical advancement for API security.

Heather Calloway (CISO) — STRONG ACCEPT

V-API presents a compelling, evidence-backed approach to API security testing, leveraging functional correlation to dramatically improve vulnerability discovery and efficiency. Its ability to find numerous previously unknown vulnerabilities provides a clear directive for security leaders to refine their testing strategies, reducing real-world business exposure.

→ Top-rated talks at 33rd USENIX Security Symposium

All talks from 33rd USENIX Security Symposium