Augmenting API Security Testing with Automated LLM-Driven Test Generation
Augmenting API Security Testing with Automated LLM-Driven Test Generation
Emil Marian Pasca, Rudolf Erdei, Daniela Delinschi, Oliviu Matei
Abstract. API security testing is an essential step in modern software development, but manually crafting comprehensive test suites for security vulnerabilities is time-consuming and prone to human bias. This paper proposes a framework that augments API security testing with Large Language Model (LLM) driven automated test generation. The approach leverages LLMs to interpret OpenAPI specifications and produce contextually relevant security test cases that target common vulnerability classes (injection, broken object level authorization, mass assignment, etc.). The generated tests are integrated with established API testing pipelines to provide continuous and reproducible security validation. Initial experimental results indicate that the LLM-driven generation expands the coverage of security tests beyond what is typically achievable with rule-based or human-written test suites.
Keywords: API security; large language models; automated test generation; OWASP API Top 10; software testing
📋 Cite this publication
Emil Marian Pasca, Rudolf Erdei, Daniela Delinschi, Oliviu Matei, "Augmenting API Security Testing with Automated LLM-Driven Test Generation", Proc. 17th Int. Conf. on Computational Intelligence in Security for Information Systems (CISIS 2024), 2024, 2023.
Reference: Proc. 17th Int. Conf. on Computational Intelligence in Security for Information Systems (CISIS 2024), 2024.
An Enhanced Hybrid Machine Learning Model for Plant Disease Detection and Classification
An Enhanced Hybrid Machine Learning Model for Plant Disease Detection and ClassificationMara...
A GIS-Driven, Machine Learning-Enhanced Framework for Adaptive Land Bonitation
A GIS-Driven, Machine Learning-Enhanced Framework for Adaptive Land BonitationBogdan Văduva, Anca...
Competition between Dandelion and Prüfer encoded genetic algorithms for solving the clustered minimum routing tree problem
Competition between Dandelion and Prüfer encoded genetic algorithms for solving the clustered...
Guide in Designing an Asynchronous Performance-Centric Framework for Heterogeneous Microservices in Time-Critical Cybersecurity Applications. The BIECO Use Case
The generalized traveling salesman problem (GTSP) is an extension of the classical traveling salesman
problem (TSP), and it is among the most researched combinatorial optimization problems due to its theoretical properties, complexity aspects, and real-life applications in various areas: location-routing problems, material flow design problem, distribution of medical supplies, urban waste collection management, airport selection and routing the courier airplanes, image retrieval and ranking, digital garment manufacturing, etc.
Trend-Enabled Recommender System with Diversity Enhancer for Crop Recommendation
The generalized traveling salesman problem (GTSP) is an extension of the classical traveling salesman
problem (TSP), and it is among the most researched combinatorial optimization problems due to its theoretical properties, complexity aspects, and real-life applications in various areas: location-routing problems, material flow design problem, distribution of medical supplies, urban waste collection management, airport selection and routing the courier airplanes, image retrieval and ranking, digital garment manufacturing, etc.
Privacy-Conducive Data Ecosystem Architecture: By-Design Vulnerability Assessment Using Privacy Risk Expansion Factor and Privacy Exposure Index
Privacy-Conducive Data Ecosystem Architecture: By-Design Vulnerability Assessment Using Privacy...
A Vulnerable-by-Design IoT Sensor Framework for Cybersecurity in Smart Agriculture
A Vulnerable-by-Design IoT Sensor Framework for Cybersecurity in Smart AgricultureEmil Marian...
A Privacy Assessment Framework For Data Tiers In Multilayered Ecosystem Architectures
A Privacy Assessment Framework For Data Tiers In Multilayered Ecosystem ArchitecturesIonela...
LLM-Driven, Self-Improving Framework for Security Test Automation: Leveraging Karate DSL for Augmented API Resilience
LLM-Driven, Self-Improving Framework for Security Test Automation: Leveraging Karate DSL for...
Sustainability of the Integrated Waste Management System: A Case Study of Bihor County, Romania
Sustainability of the Integrated Waste Management System: A Case Study of Bihor County,...
Optimizing fertilization and crop management for triticale in the Lăpuș depression, Romania
Optimizing fertilization and crop management for triticale in the Lăpuș depression, RomaniaI....
Using Automation and Artificial Intelligence in the Management of European Social Fund Projects
Using Automation and Artificial Intelligence in the Management of European Social Fund...













0 Comments