Enhancing API Security Testing against BOLA and Authentication Vulnerabilities through an LLM-Enhanced Framework
Enhancing API Security Testing against BOLA and Authentication Vulnerabilities through an LLM-Enhanced Framework
Emil Marian Pasca, Rudolf Erdei, Daniela Delinschi, Oliviu Matei
Abstract. Broken Object Level Authorization (BOLA) and authentication-related issues are consistently among the most critical vulnerabilities in modern APIs. This paper introduces an LLM-enhanced framework specifically designed to improve security testing against BOLA and authentication vulnerabilities. The framework augments traditional API testing pipelines with Large Language Models that generate context-aware test cases, identify suspicious authorization patterns and propose targeted attack scenarios based on the API specification and observed traffic. Experimental evaluations on representative APIs show that the proposed framework substantially increases the detection rate of BOLA and authentication flaws compared to baseline approaches, while keeping false positive rates manageable.
Keywords: API security; BOLA; authentication; large language models; vulnerability assessment
📋 Cite this publication
Emil Marian Pasca, Rudolf Erdei, Daniela Delinschi, Oliviu Matei, "Enhancing API Security Testing against BOLA and Authentication Vulnerabilities through an LLM-Enhanced Framework", Proc. 19th SOCO Int. Conf. on Soft Computing Models in Industrial and Environmental Applications, Springer, 2024, 2023.
Reference: Proc. 19th SOCO Int. Conf. on Soft Computing Models in Industrial and Environmental Applications, Springer, 2024.
An Enhanced Hybrid Machine Learning Model for Plant Disease Detection and Classification
An Enhanced Hybrid Machine Learning Model for Plant Disease Detection and ClassificationMara...
A GIS-Driven, Machine Learning-Enhanced Framework for Adaptive Land Bonitation
A GIS-Driven, Machine Learning-Enhanced Framework for Adaptive Land BonitationBogdan Văduva, Anca...
Competition between Dandelion and Prüfer encoded genetic algorithms for solving the clustered minimum routing tree problem
Competition between Dandelion and Prüfer encoded genetic algorithms for solving the clustered...
Guide in Designing an Asynchronous Performance-Centric Framework for Heterogeneous Microservices in Time-Critical Cybersecurity Applications. The BIECO Use Case
The generalized traveling salesman problem (GTSP) is an extension of the classical traveling salesman
problem (TSP), and it is among the most researched combinatorial optimization problems due to its theoretical properties, complexity aspects, and real-life applications in various areas: location-routing problems, material flow design problem, distribution of medical supplies, urban waste collection management, airport selection and routing the courier airplanes, image retrieval and ranking, digital garment manufacturing, etc.
Trend-Enabled Recommender System with Diversity Enhancer for Crop Recommendation
The generalized traveling salesman problem (GTSP) is an extension of the classical traveling salesman
problem (TSP), and it is among the most researched combinatorial optimization problems due to its theoretical properties, complexity aspects, and real-life applications in various areas: location-routing problems, material flow design problem, distribution of medical supplies, urban waste collection management, airport selection and routing the courier airplanes, image retrieval and ranking, digital garment manufacturing, etc.
Privacy-Conducive Data Ecosystem Architecture: By-Design Vulnerability Assessment Using Privacy Risk Expansion Factor and Privacy Exposure Index
Privacy-Conducive Data Ecosystem Architecture: By-Design Vulnerability Assessment Using Privacy...
A Vulnerable-by-Design IoT Sensor Framework for Cybersecurity in Smart Agriculture
A Vulnerable-by-Design IoT Sensor Framework for Cybersecurity in Smart AgricultureEmil Marian...
Sustainability of the Integrated Waste Management System: A Case Study of Bihor County, Romania
Sustainability of the Integrated Waste Management System: A Case Study of Bihor County,...
A Privacy Assessment Framework For Data Tiers In Multilayered Ecosystem Architectures
A Privacy Assessment Framework For Data Tiers In Multilayered Ecosystem ArchitecturesIonela...
LLM-Driven, Self-Improving Framework for Security Test Automation: Leveraging Karate DSL for Augmented API Resilience
LLM-Driven, Self-Improving Framework for Security Test Automation: Leveraging Karate DSL for...
Optimizing fertilization and crop management for triticale in the Lăpuș depression, Romania
Optimizing fertilization and crop management for triticale in the Lăpuș depression, RomaniaI....
Using Automation and Artificial Intelligence in the Management of European Social Fund Projects
Using Automation and Artificial Intelligence in the Management of European Social Fund...













0 Comments