Enhancing API Security Testing against BOLA and Authentication Vulnerabilities through an LLM-Enhanced Framework
Enhancing API Security Testing against BOLA and Authentication Vulnerabilities through an LLM-Enhanced Framework
Emil Marian Pasca, Rudolf Erdei, Daniela Delinschi, Oliviu Matei
Abstract. Broken Object Level Authorization (BOLA) and authentication-related issues are consistently among the most critical vulnerabilities in modern APIs. This paper introduces an LLM-enhanced framework specifically designed to improve security testing against BOLA and authentication vulnerabilities. The framework augments traditional API testing pipelines with Large Language Models that generate context-aware test cases, identify suspicious authorization patterns and propose targeted attack scenarios based on the API specification and observed traffic. Experimental evaluations on representative APIs show that the proposed framework substantially increases the detection rate of BOLA and authentication flaws compared to baseline approaches, while keeping false positive rates manageable.
Keywords: API security; BOLA; authentication; large language models; vulnerability assessment
📋 Cite this publication
Emil Marian Pasca, Rudolf Erdei, Daniela Delinschi, Oliviu Matei, "Enhancing API Security Testing against BOLA and Authentication Vulnerabilities through an LLM-Enhanced Framework", Proc. 19th SOCO Int. Conf. on Soft Computing Models in Industrial and Environmental Applications, Springer, 2024, 2023.
Reference: Proc. 19th SOCO Int. Conf. on Soft Computing Models in Industrial and Environmental Applications, Springer, 2024.
Benefits and limitations of digitalization in managing European Social funded projects
Benefits and limitations of digitalization in managing European Social funded projectsMatei...
Aggregation Strategy for Federated Machine Learning Algorithm
Aggregation Strategy for Federated Machine Learning AlgorithmRudolf Erdei, Daniela Delinschi,...
Using Markov chains for determining the proximity contagion of smart specialization of localities
Using Markov chains for determining the proximity contagion of smart specialization of...
Advancements in Machine Learning Algorithms for Precision Crop Yield Prediction: A Comprehensive Review with focus on European Union
Advancements in Machine Learning Algorithms for Precision Crop Yield Prediction: A Comprehensive...
TPC Net: An Efficient CNN Architecture for Tomato Plant Disease and Pest Classification
TPC Net: An Efficient CNN Architecture for Tomato Plant Disease and Pest ClassificationOvidiu...
A new vision of social behavior on genetic algorithm performance
A new vision of social behavior on genetic algorithm performanceAndreea Tatar, Nicolae Fat, Adrian...
A comparative study of different genetic algorithms approaches to capacitated vehicle routing problem for collection of agricultural products
A comparative study of different genetic algorithms approaches to capacitated vehicle routing...
Using Machine Learning for Identifying the Intrinsic Economic Specializations of Localities
Using Machine Learning for Identifying the Intrinsic Economic Specializations of LocalitiesOliviu...
Embedding GIS in crop field bonitation computation
Embedding GIS in crop field bonitation computationBogdan Văduva, Oliviu Matei, Anca Avram, Laura...
A comparative study of machine learning models for plant disease identification
A comparative study of machine learning models for plant disease identificationMăcelaru Mara,...
A Novel CNN Approach for Accurate Tomato Disease Classification
A Novel CNN Approach for Accurate Tomato Disease ClassificationOvidiu Cosma, Laura Cosma Abstract....
Design of a collaborative network for mapping digital skills for Industry 5.0
Design of a collaborative network for mapping digital skills for Industry 5.0Maria Gustavsson,...













0 Comments