AI 中文总结
本文扩展EvoMaster新增9个预言机,通过构造HTTP调用序列场景,成功检测出9个人工API的所有注入故障及36个现实API的166个HTTP语义层面故障。
AI 中文摘要
背景:REST API在工业界被广泛使用,这些API采用HTTP进行通信,若未遵循HTTP规范,会导致API难以理解和使用,还可能引发严重的软件故障,造成恶劣后果。目标:定义新颖的自动化技术,以自动发现现有REST API中HTTP语义层面的故障。方法:我们对最先进的模糊测试工具EvoMaster进行扩展,新增9个预言机,用于检测HTTP语义层面的故障。当标准模糊测试过程生成N个测试用例后,会执行一个新的阶段,将这N个测试用例作为起点,创建新的场景(即新的HTTP调用序列),旨在验证这9个预言机中定义的特定HTTP属性。结果:对9个注入了故障的人工API进行实验,结果表明我们的新颖技术可成功检测出所有故障;对WFD语料库中的36个API开展进一步实验,结果显示我们的新颖技术可自动发现这些现实世界API中的166个现有故障。结论:REST API使用HTTP,因此需要遵循其语义,以避免误导客户端并引入细微的软件故障。本文提出的新颖技术被证实可有效自动发现此类故障。
英文摘要
Context: REST APIs are widely used in industry. These APIs use HTTP for their communications. Failures in following the specifications of HTTP can lead to confusing and hard to use APIs, with possibly serious software faults with dire consequences. Objectives: Define novel automated techniques to automatically find HTTP semantics-level faults in existing REST APIs. Methods: We extended the state-of-the-art fuzzer EvoMaster with 9 new oracles to detect HTTP semanticslevel faults. Once the standard fuzzing process is finished generating N test cases, a new phase is executed in which these N tests are used as a starting point to create new scenarios (i.e., new sequences of HTTP calls) aimed at validating specific HTTP properties defined in these 9 oracles. Results: Experiments on 9 artificial APIs with inject faults show that our novel techniques can successfully detect all of them. Further experiments on 36 APIs from the WFD corpus show that our novel techniques can automatically find 166 existing faults in these real-world APIs. Conclusion: REST APIs use HTTP, and, as such, they need to follow its semantics to avoid misleading their clients and introducing subtle software faults. The novel techniques presented in this paper are shown to be effective at automatically finding several of this type of faults.