arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.12770cs.SE

通过静态和动态分析检测REST API中的HTTP状态码误用

Detecting HTTP Status Code Misuses in REST APIs via Static and Dynamic Analysis

Alix Decrop, Andrea Arcuri, Mike Papadakis, Pierre-Yves Schobbens, Gilles Perrouin

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出结合静态与动态分析的方法,基于30条规则检测REST API中HTTP状态码误用,经2,625个真实规范验证,发现误用频繁且两种方法互补有效。

中文摘要 AI 辅助

REST API广泛应用于Web上的客户端-服务器通信。由于REST基于HTTP,服务器响应包含状态码以指示请求的结果(例如,200 OK表示成功,404 Not Found表示资源不可用)。虽然HTTP状态码是标准化的,但其语义在REST中并未强制执行,导致实践中出现许多误用(例如,使用500 Internal Server Error来描述客户端错误)。此类误用可能产生不良后果,如降低互操作性、误导API客户端或导致测试工具产生误报。在本文中,我们提出了一种结合静态和动态分析的方法来检测REST API中的HTTP状态码误用。我们首先研究了2,625个真实的REST API规范,以识别相关的状态码,并基于HTTP标准和REST API原则推导出一组30条使用规则。然后,我们实现了工具来识别OpenAPI规范(静态分析)和API行为(动态分析)中的此类规则违规。我们的评估发现,状态码误用在REST API中频繁且系统性地存在,静态和动态方法均能检测到各种误用。我们强调这两种方法可以互补使用,并为REST API测试人员和用户提供见解。

英文摘要

REST APIs are widely used on the web for client-server communications. As REST is based on HTTP, server responses contain status codes to indicate the outcome of requests (e.g., 200 OK for a success and 404 Not Found for an unavailable resource). While HTTP status codes are standardized, their semantics are not enforced in REST, leading to many misuses in practice (e.g., using 500 Internal Server Error to describe a client error). Such misuses may have nefarious consequences, such as reducing interoperability, misleading API clients, or causing false positives in testing tools. In this paper, we present a combined static and dynamic analysis approach for detecting HTTP status code misuses in REST APIs. We first study 2,625 real-world REST API specifications to identify relevant status codes and derive a set of 30 usage rules based on HTTP standards and REST API principles. We then implement tools to identify such rule violations in OpenAPI specifications (static analysis) and in API behavior (dynamic analysis). Our evaluation finds that status code misuses are frequent and systematic in REST APIs, with both static and dynamic approaches detecting various misuses. We highlight that both approaches may be used in a complementary manner, and also provide insight for REST API testers and users alike.

发表机构

  • University of Namur(南纳慕尔大学)
  • Kristiania University of Applied Sciences(克里斯蒂安应用科学大学)
  • Oslo Metropolitan University(奥斯陆大都会大学)
  • SnT, University of Luxembourg(卢森堡大学科学与技术中心)

机构由 AI 辅助整理,请以论文原文为准。

↑