Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Payload Analysis of Adversaries' Tooling: Automated Identification of Fuzzers

View through CrossRef
API fuzzing, a technique widely used to uncover vulnerabilities in web applications, poses significant security risks when exploited maliciously, leading to service disruptions and data breaches. While firewalls can block unauthorized fuzzing attempts, they limit defenders' ability to gather data on attacker methodologies, reducing actionable cyber threat intelligence. Identifying the responsible fuzzers enables defenders to trace the attacker, uncover their motives, and assess the potential impact, which helps security teams prepare more effectively, mitigate attacks, and develop targeted countermeasures to enhance the security of web APIs. However, analyzing the payloads generated by fuzzers remains largely unexplored and presents significant challenges. For instance, fuzzers often generate similar payloads due to shared initial seeds and similar fuzzing strategies, making accurate fuzzer identification more complex. To analyze this, we experimented with four well-known API fuzzers; APIFuzzer, Kiterunner, RESTler, and Schemathesis, and created a comprehensive dataset of their payloads targeting five different web APIs. Our thorough analysis reveals that the overlapping payloads, i.e., the identical generated payloads across these fuzzers, can be substantially large. For instance, ≈17% of payloads generated with Schemathesis overlapped with ≈12% of the payloads generated with RESTler across different web APIs. As a result, defining distinctive payload features that machine learning models can learn to differentiate and identify their fuzzer accurately becomes more difficult. Alternatively, deep learning techniques, known for their ability to automatically extract features, present a compelling alternative. To evaluate this, we experimented with an architecture combining a bidirectional Transformers-based encoder-decoder and a machine learning classifier to classify fuzzers based on their payloads. Rigorous evaluation using k-fold cross-validation demonstrated high precision and recall, averaging 89%, showcasing this combinatorial architecture's robustness and effectiveness. Our findings demonstrate the potential of combining deep learning and machine learning for fuzzer identification and enhancing web API security.
Institute of Electrical and Electronics Engineers (IEEE)
Title: Payload Analysis of Adversaries' Tooling: Automated Identification of Fuzzers
Description:
API fuzzing, a technique widely used to uncover vulnerabilities in web applications, poses significant security risks when exploited maliciously, leading to service disruptions and data breaches.
While firewalls can block unauthorized fuzzing attempts, they limit defenders' ability to gather data on attacker methodologies, reducing actionable cyber threat intelligence.
Identifying the responsible fuzzers enables defenders to trace the attacker, uncover their motives, and assess the potential impact, which helps security teams prepare more effectively, mitigate attacks, and develop targeted countermeasures to enhance the security of web APIs.
However, analyzing the payloads generated by fuzzers remains largely unexplored and presents significant challenges.
For instance, fuzzers often generate similar payloads due to shared initial seeds and similar fuzzing strategies, making accurate fuzzer identification more complex.
To analyze this, we experimented with four well-known API fuzzers; APIFuzzer, Kiterunner, RESTler, and Schemathesis, and created a comprehensive dataset of their payloads targeting five different web APIs.
Our thorough analysis reveals that the overlapping payloads, i.
e.
, the identical generated payloads across these fuzzers, can be substantially large.
For instance, ≈17% of payloads generated with Schemathesis overlapped with ≈12% of the payloads generated with RESTler across different web APIs.
As a result, defining distinctive payload features that machine learning models can learn to differentiate and identify their fuzzer accurately becomes more difficult.
Alternatively, deep learning techniques, known for their ability to automatically extract features, present a compelling alternative.
To evaluate this, we experimented with an architecture combining a bidirectional Transformers-based encoder-decoder and a machine learning classifier to classify fuzzers based on their payloads.
Rigorous evaluation using k-fold cross-validation demonstrated high precision and recall, averaging 89%, showcasing this combinatorial architecture's robustness and effectiveness.
Our findings demonstrate the potential of combining deep learning and machine learning for fuzzer identification and enhancing web API security.

Related Results

Abstract 1805: Dual-payload TME-activated ADC platform
Abstract 1805: Dual-payload TME-activated ADC platform
Abstract The combination of Antibody-Drug Conjugates (ADCs) and Immuno-Oncology (IO) agents is regarded as one of the most exciting and promising trends in the rapid...
Antibody-mediated co-delivery of programmable drug combinations
Antibody-mediated co-delivery of programmable drug combinations
Abstract Drug combinations often fail in clinic due to poor disease site tropism and additive toxicities1,2. Targeted delivery by antibody-drug conjugates (ADCs) reduces to...
Aircraft Tooling Collaborative Design Based on Multi-agent and PDM
Aircraft Tooling Collaborative Design Based on Multi-agent and PDM
In airplane research and development, tooling design is desired to be undertaken with airplane product design concurrently together with the considerations of downstream processes ...
Optimisation of tower crane rotation mechanism force acceleration mode at steady payload hoisting
Optimisation of tower crane rotation mechanism force acceleration mode at steady payload hoisting
The process of optimisation of the force acceleration mode of the rotation mechanism of the tower crane with the beam jib at steady payload hoisting was examined in the presented p...
Abstract 1691: Site-specific dual-payload antibody conjugation enhances antitumor efficacy
Abstract 1691: Site-specific dual-payload antibody conjugation enhances antitumor efficacy
Abstract We have developed a site-specific conjugation platform enabling controlled dual-payload delivery on antibodies. The antibody is enzymatically trimmed and...
Control of a Multimode Double-Pendulum Overhead Crane System Using Input Shaping Controllers
Control of a Multimode Double-Pendulum Overhead Crane System Using Input Shaping Controllers
This paper investigates the impact of higher derivative input shaping for minimizing both oscillations, namely hook and payload of a multimode double-pendulum overhead crane (MDPOC...
Monte Carlo Simulation of Supply and Demand for Payload Limited Routes
Monte Carlo Simulation of Supply and Demand for Payload Limited Routes
Large commercial aircraft by design are typically not capable of transporting maximum fuel capacity and maximum payload simultaneously. Beyond the maximum payload range, fuel requi...
Threat Modeling for Cyber Warfare Against Less Cyber-Dependent Adversaries
Threat Modeling for Cyber Warfare Against Less Cyber-Dependent Adversaries
Cyber warfare poses a substantial threat in today's interconnected world, where digital attacks can transcend physical boundaries and affect targets globally. Technologically, less...

Back to Top