Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

AuthStateBench: A Standards-Aligned Benchmark for Stateful Authorization and Authentication Workflows

View through CrossRef
Authentication and authorization weaknesses in modern web applications rarely arise as isolated request-level defects. They often depend on role changes, session lifecycle conditions, object ownership boundaries, API authorization rules, and business workflow ordering. Existing vulnerability benchmarks and scanner evaluations remain valuable, but they often represent weaknesses as code-level or input-output defects and therefore underrepresent semantic failures such as IDOR/BOLA, function-level authorization bypass, stale-session reuse, tenant-boundary violation, privilege transition errors, and workflow bypass. This article introduces AuthStateBench, a standards-aligned benchmark design for modeling stateful authorization and authentication workflow vulnerabilities in web applications and APIs. The study uses a structured literature-based and standards-mapping methodology that draws on access-control testing research, stateful web testing, web logic flaw analysis, scanner-evaluation studies, vulnerability benchmark literature, AI-assisted vulnerability-analysis work, and major security guidance including OWASP Top 10, OWASP API Security Top 10, OWASP ASVS, OWASP WSTG, NIST SSDF, MITRE CWE, CISA Secure by Design, OAuth 2.0 security guidance, OpenID Connect, and software-assurance benchmark resources. AuthStateBench contributes a four-dimensional state model built around role state, session state, object-ownership state, and workflow state; a scenario taxonomy; a benchmark scenario template; standards-mapping logic; formal scenario and coverage equations; and comparison criteria for manual, scanner-assisted, AI-assisted, and standards-based assessment. The article does not claim empirical detection accuracy, tool execution, live-system testing, or dataset results. Instead, it provides a reproducible design artifact and validation roadmap for future controlled implementation and comparative evaluation.
Title: AuthStateBench: A Standards-Aligned Benchmark for Stateful Authorization and Authentication Workflows
Description:
Authentication and authorization weaknesses in modern web applications rarely arise as isolated request-level defects.
They often depend on role changes, session lifecycle conditions, object ownership boundaries, API authorization rules, and business workflow ordering.
Existing vulnerability benchmarks and scanner evaluations remain valuable, but they often represent weaknesses as code-level or input-output defects and therefore underrepresent semantic failures such as IDOR/BOLA, function-level authorization bypass, stale-session reuse, tenant-boundary violation, privilege transition errors, and workflow bypass.
This article introduces AuthStateBench, a standards-aligned benchmark design for modeling stateful authorization and authentication workflow vulnerabilities in web applications and APIs.
The study uses a structured literature-based and standards-mapping methodology that draws on access-control testing research, stateful web testing, web logic flaw analysis, scanner-evaluation studies, vulnerability benchmark literature, AI-assisted vulnerability-analysis work, and major security guidance including OWASP Top 10, OWASP API Security Top 10, OWASP ASVS, OWASP WSTG, NIST SSDF, MITRE CWE, CISA Secure by Design, OAuth 2.
0 security guidance, OpenID Connect, and software-assurance benchmark resources.
AuthStateBench contributes a four-dimensional state model built around role state, session state, object-ownership state, and workflow state; a scenario taxonomy; a benchmark scenario template; standards-mapping logic; formal scenario and coverage equations; and comparison criteria for manual, scanner-assisted, AI-assisted, and standards-based assessment.
The article does not claim empirical detection accuracy, tool execution, live-system testing, or dataset results.
Instead, it provides a reproducible design artifact and validation roadmap for future controlled implementation and comparative evaluation.

Related Results

Machine Learning for Authentication and Authorization in IoT: Taxonomy, Challenges and Future Research Direction
Machine Learning for Authentication and Authorization in IoT: Taxonomy, Challenges and Future Research Direction
With the ongoing efforts for widespread Internet of Things (IoT) adoption, one of the key factors hindering the wide acceptance of IoT is security. Securing IoT networks such as th...
DEEP LEARNING-BASED ENHANCED CLOUD AUTHENTICATION USING COGNITIVE BIOMETRICS AND SECURE ENCRYPTION TECHNIQUES
DEEP LEARNING-BASED ENHANCED CLOUD AUTHENTICATION USING COGNITIVE BIOMETRICS AND SECURE ENCRYPTION TECHNIQUES
With the increasing reliance on digital systems, the want for tightly closed and green authentication mechanisms has emerge as paramount. conventional password-based totally authen...
An Efficient Blockchain-Based Verification Scheme with Transferable Authentication Authority
An Efficient Blockchain-Based Verification Scheme with Transferable Authentication Authority
Abstract In some situations, the transfer of authentication authority is necessary for user authentication. In traditional authentication, a trust mechanism based on a trus...
IMPLEMENTASI AUTHENTICATION & AUTHORIZATION BERBASIS JWT PADA SISTEM PENGELOLAAN PERKULIAHAN MENGGUNAKAN ALGORITMA HMAC
IMPLEMENTASI AUTHENTICATION & AUTHORIZATION BERBASIS JWT PADA SISTEM PENGELOLAAN PERKULIAHAN MENGGUNAKAN ALGORITMA HMAC
AbstrakKeamanan dan kerahasiaan data menjadi hal yang sangat penting karena data tersebut bisa digunakan oleh orang yang tidak bertanggung jawab untuk berbuat kejahatan. Hal terseb...
An Authentication and Key Agreement Scheme Based on Roadside Unit Cache for VANET
An Authentication and Key Agreement Scheme Based on Roadside Unit Cache for VANET
Vehicular Ad Hoc Network (VANET) is a wireless Mobile Ad Hoc Network that is used for communication between vehicles, vehicles and fixed access points, and vehicles and pedestrians...
Attribute-based multiuser authentication scheme between IoT devices for 5G environment
Attribute-based multiuser authentication scheme between IoT devices for 5G environment
Background/Objectives: Due to the development of mobile communication technology, infrastructure construction from 4G to 5G service, which is currently being serviced, is actively ...
EVALUATING USER AUTHENTICATION PROTOCOLS AND SECURITY ALGORITHMS FOR NETWORKS
EVALUATING USER AUTHENTICATION PROTOCOLS AND SECURITY ALGORITHMS FOR NETWORKS
This paper addresses the want for evaluating consumer authentication protocols and protection algorithms for networks. Specially, this paper specializes in the effectiveness and sa...
A KCP-DCNN-Based Two-Step Verification Multimodal Biometric Authentication System featuring QR Code Fabrication
A KCP-DCNN-Based Two-Step Verification Multimodal Biometric Authentication System featuring QR Code Fabrication
Abstract Starting with for, need change Enhanced authentication performance, the concept of multi-biometrics authentication systems has emerged as a promising solution in t...

Back to Top