{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T09:09:43Z","timestamp":1784365783802,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":17,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819234226","type":"print"},{"value":"9789819234233","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T00:00:00Z","timestamp":1784419200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T00:00:00Z","timestamp":1784419200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-981-92-3423-3_50","type":"book-chapter","created":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T08:49:03Z","timestamp":1784364543000},"page":"619-630","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["BACHunter: An Automated Fuzzing Framework for Discovering Broken Access Control Vulnerabilities in Java Web Applications"],"prefix":"10.1007","author":[{"given":"Yiwen","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaorui","family":"Gong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,19]]},"reference":[{"key":"50_CR1","unstructured":"OWASP Foundation: OWASP Top 10:2021 (2021). https:\/\/owasp.org\/Top10\/2021\/"},{"key":"50_CR2","doi-asserted-by":"crossref","unstructured":"Lu, J., Li, H., Liu, C., Li, L., Cheng, K.: Detecting missing-permission-check vulnerabilities in distributed cloud systems. In: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (CCS), pp. 2145\u20132158. ACM (2022)","DOI":"10.1145\/3548606.3560589"},{"key":"50_CR3","doi-asserted-by":"publisher","unstructured":"Liu, F., Shi, Y., Zhang, Y., Yang, G., Li, E., Yang, M.: MOCGuard: automatically detecting missing-owner-check vulnerabilities in java web applications. In: 2025 IEEE Symposium on Security and Privacy (SP), pp. 903\u2013919 (2025). https:\/\/doi.org\/10.1109\/SP61157.2025.00010","DOI":"10.1109\/SP61157.2025.00010"},{"key":"50_CR4","doi-asserted-by":"publisher","unstructured":"Liu, F., et al.: BACScan: automatic black-box detection of broken-access-control vulnerabilities in web applications. In: Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security, pp. 1320\u20131333. Association for Computing Machinery, New York, NY, USA (2025). https:\/\/doi.org\/10.1145\/3719027.3744825","DOI":"10.1145\/3719027.3744825"},{"key":"50_CR5","doi-asserted-by":"publisher","unstructured":"Balzarotti, D., Cova, M., Felmetsger, V.V., Vigna, G.: Multi-MODULE VULNERABILITY ANALYSIS OF WEB-BASED APPLICATIONS. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 25\u201335. Association for Computing Machinery, New York, NY, USA (2007). https:\/\/doi.org\/10.1145\/1315245.1315250","DOI":"10.1145\/1315245.1315250"},{"key":"50_CR6","doi-asserted-by":"publisher","unstructured":"Cova, M., Balzarotti, D., Felmetsger, V., Vigna, G.: Swaddler: an approach for the anomaly-based detection of state violations in web applications. In: Kr\u00fcgel, C., Lippmann, R., and Clark, A.J. (eds.) Recent Advances in Intrusion Detection, 10th International Symposium, RAID 2007, Gold Goast, Australia, 5\u20137 September 2007, Proceedings, pp. 63\u201386. Springer (2007). https:\/\/doi.org\/10.1007\/978-3-540-74320-0_4","DOI":"10.1007\/978-3-540-74320-0_4"},{"key":"50_CR7","unstructured":"Felmetsger, V., Cavedon, L., Kruegel, C., Vigna, G.: Toward automated detection of logic vulnerabilities in web applications. In: 19th USENIX Security Symposium, Washington, DC, USA, 11\u201313 August 2010, Proceedings, pp. 143\u2013160. USENIX Association (2010)"},{"key":"50_CR8","doi-asserted-by":"publisher","unstructured":"Son, S., McKinley, K.S., Shmatikov, V.: RoleCast: finding missing security checks when you do not know what checks are. In: Lopes, C.V. and Fisher, K. (eds.) Proceedings of the 26th Annual ACM SIGPLAN Conference on Object-Oriented Programming, Systems, Languages, and Applications, OOPSLA 2011, part of SPLASH 2011, Portland, OR, USA, 22\u201327 October 2011, pp. 1069\u20131084. ACM (2011). https:\/\/doi.org\/10.1145\/2048066.2048146","DOI":"10.1145\/2048066.2048146"},{"key":"50_CR9","unstructured":"Sun, F., Xu, L., Su, Z.: Static detection of access control vulnerabilities in web applications. In: 20th USENIX Security Symposium, San Francisco, CA, USA, 8\u201312 August 2011, Proceedings. USENIX Association (2011)"},{"key":"50_CR10","doi-asserted-by":"publisher","unstructured":"Hall\u00e9, S., Ettema, T., Bunch, C., Bultan, T.: Eliminating navigation errors in web applications via model checking and runtime enforcement of navigation state machines. In: Pecheur, C., Andrews, J., Nitto, E.D. (eds.) ASE 2010, 25th IEEE\/ACM International Conference on Automated Software Engineering, Antwerp, Belgium, 20\u201324 September 2010, pp. 235\u2013244. ACM (2010). https:\/\/doi.org\/10.1145\/1858996.1859044","DOI":"10.1145\/1858996.1859044"},{"key":"50_CR11","doi-asserted-by":"crossref","unstructured":"Li, X., Si, X., Xue, Y.: Automated black-box detection of access control vulnerabilities in web applications. In: Fourth ACM Conference on Data and Application Security and Privacy (CODASPY), pp. 49\u201360. ACM (2014)","DOI":"10.1145\/2557547.2557552"},{"key":"50_CR12","doi-asserted-by":"crossref","unstructured":"Kushnir, M., Favre, O., Rennhard, M., Esposito, D., Zahnd, V.: Automated black box detection of HTTP GET request-based access control vulnerabilities in web applications. In: International Conference on Information Systems Security and Privacy (2021)","DOI":"10.5220\/0010300102040216"},{"key":"50_CR13","unstructured":"Barabanov, A., Dergunov, D., Makrushin, D., Teplov, A.: Automatic detection of access control vulnerabilities via API specification processing. CoRR. abs\/2201.10833 (2022)"},{"key":"50_CR14","doi-asserted-by":"publisher","first-page":"376","DOI":"10.1007\/s42979-022-01271-1","volume":"3","author":"M Rennhard","year":"2022","unstructured":"Rennhard, M., Kushnir, M., Favre, O., Esposito, D., Zahnd, V.: Automating the detection of access control vulnerabilities in web applications. SN Comput. Sci. 3, 376 (2022). https:\/\/doi.org\/10.1007\/s42979-022-01271-1","journal-title":"SN Comput. Sci."},{"key":"50_CR15","unstructured":"Dharmaadi, I.P.A., Alhanahnah, M., Pham, V.-T., Mohsen, F., Turkmen, F.: BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications (2025)"},{"key":"50_CR16","doi-asserted-by":"crossref","unstructured":"Arcuri, A.: EvoMaster: evolutionary multi-context automated system test generation. In: 2018 IEEE 11th International Conference on Software Testing, Verification and Validation (ICST), pp. 394\u2013397 (2018)","DOI":"10.1109\/ICST.2018.00046"},{"key":"50_CR17","unstructured":"route-detect.https:\/\/github.com\/mschwager\/route-detect"}],"container-title":["Lecture Notes in Computer Science","Advanced Intelligent Computing Technology and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-3423-3_50","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T08:49:05Z","timestamp":1784364545000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-3423-3_50"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,19]]},"ISBN":["9789819234226","9789819234233"],"references-count":17,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-3423-3_50","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,19]]},"assertion":[{"value":"19 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICIC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Intelligent Computing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toronto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Canada","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icic2026a","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ic-icc.cn\/2026\/index.htm","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}