{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T21:52:09Z","timestamp":1777499529373,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":38,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,11,8]],"date-time":"2020-11-08T00:00:00Z","timestamp":1604793600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,11,8]]},"DOI":"10.1145\/3368089.3409719","type":"proceedings-article","created":{"date-parts":[[2020,11,10]],"date-time":"2020-11-10T21:08:44Z","timestamp":1605042524000},"page":"725-736","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":50,"title":["Intelligent REST API data fuzzing"],"prefix":"10.1145","author":[{"given":"Patrice","family":"Godefroid","sequence":"first","affiliation":[{"name":"Microsoft Research, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7069-4069","authenticated-orcid":false,"given":"Bo-Yuan","family":"Huang","sequence":"additional","affiliation":[{"name":"Princeton University, USA"}]},{"given":"Marina","family":"Polishchuk","sequence":"additional","affiliation":[{"name":"Microsoft Research, USA"}]}],"member":"320","published-online":{"date-parts":[[2020,11,8]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"crossref","unstructured":"[n. d.]. Apigee Docs. https:\/\/docs.apigee.com\/ Last accessed 2019-11-22.  [n. d.]. Apigee Docs. https:\/\/docs.apigee.com\/ Last accessed 2019-11-22.","DOI":"10.1080\/2040350X.2019.1677066"},{"key":"e_1_3_2_2_2_1","unstructured":"[n. d.]. Postman | API Development Environment. https:\/\/www.getpostman.com\/ Last accessed 2019-11-22.  [n. d.]. Postman | API Development Environment. https:\/\/www.getpostman.com\/ Last accessed 2019-11-22."},{"key":"e_1_3_2_2_3_1","unstructured":"[n. d.]. SoapUI. https:\/\/www.soapui.org\/ Last accessed 2019-11-22.  [n. d.]. SoapUI. https:\/\/www.soapui.org\/ Last accessed 2019-11-22."},{"key":"e_1_3_2_2_4_1","unstructured":"[n. d.]. vREST-Automated REST API Testing Tool. https:\/\/vrest.io\/ Last accessed 2019-11-22.  [n. d.]. vREST-Automated REST API Testing Tool. https:\/\/vrest.io\/ Last accessed 2019-11-22."},{"key":"e_1_3_2_2_5_1","unstructured":"2019. APIFortress. http:\/\/apifortress.com Last accessed 2019-11-22.  2019. APIFortress. http:\/\/apifortress.com Last accessed 2019-11-22."},{"key":"e_1_3_2_2_6_1","unstructured":"2019. HttpMaster. http:\/\/www.httpmaster. net Last accessed 2019-11-22.  2019. HttpMaster. http:\/\/www.httpmaster. net Last accessed 2019-11-22."},{"key":"e_1_3_2_2_7_1","unstructured":"2019. Mass Assignment Cheat Sheet. https:\/\/github.com\/OWASP\/ CheatSheetSeries\/blob\/master\/cheatsheets\/Mass_Assignment_Cheat_Sheet. md Last accessed 2019-11-22.  2019. Mass Assignment Cheat Sheet. https:\/\/github.com\/OWASP\/ CheatSheetSeries\/blob\/master\/cheatsheets\/Mass_Assignment_Cheat_Sheet. md Last accessed 2019-11-22."},{"key":"e_1_3_2_2_8_1","unstructured":"2019. Microsoft Azure DNS Service Documentation. https:\/\/docs.microsoft.com\/ en-us\/azure\/dns\/ Last accessed 2019-11-22.  2019. Microsoft Azure DNS Service Documentation. https:\/\/docs.microsoft.com\/ en-us\/azure\/dns\/ Last accessed 2019-11-22."},{"key":"e_1_3_2_2_9_1","unstructured":"2019. OWASP API Security. https:\/\/www.owasp.org\/index.php\/OWASP_API_Security_Project Last accessed 2019-11-22.  2019. OWASP API Security. https:\/\/www.owasp.org\/index.php\/OWASP_API_Security_Project Last accessed 2019-11-22."},{"key":"e_1_3_2_2_10_1","unstructured":"S. Allamaraju. 2010. RESTful Web Services Cookbook. O'Reilly.  S. Allamaraju. 2010. RESTful Web Services Cookbook. O'Reilly."},{"key":"e_1_3_2_2_11_1","unstructured":"Amazon. 2019. Amazon Web Services (AWS)-Cloud Computing Services. https: \/\/aws.amazon.com\/ Last accessed 2019-11-22.  Amazon. 2019. Amazon Web Services (AWS)-Cloud Computing Services. https: \/\/aws.amazon.com\/ Last accessed 2019-11-22."},{"key":"e_1_3_2_2_12_1","unstructured":"APIFuzzer [n. d.]. APIFuzzer. https:\/\/github.com\/KissPeter\/APIFuzzer.  APIFuzzer [n. d.]. APIFuzzer. https:\/\/github.com\/KissPeter\/APIFuzzer."},{"key":"e_1_3_2_2_13_1","unstructured":"AppSpider [n. d.]. AppSpider. https:\/\/www.rapid7.com\/products\/appspider.  AppSpider [n. d.]. AppSpider. https:\/\/www.rapid7.com\/products\/appspider."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3293455"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00083"},{"key":"e_1_3_2_2_16_1","unstructured":"Boofuzz [n. d.]. BooFuzz. https:\/\/github.com\/jtpereyda\/boofuzz.  Boofuzz [n. d.]. BooFuzz. https:\/\/github.com\/jtpereyda\/boofuzz."},{"key":"e_1_3_2_2_17_1","unstructured":"Burp [n. d.]. Burp Suite. https:\/\/portswigger.net\/burp.  Burp [n. d.]. Burp Suite. https:\/\/portswigger.net\/burp."},{"key":"e_1_3_2_2_18_1","volume-title":"Architectural styles and the design of network-based software architectures","author":"Fielding Roy T."},{"key":"e_1_3_2_2_19_1","volume-title":"Proceedings of the 4th USENIX Windows System Symposium","author":"Forrester J. E."},{"key":"e_1_3_2_2_20_1","unstructured":"fuzz-lightyear [n. d.]. Fuzz-Lightyear. https:\/\/github.com\/Yelp\/fuzz-lightyear.  fuzz-lightyear [n. d.]. Fuzz-Lightyear. https:\/\/github.com\/Yelp\/fuzz-lightyear."},{"key":"e_1_3_2_2_21_1","unstructured":"Fuzzy-Swagger [n. d.]. Fuzzy-Swagger. https:\/\/github.com\/namuan\/fuzzyswagger.  Fuzzy-Swagger [n. d.]. Fuzzy-Swagger. https:\/\/github.com\/namuan\/fuzzyswagger."},{"key":"e_1_3_2_2_22_1","unstructured":"T. Gallagher B. Jefries and L. Landauer. 2006. Hunting Security Bugs. Microsoft Press.  T. Gallagher B. Jefries and L. Landauer. 2006. Hunting Security Bugs. Microsoft Press."},{"key":"e_1_3_2_2_23_1","first-page":"151","volume-title":"Proceedings of NDSS' 2008 (Network and Distributed Systems Security)","author":"Godefroid P."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3317550.3321438"},{"key":"e_1_3_2_2_25_1","unstructured":"Microsoft. 2019. Azure REST API Specifications. https:\/\/github.com\/Azure\/azurerest-api-specs Last accessed 2019-11-22.  Microsoft. 2019. Azure REST API Specifications. https:\/\/github.com\/Azure\/azurerest-api-specs Last accessed 2019-11-22."},{"key":"e_1_3_2_2_26_1","unstructured":"Microsoft. 2019. Microsoft Azure Cloud Computing Platform & Services. https: \/\/azure.microsoft.com\/en-us\/ Last accessed 2019-11-22.  Microsoft. 2019. Microsoft Azure Cloud Computing Platform & Services. https: \/\/azure.microsoft.com\/en-us\/ Last accessed 2019-11-22."},{"key":"e_1_3_2_2_27_1","unstructured":"S. Newman. 2015. Building Microservices. O'Reilly.  S. Newman. 2015. Building Microservices. O'Reilly."},{"key":"e_1_3_2_2_28_1","unstructured":"Peach 2019. Peach Fuzzer. http:\/\/www.peachfuzzer.com\/. Last accessed 2019-11-22.  Peach 2019. Peach Fuzzer. http:\/\/www.peachfuzzer.com\/. Last accessed 2019-11-22."},{"key":"e_1_3_2_2_29_1","unstructured":"QualysWAS [n. d.]. Qualys Web Application Scanning (WAS). https:\/\/www. qualys.com\/apps\/web-app-scanning\/.  QualysWAS [n. d.]. Qualys Web Application Scanning (WAS). https:\/\/www. qualys.com\/apps\/web-app-scanning\/."},{"key":"e_1_3_2_2_30_1","unstructured":"REST-assured 2019. REST Assured. http:\/\/rest-assured.io\/. Last accessed 2019-11-22.  REST-assured 2019. REST Assured. http:\/\/rest-assured.io\/. Last accessed 2019-11-22."},{"key":"e_1_3_2_2_31_1","article-title":"Metamorphic Testing of RESTful Web APIs","volume":"44","author":"Segura Sergio","year":"2018","journal-title":"ACM Transactions on Software Engineering"},{"key":"e_1_3_2_2_32_1","unstructured":"SPIKE 2019. SPIKE Fuzzer. http:\/\/resources.infosecinstitute. com\/fuzzerautomation-with-spike\/. Last accessed 2019-11-22.  SPIKE 2019. SPIKE Fuzzer. http:\/\/resources.infosecinstitute. com\/fuzzerautomation-with-spike\/. Last accessed 2019-11-22."},{"key":"e_1_3_2_2_33_1","unstructured":"Sulley [n. d.]. Sulley. https:\/\/github.com\/OpenRCE\/sulley.  Sulley [n. d.]. Sulley. https:\/\/github.com\/OpenRCE\/sulley."},{"key":"e_1_3_2_2_34_1","volume-title":"Fuzzing: Brute Force Vulnerability Discovery","author":"Sutton M.","year":"2007"},{"key":"e_1_3_2_2_35_1","unstructured":"Swagger [n. d.]. Swagger. https:\/\/swagger.io\/.  Swagger [n. d.]. Swagger. https:\/\/swagger.io\/."},{"key":"e_1_3_2_2_36_1","unstructured":"Swagger-Fuzzer [n. d.]. Swagger-Fuzzer. https:\/\/github.com\/Lothiraldan\/ swagger-fuzzer.  Swagger-Fuzzer [n. d.]. Swagger-Fuzzer. https:\/\/github.com\/Lothiraldan\/ swagger-fuzzer."},{"key":"e_1_3_2_2_37_1","unstructured":"TnT-Fuzzer [n. d.]. TnT-Fuzzer. https:\/\/github.com\/Teebytes\/TnT-Fuzzer.  TnT-Fuzzer [n. d.]. TnT-Fuzzer. https:\/\/github.com\/Teebytes\/TnT-Fuzzer."},{"key":"e_1_3_2_2_38_1","unstructured":"M. Zalewski. 2015. AFL (American Fuzzy Lop). http:\/\/lcamtuf.coredump.cx\/afl\/.  M. Zalewski. 2015. AFL (American Fuzzy Lop). http:\/\/lcamtuf.coredump.cx\/afl\/."}],"event":{"name":"ESEC\/FSE '20: 28th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering","location":"Virtual Event USA","acronym":"ESEC\/FSE '20","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3368089.3409719","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3368089.3409719","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:40Z","timestamp":1750203880000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3368089.3409719"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,11,8]]},"references-count":38,"alternative-id":["10.1145\/3368089.3409719","10.1145\/3368089"],"URL":"https:\/\/doi.org\/10.1145\/3368089.3409719","relation":{},"subject":[],"published":{"date-parts":[[2020,11,8]]},"assertion":[{"value":"2020-11-08","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}