{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:14:31Z","timestamp":1750220071456,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,12,5]],"date-time":"2022-12-05T00:00:00Z","timestamp":1670198400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001381","name":"National Research Foundation Singapore","doi-asserted-by":"publisher","award":["Campus for Research Excellence and Technological Enterprise,Future Communications Research & Development programmes"],"award-info":[{"award-number":["Campus for Research Excellence and Technological Enterprise,Future Communications Research & Development programmes"]}],"id":[{"id":"10.13039\/501100001381","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Infocomm Media Development Authority","award":["Future Communications Research & Development Programme"],"award-info":[{"award-number":["Future Communications Research & Development Programme"]}]},{"DOI":"10.13039\/501100007040","name":"Singapore University of Technology and Design","doi-asserted-by":"publisher","award":["SRG ISTD 2020 157"],"award-info":[{"award-number":["SRG ISTD 2020 157"]}],"id":[{"id":"10.13039\/501100007040","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,12,5]]},"DOI":"10.1145\/3564625.3564654","type":"proceedings-article","created":{"date-parts":[[2022,12,3]],"date-time":"2022-12-03T01:01:29Z","timestamp":1670029289000},"page":"400-411","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["From Hindsight to Foresight: Enhancing Design Artifacts for Business Logic Flaw Discovery"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8510-7274","authenticated-orcid":false,"given":"Carmen","family":"Cheh","sequence":"first","affiliation":[{"name":"Advanced Digital Sciences Center, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5063-3151","authenticated-orcid":false,"given":"Nicholas","family":"Tay","sequence":"additional","affiliation":[{"name":"Singapore University of Technology and Design, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9584-0082","authenticated-orcid":false,"given":"Binbin","family":"Chen","sequence":"additional","affiliation":[{"name":"Singapore University of Technology and Design, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,12,5]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2008. Sonarqube. https:\/\/www.sonarqube.org\/  2008. Sonarqube. https:\/\/www.sonarqube.org\/"},{"key":"e_1_3_2_1_2_1","unstructured":"2010. Owncloud. https:\/\/owncloud.com  2010. Owncloud. https:\/\/owncloud.com"},{"key":"e_1_3_2_1_3_1","unstructured":"2012. GAUNTLT: Go Ahead Be Mean To Your Code. http:\/\/gauntlt.org  2012. GAUNTLT: Go Ahead Be Mean To Your Code. http:\/\/gauntlt.org"},{"key":"e_1_3_2_1_4_1","unstructured":"2012. Nmap - The Network Mapper. https:\/\/nmap.org  2012. Nmap - The Network Mapper. https:\/\/nmap.org"},{"key":"e_1_3_2_1_5_1","unstructured":"2013. BDD Security By IriusRisk. https:\/\/github.com\/iriusrisk\/bdd-security  2013. BDD Security By IriusRisk. https:\/\/github.com\/iriusrisk\/bdd-security"},{"key":"e_1_3_2_1_6_1","unstructured":"2016. Behat. https:\/\/docs.behat.org\/en\/latest\/  2016. Behat. https:\/\/docs.behat.org\/en\/latest\/"},{"key":"e_1_3_2_1_7_1","unstructured":"2018. Lack of Payment Type Validation in Uber. https:\/\/hackerone.com\/reports\/162199  2018. Lack of Payment Type Validation in Uber. https:\/\/hackerone.com\/reports\/162199"},{"key":"e_1_3_2_1_8_1","unstructured":"2019. Enable 2FA without Email Verification in Moneybird. https:\/\/hackerone.com\/reports\/649533  2019. Enable 2FA without Email Verification in Moneybird. https:\/\/hackerone.com\/reports\/649533"},{"key":"e_1_3_2_1_9_1","unstructured":"2019. Manipulate Order Amount in Zomato. https:\/\/hackerone.com\/reports\/614523  2019. Manipulate Order Amount in Zomato. https:\/\/hackerone.com\/reports\/614523"},{"key":"e_1_3_2_1_10_1","unstructured":"2019. Total Price Manipulation in Upserve. https:\/\/hackerone.com\/reports\/364843  2019. Total Price Manipulation in Upserve. https:\/\/hackerone.com\/reports\/364843"},{"key":"e_1_3_2_1_11_1","unstructured":"2020. Bypass Subscription in Imgur. https:\/\/hackerone.com\/reports\/1029027  2020. Bypass Subscription in Imgur. https:\/\/hackerone.com\/reports\/1029027"},{"key":"e_1_3_2_1_12_1","unstructured":"2021. Account Takeover via Email Change in New Relic. https:\/\/hackerone.com\/reports\/1089467  2021. Account Takeover via Email Change in New Relic. https:\/\/hackerone.com\/reports\/1089467"},{"key":"e_1_3_2_1_13_1","unstructured":"2021. Cucumber Syntax. https:\/\/cucumber.io\/docs\/cucumber\/  2021. Cucumber Syntax. https:\/\/cucumber.io\/docs\/cucumber\/"},{"key":"e_1_3_2_1_14_1","unstructured":"2021. Gherkin parser for Python. https:\/\/github.com\/cucumber\/gherkin-python  2021. Gherkin parser for Python. https:\/\/github.com\/cucumber\/gherkin-python"},{"key":"e_1_3_2_1_15_1","unstructured":"2021. Gherkin Syntax. https:\/\/cucumber.io\/docs\/gherkin\/  2021. Gherkin Syntax. https:\/\/cucumber.io\/docs\/gherkin\/"},{"key":"e_1_3_2_1_16_1","unstructured":"2021. GitHub - Sylius. https:\/\/github.com\/Sylius\/Sylius  2021. GitHub - Sylius. https:\/\/github.com\/Sylius\/Sylius"},{"key":"e_1_3_2_1_17_1","unstructured":"2021. Netsparker. https:\/\/www.netsparker.com\/  2021. Netsparker. https:\/\/www.netsparker.com\/"},{"key":"e_1_3_2_1_18_1","unstructured":"2021. Sylius - Open Source Headless eCommerce Platform. https:\/\/sylius.com  2021. Sylius - Open Source Headless eCommerce Platform. https:\/\/sylius.com"},{"key":"e_1_3_2_1_19_1","unstructured":"2022. Account Takeover in TikTok. https:\/\/hackerone.com\/reports\/1404612  2022. Account Takeover in TikTok. https:\/\/hackerone.com\/reports\/1404612"},{"key":"e_1_3_2_1_20_1","unstructured":"2022. Business Logic Vulnerability. https:\/\/owasp.org\/www-community\/vulnerabilities\/Business_logic_vulnerability  2022. Business Logic Vulnerability. https:\/\/owasp.org\/www-community\/vulnerabilities\/Business_logic_vulnerability"},{"key":"e_1_3_2_1_21_1","unstructured":"2022. CWE-837 Improper Enforcement of a Single Unique Action. https:\/\/cwe.mitre.org\/data\/definitions\/837.html  2022. CWE-837 Improper Enforcement of a Single Unique Action. https:\/\/cwe.mitre.org\/data\/definitions\/837.html"},{"key":"e_1_3_2_1_22_1","unstructured":"2022. CWE-841 Improper Enforcement of Behavioral Workflow. https:\/\/cwe.mitre.org\/data\/definitions\/841.html  2022. CWE-841 Improper Enforcement of Behavioral Workflow. https:\/\/cwe.mitre.org\/data\/definitions\/841.html"},{"key":"e_1_3_2_1_23_1","unstructured":"2022. Password Reset Link Does Not Expire in QIWI. https:\/\/hackerone.com\/reports\/1401891  2022. Password Reset Link Does Not Expire in QIWI. https:\/\/hackerone.com\/reports\/1401891"},{"key":"e_1_3_2_1_24_1","unstructured":"2022. Pay Arbitrary Amount in Zomato. https:\/\/hackerone.com\/reports\/1408782  2022. Pay Arbitrary Amount in Zomato. https:\/\/hackerone.com\/reports\/1408782"},{"volume-title":"Semi-Automatic Security Testing of Web Applications with Fault Models and Properties. Ph.\u00a0D. Dissertation","author":"B\u0171chler Matthias\u00a0Ren\u00e9","key":"e_1_3_2_1_25_1","unstructured":"Matthias\u00a0Ren\u00e9 B\u0171chler . 2015. Semi-Automatic Security Testing of Web Applications with Fault Models and Properties. Ph.\u00a0D. Dissertation . Technical University of Munich . Matthias\u00a0Ren\u00e9 B\u0171chler. 2015. Semi-Automatic Security Testing of Web Applications with Fault Models and Properties. Ph.\u00a0D. Dissertation. Technical University of Munich."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866375"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev53368.2022.00029"},{"key":"e_1_3_2_1_28_1","volume-title":"28th USENIX Security Symposium. USENIX Association","author":"Chen Yi","year":"2019","unstructured":"Yi Chen , Luyi Xing , Yue Qin , Xiaojing Liao , XiaoFeng Wang , Kai Chen , and Wei Zou . 2019 . Devils in the Guidance: Predicting Logic Vulnerabilities in Payment Syndication Services through Automated Documentation Analysis . In 28th USENIX Security Symposium. USENIX Association , Santa Clara, CA, 747\u2013764. Yi Chen, Luyi Xing, Yue Qin, Xiaojing Liao, XiaoFeng Wang, Kai Chen, and Wei Zou. 2019. Devils in the Guidance: Predicting Logic Vulnerabilities in Payment Syndication Services through Automated Documentation Analysis. In 28th USENIX Security Symposium. USENIX Association, Santa Clara, CA, 747\u2013764."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2018.01.008"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/bs.adcom.2015.11.003"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1002\/stvr.1580"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1049\/iet-ifs.2018.5615"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCSCT.2008.116"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2484313.2484375"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2018.00017"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/IWAST.2009.5069042"},{"key":"e_1_3_2_1_38_1","volume-title":"Steve Ragan, and Chelsea Tuttle.","author":"Mckeay Martin","year":"2021","unstructured":"Martin Mckeay , Amanda Goedde , Chris Eng , Steve Ragan, and Chelsea Tuttle. 2021 . API : The Attack Surface that Connects Us All. Technical Report. Akamai . Martin Mckeay, Amanda Goedde, Chris Eng, Steve Ragan, and Chelsea Tuttle. 2021. API: The Attack Surface that Connects Us All. Technical Report. Akamai."},{"key":"e_1_3_2_1_39_1","volume-title":"Model-Based Security Vulnerability Testing. In Australian Software Engineering Conference. 284\u2013296","author":"Pari\u00a0Salas A.","year":"2007","unstructured":"Percy\u00a0 A. Pari\u00a0Salas , Padmanabhan Krishnan , and Kelvin\u00a0 J. Ross . 2007 . Model-Based Security Vulnerability Testing. In Australian Software Engineering Conference. 284\u2013296 . Percy\u00a0A. Pari\u00a0Salas, Padmanabhan Krishnan, and Kelvin\u00a0J. Ross. 2007. Model-Based Security Vulnerability Testing. In Australian Software Engineering Conference. 284\u2013296."},{"key":"e_1_3_2_1_40_1","volume-title":"Toward Black-Box Detection of Logic Flaws in Web Applications. In 21st Annual Network and Distributed System Security Symposium. The Internet Society.","author":"Pellegrino Giancarlo","year":"2014","unstructured":"Giancarlo Pellegrino and Davide Balzarotti . 2014 . Toward Black-Box Detection of Logic Flaws in Web Applications. In 21st Annual Network and Distributed System Security Symposium. The Internet Society. Giancarlo Pellegrino and Davide Balzarotti. 2014. Toward Black-Box Detection of Logic Flaws in Web Applications. In 21st Annual Network and Distributed System Security Symposium. The Internet Society."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.20473\/jisebi.6.1.27-36"},{"key":"e_1_3_2_1_42_1","unstructured":"Prerana\u00a0Pradeepkumar Rane. 2017. Automatic generation of test cases for agile using natural language processing. Ph.\u00a0D. Dissertation. Virginia Tech.  Prerana\u00a0Pradeepkumar Rane. 2017. Automatic generation of test cases for agile using natural language processing. Ph.\u00a0D. Dissertation. Virginia Tech."}],"event":{"name":"ACSAC: Annual Computer Security Applications Conference","acronym":"ACSAC","location":"Austin TX USA"},"container-title":["Proceedings of the 38th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3564654","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3564625.3564654","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:09:12Z","timestamp":1750183752000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3564654"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,5]]},"references-count":41,"alternative-id":["10.1145\/3564625.3564654","10.1145\/3564625"],"URL":"https:\/\/doi.org\/10.1145\/3564625.3564654","relation":{},"subject":[],"published":{"date-parts":[[2022,12,5]]},"assertion":[{"value":"2022-12-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}