{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,23]],"date-time":"2026-01-23T00:17:58Z","timestamp":1769127478823,"version":"3.49.0"},"reference-count":96,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2023,9,28]],"date-time":"2023-09-28T00:00:00Z","timestamp":1695859200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"European Research Council"},{"name":"European Union\u2019s Horizon 2020 research and innovation programme","award":["864972"],"award-info":[{"award-number":["864972"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2023,11,30]]},"abstract":"<jats:p>\n            JavaScript is one of the most popular programming languages. However, its dynamic nature poses several challenges to automated testing techniques. In this paper, we propose an approach and open-source tool support to enable white-box testing of JavaScript applications using\n            <jats:bold>Search-Based Software Testing (SBST)<\/jats:bold>\n            techniques. We provide an automated approach to collect search-based heuristics like the common\n            <jats:italic>Branch Distance<\/jats:italic>\n            and to enable\n            <jats:italic>Testability Transformations<\/jats:italic>\n            . To empirically evaluate our results, we integrated our technique into the\n            <jats:sc>EvoMaster<\/jats:sc>\n            test generation tool, and carried out analyses on the automated\n            <jats:italic>system testing<\/jats:italic>\n            of RESTful and GraphQL APIs. Experiments on eight Web APIs running on NodeJS show that our technique leads to significantly better results than existing black-box and grey-box testing tools, in terms of code coverage and fault detection.\n          <\/jats:p>","DOI":"10.1145\/3593801","type":"journal-article","created":{"date-parts":[[2023,4,24]],"date-time":"2023-04-24T12:13:13Z","timestamp":1682338393000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["JavaScript SBST Heuristics to Enable Effective Fuzzing of NodeJS Web APIs"],"prefix":"10.1145","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1204-9322","authenticated-orcid":false,"given":"Man","family":"Zhang","sequence":"first","affiliation":[{"name":"Kristiania University College, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7103-2179","authenticated-orcid":false,"given":"Asma","family":"Belhadi","sequence":"additional","affiliation":[{"name":"Kristiania University College, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0799-2930","authenticated-orcid":false,"given":"Andrea","family":"Arcuri","sequence":"additional","affiliation":[{"name":"Kristiania University College and Oslo Metropolitan University, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,9,28]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"(n. d.). Babel. https:\/\/babeljs.io\/. Online Accessed May 20 2022."},{"key":"e_1_3_2_3_2","unstructured":"(n. d.). C8. https:\/\/github.com\/bcoe\/c8. Online Accessed May 20 2022."},{"key":"e_1_3_2_4_2","unstructured":"(n. d.). cyclotron. https:\/\/github.com\/ExpediaInceCommercePlatform\/cyclotron. Online Accessed May 20 2022."},{"key":"e_1_3_2_5_2","unstructured":"(n. d.). disease-sh-api. https:\/\/github.com\/disease-sh\/API. Online Accessed May 20 2022."},{"key":"e_1_3_2_6_2","unstructured":"(n. d.). E-Commerce Server. https:\/\/github.com\/react-shop\/react-ecommerce. Online Accessed May 20 2022."},{"key":"e_1_3_2_7_2","unstructured":"(n. d.). ECMAScript Specification. https:\/\/www.ecma-international.org\/ecma-262\/. Online Accessed May 20 2022."},{"key":"e_1_3_2_8_2","unstructured":"(n. d.). Electron. https:\/\/www.electronjs.org\/. Online Accessed May 20 2022."},{"key":"e_1_3_2_9_2","unstructured":"(n. d.). EvoMaster Benchmark (EMB). https:\/\/github.com\/EMResearch\/EMB. Online Accessed May 20 2022."},{"key":"e_1_3_2_10_2","unstructured":"(n. d.). Ionic. https:\/\/ionicframework.com\/. Online Accessed May 20 2022."},{"key":"e_1_3_2_11_2","unstructured":"(n. d.). JEDI. https:\/\/github.com\/aelyasov\/JEDI. Online Accessed May 20 2022."},{"key":"e_1_3_2_12_2","unstructured":"(n. d.). Jest. https:\/\/jestjs.io\/. Online Accessed May 20 2022."},{"key":"e_1_3_2_13_2","unstructured":"(n. d.). JUnit. http:\/\/junit.sourceforge.net\/. Online Accessed May 20 2022."},{"key":"e_1_3_2_14_2","unstructured":"(n. d.). MongoDB. https:\/\/www.mongodb.com\/. Online Accessed May 20 2022."},{"key":"e_1_3_2_15_2","unstructured":"(n. d.). nestjs-realworld-example-app. https:\/\/github.com\/lujakob\/nestjs-realworld-example-app. Online Accessed May 20 2022."},{"key":"e_1_3_2_16_2","unstructured":"(n. d.). NodeJS. https:\/\/nodejs.org\/. Online Accessed May 20 2022."},{"key":"e_1_3_2_17_2","unstructured":"(n. d.). React-Finland. https:\/\/github.com\/ReactFinland\/graphql-api. Online Accessed May 20 2022."},{"key":"e_1_3_2_18_2","unstructured":"(n. d.). realworld API Specification. https:\/\/github.com\/gothinkster\/realworld. Online Accessed May 20 2022."},{"key":"e_1_3_2_19_2","unstructured":"(n. d.). Redis. https:\/\/redis.io\/. Online Accessed May 20 2022."},{"key":"e_1_3_2_20_2","unstructured":"(n. d.). RestAssured. https:\/\/github.com\/rest-assured\/rest-assured. Online Accessed May 20 2022."},{"key":"e_1_3_2_21_2","unstructured":"(n. d.). restler-fuzzer. https:\/\/github.com\/microsoft\/restler-fuzzer. Online Accessed May 20 2022."},{"key":"e_1_3_2_22_2","unstructured":"(n. d.). RESTTESTGEN. https:\/\/github.com\/resttestgenicst2020\/submission_icst2020. Online Accessed May 20 2022."},{"key":"e_1_3_2_23_2","unstructured":"(n. d.). SpaceX-API. https:\/\/github.com\/r-spacex\/SpaceX-API. Online Accessed May 20 2022."},{"key":"e_1_3_2_24_2","unstructured":"(n. d.). The State of the OCTOVERSE. https:\/\/octoverse.github.com\/."},{"key":"e_1_3_2_25_2","unstructured":"(n. d.). SuperAgent. https:\/\/visionmedia.github.io\/superagent\/. Online Accessed May 20 2022."},{"issue":"6","key":"e_1_3_2_26_2","doi-asserted-by":"crossref","first-page":"742","DOI":"10.1109\/TSE.2009.52","article-title":"A systematic review of the application and empirical investigation of search-based test-case generation","volume":"36","author":"Ali S.","year":"2010","unstructured":"S. Ali, L. C. Briand, H. Hemmati, and R. K. Panesar-Walawege. 2010. A systematic review of the application and empirical investigation of search-based test-case generation. IEEE Transactions on Software Engineering (TSE) 36, 6 (2010), 742\u2013762.","journal-title":"IEEE Transactions on Software Engineering (TSE)"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1002\/stvr.v16:3"},{"issue":"5","key":"e_1_3_2_28_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3106739","article-title":"A survey of dynamic analysis and test generation for JavaScript","volume":"50","author":"Andreasen Esben","year":"2017","unstructured":"Esben Andreasen, Liang Gong, Anders M\u00f8ller, Michael Pradel, Marija Selakovic, Koushik Sen, and Cristian-Alexandru Staicu. 2017. A survey of dynamic analysis and test generation for JavaScript. ACM Computing Surveys (CSUR) 50, 5 (2017), 1\u201336.","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"e_1_3_2_29_2","volume-title":"IEEE International Conference on Software Testing, Verification and Validation (ICST)","author":"Arcuri Andrea","year":"2018","unstructured":"Andrea Arcuri. 2018. EvoMaster: Evolutionary multi-context automated system test generation. In IEEE International Conference on Software Testing, Verification and Validation (ICST). IEEE."},{"key":"e_1_3_2_30_2","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1016\/j.infsof.2018.05.003","article-title":"Test suite generation with the many independent objective (MIO) algorithm","volume":"104","author":"Arcuri Andrea","year":"2018","unstructured":"Andrea Arcuri. 2018. Test suite generation with the many independent objective (MIO) algorithm. Information and Software Technology 104 (2018), 195\u2013206.","journal-title":"Information and Software Technology"},{"issue":"1","key":"e_1_3_2_31_2","first-page":"3","article-title":"RESTful API automated test case generation with EvoMaster","volume":"28","author":"Arcuri Andrea","year":"2019","unstructured":"Andrea Arcuri. 2019. RESTful API automated test case generation with EvoMaster. ACM Transactions on Software Engineering and Methodology (TOSEM) 28, 1 (2019), 3.","journal-title":"ACM Transactions on Software Engineering and Methodology (TOSEM)"},{"issue":"3","key":"e_1_3_2_32_2","doi-asserted-by":"crossref","first-page":"72","DOI":"10.1109\/MS.2020.3013820","article-title":"Automated black-and white-box testing of RESTful APIs With EvoMaster","volume":"38","author":"Arcuri Andrea","year":"2020","unstructured":"Andrea Arcuri. 2020. Automated black-and white-box testing of RESTful APIs With EvoMaster. IEEE Software 38, 3 (2020), 72\u201378.","journal-title":"IEEE Software"},{"key":"e_1_3_2_33_2","first-page":"265","volume-title":"ACM Int. Symposium on Software Testing and Analysis (ISSTA)","author":"Arcuri A.","year":"2011","unstructured":"A. Arcuri and L. Briand. 2011. Adaptive random testing: An illusion of effectiveness?. In ACM Int. Symposium on Software Testing and Analysis (ISSTA). 265\u2013275."},{"issue":"3","key":"e_1_3_2_34_2","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1002\/stvr.1486","article-title":"A Hitchhiker\u2019s guide to statistical tests for assessing randomized algorithms in software engineering","volume":"24","author":"Arcuri A.","year":"2014","unstructured":"A. Arcuri and L. Briand. 2014. A Hitchhiker\u2019s guide to statistical tests for assessing randomized algorithms in software engineering. Software Testing, Verification and Reliability (STVR) 24, 3 (2014), 219\u2013250.","journal-title":"Software Testing, Verification and Reliability (STVR)"},{"issue":"4","key":"e_1_3_2_35_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3391533","article-title":"Handling SQL databases in automated system test generation","volume":"29","author":"Arcuri Andrea","year":"2020","unstructured":"Andrea Arcuri and Juan P. Galeotti. 2020. Handling SQL databases in automated system test generation. ACM Transactions on Software Engineering and Methodology (TOSEM) 29, 4 (2020), 1\u201331.","journal-title":"ACM Transactions on Software Engineering and Methodology (TOSEM)"},{"issue":"1","key":"e_1_3_2_36_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3477271","article-title":"Enhancing search-based testing with testability transformations for existing APIs","volume":"31","author":"Arcuri Andrea","year":"2021","unstructured":"Andrea Arcuri and Juan P. Galeotti. 2021. Enhancing search-based testing with testability transformations for existing APIs. ACM Transactions on Software Engineering and Methodology (TOSEM) 31, 1 (2021), 1\u201334.","journal-title":"ACM Transactions on Software Engineering and Methodology (TOSEM)"},{"issue":"57","key":"e_1_3_2_37_2","doi-asserted-by":"crossref","first-page":"2153","DOI":"10.21105\/joss.02153","article-title":"EvoMaster: A search-based system test generation tool","volume":"6","author":"Arcuri Andrea","year":"2021","unstructured":"Andrea Arcuri, Juan Pablo Galeotti, Bogdan Marculescu, and Man Zhang. 2021. EvoMaster: A search-based system test generation tool. Journal of Open Source Software 6, 57 (2021), 2153.","journal-title":"Journal of Open Source Software"},{"key":"e_1_3_2_38_2","unstructured":"Andrea Arcuri ZhangMan asmab89 Bogdan Amid Golmohammadi Juan Pablo Galeotti Seran Alberto Mart\u00edn L\u00f3pez Agustina Aldasoro Annibale Panichella and Kyle Niemeyer. 2022. EMResearch\/EvoMaster:. (June2022). DOI:10.5281\/zenodo.6651631"},{"key":"e_1_3_2_39_2","unstructured":"Andrea Arcuri ZhangMan Bogdan asmab89 Amid Golmohammadi Juan Pablo Galeotti Alberto Mart\u00edn L\u00f3pez Agustina Aldasoro Annibale Panichella and Kyle Niemeyer. 2022. EMResearch\/EvoMaster:. (Feb.2022). DOI:10.5281\/zenodo.6106776"},{"key":"e_1_3_2_40_2","unstructured":"Andrea Arcuri ZhangMan Amid Golmohammadi and asmab89. 2022. EMResearch\/EMB:. (Feb.2022). DOI:10.5281\/zenodo.6106830"},{"key":"e_1_3_2_41_2","first-page":"748","volume-title":"ACM\/IEEE International Conference on Software Engineering (ICSE)","author":"Atlidakis Vaggelis","year":"2019","unstructured":"Vaggelis Atlidakis, Patrice Godefroid, and Marina Polishchuk. 2019. RESTler: Stateful REST API fuzzing. In ACM\/IEEE International Conference on Software Engineering (ICSE). 748\u2013758."},{"key":"e_1_3_2_42_2","first-page":"108","volume-title":"ACM Int. Symposium on Software Testing and Analysis (ISSTA)","author":"Baresel A.","year":"2004","unstructured":"A. Baresel, D. Binkley, M. Harman, and B. Korel. 2004. Evolutionary testing in the presence of loop-assigned flags: A testability transformation approach. In ACM Int. Symposium on Software Testing and Analysis (ISSTA). 108\u2013118."},{"key":"e_1_3_2_43_2","first-page":"2442","volume-title":"Genetic and Evolutionary Computation Conference (GECCO)","author":"Baresel A.","year":"2003","unstructured":"A. Baresel and H. Sthamer. 2003. Evolutionary testing of flag conditions. In Genetic and Evolutionary Computation Conference (GECCO). 2442\u20132454."},{"key":"e_1_3_2_44_2","volume-title":"Genetic and Evolutionary Computation Conference (GECCO)","author":"Belhadi Asma","year":"2022","unstructured":"Asma Belhadi, Man Zhang, and Andrea Arcuri. 2022. Evolutionary-based automated testing for GraphQL APIs. In Genetic and Evolutionary Computation Conference (GECCO)."},{"key":"e_1_3_2_45_2","unstructured":"Asma Belhadi Man Zhang and Andrea Arcuri. 2022. White-Box and Black-Box Fuzzing for GraphQL APIs. (2022). DOI:10.48550\/ARXIV.2209.05833"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/2000791.2000796"},{"key":"e_1_3_2_47_2","doi-asserted-by":"crossref","first-page":"226","DOI":"10.1109\/SCAM52516.2021.00035","volume-title":"2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM)","author":"Corradini Davide","year":"2021","unstructured":"Davide Corradini, Amedeo Zampieri, Michele Pasqua, and Mariano Ceccato. 2021. Empirical comparison of black-box test case generation tools for RESTful APIs. In 2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM). IEEE, 226\u2013236."},{"key":"e_1_3_2_48_2","doi-asserted-by":"crossref","unstructured":"Davide Corradini Amedeo Zampieri Michele Pasqua Emanuele Viglianisi Michael Dallago and Mariano Ceccato. 2021. Replication Package: Automated Black-Box Testing of Nominal and Error Scenarios in RESTful APIs. (Dec.2021). DOI:10.5281\/zenodo.5803118","DOI":"10.1002\/stvr.1808"},{"key":"e_1_3_2_49_2","doi-asserted-by":"crossref","first-page":"e1808","DOI":"10.1002\/stvr.1808","article-title":"Automated black-box testing of nominal and error scenarios in RESTful APIs","author":"Corradini Davide","year":"2022","unstructured":"Davide Corradini, Amedeo Zampieri, Michele Pasqua, Emanuele Viglianisi, Michael Dallago, and Mariano Ceccato. 2022. Automated black-box testing of nominal and error scenarios in RESTful APIs. Software Testing, Verification and Reliability (2022), e1808.","journal-title":"Software Testing, Verification and Reliability"},{"key":"e_1_3_2_50_2","doi-asserted-by":"crossref","first-page":"3630","DOI":"10.1007\/s10664-019-09725-6","article-title":"Evolutionary fuzzing of Android OS vendor system services","volume":"24","author":"Cotroneo Domenico","year":"2019","unstructured":"Domenico Cotroneo, Antonio Ken Iannillo, and Roberto Natella. 2019. Evolutionary fuzzing of Android OS vendor system services. Empirical Software Engineering 24 (2019), 3630\u20133658.","journal-title":"Empirical Software Engineering"},{"key":"e_1_3_2_51_2","doi-asserted-by":"crossref","first-page":"95","DOI":"10.1145\/3213846.3213848","volume-title":"Proceedings of the 27th ACM SIGSOFT International Symposium on Software Testing and Analysis","author":"Cummins Chris","year":"2018","unstructured":"Chris Cummins, Pavlos Petoumenos, Alastair Murray, and Hugh Leather. 2018. Compiler fuzzing through deep learning. In Proceedings of the 27th ACM SIGSOFT International Symposium on Software Testing and Analysis. 95\u2013105."},{"key":"e_1_3_2_52_2","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1109\/EDOC.2018.00031","volume-title":"2018 IEEE 22nd International Enterprise Distributed Object Computing Conference (EDOC)","author":"Ed-Douibi Hamza","year":"2018","unstructured":"Hamza Ed-Douibi, Javier Luis C\u00e1novas Izquierdo, and Jordi Cabot. 2018. Automatic generation of test cases for REST APIs: A specification-based approach. In 2018 IEEE 22nd International Enterprise Distributed Object Computing Conference (EDOC). 181\u2013190."},{"key":"e_1_3_2_53_2","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1109\/ISSRE.2018.00020","volume-title":"2018 IEEE 29th International Symposium on Software Reliability Engineering (ISSRE)","author":"Elyasov Alexander","year":"2018","unstructured":"Alexander Elyasov, I. S. W. B. Prasetya, and Jurriaan Hage. 2018. Search-based test data generation for JavaScript functions that interact with the DOM. In 2018 IEEE 29th International Symposium on Software Reliability Engineering (ISSRE). IEEE, 88\u201399."},{"key":"e_1_3_2_54_2","first-page":"416","volume-title":"ACM Symposium on the Foundations of Software Engineering (FSE)","author":"Fraser Gordon","year":"2011","unstructured":"Gordon Fraser and Andrea Arcuri. 2011. EvoSuite: Automatic test suite generation for object-oriented software. In ACM Symposium on the Foundations of Software Engineering (FSE). 416\u2013419."},{"key":"e_1_3_2_55_2","first-page":"178","volume-title":"ACM\/IEEE International Conference on Software Engineering (ICSE)","author":"Fraser G.","year":"2012","unstructured":"G. Fraser and A. Arcuri. 2012. Sound empirical evidence in software testing. In ACM\/IEEE International Conference on Software Engineering (ICSE). 178\u2013188."},{"issue":"8","key":"e_1_3_2_56_2","doi-asserted-by":"crossref","first-page":"473","DOI":"10.1109\/32.624304","article-title":"ADTEST: A test data generation suite for ADA software systems","volume":"23","author":"Gallagher Matthew J.","year":"1997","unstructured":"Matthew J. Gallagher and V. Lakshmi Narasimhan. 1997. ADTEST: A test data generation suite for ADA software systems. IEEE Transactions on Software Engineering (TSE) 23, 8 (1997), 473\u2013484.","journal-title":"IEEE Transactions on Software Engineering (TSE)"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00040"},{"key":"e_1_3_2_58_2","doi-asserted-by":"crossref","first-page":"474","DOI":"10.1109\/ICSE.2009.5070546","volume-title":"2009 IEEE 31st International Conference on Software Engineering","author":"Ganesh Vijay","year":"2009","unstructured":"Vijay Ganesh, Tim Leek, and Martin Rinard. 2009. Taint-based directed whitebox fuzzing. In 2009 IEEE 31st International Conference on Software Engineering. IEEE, 474\u2013484."},{"issue":"2","key":"e_1_3_2_59_2","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1145\/3363824","article-title":"Fuzzing: Hack, art, and science","volume":"63","author":"Godefroid Patrice","year":"2020","unstructured":"Patrice Godefroid. 2020. Fuzzing: Hack, art, and science. Commun. ACM 63, 2 (2020), 70\u201376.","journal-title":"Commun. ACM"},{"key":"e_1_3_2_60_2","first-page":"725","volume-title":"ACM Symposium on the Foundations of Software Engineering (FSE) (ESEC\/FSE 2020)","author":"Godefroid Patrice","year":"2020","unstructured":"Patrice Godefroid, Bo-Yuan Huang, and Marina Polishchuk. 2020. Intelligent REST API data fuzzing. In ACM Symposium on the Foundations of Software Engineering (FSE) (ESEC\/FSE 2020). ACM, 725\u2013736."},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-011-0568-8"},{"key":"e_1_3_2_62_2","first-page":"269","volume-title":"2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE)","author":"Gu Tianxiao","year":"2019","unstructured":"Tianxiao Gu, Chengnian Sun, Xiaoxing Ma, Chun Cao, Chang Xu, Yuan Yao, Qirun Zhang, Jian Lu, and Zhendong Su. 2019. Practical GUI testing of Android applications via model abstraction and refinement. In 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE). IEEE, 269\u2013280."},{"key":"e_1_3_2_63_2","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/978-3-319-92970-5_1","volume-title":"International Conference on Software Engineering and Formal Methods","author":"Harman Mark","year":"2018","unstructured":"Mark Harman. 2018. We need a testability transformation semantics. In International Conference on Software Engineering and Formal Methods. Springer, 3\u201317."},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-78917-8_11"},{"key":"e_1_3_2_65_2","first-page":"1351","volume-title":"Genetic and Evolutionary Computation Conference (GECCO)","author":"Harman M.","year":"2002","unstructured":"M. Harman, L. Hu, R. Hierons, A. Baresel, and H. Sthamer. 2002. Improving evolutionary testing by flag removal. In Genetic and Evolutionary Computation Conference (GECCO). 1351\u20131358."},{"issue":"14","key":"e_1_3_2_66_2","doi-asserted-by":"crossref","first-page":"833","DOI":"10.1016\/S0950-5849(01)00189-6","article-title":"Search-based software engineering","volume":"43","author":"Harman M.","year":"2001","unstructured":"M. Harman and B. F. Jones. 2001. Search-based software engineering. Journal of Information & Software Technology 43, 14 (2001), 833\u2013839.","journal-title":"Journal of Information & Software Technology"},{"issue":"1","key":"e_1_3_2_67_2","first-page":"11","article-title":"Search-based software engineering: Trends, techniques and applications","volume":"45","author":"Harman Mark","year":"2012","unstructured":"Mark Harman, S. Afshin Mansouri, and Yuanyuan Zhang. 2012. Search-based software engineering: Trends, techniques and applications. ACM Computing Surveys (CSUR) 45, 1 (2012), 11.","journal-title":"ACM Computing Surveys (CSUR)"},{"issue":"5","key":"e_1_3_2_68_2","doi-asserted-by":"crossref","first-page":"649","DOI":"10.1109\/TSE.2010.62","article-title":"An analysis and survey of the development of mutation testing","volume":"37","author":"Jia Yue","year":"2011","unstructured":"Yue Jia and Mark Harman. 2011. An analysis and survey of the development of mutation testing. IEEE Transactions on Software Engineering (TSE) 37, 5 (2011), 649\u2013678.","journal-title":"IEEE Transactions on Software Engineering (TSE)"},{"key":"e_1_3_2_69_2","volume-title":"IEEE International Conference on Software Testing, Verification and Validation (ICST)","author":"Karlsson Stefan","year":"2020","unstructured":"Stefan Karlsson, Adnan Causevic, and Daniel Sundmark. 2020. QuickREST: Property-based test generation of OpenAPI described RESTful APIs. In IEEE International Conference on Software Testing, Verification and Validation (ICST). IEEE."},{"issue":"8","key":"e_1_3_2_70_2","doi-asserted-by":"crossref","first-page":"870","DOI":"10.1109\/32.57624","article-title":"Automated software test data generation","volume":"16","author":"Korel Bogdan","year":"1990","unstructured":"Bogdan Korel. 1990. Automated software test data generation. IEEE Transactions on Software Engineering 16, 8 (1990), 870\u2013879.","journal-title":"IEEE Transactions on Software Engineering"},{"issue":"1","key":"e_1_3_2_71_2","doi-asserted-by":"crossref","first-page":"112","DOI":"10.1016\/j.infsof.2012.03.009","article-title":"AUSTIN: An open source tool for search based software testing of C programs","volume":"55","author":"Lakhotia Kiran","year":"2013","unstructured":"Kiran Lakhotia, Mark Harman, and Hamilton Gross. 2013. AUSTIN: An open source tool for search based software testing of C programs. Information and Software Technology 55, 1 (2013), 112\u2013125.","journal-title":"Information and Software Technology"},{"key":"e_1_3_2_72_2","first-page":"237","volume-title":"Search Based Software Engineering - Third International Symposium, SSBSE 2011, Szeged, Hungary, September 10-12, 2011. Proceedings","author":"Li Y.","year":"2011","unstructured":"Y. Li and G. Fraser. 2011. Bytecode testability transformation. In Search Based Software Engineering - Third International Symposium, SSBSE 2011, Szeged, Hungary, September 10-12, 2011. Proceedings. 237\u2013251. DOI:10.1007\/978-3-642-23716-4_21"},{"issue":"6","key":"e_1_3_2_73_2","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1145\/2813885.2737986","article-title":"Many-core compiler fuzzing","volume":"50","author":"Lidbury Christopher","year":"2015","unstructured":"Christopher Lidbury, Andrei Lascu, Nathan Chong, and Alastair F. Donaldson. 2015. Many-core compiler fuzzing. ACM SIGPLAN Notices 50, 6 (2015), 65\u201376.","journal-title":"ACM SIGPLAN Notices"},{"key":"e_1_3_2_74_2","doi-asserted-by":"crossref","first-page":"440","DOI":"10.1145\/3395363.3397358","volume-title":"Proceedings of the 29th ACM SIGSOFT International Symposium on Software Testing and Analysis","author":"Lin Yun","year":"2020","unstructured":"Yun Lin, Jun Sun, Gordon Fraser, Ziheng Xiu, Ting Liu, and Jin Song Dong. 2020. Recovering fitness gradients for interprocedural Boolean flags in search-based testing. In Proceedings of the 29th ACM SIGSOFT International Symposium on Software Testing and Analysis. 440\u2013451."},{"key":"e_1_3_2_75_2","doi-asserted-by":"crossref","first-page":"377","DOI":"10.1109\/ICST53961.2022.00018","volume-title":"2022 IEEE Conference on Software Testing, Verification and Validation (ICST)","author":"Mahmood Riyadh","year":"2022","unstructured":"Riyadh Mahmood, Jay Pennington, Danny Tsang, Tan Tran, and Andrea Bogle. 2022. A framework for automated API fuzzing at enterprise scale. In 2022 IEEE Conference on Software Testing, Verification and Validation (ICST). IEEE, 377\u2013388."},{"issue":"11","key":"e_1_3_2_76_2","doi-asserted-by":"crossref","first-page":"2312","DOI":"10.1109\/TSE.2019.2946563","article-title":"The art, science, and engineering of fuzzing: A survey","volume":"47","author":"Man\u00e8s Valentin J. M.","year":"2019","unstructured":"Valentin J. M. Man\u00e8s, HyungSeok Han, Choongwoo Han, Sang Kil Cha, Manuel Egele, Edward J. Schwartz, and Maverick Woo. 2019. The art, science, and engineering of fuzzing: A survey. IEEE Transactions on Software Engineering 47, 11 (2019), 2312\u20132331.","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_77_2","first-page":"94","volume-title":"ACM Int. Symposium on Software Testing and Analysis (ISSTA)","author":"Mao Ke","year":"2016","unstructured":"Ke Mao, Mark Harman, and Yue Jia. 2016. Sapienz: Multi-objective automated testing for Android applications. In ACM Int. Symposium on Software Testing and Analysis (ISSTA). ACM, 94\u2013105."},{"issue":"3","key":"e_1_3_2_78_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3491038","article-title":"On the faults found in REST APIs by automated test generation","volume":"31","author":"Marculescu Bogdan","year":"2022","unstructured":"Bogdan Marculescu, Man Zhang, and Andrea Arcuri. 2022. On the faults found in REST APIs by automated test generation. ACM Transactions on Software Engineering and Methodology (TOSEM) 31, 3 (2022), 1\u201343.","journal-title":"ACM Transactions on Software Engineering and Methodology (TOSEM)"},{"key":"e_1_3_2_79_2","volume-title":"International Conference on Service-Oriented Computing","author":"Martin-Lopez Alberto","year":"2020","unstructured":"Alberto Martin-Lopez, Sergio Segura, and Antonio Ruiz-Cort\u00e9s. 2020. RESTest: Black-box constraint-based testing of RESTful Web APIs. In International Conference on Service-Oriented Computing."},{"issue":"2","key":"e_1_3_2_80_2","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1002\/stvr.294","article-title":"Search-based software test data generation: A survey","volume":"14","author":"McMinn P.","year":"2004","unstructured":"P. McMinn. 2004. Search-based software test data generation: A survey. Software Testing, Verification and Reliability 14, 2 (2004), 105\u2013156.","journal-title":"Software Testing, Verification and Reliability"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1145\/1525880.1525884"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1145\/96267.96279"},{"key":"e_1_3_2_83_2","first-page":"1","volume-title":"Proceedings of the 20th International Symposium on Principles and Practice of Declarative Programming","author":"Santos Jos\u00e9 Fragoso","year":"2018","unstructured":"Jos\u00e9 Fragoso Santos, Petar Maksimovi\u0107, Th\u00e9otime Grohens, Julian Dolby, and Philippa Gardner. 2018. Symbolic execution for JavaScript. In Proceedings of the 20th International Symposium on Principles and Practice of Declarative Programming. 1\u201314."},{"key":"e_1_3_2_84_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3276531","article-title":"Test generation for higher-order functions in dynamic languages","volume":"2","author":"Selakovic Marija","year":"2018","unstructured":"Marija Selakovic, Michael Pradel, Rezwana Karim, and Frank Tip. 2018. Test generation for higher-order functions in dynamic languages. Proceedings of the ACM on Programming Languages 2, OOPSLA (2018), 1\u201327.","journal-title":"Proceedings of the ACM on Programming Languages"},{"key":"e_1_3_2_85_2","first-page":"488","volume-title":"Proceedings of the 2013 9th Joint Meeting on Foundations of Software Engineering","author":"Sen Koushik","year":"2013","unstructured":"Koushik Sen, Swaroop Kalasapur, Tasneem Brutch, and Simon Gibbs. 2013. Jalangi: A selective record-replay and dynamic analysis framework for JavaScript. In Proceedings of the 2013 9th Joint Meeting on Foundations of Software Engineering. 488\u2013498."},{"key":"e_1_3_2_86_2","doi-asserted-by":"crossref","first-page":"27","DOI":"10.1109\/ASE.2017.8115615","volume-title":"2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE)","author":"Song Wei","year":"2017","unstructured":"Wei Song, Xiangxing Qian, and Jeff Huang. 2017. EHBDroid: Beyond GUI testing for Android applications. In 2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 27\u201337."},{"key":"e_1_3_2_87_2","volume-title":"IEEE International Conference on Software Testing, Verification and Validation (ICST)","author":"Viglianisi Emanuele","year":"2020","unstructured":"Emanuele Viglianisi, Michael Dallago, and Mariano Ceccato. 2020. RESTTESTGEN: Automated black-box testing of RESTful APIs. In IEEE International Conference on Software Testing, Verification and Validation (ICST). IEEE."},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2009.06.037"},{"issue":"14","key":"e_1_3_2_89_2","doi-asserted-by":"crossref","first-page":"841","DOI":"10.1016\/S0950-5849(01)00190-2","article-title":"Evolutionary test environment for automatic structural testing","volume":"43","author":"Wegener J.","year":"2001","unstructured":"J. Wegener, A. Baresel, and H. Sthamer. 2001. Evolutionary test environment for automatic structural testing. Information and Software Technology 43, 14 (2001), 841\u2013854.","journal-title":"Information and Software Technology"},{"key":"e_1_3_2_90_2","unstructured":"Andreas Zeller Rahul Gopinath Marcel B\u00f6hme Gordon Fraser and Christian Holler. 2019. The Fuzzing Book . (2019)."},{"issue":"1","key":"e_1_3_2_91_2","article-title":"Adaptive hypermutation for search-based system test generation: A study on REST APIs with EvoMaster","volume":"31","author":"Zhang Man","year":"2021","unstructured":"Man Zhang and Andrea Arcuri. 2021. Adaptive hypermutation for search-based system test generation: A study on REST APIs with EvoMaster. ACM Transactions on Software Engineering and Methodology (TOSEM) 31, 1 (2021).","journal-title":"ACM Transactions on Software Engineering and Methodology (TOSEM)"},{"key":"e_1_3_2_92_2","doi-asserted-by":"crossref","unstructured":"Man Zhang and Andrea Arcuri. 2022. Open Problems in Fuzzing RESTful APIs: A Comparison of Tools. (2022). DOI:10.48550\/ARXIV.2205.05325","DOI":"10.1145\/3597205"},{"key":"e_1_3_2_93_2","doi-asserted-by":"publisher","DOI":"10.1145\/3585009"},{"key":"e_1_3_2_94_2","volume-title":"IEEE International Conference on Software Testing, Verification and Validation (ICST)","author":"Zhang Man","year":"2022","unstructured":"Man Zhang, Asma Belhadi, and Andrea Arcuri. 2022. JavaScript instrumentation for search-based software testing: A study with RESTful APIs. In IEEE International Conference on Software Testing, Verification and Validation (ICST). IEEE."},{"key":"e_1_3_2_95_2","doi-asserted-by":"crossref","first-page":"1426","DOI":"10.1145\/3321707.3321815","volume-title":"Proceedings of the Genetic and Evolutionary Computation Conference","author":"Zhang Man","year":"2019","unstructured":"Man Zhang, Bogdan Marculescu, and Andrea Arcuri. 2019. Resource-based test case generation for RESTful web services. In Proceedings of the Genetic and Evolutionary Computation Conference. 1426\u20131434."},{"issue":"4","key":"e_1_3_2_96_2","first-page":"1","article-title":"Resource and dependency based test case generation for RESTful Web services","volume":"26","author":"Zhang Man","year":"2021","unstructured":"Man Zhang, Bogdan Marculescu, and Andrea Arcuri. 2021. Resource and dependency based test case generation for RESTful Web services. Empirical Software Engineering 26, 4 (2021), 1\u201361.","journal-title":"Empirical Software Engineering"},{"key":"e_1_3_2_97_2","doi-asserted-by":"publisher","DOI":"10.1145\/3512345"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3593801","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3593801","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:47:50Z","timestamp":1750178870000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3593801"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,9,28]]},"references-count":96,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2023,11,30]]}},"alternative-id":["10.1145\/3593801"],"URL":"https:\/\/doi.org\/10.1145\/3593801","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,9,28]]},"assertion":[{"value":"2022-05-20","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-03-15","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-09-28","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}