Write a Blog >>
ICST 2022
Mon 4 - Fri 8 April 2022
Tue 5 Apr 2022 19:30 - 19:45 at Margaret Hamilton - ICST GUI Testing and Fuzzing Chair(s): Andrea Stocco

Web-based Application Programming Interfaces (APIs) are often described using SOAP, OpenAPI, and GraphQL specifications. These specifications provide a consistent way to define web services and enable automated fuzz testing. As such, many fuzzers take advantage of these specifications. However, in an enterprise setting, the tools are usually installed and scaled by individual teams, leading to duplication of efforts. There is a need for an enterprise-wide fuzz testing solution to provide shared, cost efficient, off-nominal testing at scale where fuzzers can be plugged-in as needed. Internet cloud-based fuzz testing-as-a-service solutions mitigate scalability concerns but are not always feasible as they require artifacts to be uploaded to external infrastructure. Typically, corporate policies prevent sharing artifacts with third parties due to cost, intellectual property, and security concerns. We utilize API specifications and combine them with cluster computing elasticity to build an automated, scalable framework that can fuzz multiple apps at once and retain the trust boundary of the enterprise.

Tue 5 Apr

Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change

19:30 - 20:45
ICST GUI Testing and FuzzingResearch Papers / Tool Demos at Margaret Hamilton
Chair(s): Andrea Stocco Università della Svizzera italiana (USI)
19:30
15m
Talk
A Framework for Automated API Fuzzing at Enterprise Scale
Research Papers
Riyadh Mahmood The Aerospace Corporation, Jay Pennington The Aerospace Corporation, Danny Tsang The Aerospace Corporation, Tan Tran The Aerospace Corporation, Andrea Bogle The Aerospace Corporation
19:45
15m
Talk
GUI Test Transfer from Web to Android
Research Papers
Jun-Wei Lin University of California, Irvine, Sam Malek University of California at Irvine, USA
20:00
15m
Talk
DTLS-Fuzzer: A DTLS Protocol State Fuzzer
Tool Demos
Paul Fiterau-Brostean Uppsala University, Bengt Jonsson Uppsala University, Sweden, Konstantinos (Kostis) Sagonas Uppsala University, Sweden, Fredrik Tåkvist Uppsala University
Pre-print Media Attached
20:15
15m
Talk
Automated Detection of TalkBack Interactive Accessibility Failures in Android Applications
Research Papers
Ali S. Alotaibi University of Southern California, Paul T. Chiou University of Southern California, William G.J. Halfond University of Southern California
20:30
15m
Live Q&A
Discussion and Q&A
Research Papers