Názov:Application level fuzzing
Vedúci:Ing. Peter Gasper
Kµúčové slová:fuzzing, OpenAPI, black-box, fuzzer, generation-based
Abstrakt:In this work, we researched techniques used for fuzzing web services. We paid attention mainly to the black-box automated fuzzing. For the automatic exploration of the structure of web services, we utilized OpenAPI specification. After knowing the structure of the web service were able to create a generation-based smart fuzzer that will construct requests that comply with the OpenAPI specification of the API. Thanks to which we were able to achieve large code coverage and find bugs in such battle-tested production-grade software as Kubernetes, Gitea, or Vault.

