AI-Assisted Security Testing of REST APIs: A Conceptual Framework for Vulnerability Detection and Validation
REST APIs are widely used in modern web and mobile applications, making their security an important concern. Traditional API security testing often depends on predefined test cases and vulnerability patterns, which may not adequately adapt to different API structures and contexts. Recent advances in artificial intelligence, particularly large language models, provide opportunities to support automated security test generation. However, AI-based approaches require reliable API information, contextual understanding, controlled test execution, and evidence-based vulnerability validation. This paper proposes a conceptual framework for AI-assisted security testing of REST APIs. The framework integrates an API Information Collector, API Context Analyzer, AI Security Test Generator, Dynamic Test Executor, and Vulnerability Validator. The proposed approach uses API specifications, endpoint information, parameters, authentication requirements, and response behavior to generate context-aware security tests. The framework focuses on common REST API security problems, including broken object-level authorization, broken authentication, excessive data exposure, injection, and security misconfiguration. A validation stage is included to distinguish potential vulnerabilities from false positives using observable security evidence. The framework is conceptual and has not been experimentally evaluated in this study. Therefore, no performance or accuracy claims are made. The paper provides a structured foundation for future implementation and empirical evaluation of AI-assisted REST API security testing.
Authors
- Muhammad Afaq
Institutions
- University of the Punjab (PK)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-18
- DOI
- https://doi.org/10.5281/zenodo.22834978
- Primary Topic
- Web Application Security Vulnerabilities
- Type
- preprint