Tool report: EvoMaster—black and white box search-based fuzzing for REST, GraphQL and RPC APIs

Andrea Arcuri,Man Zhang,Susruthan Seran,Juan Pablo Galeotti,Amid Golmohammadi,Onur Duman,Agustina Aldasoro,Hernan Ghianni
DOI: https://doi.org/10.1007/s10515-024-00478-1
IF: 1.677
2024-11-30
Automated Software Engineering
Abstract:In this paper, we present the latest version 3.0.0 of EvoMaster , an open-source search-based fuzzer aimed at Web APIs. We discuss and present all its recent improvements, including advanced white-box heuristics, advanced search algorithms, support for databases and external services, as well as dealing with GraphQL and RPC APIs besides the original use case for REST APIs. The tool's installers have been downloaded more than 3000 times. EvoMaster is in daily use for fuzzing millions of lines of code in hundreds of APIs in large Fortune 500 companies, such as for example the e-commerce Meituan.
computer science, software engineering
What problem does this paper attempt to address?