Content area

Abstract

RESTful APIs have been adopted as the standard way of developing web services, allowing for smooth communication between clients and servers. Their simplicity, scalability, and compatibility have made them crucial to modern web environments. However, the increased adoption of RESTful APIs has simultaneously exposed these interfaces to significant security threats that jeopardize the availability, confidentiality, and integrity of web services. This survey focuses exclusively on RESTful APIs, providing an in-depth perspective distinct from studies addressing other API types such as GraphQL or SOAP. We highlight concrete threats—such as injection attacks and insecure direct object references (IDOR)—to illustrate the evolving risk landscape. Our work systematically reviews state-of-the-art detection methods, including static code analysis and penetration testing, and proposes a novel taxonomy that categorizes vulnerabilities such as authentication and authorization issues. Unlike existing taxonomies focused on general web or network-level threats, our taxonomy emphasizes API-specific design flaws and operational dependencies, offering a more granular and actionable framework for RESTful API security. By critically assessing current detection methodologies and identifying key research gaps, we offer a structured framework that advances the understanding and mitigation of RESTful API vulnerabilities. Ultimately, this work aims to drive significant advancements in API security, thereby enhancing the resilience of web services against evolving cyber threats.

Details

1009240
Title
Towards Secure APIs: A Survey on RESTful API Vulnerability Detection
Publication title
Volume
84
Issue
3
Pages
4223-4257
Number of pages
36
Publication year
2025
Publication date
2025
Section
REVIEW
Publisher
Tech Science Press
Place of publication
Henderson
Country of publication
United States
Publication subject
ISSN
1546-2218
e-ISSN
1546-2226
Source type
Scholarly Journal
Language of publication
English
Document type
Journal Article
Publication history
 
 
Online publication date
2025-07-30
Milestone dates
2025-05-06 (Received); 2025-06-24 (Accepted)
Publication history
 
 
   First posting date
30 Jul 2025
ProQuest document ID
3238361630
Document URL
https://www.proquest.com/scholarly-journals/towards-secure-apis-survey-on-restful-api/docview/3238361630/se-2?accountid=208611
Copyright
© 2025. This work is licensed under https://creativecommons.org/licenses/by/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Last updated
2025-08-11
Database
ProQuest One Academic