Providing Security Properties of Cloud Service by Using REST APIs
摘要
REST APIs can be used to programmatically access the most recent cloud and Internet services. As demonstrated in this paper, an inducer should be able to compromise a service by taking advantage of vulnerabilities in its REST API. Four security principles are discussed here. Desirable features should be able to be captured through REST APIs and services. The four security principles are as follows: X, X, X, and X. Examples of HTTP requests include GET, PUT, POST, and DELETE. Roy Fielding developed the idea of representational state transfer, and his work on representational state transfer is known by the abbreviation REST. A nice illustration is the usage of a POST request to create a record and a GET request to retrieve it. The first is an update request (PUT), and the second is a deletion request (DELETE). A web architectural design called REST controls how both clients and servers behave. However, application programming interface (API) is a more official term. On the other hand, API is a more comprehensive set of protocols that may be applied to many platforms to help it connect with other software. REST is compatible only with web applications. Most of the time, it manages HTTP requests and responses. Next, we show how a stateful REST API–based fuzzer can be expanded with an active property checker. These regulations automatically evaluate and detect violations. The first stateful web service is REST. You may use a REST API fuzzing tool to automatically test cloud services by using their REST APIs. APIs may also be used to find dependability and security holes in those services. We describe how to apply these checkers in a remarkably consistent and time-saving way, and we frequently use these checks to address new issues found in various Azure and Office365 cloud deployments. Finally, we discuss the potential security risks of these services.