Hackers of India

Astra: Automated Security Testing For REST APIs

 Ankur Bhargava   Prajal Kulkarni   Sagar Popat 

2018/08/08

Abstract

REST API penetration testing is complex due to continuous changes in existing APIs and addition of new APIs. Astra (Sanskrit: अस्त्र) can be used by security engineers or developers as an integral part of their process, so they can detect and patch vulnerabilities in the initial phase of the development cycle. Astra can automatically detect and test login & logout (Authentication API), which makes it easy for anyone to integrate this into CICD pipeline. Astra can take API collection as an input so this can also be used for testing APIs in stand-alone mode.