Hackers of India

Astra: Automated Security Testing For REST APIs

 Sagar Popat   Harsh Grover 

2018/12/06

Abstract

REST API penetration testing is complex due to continuous changes in existing APIs and the addition of new APIs. Astra (Sanskrit: अस्त्र) can be used by security engineers or developers as an integral part of their process, so they can detect and patch vulnerabilities in the initial phase of the development cycle. Astra can automatically detect and test login & logout (Authentication API), which makes it easy for anyone to integrate this into CICD pipeline. Astra can take API collection as an input so this can also be used for testing APIs in stand-alone mode.