Automated Test Generation for REST APIs: No Time to Rest Yet
arXiv:2204.08348 · doi:10.1145/3533767.3534401
Abstract
Modern web services routinely provide REST APIs for clients to access their functionality. These APIs present unique challenges and opportunities for automated testing, driving the recent development of many techniques and tools that generate test cases for API endpoints using various strategies. Understanding how these techniques compare to one another is difficult, as they have been evaluated on different benchmarks and using different metrics. To fill this gap, we performed an empirical study aimed to understand the landscape in automated testing of REST APIs and guide future research in this area. We first identified, through a systematic selection process, a set of 10 state-of-the-art REST API testing tools that included tools developed by both researchers and practitioners. We then applied these tools to a benchmark of 20 real-world open-source RESTful services and analyzed their performance in terms of code coverage achieved and unique failures triggered. This analysis allowed us to identify strengths, weaknesses, and limitations of the tools considered and of their underlying strategies, as well as implications of our findings for future research in this area.
13 pages, 6 figures, In Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA) 2022
References in corpus (5)
- Exploring the Attack Surface of Blockchain: A Systematic Overview
- EvoMaster: Evolutionary Multi-context Automated System Test Generation
- RESTful API Automated Test Case Generation
- Pythia: Grammar-Based Fuzzing of REST APIs with Coverage-guided Feedback and Learning-based Mutations
- Morest: Model-based RESTful API Testing with Execution Feedback
Cited by in corpus (6)
- KAT: Dependency-aware Automated API Testing with Large Language Models
- Testing Real-World Healthcare IoT Application: Experiences and Lessons Learned
- Automated Test Generation for Medical Rules Web Services: A Case Study at the Cancer Registry of Norway
- REST API Testing in DevOps: A Study on an Evolving Healthcare IoT Application
- OOPS: Automated generation of REST API specification via LLMs
- COTS: Connected OpenAPI Test Synthesis for RESTful Applications