| [1]OWASP. API1: 2023 broken object level authorization[EBOL]. 2023[20230718]. https:owasp.orgAPISecurityeditions2023en0xa1brokenobjectlevelauthorization[2]Vithanage N M, Jeyamohan N. WebGuardia—An integrated penetration testing system to detect Web application vulnerabilities[C] Proc of the 2016 Int Conf on Wireless Communications, Signal Processing and Networking (WiSPNET). Piscataway, NJ: IEEE, 2016: 221227[3]Kumar Shrestha A, Singh Maharjan P, Paudel S. Identification and illustration of insecure direct object references and their countermeasures[J]. International Journal of Computer Applications, 2015, 114(18): 3944[4]Pratama I P A E, Rhusuli A M. Penetration testing on Web application using insecure direct object references (IDOR) method[C] Proc of the 2022 Int Conf on ICT for Smart Society (ICISS). Piscataway, NJ: IEEE, 2022: 0107[5]Hadavi M A, Bagherdaei A, Ghasemi S. IDOT: Blackbox detection of access control violations in Web applications[J]. The ISC International Journal of Information Security, 2021, 13(2): 117129[6]Huang Y, Shi C, Lu J, et al. Detecting broken objectlevel authorization vulnerabilities in databasebacked applications[C] Proc of the 2024 ACM SIGSAC Conf on Computer and Communications Security. New York: ACM, 2024: 29342948[7]Monshizadeh M, Naldurg P, Venkatakrishnan V N. MACE: Detecting privilege escalation vulnerabilities in Web applications [C] Proc of the 2014 ACM SIGSAC Conf on Computer and Communications Security. New York: ACM, 2014: 690701[8]陈虹, 谢金彤, 金海波, 等. 基于多访问控制的智能合约重入攻击防御方法[J]. 信息安全研究, 2025, 11(4): 333342[9]OWASP. Insecure direct object reference preventionOWASP cheat sheet series[EBOL]. 2023 [20250614]. https:cheatsheetseries.owasp.orgcheatsheetsInsecure_Direct_Object_Reference_Prevention_Cheat_Sheet.html[10]Spring. Spring security[EBOL]. [20250614]. https:spring.ioprojectsspringsecurity[11]Wang C, Liu J, Peng X, et al. Boosting static resource leak detection via LLMbased resourceoriented intention inference[C] Proc of the 47th IEEEACM Int Conf on Software Engineering. Piscataway, NJ: IEEE, 2024: 29052917[12]Du X, Zheng G, Wang K, et al. VulRAG: Enhancing LLMbased vulnerability detection via knowledgelevel RAG[J]. arXiv preprint, arXiv:2406.11147, 2024[13]Wu F, Zhang Q, Bajaj A P, et al. Exploring the limits of ChatGPT in software security applications[J]. arXiv preprint, arXiv:2312.05275, 2023[14]MyBatis Team. MyBatis 3[EBOL]. 2024[20250614]. https:mybatis.orgmybatis3zh_CNindex.html[15]Yang C. DeepSeek v3—Advanced AI & LLM model online[EBOL]. (20241226)[20250614]. https:deepseekv3.org[16]c2nesjavalang: Pure Python Java parser and tools[EBOL]. [20250614]. https:github.comc2nesjavalang[17]Sridharan M, Chandra S, Dolby J, et al. Alias Analysis for ObjectOriented pPrograms[M] Aliasing in ObjectOriented Programming. Types, Analysis and Verification. Berlin: Springer, 2013: 196232[18]IBM. WALA[EBOL]. (20231108)[20250614]. https:sourceforge.netprojectswala[19]Andersen L O, Lee P. Program analysis and specialization for the C programming language[D]. Copenhagen: University of Copenhagen, 2005 |