Automated black-box detection of Insecure Direct Object Reference (IDOR) vulnerabilities in web applications

bracu.type.groupResearch Publications
datacite.rightsMetadata Only
dc.contributor.authorHossain, Ayemun
dc.contributor.authorSizan, Najmus Sakib
dc.contributor.authorKawsar, Bibi
dc.contributor.authorTanny, Tanusree Saha
dc.contributor.departmentDepartment of Computer Science and Engineering
dc.date.accessioned2026-08-15T13:57:09Z
dc.date.available2026-08-15T13:57:09Z
dc.date.issued2025-01-01
dc.description.abstractBroken authentication and access control are among the most critical vulnerabilities in web applications, often enabling attackers to bypass security mechanisms and gain unauthorized access. A notable instance of this class of weakness is the Insecure Direct Object Reference (IDOR) vulnerability, where object identifiers in client requests can be manipulated to expose or modify restricted resources. Despite its significance, IDOR remains difficult to detect automatically. Existing scanners are limited in scope, focusing mainly on HTTP GET and POST methods, requiring manual intervention, and often producing high false positive rates with lengthy information-gathering phases. To address these limitations, we present IDORD, a fully automated black-box tool for IDOR detection. IDORD incorporates a crawler for automated URL extraction, applies parameter mutation to craft unauthorized requests, and analyzes response behaviors to identify violations of access control policies. Unlike conventional scanners, our approach systematically evaluates all major HTTP methods, including GET, POST, PUT, and DELETE. Validation on deliberately vulnerable applications shows that IDORD improves efficiency, reduces detection time, and provides broader coverage of IDOR vulnerabilities compared to existing approaches.
dc.description.versionPublished
dc.format.extent609-614
dc.identifier.citationA. Hossain, N. S. Sizan, B. Kawsar and T. S. Tanny, "Automated Black-Box Detection of Insecure Direct Object Reference (IDOR) Vulnerabilities in Web Applications," 2025 IEEE 4th International Conference on Robotics, Automation, Artificial-Intelligence and Internet-of-Things (RAAICON), Dhaka, Bangladesh, 2025, pp. 609-614, doi: 10.1109/RAAICON69033.2025.11502030.
dc.identifier.doi10.1109/RAAICON69033.2025.11502030
dc.identifier.issn9798331592813
dc.identifier.other2-s2.0-105041067016
dc.identifier.urihttps://hdl.handle.net/10361/29097
dc.language.isoen_US
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.relation.hasversion10.1109/RAAICON69033.2025.11502030
dc.relation.ispartof2025 IEEE 4th International Conference on Robotics Automation Artificial Intelligence and Internet of Things Raaicon 2025
dc.relation.ispartofseries2025 IEEE 4th International Conference on Robotics Automation Artificial Intelligence and Internet of Things Raaicon 2025
dc.relation.urihttps://ieeexplore.ieee.org/document/11502030
dc.rightsfalse
dc.subjectAutomated vulnerability testing
dc.subjectBroken authentication
dc.subjectInsecure direct object reference
dc.subjectParameter manipulation
dc.subjectWeb application
dc.subject.lcshWeb services.
dc.subject.lcshInternet of things.
dc.titleAutomated black-box detection of Insecure Direct Object Reference (IDOR) vulnerabilities in web applications
dc.typeConference Proceeding
person.affiliation.nameDaffodil International University
person.affiliation.nameJagannath University, Bangladesh
person.affiliation.nameDaffodil International University
person.affiliation.nameBRAC University
person.identifier.scopus-author-id60676469300
person.identifier.scopus-author-id57982304800
person.identifier.scopus-author-id60676901100
person.identifier.scopus-author-id60676901200

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Demo.jpg
Size:
27.35 KB
Format:
Joint Photographic Experts Group/JPEG File Interchange Format (JFIF)

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: