Methods for Constructing Request Structures to Mobile Application Server Endpoints for Attack Surface Identification
News
Methods for Constructing Request Structures to Mobile Application Server Endpoints for Attack Surface Identification
Abstract
This paper addresses the problem of identifying the attack surface of mobile applications in the context of the increasing number of attacks exploiting API interfaces. The absence of unified approaches that consider mobile applications as entry points into corporate infrastructure is highlighted. A comprehensive approach to identifying vulnerable functionalities without analyzing the server-side implementation is proposed. The approach includes methods for discovering server interfaces and constructing HTTP request templates for dynamic application security testing (DAST) or fuzzing. The hypothesis is formulated that the proposed approach can improve the accuracy of attack surface identification and enable proactive detection of information security vulnerabilities at early stages of the software development lifecycle. The practical significance of the study lies in increasing security testing coverage and reducing the risks of exploitation through server-side interfaces. The proposed methods are applicable to major mobile platforms, including Android (Java/Kotlin) and iOS (Swift/Objective-C). Unlike traditional security analysis methods based primarily on dynamic black box testing or manual reverse engineering, the proposed approach implements static analysis with semantic extraction of interaction points. The existing automated analysis tools are mainly focused on identifying typical vulnerabilities in client code: insecure data storage, incorrect certificate validation, and redundant permissions. However, the task of systematically mapping server-side APIs based on source code analysis in order to form an attack surface remains insufficiently developed in scientific literature and practice.
Keywords
Edition
Proceedings of the Institute for System Programming, vol. 38, issue 4, part 2, 2026, pp. 161-176
ISSN 2220-6426 (Online), ISSN 2079-8156 (Print).
DOI: 10.15514/ISPRAS-2026-38(4)-24
For citation
Full text of the paper in pdf (in Russian)
Back to the contents of the volume