Pith. sign in

REVIEW 4 major objections 7 minor 204 references

A Survey on Web Application Testing: A Decade of Evolution

T0 review · 4 major / 7 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read A systematic review of 314 papers maps a decade of web application testing, from test generation and execution to evaluation metrics and tools.

desk verdict A useful but flawed survey: the RQ-organized map of 314 papers is handy, yet the unvalidated open-access/title-only corpus undercuts the 'comprehensive' claim. read the letter →

arxiv 2412.10476 v2 pith:G4SP73NP submitted 2024-12-13 cs.SE

classification cs.SE
keywords webapplicationtestingsystematicreviewtestcasegenerationexecutionevaluationmetricstoolssoftwarequalityassurancevulnerabilitydetection
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This survey sets out to establish a field-level picture of web application testing over the decade 2014-2023, based on 314 primary studies drawn from five major digital libraries. It claims that the literature can be organized around six questions: how the field evolved, how test cases are generated and executed, how results are evaluated, what tools exist, and what challenges remain. If the picture is right, it gives researchers and practitioners a reliable baseline for what has been tried, what has worked, and where the gaps are. The paper also identifies the dominant concerns of the decade, notably security- and vulnerability-oriented testing, and points to scalable automation, standardized metrics, and large language models as the next frontier.

What carries the argument

The load-bearing machinery is the literature-review protocol: six research questions, tailored keyword queries over five digital libraries, inclusion and exclusion criteria (English, WAT-related, not theses or prior surveys, open access), and snowballing from reference lists. What carries the argument is the resulting corpus of 314 primary studies, categorized by topic, generation method, execution mode, metric, tool, and challenge; the reported percentages (for example, 29.94% vulnerability detection as an objective, 27.50% model-based generation, 91.08% automated execution) are the concrete evidence for the survey's characterization of the decade.

What would settle it

A replication of the search that broadens the inclusion rules (for example, adding closed-access papers, theses, or additional libraries) and finds that the leading shares—vulnerability detection at 29.94% or automated execution at 91.08%—move by more than a few percentage points would demonstrate that the reported landscape is an artifact of the protocol rather than a property of the field.

Watch

Extended reading notes

Core claim

The paper's central claim is that its six-question framework, applied to a systematically selected corpus of 314 open-access papers, yields a fair and representative account of a decade of web application testing research. On that basis it reports that web vulnerability detection and security testing together dominate the field's objectives, that model-based testing is the most common test-case generation strategy, that automated execution prevails in local environments, and that security testing tools are the most frequently discussed tool category. It further claims that the main open problems are scaling automation to dynamic and asynchronous applications, maintaining test suites under UI churn, tool fragmentation, and the absence of standardized evaluation metrics.

Load-bearing premise

The survey's conclusions depend on the assumption that the 314 papers selected from five digital libraries using title-restricted keyword queries, open-access filtering, and exclusion of theses and prior surveys are a representative sample of web application testing research from 2014 to 2023, an assumption the authors state directly when they say they are confident the overall trends are accurate.

Editorial extensions

If this is right

  • The dominant position of security and vulnerability testing suggests that the field's center of gravity shifted toward attack-surface assurance rather than general functional correctness.
  • Model-based testing being the most common generation method implies that structural models of application behavior remain the default raw material for automated test creation.
  • The prevalence of automated execution and local environments indicates that most published work targets repeatable, controlled evaluation rather than distributed, real-world conditions.
  • The identified lack of standardized metrics means that cross-study comparisons of testing effectiveness and efficiency are not yet trustworthy.
  • Challenges around dynamic content, asynchronous operations, and UI churn imply that test-suite maintenance, not initial generation, is a key cost driver for web applications.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The survey leaves implicit that its corpus, dominated by conference papers and open-access sources, may overrepresent early-announced techniques and underrepresent industrial practice and negative results; a reader should treat the percentages as proportions of the indexed literature, not of actual testing activity.
  • One consequence the authors do not draw: the heavy concentration on security objectives suggests that web application testing research and web security research are converging, so future surveys may need to treat security tooling as a first-class testing concern rather than a separate discipline.
  • A testable extension would be to feed the same six-question taxonomy to a corpus that includes theses, closed-access venues, and the 2024-2025 literature to see whether the reported proportions shift; if they shift substantially, the decade picture is an artifact of the search boundary.
  • A reader should also note an internal inconsistency the paper itself does not address: the conclusion says the review was guided by eight research questions, while Section 3 defines six; the six in Section 3 are the operative ones and the eight appears to be an editing slip.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 7 minor

Summary. This manuscript reports a systematic literature survey of web application testing (WAT) research published between January 2014 and December 2023. The authors retrieved 314 open-access papers from ACM, Elsevier, IEEE, Springer, and Wiley using title-restricted keyword queries, then classified them according to six research questions covering publication trends, test-case generation, test execution, evaluation metrics, available tools, and challenges/future work. The paper reports proportional distributions for test objectives, generation methods, execution modes, metrics, and tool categories, and it provides an appendix listing all included studies plus a supplementary repository.

Significance. If the corpus is representative, the survey would be a useful reference for researchers and practitioners: it assembles a large catalog of WAT papers, organizes them into a structured taxonomy, and provides tables of datasets and tools with links. The authors make the underlying data available in a supplementary repository, which is a strength for reproducibility. The paper's empirical claims are arithmetic summaries of manual classifications rather than fitted or predicted quantities, so there is no circularity burden. However, the central claim of comprehensiveness rests on an unvalidated corpus-selection procedure, and there are internal contradictions between the announced scope and the executed scope. These issues are load-bearing for a survey whose main contribution is its claimed fair representation of a decade of research.

major comments (4)
  1. [§1 and §3.2] The Introduction states that the paper explores WAT 'from the perspectives of test case generation and execution, failure diagnosis, evaluation and assessment, regression testing, and available tools,' but Section 3.2 explicitly excludes 'failure diagnosis and regression testing for web applications' from the survey. This is a direct contradiction in the scope of the claimed contribution. Section 7.1 also lists 'failure diagnosis' among primary effectiveness metrics without providing a corresponding analysis subsection. The authors should either include these topics in the corpus and analysis or clearly revise the Introduction and Section 7.1 so that the stated scope matches the executed scope.
  2. [§3.2 and Table 1] The corpus-selection methodology is not validated against the field, although all reported proportions in Sections 5-8 are computed from this corpus. The search is restricted to titles containing 'web' or 'browser based' together with a test-related term, which systematically excludes influential WAT papers whose titles refer instead to Selenium, AJAX, DOM, JavaScript, or specific vulnerability names. The open-access filter further excludes paywalled papers from venues such as IEEE TSE, ACM TOSEM, ICSE, and FSE. The assertion in Section 3.2 that the authors are 'confident that the overall trends we report on are accurate and provide a fair representation' is unsupported because no recall or precision check against a gold-standard set is reported. I recommend adding a validation study, such as comparing the retrieved set against a manually assembled list of landmark WAT papers, and reporting the resulting recall; alternatively, the paper should be reframed as a survey of open-access, title-matching papers rather than a comprehensive overview.
  3. [§3.2 and Table 2] The description of the snowballing step is inconsistent with Table 2. The table shows 314 papers remaining after applying selection criteria to the keyword-based search results, but the text then says that a snowballing approach 'led to the identification and inclusion of several additional papers' and that 'eventually, 314 papers were included.' If snowballing added papers, the final count should exceed the post-filter count unless the table already includes snowballed papers. This makes the corpus-construction process irreproducible as described. Please clarify the exact role of snowballing and adjust the table or the text accordingly.
  4. [§1, §3.1, and §10] The number of research questions is internally inconsistent. The Introduction says the methodology presents 'six research questions,' Section 3.1 lists exactly six RQs, but the Conclusion states that 'Our review was guided by eight research questions.' This inconsistency affects the reader's ability to trust the organization of the survey and should be corrected.
minor comments (7)
  1. [Figures 4-10] The pie charts and tables use the Chinese column header '类别 数量' instead of English labels; these should be translated or removed for consistency with the rest of the manuscript.
  2. [§1, last paragraph] The sentence 'Sections 4 to ?? address each of the research questions' contains a literal '??' placeholder that should be replaced with specific section numbers.
  3. [§4.2] The sentence beginning 'The papers analyzed in this study were from various journals and conferences. As shown in, the majority...' has an incomplete cross-reference after 'As shown in'; the figure reference should be completed.
  4. [§7.1 and §7.2] The counts in Figures 8 and 9 sum to 268 and 266, respectively, rather than 314, indicating that some papers report multiple metrics. The text refers to these as proportions 'of the papers' without stating the denominator; please clarify that percentages are computed over metric occurrences, not over papers.
  5. [§5.2.3 and §7.2.1] There are citation inconsistencies: LoadRunner is attributed to reference [32] but the LoadRunner discussion appears in reference [87], and the WebQT tool is discussed with reference [73] in Section 7.2.1 while it appears with reference [37] in Section 5.3.3. These citations should be checked and corrected.
  6. [References] Several cited works are dated 2024, which is outside the stated 2014-2023 publication window for included studies. If these are used only as contextual or future-work references this should be made clear; if they are treated as corpus evidence, they violate the inclusion criteria.
  7. [Table 4] The OWASP AppSensor entry appears twice in the table, and the tool name 'jÄk' is inconsistent with the spelling 'jäk' used in the reference list. These duplicates and typographical inconsistencies should be fixed.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the survey's reported trends are arithmetic summaries of its own 314-paper corpus, not predictions or fitted results; the corpus-selection limitation is a validity concern, not a circular one.

full rationale

The paper is a literature survey, and its empirical content consists of counts and percentages computed by classifying the 314 retained papers (Tables 1 and 2; Figures 4 through 10). Every reported proportion — test objectives, generation methods, execution modes, metrics, tools, and venue distributions — is an arithmetic summary of the authors' manual tags on that corpus, so there is no fitted parameter, prediction, or derived quantity that could reduce to an input by construction. The methodology section (Section 3.2) explicitly concedes a possible selection limitation: 'Although some papers may have been omitted due to the focus on a subset of reputable publishers, we are confident that the overall trends we report on are accurate and provide a fair representation of the current state of the art in WAT.' This is a representativeness and validity assumption, not circularity: the summaries would still equal the tagged corpus even if the corpus were biased. Self-citations exist — the survey follows the review framework of Huang et al. [80], cites the authors' earlier WAT survey [104] as background, and points to its own supplementary material [101] — but none of these carries the load of the reported trends; the trends come from the 314 primary studies whose titles and venues are listed in Appendix A. Because the central claims are self-contained arithmetic classifications rather than derivations, the circularity score is 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The central claim rests on corpus representativeness and classification reliability rather than on free parameters or invented entities. There are no fitted constants; the survey is a descriptive literature review.

assumptions (3)
  • domain assumption The five selected digital libraries and the title-restricted keyword queries recover a representative sample of WAT research from 2014 to 2023.
    The survey's trend statistics, such as 29.94 percent vulnerability detection and 27.50 percent model-based testing, are only meaningful if the 314-paper corpus is representative. Section 3.2 states this assumption and admits that some papers may have been omitted.
  • domain assumption Manual relevance screening and classification of each retrieved paper into the proposed RQ taxonomy are accurate and consistent.
    Section 3.3 says key information was extracted and verified by co-authors, but no inter-rater agreement or coding protocol is reported.
  • ad hoc to paper The authors' taxonomy of test objectives, generation methods, execution modes, metrics, and tool categories is comprehensive and non-overlapping.
    The categories in Figures 4 through 10 are introduced for this survey, and no validation against an external classification is provided.

how reviews work

0 comments
Cite this review

Pith. "Pith review of A Survey on Web Application Testing: A Decade of Evolution." pith.science (2026). https://pith.science/paper/G4SP73NP

@misc{pith2026241210476,
  author       = {Pith},
  title        = {Pith review of: A Survey on Web Application Testing: A Decade of Evolution},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/G4SP73NP}},
  note         = {Machine review of arXiv:2412.10476}
}
read the original abstract

As one of the most popular software applications, a web application is a program, accessible through the web, to dynamically generate content based on user interactions or contextual data, for example, online shopping platforms, social networking sites, and financial services. Web applications operate in diverse environments and leverage web technologies such as HTML, CSS, JavaScript, and Ajax, often incorporating features like asynchronous operations to enhance user experience. Due to the increasing user and popularity of web applications, approaches to their quality have become increasingly important. Web Application Testing (WAT) plays a vital role in ensuring web applications' functionality, security, and reliability. Given the speed with which web technologies are evolving, WAT is especially important. Over the last decade, various WAT approaches have been developed. The diversity of approaches reflects the many aspects of web applications, such as dynamic content, asynchronous operations, and diverse user environments. This paper provides a comprehensive overview of the main achievements during the past decade: It examines the main steps involved in WAT, including test-case generation and execution, and evaluation and assessment. The currently available tools for WAT are also examined. The paper also discusses some open research challenges and potential future WAT work.

Figures

Figures reproduced from arXiv: 2412.10476 by the authors.

Figure 1
Figure 1. Structure of this survey paper [PITH_FULL_IMAGE:figures/full_fig_p005_1.png] view at source ↗
Figure 2
Figure 2. WAT papers published between January 1, 2014, and December 31, 2023. [PITH_FULL_IMAGE:figures/full_fig_p007_2.png] view at source ↗
Figure 3
Figure 3. Venue distribution of surveyed papers. for example, require stringent security measures, whereas government portals may focus on accessibility. • E-commerce Platforms: E-commerce applications such as Magento, Shopify, and custom￾built online stores are popular WAT AUTs. This may be due to their complex transactional workflows, which involve user authentication, shopping carts, and payment gateways [144]. Testing oft… view at source ↗
Figures from the paper (7 more)
Figure 4
Figure 4. Figure 4: Proportions of test objectives in surveyed papers. [PITH_FULL_IMAGE:figures/full_fig_p010_4.png]
Figure 5
Figure 5. Figure 5: Proportions of generation methods in surveyed papers. [PITH_FULL_IMAGE:figures/full_fig_p012_5.png]
Figure 6
Figure 6. Figure 6: Proportions of execution environments in surveyed papers. [PITH_FULL_IMAGE:figures/full_fig_p014_6.png]
Figure 7
Figure 7. Figure 7: Proportions of execution methods in surveyed papers. [PITH_FULL_IMAGE:figures/full_fig_p016_7.png]
Figure 8
Figure 8. Figure 8: Proportions of test effectiveness metrics in surveyed papers. [PITH_FULL_IMAGE:figures/full_fig_p017_8.png]
Figure 9
Figure 9. Figure 9: Proportions of test efficiency metrics in survey papers. [PITH_FULL_IMAGE:figures/full_fig_p019_9.png]
Figure 10
Figure 10. Figure 10: Proportions of testing tools in surveyed papers. [PITH_FULL_IMAGE:figures/full_fig_p021_10.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

204 extracted references · 78 canonical work pages

  1. [1]

    R Aditya, AJ Advaith, G Sabarinath, Rahul S Rajeev, Sreya Sunil Kurup, and T Anjali. 2023. An ensemble approach for visual testing of web applications. In Proceedings of the 3rd International Conference on Emerging Frontiers in Electrical and Electronic Technologies (ICEFEET’23). 1–5

  2. [2]

    Ole Agesen. 1995. The cartesian product algorithm: Simple and precise type inference of parametric polymorphism. In Proceedings of the 9th European Conference on Object-Oriented Programming (ECOOP’95) . 2–26

  3. [3]

    Pelin Akpinar, Mehmet S Aktas, Alper Bugra Keles, Yunus Balaman, Zeynep Ozdemir Guler, and Oya Kalipsiz

  4. [4]

    Rim Akrout, Eric Alata, Mohamed Kaaniche, and Vincent Nicomette. 2014. An automated black box approach for web vulnerability identification and attack scenario generation. Journal of the Brazilian Computer Society 20 (2014), 1–16

  5. [5]

    Saranya Alagarsamy, Chakkrit Tantithamthavorn, and Aldeida Aleti. 2024. A3test: Assertion-augmented automated test case generation. Information and Software Technology 176 (2024), 107565

  6. [6]

    Amira Ali and Nagwa Badr. 2015. Performance testing as a service for web applications. In Proceedings of the IEEE 7th International Conference on Intelligent Computing and Information Systems (ICICIS’15) . 356–361

  7. [7]

    Malik Muhammad Ali-Shahid and Shahida Sulaiman. 2015. A case study on reliability and usability testing of a web portal. In Proceedings of the 9th Malaysian Software Engineering Conference (MySEC’15) . 31–36

  8. [8]

    Hamza Alkofahi, David Umphress, and Heba Alawneh. 2022. Discovering authorization business rules toward detecting web applications logic flaws. In Proceedings of the 2022 International Arab Conference on Information Technology (ACIT’22). 1–7

Show all 204 references
  1. [9]

    Shayma Ahmed Altayaran and Wael Elmedany. 2021. Integrating web application security penetration testing into the software development life cycle: A systematic literature review. InProceedings of the 2021 International Conference on Data Analytics for Business and Industry (IC...

  2. [10]

    Richard Amankwah, Jinfu Chen, Patrick Kwaku Kudjo, Beatrice Korkor Agyemang, and Alfred Adutwum Amponsah

  3. [11]

    Saule Amanzholova, Darya Akhmetova, and Azhar Sagymbekova. 2021. Development of a web-resources testing system for compliance with GDPR regulation. In Proceedings of the 7th International Conference on Engineering and MIS (ICEMIS’21)). 1–6

  4. [12]

    Service Oriented Computing and Applications 14 (2020), 297–307

    An automated framework for evaluating open-source web scanner vulnerability severity. Service Oriented Computing and Applications 14 (2020), 297–307

  5. [13]

    Mohammadhossein Amouei, Mohsen Rezvani, and Mansoor Fateh. 2021. RAT: Reinforcement-learning-driven and adaptive testing for vulnerability discovery in web application firewalls. IEEE Transactions on Dependable and Secure Computing 19, 5 (2021), 3371–3386

  6. [14]

    Paul Ammann and Jeff Offutt. 2017. Introduction to software testing . Cambridge University Press

  7. [15]

    Saswat Anand, Edmund K Burke, Tsong Yueh Chen, John Clark, Myra B Cohen, Wolfgang Grieskamp, Mark Harman, Mary Jean Harrold, Phil McMinn, Antonia Bertolino, et al . 2013. An orchestrated survey of methodologies for automated software test case generation. Journal of systems an...

  8. [16]

    Karthik Anagandula and Pavol Zavarsky. 2020. An analysis of effectiveness of black-box web application scanners in detection of stored SQL injection and stored XSS vulnerabilities. In Proceedings of the 3rd International Conference on Data Intelligence and Security (ICDIS’20) . 40–48

  9. [17]

    Jinat Ara, Cecilia Sik-Lanyi, and Arpad Kelemen. 2024. Accessibility engineering in web evaluation process: A systematic literature review. Universal Access in the Information Society 23, 2 (2024), 653–686. J. ACM, Vol. 37, No. 4, Article 111. Publication date: August 2018. A ...

  10. [18]

    Dennis Appelt, Cu D Nguyen, Annibale Panichella, and Lionel C Briand. 2018. A machine-learning-driven evolutionary approach for testing web application firewalls. IEEE Transactions on Reliability 67, 3 (2018), 733–757

  11. [19]

    Anuja Arora and Madhavi Sinha. 2013. Dynamic content testing of web application using user session based state testing. In Proceedings of the 4th International Conference-Confluence The Next Generation Information Technology Summit (Confluence’13). 22–28

  12. [20]

    Andrea Arcuri, Man Zhang, Amid Golmohammadi, Asma Belhadi, Juan P Galeotti, Bogdan Marculescu, and Susruthan Seran. 2023. EMB: A curated corpus of web/enterprise applications and library support for software testing research. In Proceedings of the 16th IEEE Conference on Softw...

  13. [21]

    Murat Aydos, Çiğdem Aldan, Evren Coşkun, and Alperen Soydan. 2022. Security testing of web applications: A systematic mapping of the literature. Journal of King Saud University-Computer and Information Sciences 34, 9 (2022), 6775–6792

  14. [22]

    Nor Fatimah Awang, Ahmad Dahari Jarno, Syahaneim Marzuki, Nor Azliana Akmal Jamaludin, Khairani Abd Majid, and Taniza Tajuddin. 2019. Method for generating test data for detecting SQL injection vulnerability in web application. In Proceedings of the 7th International Conferenc...

  15. [23]

    Sebastian Balsam and Deepti Mishra. 2024. Web application testing—Challenges and opportunities.Journal of Systems and Software (2024), 112186

  16. [24]

    Juliana Marino Balera and Valdivino Alexandre de Santiago Júnior. 2022. Multiperspective web testing supported by a generation hyper-heuristic. In Proceedings of the 22nd International Conference on Computational Science and Its Applications (ICCSA’22). 447–462

  17. [25]

    Wafa Ben Jaballah and Nizar Kheir. 2016. A grey-box approach for detecting malicious user interactions in web applications. In Proceedings of the 8th ACM CCS International Workshop on Managing Insider Security Threats (MIST’16) . 1–12

  18. [26]

    Giuseppe Beltrano, Claudia Greco, Michele Ianni, and Giancarlo Fortino. 2023. Deep learning-based detection of CSRF vulnerabilities in web applications. In Proceedings of the 2023 IEEE International Conference on Dependable, Autonomic and Secure Computing, International Confer...

  19. [27]

    Oussama Beroual, Francis Guérin, and Sylvain Hallé. 2020. Detecting responsive web design bugs with declarative specifications. In Proceedings of the 20th International Conference on Web Engineering (ICWE’20) . 3–18

  20. [28]

    Berners-Lee

    T.J. Berners-Lee. 1992. The world-wide web. Computer networks and ISDN systems 25, 4 (1992), 454–459

  21. [29]

    SM Bindu Bhargavi and V Suma. 2022. A survey of the software test methods and identification of critical success factors for automation. SN Computer Science 3, 6 (2022), 449

  22. [30]

    Thilini Bhagya, Jens Dietrich, and Hans Guesgen. 2019. Generating mock skeletons for lightweight web-service testing. In Proceedings of the 26th Asia-Pacific Software Engineering Conference (APSEC’19) . 181–188

  23. [31]

    Josip Bozic, Bernhard Garn, Dimitris E Simos, and Franz Wotawa. 2015. Evaluation of the IPO-family algorithms for test case generation in web security testing. In Proceedings of the IEEE 8th International Conference on Software Testing, Verification and Validation Workshops (I...

  24. [32]

    Josip Bozic, Bernhard Garn, Ioannis Kapsalis, Dimitris Simos, Severin Winkler, and Franz Wotawa. 2015. Attack pattern- based combinatorial testing with constraints for web security testing. In Proceedings of the 2015 IEEE International Conference on Software Quality, Reliabili...

  25. [33]

    Stefano Calzavara, Mauro Conti, Riccardo Focardi, Alvise Rabitti, and Gabriele Tolomei. 2020. Machine learning for web vulnerability detection: The case of cross-site request forgery. IEEE Security and Privacy 18, 3 (2020), 8–16

  26. [34]

    Jianhua Cai and Qingchun Hu. 2014. Analysis for cloud testing of web application. In Proceedings of the 2nd International Conference on Systems and Informatics (ICSAI’14) . 293–297

  27. [35]

    Milton Campoverde-Molina, Sergio Luján-Mora, and Llorenç Valverde. 2021. Process model for continuous testing of web accessibility. IEEE Access 9 (2021), 139576–139593

  28. [36]

    Stefano Calzavara, Hugo Jonker, Benjamin Krumnow, and Alvise Rabitti. 2021. Measuring web session security at scale. Computers & Security 111 (2021), 102472

  29. [37]

    Xiaoning Chang, Zheheng Liang, Yifei Zhang, Lei Cui, Zhenyue Long, Guoquan Wu, Yu Gao, Wei Chen, Jun Wei, and Tao Huang. 2023. A reinforcement learning approach to generating test cases for web applications. In Proceedings of the 2023 IEEE/ACM International Conference on Autom...

  30. [38]

    Nazanin Bayati Chaleshtari, Fabrizio Pastore, Arda Goknil, and Lionel C Briand. 2023. Metamorphic testing for web system security. IEEE Transactions on Software Engineering 49, 6 (2023), 3430–3471

  31. [39]

    Wei Chen, Hanyang Cao, and Xavier Blanc. 2021. An improving approach for DOM-based web test suite repair. In Proceedings of the 21st International Conference on Web Engineering (ICWE’21) . 372–387

  32. [40]

    Tsong Yueh Chen, Fei-Ching Kuo, Huai Liu, Pak-Lok Poon, Dave Towey, TH Tse, and Zhi Quan Zhou. 2018. Meta- morphic testing: A review of challenges and opportunities. Comput. Surveys 51, 1 (2018), 4–1

  33. [41]

    Yanpeng Cui, Junjie Cui, and Jianwei Hu. 2020. A survey on XSS attack detection and prevention in web applications. In Proceedings of the 12th International Conference on Machine Learning and Computing (ICMLC’20) . 443–449

  34. [42]

    Anna Corazza, Sergio Di Martino, Adriano Peron, and Luigi Libero Lucio Starace. 2021. Web application testing: Using tree kernels to detect near-duplicate states in automated model inference. In Proceedings of the 15th ACM/IEEE J. ACM, Vol. 37, No. 4, Article 111. Publication ...

  35. [43]

    Romulo de Almeida Neves, Willian Massami Watanabe, and Rafael Oliveira. 2022. Morpheus web testing: A tool for generating test cases for widget based web applications. Journal of Web Engineering 21, 2 (2022), 119–144

  36. [44]

    Xiao Dawei, Jiang Liqiu, Xu Xinpeng, and Wang Yuhang. 2016. Web application automatic testing solution. In Proceedings of the 3rd International Conference on Information Science and Control Engineering (ICISCE’16) . 1183–1187

  37. [45]

    Jessica Lasch de Moura, Andrea Schwertner Charao, João Carlos Damasceno Lima, and Benhur de Oliveira Stein

  38. [46]

    Flávio Rezende de Jesus, Leandro Guarino de Vasconcelos, and Laércio A Baldochi. 2015. Leveraging task-based data to support functional testing of web applications. In Proceedings of the 30th Annual ACM Symposium on Applied Computing (SAC’15). 783–790

  39. [47]

    Dilek Yilmazer Demirel and Mehmet Tahir Sandikkaya. 2023. ACUM: An approach to combining unsupervised methods for detecting malicious web sessions. In Proceedings of the 8th International Conference on Computer Science and Engineering (UBMK’23). 288–293

  40. [48]

    R Sri Devi and M Mohan Kumar. 2020. Testing for security weakness of web applications using ethical hacking. In Proceedings of the 2020 4th International Conference on Trends in Electronics and Informatics (ICOEI’20) . IEEE, 354–361

  41. [49]

    Vidroha Debroy, Lance Brimble, Matthew Yost, and Archana Erry. 2018. Automating web application testing from the ground up: Experiences and lessons learned in an industrial setting. In Proceedings of the IEEE 11th International Conference on Software Testing, Verification and ...

  42. [50]

    Serdar Doğan, Aysu Betin-Can, and Vahid Garousi. 2014. Web application testing: A systematic literature review. Journal of Systems and Software 91 (2014), 174–201

  43. [51]

    K Naveen Durai, R Subha, and Anandakumar Haldorai. 2021. A novel method to detect and prevent SQLIA using ontology to cloud web security. Wireless Personal Communications 117, 4 (2021), 2995–3014

  44. [52]

    Arilo C Dias Neto, Rajesh Subramanyan, Marlon Vieira, and Guilherme H Travassos. 2007. A survey on model-based testing approaches: A systematic review. InProceedings of the 1st ACM international workshop on Empirical assessment of software engineering languages and technologie...

  45. [53]

    Gerald D Everett and Raymond McLeod Jr. 2007. Software testing: Testing across the entire software development life cycle. John Wiley and Sons

  46. [54]

    Yujia Fan, Sinan Wang, Zebang Fei, Yao Qin, Huaxuan Li, and Yepang Liu. 2024. Can cooperative multi-agent reinforcement learning boost automatic web testing? An exploratory study. In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering (A...

  47. [55]

    Sebastian Elbaum, Hui Nee Chin, Matthew B Dwyer, and Matthew Jorde. 2008. Carving and replaying differential unit test cases from system test cases. IEEE Transactions on Software Engineering 35, 1 (2008), 29–45

  48. [56]

    Michael Felderer, Matthias Büchler, Martin Johns, Achim D Brucker, Ruth Breu, and Alexander Pretschner. 2016. Security testing: A survey. In Advances in Computers. Vol. 101. 1–51

  49. [57]

    Ana Fidalgo, Ibéria Medeiros, Paulo Antunes, and Nuno Neves. 2020. Towards a deep learning model for vulnerability detection on web application variants. In Proceedings of the 13th IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW’...

  50. [58]

    Yujia Fan, Siyi Wang, Sinan Wang, Yepang Liu, Guoyao Wen, and Qi Rong. 2023. A comprehensive evaluation of Q-learning based automatic web GUI testing. InProceedings of the 10th International Conference on Dependable Systems and Their Applications (DSA’23). 12–23

  51. [59]

    Tommaso Fulcini and Luca Ardito. 2022. Gamified exploratory GUI testing of web applications: A preliminary evaluation. In Proceedings of the 2022 IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW’22). 215–222

  52. [60]

    Disha Garg, Abhishek Singhal, and Abhay Bansal. 2015. A framework for testing web applications using action word based testing. In Proceedings of the 1st International Conference on Next Generation Computing Technologies (NGCT’15) . 593–598

  53. [61]

    Mridha Md Nafis Fuad and Kazi Sakib. 2023. WebEV: A dataset on the behavior of testers for web application end to end testing. In Proceedings of the IEEE/ACM 31st International Conference on Program Comprehension (ICPC’23) . 79–83

  54. [62]

    Vahid Garousi, Alper Buğra Keleş, Yunus Balaman, Zeynep Özdemir Güler, and Andrea Arcuri. 2021. Model-based testing in practice: An experience report from the web applications domain. Journal of Systems and Software 180 J. ACM, Vol. 37, No. 4, Article 111. Publication date: Au...

  55. [63]

    Vahid Garousi, Ali Mesbah, Aysu Betin-Can, and Shabnam Mirshokraie. 2013. A systematic mapping study of web application testing. Information and Software Technology 55, 8 (2013), 1374–1396

  56. [64]

    Bernhard Garn, Ioannis Kapsalis, Dimitris E Simos, and Severin Winkler. 2014. On the applicability of combinatorial testing to web application security testing: A case study. In Proceedings of the 2014 Workshop on Joining AcadeMiA and Industry Contributions to Test Automation ...

  57. [65]

    Bronjon Gogoi, Tasiruddin Ahmed, and Ratnaboli Ghorai Dinda. 2022. PHP web shell detection through static analysis of AST using LSTM based deep learning. In Proceedings of the 1st International Conference on Artificial Intelligence Trends and Pattern Recognition (ICAITPR’22) . 1–6

  58. [66]

    Amid Golmohammadi, Man Zhang, and Andrea Arcuri. 2023. Testing restful APIs: A survey. ACM Transactions on Software Engineering and Methodology 33, 1 (2023), 1–41

  59. [67]

    Jesse James Garrett et al. 2005. Ajax: A new approach to web applications. Technical Report (2005)

  60. [68]

    Zhibin Guan, Jiajie Wang, Xiaomeng Wang, Wei Xin, Jing Cui, and Xiangping Jing. 2021. A comparative study of RNN-based methods for web malicious code detection. In Proceedings of the IEEE 6th International Conference on Computer and Communication Systems (ICCCS’21) . 769–773

  61. [69]

    Marco Guarnieri, Petar Tsankov, Tristan Buchs, Mohammad Torabi Dashti, and David Basin. 2017. Test execution checkpointing for web applications. In Proceedings of the 26th ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA’17). 203–214

  62. [70]

    Maciej Grzenda, Stanisław Kaźmierczak, Marcin Luckner, Grzegorz Borowik, and Jacek Mańdziuk. 2023. Evaluation of machine learning methods for impostor detection in web applications. Expert Systems with Applications 231 (2023), 120736

  63. [71]

    Mukesh Kumar Gupta, Mahesh Chandra Govil, and Girdhari Singh. 2015. Text-mining based predictive model to detect XSS vulnerable files in web applications. In Proceedings of the 2015 Annual IEEE India Conference (INDICON’15) . 1–6

  64. [72]

    Nishant Gupta, Vibhash Yadav, and Mayank Singh. 2018. Automated regression test case generation for web application: A survey. Comput. Surveys 51, 4 (2018), 1–25

  65. [73]

    Govil, and Girdhari Singh

    Mukesh Kumar Gupta, M.C. Govil, and Girdhari Singh. 2014. Static analysis approaches to detect SQL injection and cross site scripting vulnerabilities in web applications: A survey. In Proceedings of the 1st International Conference on Recent Advances and Innovations in Enginee...

  66. [74]

    Elahe Habibi and Seyed-Hassan Mirian-Hosseinabadi. 2015. Event-driven web application testing based on model- based mutation testing. Information and Software Technology 67 (2015), 159–179

  67. [75]

    Axel Halin, Alexandre Nuttinck, Mathieu Acher, Xavier Devroey, Gilles Perrouin, and Benoit Baudry. 2019. Test them all, is it worth it? Assessing configuration sampling on the JHipster web development stack. Empirical Software Engineering 24 (2019), 674–717

  68. [76]

    Rashmi Gupta and Neha Bajpai. 2014. A keyword-driven tool for testing Web applications (KeyDriver).IEEE Potentials 33, 5 (2014), 35–42

  69. [77]

    Samer Hanna and Hayat Jaber. 2019. An approach for web applications test data generation based on analyzing client side user input fields. In Proceedings of the 2nd International Conference on New Trends in Computing Sciences (ICTCS’19). 1–6

  70. [78]

    Samer Hanna and Malcolm Munro. 2018. Test case generation for semantic-based user input validation of web applications. International Journal of Web Engineering and Technology 13, 3 (2018), 225–254

  71. [79]

    Samer Hanna and Amro Al-Said Ahmad. 2022. Web applications testing techniques: A systematic mapping study. International Journal of Web Engineering and Technology 17, 4 (2022), 372–412

  72. [80]

    Rubing Huang, Weifeng Sun, Yinyin Xu, Haibo Chen, Dave Towey, and Xin Xia. 2021. A survey on adaptive random testing. IEEE Transactions on Software Engineering 47, 10 (2021), 2052–2083

  73. [81]

    CP Indumathi and A Sabeena Begum. 2016. Web database testing using ER diagram and state transition model. In Proceedings of the 2016 International Conference on Communication and Signal Processing (ICCSP’16) . 1937–1942

  74. [82]

    Mark Harman, Yue Jia, and Yuanyuan Zhang. 2015. Achievements, open problems and challenges for search based software testing. In Proceedings of the IEEE 8th International Conference on Software Testing, Verification and Validation (ICST’15). 1–12

  75. [83]

    Beakcheol Jang, Myeonghwi Kim, Gaspard Harerimana, and Jong Wook Kim. 2019. Q-learning algorithms: A comprehensive classification and applications. IEEE access 7 (2019), 133653–133667

  76. [84]

    Mehdi Jazayeri. 2007. Some trends in web application development. InProccedings of the Future of Software Engineering (FOSE’07). 199–213

  77. [85]

    Indranil Jana and Alina Oprea. 2019. AppMine: Behavioral analytics for web application vulnerability detection. In Proceedings of the 2019 ACM SIGSAC Conference on Cloud Computing Security Workshop (CCSW’19) . 69–80

  78. [86]

    Ali Karimoddini, Mubbashar Altaf Khan, Solomon Gebreyohannes, Mike Heiges, Ethan Trewhitt, and Abdollah Homaifar. 2022. Automatic test and evaluation of autonomous systems. IEEE Access 10 (2022), 72227–72238. J. ACM, Vol. 37, No. 4, Article 111. Publication date: August 2018. ...

  79. [87]

    Rijwan Khan and Mohd Amjad. 2016. Smoke testing of web application based on ALM tool. In Proceedings of the 2016 International Conference on Computing, Communication and Automation (ICCCA’16) . 862–866

  80. [88]

    Yue Jia and Mark Harman. 2010. An analysis and survey of the development of mutation testing. IEEE Transactions on Software Engineering 37, 5 (2010), 649–678

  81. [89]

    Vinodkumar H Kiranagi and Gopal Krishna Shyam. 2017. Feature driven hybrid test automation framework (FDHTAF) for web based or cloud based application testing. In Proceedings of the 2017 International Conference On Smart Technologies For Smart Nation (SmartTechCon’17). 1555–1559

  82. [90]

    Hiroyuki Kirinuki, Shinsuke Matsumoto, Yoshiki Higo, and Shinji Kusumoto. 2021. NLP-assisted web element identi- fication toward script-free testing. In Proceedings of the 37th IEEE International Conference on Software Maintenance and Evolution (ICSME’21). 639–643

  83. [91]

    Sandhya Kiran, Akshyansu Mohapatra, and Rajashekara Swamy. [n. d.]. Experiences in performance testing of web applications with unified authentication platform using Jmeter

  84. [92]

    Deepak Kumar, Zane Ma, Zakir Durumeric, Ariana Mirian, Joshua Mason, J Alex Halderman, and Michael Bailey

  85. [93]

    Pratap Kumar and Ravi K Sheth. 2016. A review on 0-day vulnerability testing in web application. In Proceedings of the 2nd International Conference on Information and Communication Technology for Competitive Strategies (ICTCS’16) . 1–4

  86. [94]

    Ambreen Kousar, Saif Ur Rehman Khan, Shahid Hussain, M Abdul Basit Ur Rahim, Wen-Li Wang, and Naseem Ibrahim. 2023. A systematic review on pattern-based GUI testing of android and web apps: State-of-the-art, taxonomy, challenges and future directions. In Proceedings of the 25t...

  87. [95]

    Maurizio Leotta, Matteo Biagiola, Filippo Ricca, Mariano Ceccato, and Paolo Tonella. 2020. A family of experiments to assess the impact of page object pattern in web test suite development. In Proceedings of the IEEE 13th International Conference on Software Testing, Validatio...

  88. [96]

    In Proceedings of the 26th International Conference on World Wide Web (WWW’17)

    Security challenges in an increasingly tangled web. In Proceedings of the 26th International Conference on World Wide Web (WWW’17). 677–684

  89. [97]

    Maurizio Leotta, Andrea Stocco, Filippo Ricca, and Paolo Tonella. 2015. Meta-heuristic generation of robust XPath locators for web testing. In Proceedings of the IEEE/ACM 8th International Workshop on Search-Based Software Testing (SBST’15). 36–39

  90. [98]

    Shin-Jie Lee, Yu-Xian Chen, Shang-Pin Ma, and Wen-Tin Lee. 2018. Test command auto-wait mechanisms for record and playback-style web application testing. InProceedings of the IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC’18), Vol. 2. 75–80

  91. [99]

    Lukai Li, Ruijie Cai, Yongguang Zhang, and Xiaokang Yin. 2023. Facilitating web vulnerability detection on embedded devices with root path pruning. In Proceedings of the 3rd International Conference on Computer Science, Electronic Information Engineering and Intelligent Contro...

  92. [100]

    Maurizio Leotta, Davide Paparella, and Filippo Ricca. 2024. Mutta: A novel tool for E2E web mutation testing.Software Quality Journal 32, 1 (2024), 5–26

  93. [101]

    Tao Li, Rubing Huang, Chenhui Cui, Dave Towey, and Lei Ma. 2024. More details for a survey on web application testing. https://github.com/abelli1024/wat-survey. Accessed: 2024-10-15

  94. [102]

    Guodong Li, Esben Andreasen, and Indradeep Ghosh. 2014. SymJS: Automatic symbolic testing of JavaScript web applications. In Proceedings of the 22nd ACM SIGSOFT International Symposium on Foundations of Software Engineering (FSE’14). 449–459

  95. [103]

    Xinxin Li and Hongwei Zeng. 2014. Modeling web application for cross-browser compatibility testing. In Proceed- ings of the 15th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD’14). 1–5

  96. [104]

    Tao Li, Chenhui Cui, Lei Ma, Dave Towey, Yujie Xie, and Rubing Huang. 2024. Leveraging large language models for automated web-form-test generation: An empirical study. arXiv 2405.09965 (2024)

  97. [105]

    Hongliang Liang, Xiangyu Li, Da Xiao, Jie Liu, Yanjie Zhou, Aibo Wang, and Jin Li. 2023. Generative pre-trained transformer-based reinforcement learning for testing web application firewalls. IEEE Transactions on Dependable and Secure Computing 21, 1 (2023), 309–324

  98. [106]

    Xiaowei Li, Xujie Si, and Yuan Xue. 2014. Automated black-box detection of access control vulnerabilities in web applications. In Proceedings of the 4th ACM Conference on Data and Application Security and Privacy (SP’14) . 49–60

  99. [107]

    Cuauhtémoc López-Martín. 2022. Machine learning techniques for software testing effort prediction. Software Quality Journal 30, 1 (2022), 65–100

  100. [108]

    Yuan-Fang Li, Paramjit K Das, and David L Dowe. 2014. Two decades of Web application testing-A survey of recent advances. Information Systems 43 (2014), 20–54

  101. [109]

    Romaric Ludinard, Eric Totel, Frédéric Tronel, Vincent Nicomette, Mohamed Kaâniche, Eric Alata, Rim Akrout, and Yann Bachy. 2018. An invariant-based approach for detecting attacks against data in web applications. In Application Development and Design: Concepts, Methodologies,...

  102. [110]

    Jun-Wei Lin, Farn Wang, and Paul Chu. 2017. Using semantic similarity in crawling-based web application testing. In Proceedings of the 10th IEEE International Conference on Software Testing, Verification and Validation (ICST’17) . 138–148

  103. [111]

    Mostafa Mahdieh, Seyed-Hassan Mirian-Hosseinabadi, and Mohsen Mahdieh. 2022. Test case prioritization using test case diversification and fault-proneness estimations. Automated Software Engineering 29, 2 (2022), 50

  104. [112]

    Ouarda Lounis, Salah Eddine Bouhouita Guermeche, and Lalia Saoudi. 2014. A new algorithm for detecting SQL injection attack in Web application. In Proceedings of the 2014 Science and Information Conference (SAI’14) . 589–594. J. ACM, Vol. 37, No. 4, Article 111. Publication da...

  105. [113]

    Leonardo Mariani, Mauro Pezzè, Oliviero Riganelli, and Mauro Santoro. 2014. Link: Exploiting the web of data to generate test inputs. In Proceedings of the 23rd International Symposium on Software Testing and Analysis (ISSTA’14) . 373–384

  106. [114]

    Federico Macchi, Pierpaolo Rosin, Juan Marcos Mervi, and Luca Turchet. 2021. Image-based approaches for automating GUI testing of interactive web-based applications. InProceedings of the 28th Conference of Open Innovations Association (FRUCT’21). 278–285

  107. [115]

    Beatriz Martins and Carlos Duarte. 2023. A large-scale web accessibility analysis considering technology adoption. Universal Access in the Information Society (2023), 1–16

  108. [116]

    Abdalla Wasef Marashdih, Zarul Fitri Zaaba, Khaled Suwais, and Nur Azimah Mohd. 2019. Web application security: An investigation on static analysis with other algorithms to detect cross site scripting. Procedia Computer Science 161 (2019), 1173–1181

  109. [117]

    Guilherme Ricken Mattiello and André Takeshi Endo. 2022. Model-based testing leveraged for automated web tests. Software Quality Journal 30, 3 (2022), 621–649

  110. [118]

    Fabian Marquardt and Lennart Buhl. 2021. Déjà vu? Client-side fingerprinting and version detection of web application software. In Proceedings of the IEEE 46th Conference on Local Computer Networks (LCN’21) . 81–89

  111. [119]

    Ali Mesbah, Arie Van Deursen, and Stefan Lenselink. 2012. Crawling Ajax-based web applications through dynamic analysis of user interface state changes. ACM Transactions on the Web 6, 1 (2012), 1–30

  112. [120]

    Achmad Fahrurrozi Maskur and Yudistira Dwi Wardhana Asnar. 2019. Static code analysis tools with the taint analysis method for detecting web application vulnerability. In Proceedings of the 2019 International Conference on Data and Software Engineering (ICoDSE’19) . 1–6

  113. [121]

    Shabnam Mirshokraie, Ali Mesbah, and Karthik Pattabiraman. 2014. Guided mutation testing for JavaScript web applications. IEEE Transactions on Software Engineering 41, 5 (2014), 429–444

  114. [122]

    Ibéria Medeiros, Nuno Neves, and Miguel Correia. 2016. DEKANT: A static analysis tool that learns to detect web application vulnerabilities. In Proceedings of the 25th International Symposium on Software Testing and Analysis (ISSTA’16). 1–11

  115. [123]

    Humaid Mollah and Petra van den Bos. 2023. From user stories to end-to-end web testing. In Proceedings of the 16th IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW’23) . 140–148

  116. [124]

    Amin Milani Fard, Mehdi Mirzaaghaei, and Ali Mesbah. 2014. Leveraging existing tests in automated test generation for web applications. In Proceedings of the 29th ACM/IEEE International Conference on Automated Software Engineering (ASE’14). 67–78

  117. [125]

    Joydeep Mukherjee, Mea Wang, and Diwakar Krishnamurthy. 2014. Performance testing web applications on the cloud. In Proceedings of the IEEE 7th International Conference on Software Testing, Verification and Validation Workshops (ICSTW’14). 363–369

  118. [126]

    Fawaz Mahiuob Mohammed Mokbal, Wang Dan, Azhar Imran, Lin Jiuchuan, Faheem Akhtar, and Wang Xiaoxi

  119. [127]

    Miguel Nabuco and Ana CR Paiva. 2014. Model-based test case generation for web applications. In Proceedings of the 14th International Conference on Computational Science and Its Applications (ICCSA’14) . 248–262

  120. [128]

    Leckraj Nagowah and Kreshnah Kora-Ramiah. 2017. Automated complete test case coverage for web based applications. In Proceedings of the 2017 International Conference on Infocom Technologies and Unmanned Systems (Trends and Future Directions) (ICTUS’17). 383–390

  121. [129]

    Thiago Santos de Moura, Everton LG Alves, Hugo Feitosa de Figueirêdo, and Cláudio de Souza Baptista. 2023. Cytestion: Automated GUI testing for web applications. InProceedings of the XXXVII Brazilian Symposium on Software Engineering (SBSI’23). 388–397

  122. [130]

    Andy Neumann, Nuno Laranjeiro, and Jorge Bernardino. 2018. An analysis of public REST web service APIs. IEEE Transactions on Services Computing 14, 4 (2018), 957–970. J. ACM, Vol. 37, No. 4, Article 111. Publication date: August 2018. 111:32 Tao Li, Rubing Huang, Chenhui Cui, ...

  123. [131]

    Muhammad Takdir Muslihi and Daniyal Alghazzawi. 2020. Detecting SQL injection on web application using deep learning techniques: A systematic literature review. In Proceedings of the 3rd International Conference on Vocational Education and Electrical Engineering (ICVEE’20) . 1–6

  124. [132]

    Hung Viet Nguyen, Hung Dang Phan, Christian Kästner, and Tien N Nguyen. 2019. Exploring output-based coverage for testing PHP web applications. Automated Software Engineering 26 (2019), 59–85

  125. [133]

    Vu Nguyen, Thanh To, and Gia-Han Diep. 2021. Generating and selecting resilient and maintainable locators for web automated testing. Software Testing, Verification and Reliability 31, 3 (2021), e1760

  126. [134]

    Sangeeta Nagpure and Sonal Kurkure. 2017. Vulnerability assessment and penetration testing of web application. In Proceedings of the 2017 International Conference on Computing, Communication, Control and Automation (ICCUBEA’17) . 1–6

  127. [135]

    K Nirmal, B Janet, and Rajagopal Kumar. 2021. Analyzing and eliminating phishing threats in IoT, network and other Web applications using iterative intersection. Peer-to-Peer Networking and Applications 14 (2021), 2327–2339

  128. [136]

    Hanh-Phuc Nguyen, Thanh-Nhan Luong, and Ninh-Thuan Truong. 2022. Generating test paths to detect XSS vulnerabilities of web applications. In Proceedings of the 9th NAFOSTED Conference on Information and Computer Science (NICS’22). 287–293

  129. [137]

    Jeff Offutt and Sunitha Thummala. 2019. Testing concurrent user behavior of synchronous web applications with Petri nets. Software and Systems Modeling 18 (2019), 913–936

  130. [138]

    Agnija Onukrane, Heinrihs Kristians Skrodelis, Galina Merkurjeva, and Andrejs Romanovs. 2023. Navigating web application security: A survey of vulnerabilities and detection solutions. In Proceedings of the IEEE 64th International Scientific Conference on Information Technology...

  131. [139]

    Changhai Nie and Hareton Leung. 2011. A survey of combinatorial testing. Comput. Surveys 43, 2 (2011), 1–29

  132. [140]

    Nicey Paul and Robin Tommy. 2018. An approach of automated testing on web based platform using machine learning and Selenium. In Proceedings of the 2018 International Conference on Inventive Research in Computing Applications (ICIRCA’18). 851–856

  133. [141]

    Paulo Nunes, Ibéria Medeiros, José Fonseca, Nuno Neves, Miguel Correia, and Marco Vieira. 2019. An empirical study on combining diverse static analysis tools for web security vulnerabilities based on development scenarios. Computing 101 (2019), 161–185

  134. [142]

    Elis Pelivani and Betim Cico. 2021. A comparative study of automation testing tools for web applications. InProceedings of the 10th Mediterranean Conference on Embedded Computing (MECO’21) . 1–6

  135. [143]

    Giancarlo Pellegrino, Constantin Tschürtz, Eric Bodden, and Christian Rossow. 2015. jäk: Using dynamic analysis to crawl and test modern web applications. In Proceedings of the 18th International Symposium on Research in Attacks, Intrusions, and Defenses (RAID’15) . 295–316

  136. [144]

    Vikas Panthi and Durga Prasad Mohapatra. 2017. An approach for dynamic web application testing using MBT. International Journal of System Assurance Engineering and Management 8 (2017), 1704–1716

  137. [145]

    Irfan Prazina, Šeila Bećirović, Emir Cogo, and Vensada Okanović. 2023. Methods for automatic web page layout testing and analysis: A review. IEEE Access 11 (2023), 13948–13964

  138. [146]

    Silvio Pavanetto and Marco Brambilla. 2020. Generation of realistic navigation paths for web site testing using recurrent neural networks and generative adversarial neural networks. In Proceedings of the 20 the International Conference on Web Engineering (ICWE’20) . 244–258

  139. [147]

    Mayang Anglingsari Putri, Hilman Nuril Hadi, and Fatwa Ramdani. 2017. Performance testing analysis on web application: Study case student admission web system. InProceedings of the 2017 International Conference on Sustainable Information Engineering and Technology (SIET’17) . 1–5

  140. [148]

    Xiao-Fang Qi, Zi-Yuan Wang, Jun-Qiang Mao, and Peng Wang. 2017. Automated testing of web applications using combinatorial strategies. Journal of Computer Science and Technology 32, 1 (2017), 199–210

  141. [149]

    I Putu Agus Eka Pratama and Alvin Maulana Rhusuli. 2022. Penetration testing on web application using insecure direct object references (IDOR) method. In Proceedings of the 2022 International Conference on ICT for Smart Society (ICISS’22). 01–07

  142. [150]

    Karishma Rahman and Clemente Izurieta. 2022. A mapping study of security vulnerability detection approaches for web applications. In Proceedings of the 48th Euromicro Conference on Software Engineering and Advanced Applications (SEAA’22). 491–494

  143. [151]

    Pratama Aji Prisadi, Setiyo Cahyono, Ryan Muhammad Azizulfiqar, and Alfido Osdie. 2023. Implementation of distributed attack penetration testing automation using dynamic infrastructure framework Axiom on web-based systems. In Proceedings of the 2023 International Conference on...

  144. [152]

    Paresh Rathod, Viljami Julkunen, Tero Kaisti, and Janne Nissilä. 2015. Automatic acceptance testing of the web application security with ITU-T X. 805 framework. In Proceedings of the 2nd International Conference on Computer Science, Computer Engineering, and Social Media (CSCE...

  145. [153]

    Marc Rennhard, Malte Kushnir, Olivier Favre, Damiano Esposito, and Valentin Zahnd. 2022. Automating the detection of access control vulnerabilities in web applications. SN Computer Science 3, 5 (2022), 376

  146. [154]

    Sajjad Rafique, Mamoona Humayun, Bushra Hamid, Ansar Abbas, Muhammad Akhtar, and Kamil Iqbal. 2015. Web application security vulnerabilities detection approaches: A systematic mapping study. InProceedings of the IEEE/ACIS 16th International Conference on Software Engineering, ...

  147. [155]

    Fernando Román Muñoz, Iván Israel Sabido Cortes, and Luis Javier García Villalba. 2018. Enlargement of vulnerable web applications for testing. The Journal of Supercomputing 74 (2018), 6598–6617

  148. [156]

    Branislav Rajić, Žarko Stanisavljević, and Pavle Vuletić. 2023. Early web application attack detection using network traffic analysis. International Journal of Information Security 22, 1 (2023), 77–91

  149. [157]

    Divya Saharan, Yogesh Kumar, and Rahul Rishi. 2018. Analytical study and implementation of web performance testing tools. In Proceedings of the 2018 International Conference on Recent Innovations in Electrical, Electronics and Communication Engineering (ICRIEECE’18). 2370–2377

  150. [158]

    Sreedevi Sampath and Sara Sprenkle. 2016. Advances in web application testing, 2010–2014. InAdvances in Computers. Vol. 101. 155–191

  151. [159]

    Jesús-Ángel Román-Gallego, María-Luisa Pérez-Delgado, Marcos Luengo Viñuela, and María-Concepción Vega- Hernández. 2023. Artificial intelligence web application firewall for advanced detection of web injection attacks. Expert Systems (2023), e13505

  152. [160]

    Sergio Segura, Gordon Fraser, Ana B Sanchez, and Antonio Ruiz-Cortés. 2016. A survey on metamorphic testing. IEEE Transactions on Software Engineering 42, 9 (2016), 805–824

  153. [161]

    Yeonhee Ryou and Sukyoung Ryu. 2018. Automatic detection of visibility faults by layout changes in HTML5 web pages. In Proceedings of the IEEE 11th International Conference on Software Testing, Verification and Validation (ICST’18) . 182–192

  154. [162]

    Muzammil Shahbaz, Phil McMinn, and Mark Stevenson. 2015. Automatic generation of valid and invalid test data for string validation routines using web searches and regular expressions. Science of Computer Programming 97 (2015), 405–425

  155. [163]

    Pojan Shahrivar, Stuart Millar, and Ezzeldin Shereen. 2023. Detecting web application DAST attacks with machine learning. In Proceedings of the 2023 IEEE Conference on Dependable and Secure Computing (DSC’23) . 1–8

  156. [164]

    Katharine Sanderson. 2023. GPT-4 is here: What scientists think. Nature 615, 7954 (2023), 773–773

  157. [165]

    Navneet Singh, Vishtasp Meherhomji, and BR Chandavarkar. 2020. Automated versus manual approach of web application penetration testing. In Proceedings of the 11th International Conference on Computing, Communication and Networking Technologies (ICCCNT’20). 1–6

  158. [166]

    Saad Shafiq, Atif Mashkoor, Christoph Mayr-Dorn, and Alexander Egyed. 2021. A literature review of using machine learning in software development life cycle stages. IEEE Access 9 (2021), 140896–140920

  159. [167]

    Dimitri Michel Stallenberg and Annibale Panichella. 2019. JCOMIX: A search-based tool to detect XML injection vulnerabilities in web applications. InProceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of S...

  160. [168]

    Anastasios Stasinopoulos, Christoforos Ntantogian, and Christos Xenakis. 2019. Commix: Automating evaluation and exploitation of command injection vulnerabilities in Web applications. International Journal of Information Security 18 (2019), 49–72

  161. [169]

    Elwin Shaji and Narayanan Subramanian. 2021. Assessing non-intrusive vulnerability scanning methodologies for detecting web application vulnerabilities on large scale. In Proceedings of the 2021 International Conference on System, Computation, Automation and Networking (ICSCAN...

  162. [170]

    Xin Su and Xiaohui Li. 2021. Elastic performance test method of web server in cloud computing environment.Journal of Web Engineering 20, 5 (2021), 1641–1658

  163. [171]

    Ferda Özdemir Sönmez and Banu Günel Kiliç. 2021. Holistic web application security visualization for multi-project and multi-phase dynamic application security test results. IEEE Access 9 (2021), 25858–25884

  164. [172]

    Nezih Sunman, Yiğit Soydan, and Hasan Sözer. 2022. Automated web application testing driven by pre-recorded test cases. Journal of Systems and Software 193 (2022), 111441

  165. [173]

    Sunitha Thummala and Jeff Offutt. 2016. Using Petri nets to test concurrent behavior of web applications. InProceedings of the IEEE 9th International Conference on Software Testing, Verification and Validation Workshops (ICSTW’16). 189–198

  166. [174]

    Andrea Stocco, Maurizio Leotta, Filippo Ricca, and Paolo Tonella. 2016. Automatic page object generation with APOGEN. In Proceedings of the 16th International Conference on Web Engineering (ICWE’16) . 533–537

  167. [175]

    Pariwish Touseef, Khubaib Amjad Alam, Abid Jamil, Hamza Tauseef, Sahar Ajmal, Rimsha Asif, Bisma Rehman, and Sumaira Mustafa. 2019. Analysis of automated web application security vulnerabilities testing. In Proceedings of the 3rd International Conference on Future Networks and...

  168. [176]

    Chungha Sung, Markus Kusano, Nishant Sinha, and Chao Wang. 2016. Static DOM event dependency analysis for testing web applications. In Proceedings of the 2016 24th ACM SIGSOFT International Symposium on Foundations of Software Engineering (FSE’16). 447–459

  169. [177]

    Nisal Madhushan Vithanage and Neera Jeyamohan. 2016. WebGuardia-An integrated penetration testing system to detect web application vulnerabilities. In Proceedings of the 2016 International Conference on Wireless Communications, Signal Processing and Networking (WiSPNET’16) . 221–227

  170. [178]

    Fatima Waheed, Farooque Azam, Muhammad Waseem Anwar, and Yawar Rasheed. 2020. Model driven approach for automatic script generation in stress testing of web applications. In Proceedings of the 6th International Conference on Computer and Technology Applications (ICCTA’20). 46–50

  171. [179]

    Vatsya Tiwari, Sachin Upadhyay, Jayati Krishna Goswami, and Sanjiv Agrawal. 2023. Analytical evaluation of web performance testing tools: Apache JMeter and SoapUI. In Proceedings of the IEEE 12th International Conference on Communication Systems and Network Technologies (CSNT’...

  172. [180]

    Shengye Wan, Yue Li, and Kun Sun. 2019. PathMarker: Protecting web contents against inside crawlers.Cybersecurity 2, 1 (2019), 9

  173. [181]

    Ganesh Vaidyanathan and Steven Mautone. 2009. Security in dynamic web content management systems applications. Commun. ACM 52, 12 (2009), 121–125

  174. [182]

    Siyi Wang, Sinan Wang, Yujia Fan, Xiaolei Li, and Yepang Liu. 2024. Leveraging large vision language model for better automatic web GUI testing. arXiv 2410.12157 (2024)

  175. [183]

    Shu-Yan Wang, Jia-Ze Sun, and Ju Zhang. 2016. The method of generating web link security testing scenario based on UML diagram. In Proceedings of the 15th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom’16). 1831–1838

  176. [184]

    Thomas A Walsh, Phil McMinn, and Gregory M Kapfhammer. 2015. Automatic detection of potential layout faults following changes to responsive web pages (N). In Proceedings of the 30th IEEE/ACM International Conference on Automated Software Engineering (ASE’15). 709–714

  177. [185]

    Wenhua Wang, Sreedevi Sampath, Yu Lei, Raghu Kacker, Richard Kuhn, and James Lawrence. 2016. Using combinatorial testing to build navigation graphs for dynamic web applications. Software Testing, Verification and Reliability 26, 4 (2016), 318–346

  178. [186]

    Qian Wang, Jinan Sun, Chen Wang, Shikun Zhang, Sisi Xuanyuan, and Bin Zheng. 2020. Access control vulnerabilities detection for web application components. In Proceedings of the IEEE 6th International Conference on Big Data Security on Cloud (BigDataSecurity’20), IEEE Internat...

  179. [187]

    Jane Webster and Richard T Watson. 2002. Analyzing the past to prepare for the future: Writing a literature review. MIS quarterly (2002), xiii–xxiii

  180. [188]

    Te-En Wei, Hahn-Ming Lee, Albert B Jeng, Hemank Lamba, and Christos Faloutsos. 2019. WebHound: a data-driven intrusion detection from real-world web access logs. Soft Computing 23 (2019), 11947–11965

  181. [189]

    Weiwei Wang, Xiaohong Guo, Zheng Li, and Ruilian Zhao. 2019. Test case generation based on client-server of web applications by memetic algorithm. In Proceedings of the IEEE 30th International Symposium on Software Reliability Engineering (ISSRE’19). 206–216

  182. [190]

    Yifan Yao, Jinhao Duan, Kaidi Xu, Yuanfang Cai, Zhibo Sun, and Yue Zhang. 2024. A survey on large language model (LLM) security and privacy: The good, the bad, and the ugly. High-Confidence Computing (2024), 100211

  183. [191]

    Weiwei Wang, Shumei Wu, Zheng Li, and Ruilian Zhao. 2023. Parallel evolutionary test case generation for web applications. Information and Software Technology 155 (2023), 107113

  184. [192]

    Bing Yu, Lei Ma, and Cheng Zhang. 2015. Incremental web application testing using page object. In Proceedings of the 3rd IEEE Workshop on Hot Topics in Web Systems and Technologies (HotWeb’15) . 1–6

  185. [193]

    Bing Zhang, Jingyue Li, Jiadong Ren, and Guoyan Huang. 2021. Efficiency and effectiveness of web application vulnerability detection approaches: A review. Comput. Surveys 54, 9 (2021), 1–35

  186. [194]

    Jianfei Xiao, Yancan Chen, Yimin Ou, Hanyi Yu, Kai Shu, and Yiyong Xiao. 2024. Baichuan2-Sum: Instruction Finetune Baichuan2-7B Model for Dialogue Summarization. In 2024 International Joint Conference on Neural Networks (IJCNN) . IEEE, 1–8

  187. [195]

    Meng-ni Zhang, Can Wang, Jia-jun Bu, Zhi Yu, Yu Zhou, and Chun Chen. 2015. A sampling method based on URL clustering for fast web accessibility evaluation. Frontiers of Information Technology and Electronic Engineering 16, 6 (2015), 449–456

  188. [196]

    Nazish Yousaf, Farooque Azam, Wasi Haider Butt, Muhammad Waseem Anwar, and Muhammad Rashid. 2019. Automated model-based test case generation for web user interfaces (WUI) from interaction flow modeling language (IFML) models. IEEE Access 7 (2019), 67331–67354

  189. [197]

    Jingling Zhao and Rulin Gong. 2015. A new framework of security vulnerabilities detection in PHP web application. In Proceedings of the 9th International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing J. ACM, Vol. 37, No. 4, Article 111. Publicat...

  190. [198]

    Junzan Zhou, Bo Zhou, and Shanping Li. 2014. LTF: A model-based load testing framework for web applications. In Proceedings of the 14th International Conference on Quality Software (QSIC’14) . 154–163

  191. [199]

    Ming Zhang, Shuaibing Lu, and Boyi Xu. 2017. An anomaly detection method based on multi-models to detect web attacks. In Proceedings of the 10th International Symposium on Computational Intelligence and Design (ISCID’17) , Vol. 2. 404–409

  192. [201]

    Simin Zhang, Bo Li, Jianxin Li, Mingming Zhang, and Yang Chen. 2015. A novel anomaly detection approach for mitigating web-based attacks against clouds. In Proceedings of the IEEE 2nd International Conference on Cyber Security and Cloud Computing (CSCloud’15) . 289–294

  193. [204]

    Yunxiao Zou, Zhenyu Chen, Yunhui Zheng, Xiangyu Zhang, and Zebao Gao. 2014. Virtual DOM coverage for effective testing of dynamic web applications. In Proceedings of the 23rd International Symposium on Software Testing and Analysis (ISSTA’14). 60–70. APPENDICES A A COMPREHENSI...

  194. [2017]

    In Proceedings of the 17th International Conference on Computational Science and Its Applications (ICCSA’17)

    Test case generation from BPMN models for automated testing of Web-based BPM applications. In Proceedings of the 17th International Conference on Computational Science and Its Applications (ICCSA’17) . 1–7

  195. [2019]

    IEEE Access 7 (2019), 100567–100580

    MLPXSS: An integrated XSS-based attack detection scheme in web applications using multilayer perceptron technique. IEEE Access 7 (2019), 100567–100580

  196. [2020]

    In Proceedings of the 2020 International Conference on Electrical, Communication, and Computer Engineering (ICECCE’20)

    Web application testing with model based testing method: Case study. In Proceedings of the 2020 International Conference on Electrical, Communication, and Computer Engineering (ICECCE’20) . 1–6

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.