VLDB 2026 Research / reviewers in the wild / expert
Onur Duman
dblp:161/6291
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0002-2489-8981ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 3 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A survey on web testing: On the rise of AI and applications in industryabstract• Analyze Web Testing methodologies, tools and trends on the last decade (2014-2025) • Analyze the rate of collaboration with industry. • Analyze the role of AI in web testing. Web application testing is an essential practice to ensure the reliability, security, and performance of web systems in an increasingly digital world. This paper presents a systematic literature survey focusing on web testing methodologies, tools, and trends from 2014 to 2025. By analyzing 258research papers, the survey identifies key trends, demographics, contributions, tools, challenges, and innovations in this domain. In addition, the survey analyzes the experimental setups adopted by the studies, including the number of participants involved and the outcomes of the experiments. Our results show that web testing research has been highly active, with ICST as the leading venue. Most studies focus on novel techniques, emphasizing automation in black-box testing. Selenium is the most widely used tool, while industrial adoption and human studies remain comparatively limited. The findings provide a detailed overview of trends, advancements, and challenges in web testing research, the evolution of automated testing methods, the role of artificial intelligence in test case generation, and gaps in current research. Special attention was given to the level of collaboration and engagement with the industry. A positive trend in using industrial systems is observed, though many tools lack open-source availability. Iva Kertusha, Gebremariam Mesfin Assres, Onur Duman, Andrea Arcuri |
Sci. Comput. Program. | 3 |
| 2026 | Handling Web Service Interactions in Fuzzing with Search-Based Mock-GenerationabstractTesting large and complex enterprise software systems can be a challenging task. This is especially the case when the functionality of the system depends on interactions with other external services over a network (e.g., external web services accessed through REST API calls). Although several techniques in the research literature have been shown to be effective at generating test cases in a good number of different software testing contexts, dealing with external services is still a major research challenge. In industry, a common approach is to mock external web services for testing purposes. However, generating and configuring mock web services can be a very time-consuming task, e.g., external services may not be under the control of the same developers of the tested application, making it challenging to identify the external services and simulate various possible responses. In this article, we present a novel search-based approach aimed at fully automated mocking of external web services as part of white-box, search-based fuzzing. We rely on code instrumentation to detect all interactions with external services, and how their response data is parsed. We then use such information to enhance a search-based approach for fuzzing. The tested application is automatically modified (by manipulating DNS lookups) to rather interact with instances of mock web servers. The search process not only generates inputs to the tested applications but also automatically configures responses in those mock web server instances, aiming at maximizing code coverage and fault-finding. An empirical study on four open source REST APIs from EMB, and one industrial API from an industry partner, shows the effectiveness of our novel techniques (i.e., in terms of line coverage and fault detection). Susruthan Seran, Man Zhang 0001, Onur Duman, Andrea Arcuri |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2025 | Tool report: EvoMaster - black and white box search-based fuzzing for REST, GraphQL and RPC APIsabstractIn this paper, we present the latest version 3.0.0 of EvoMaster, an open-source search-based fuzzer aimed at Web APIs. We discuss and present all its recent improvements, including advanced white-box heuristics, advanced search algorithms, support for databases and external services, as well as dealing with GraphQL and RPC APIs besides the original use case for REST APIs. The tool's installers have been downloaded more than 3000 times. EvoMaster is in daily use for fuzzing millions of lines of code in hundreds of APIs in large Fortune 500 companies, such as for example the e-commerce Meituan. Andrea Arcuri, Man Zhang 0001, Susruthan Seran, Juan P. Galeotti, Amid Golmohammadi, Onur Duman, Agustina Aldasoro, Hernan Ghianni |
Autom. Softw. Eng. | 6 |
| 2025 | Measuring the Security Posture of IEC 61850 Smart Grid Substations Against Supply Chain AttacksabstractRecently, there has been a surge of interest in analyzing and modeling emerging cyberattacks resulting from supply chain vulnerabilities in smart grids. These vulnerabilities are deliberately injected into devices before shipment by a malicious or trustworthy but compromised vendor during supply chain attacks. As a result, those vulnerabilities possess unique characteristics, such as stealthiness. Such characteristics, together with the limited number of vendors, demand new techniques for measuring the security posture of smart grids in the presence of those vulnerabilities. On this basis, this article first defines a supply chain risk metric to measure the risks of different devices containing those vulnerabilities based on several risk factors. Afterward, we enhance the previously defined$kSupply$metric and propose a new metric, namely$kSupplier$to include vendors in the risk assessment. Finally, we evaluate the proposed metrics and models through simulations conducted on IEEE 14 and 39-bus systems. Onur Duman, Mohsen Ghafouri, Lingyu Wang 0001, Marthe Kassouf, Ribal Atallah, Mourad Debbabi |
IEEE Trans. Ind. Informatics | 1 |
| 2024 | SecMonS: A Security Monitoring Framework for IEC 61850 Substations Based on Configuration Files and Logs
Onur Duman, Mengyuan Zhang 0001, Lingyu Wang 0001, Mourad Debbabi |
DIMVA | 1 |
| 2022 | Factor of Security (FoS): Quantifying the Security Effectiveness of Redundant Smart Grid SubsystemsabstractAccording to International Electrotechnical Commission (IEC) 61850-90-4, most smart grid substations are designed with redundancy in order to improve their availability in case of failures. Redundancy usually takes the form of having multiple subsystems with identical functionality based on the assumption that failures in one subsystem are isolated from other subsystems. However, this is not necessarily true in the case of failures caused by malicious attacks, because attackers can easily reuse their skills and tools across different subsystems under similar configurations. Taking this into consideration, this article introduces the factor of security (FoS) metrics to quantify the security effectiveness of redundant subsystems in smart grids. Specifically, we first apply the attack graph model to capture various threats in smart grids and substations; we then formally define the FoS metric and the probabilistic FoS metric, and finally we evaluate those metrics through simulations. Onur Duman, Mengyuan Zhang 0001, Lingyu Wang 0001, Mourad Debbabi, Ribal Atallah, Bernard Lebel |
IEEE Trans. Dependable Secur. Comput. | 1 |