G. 2076
Page 23
relation, response, and policy rationale.
4. Methodology
4.1 Research Design
The research design combined structured literature review, standards mapping,
conceptual synthesis, and benchmark design. The study was not conducted as an
empirical tool-evaluation experiment. No scanner was executed, no vulnerable laboratory
was deployed, no live target was tested, and no private dataset was analyzed. The method
instead used literature and standards to derive a benchmark design that can later support
implementation and evaluation.
This design is appropriate because the contribution is a scenario-construction model. A
benchmark-design article must first define what counts as a scenario, what security
property is being tested, what state must be recorded, and how relevance is mapped to
standards before performance claims can be evaluated.
4.2 Search Strategy / Data Source Strategy
The search strategy used combinations of terms such as “broken access control web
application testing,” “authorization vulnerability benchmark,” “authentication workflow
vulnerability,” “stateful web application security testing,” “IDOR BOLA benchmark,”
“role-based access control web vulnerability,” “workflow bypass web security,” “session
management vulnerability testing,” “OWASP ASVS access control requirements,” “web
vulnerability benchmark evaluation,” and “AI-assisted vulnerability detection
benchmark.” Searches prioritized peer-reviewed databases and official standards sources.
Google Scholar was used for discovery, while preference was given to publisher pages,
official project pages, government guidance, RFCs, and standards pages where available.
The source base included academic literature on access-control analysis, stateful web
testing, web logic flaws, scanner evaluation, benchmarks, and AI-assisted vulnerability
detection [26]-[46]. It also included standards and guidance from OWASP, NIST,
MITRE, CISA, FIRST, OAuth, OpenID, and ISO/IEC [1]-[25], [47]-[49].
4.3 Inclusion and Exclusion Criteria
Sources were included when they focused on web application security, API security,
authentication, authorization, session management, workflow abuse, benchmark design,
GRJNST, Volume: 04 - Issue 2 (2026) / ISSN P: 2790-7643
Article ID: 2076