Inicio  /  Applied Sciences  /  Vol: 12 Par: 8 (2022)  /  Artículo
ARTÍCULO
TITULO

A Comparative Study of Web Application Security Parameters: Current Trends and Future Directions

Jahanzeb Shahid    
Muhammad Khurram Hameed    
Ibrahim Tariq Javed    
Kashif Naseer Qureshi    
Moazam Ali and Noel Crespi    

Resumen

The growing use of the internet has resulted in an exponential rise in the use of web applications. Businesses, industries, financial and educational institutions, and the general populace depend on web applications. This mammoth rise in their usage has also resulted in many security issues that make these web applications vulnerable, thereby affecting the confidentiality, integrity, and availability of associated information systems. It has, therefore, become necessary to find vulnerabilities in these information system resources to guarantee information security. A publicly available web application vulnerability scanner is a computer program that assesses web application security by employing automated penetration testing techniques that reduce the time, cost, and resources required for web application penetration testing and eliminates test engineers? dependency on human knowledge. However, these security scanners possess various weaknesses of not scanning complete web applications and generating wrong test results. Moreover, intensive research has been carried out to quantitatively enumerate web application security scanners? results to inspect their effectiveness and limitations. However, the findings show no well-defined method or criteria available for assessing their results. In this research, we have evaluated the performance of web application vulnerability scanners by testing intentionally defined vulnerable applications and the level of their respective precision and accuracy. This was achieved by classifying the analyzed tools using the most common parameters. The evaluation is based on an extracted list of vulnerabilities from OWASP (Open Web Application Security Project).

 Artículos similares

       
 
Muhammad Tayyab, Rana Ammar Aslam, Umar Farooq, Sikandar Ali, Shahbaz Nasir Khan, Mazhar Iqbal, Muhammad Imran Khan and Naeem Saddique    
Groundwater Arsenic (As) data are often sparse and location-specific, making them insufficient to represent the heterogeneity in groundwater quality status at unsampled locations. Interpolation techniques have been used to map groundwater As data at unsa... ver más
Revista: Water

 
Thanda Shwe and Masayoshi Aritsugi    
Intelligent applications in several areas increasingly rely on big data solutions to improve their efficiency, but the processing and management of big data incur high costs. Although cloud-computing-based big data management and processing offer a promi... ver más
Revista: Applied Sciences

 
Zhiyuan Hu, Peng Yu, Guohua Xu, Yongjie Shi, Feng Gu and Aijun Zou    
Tiltrotors permit aircrafts to operate vertically with lift, yet convert to ordinary forward flight with thrust. The challenge is to design a tiltrotor blade yielding maximum lift and thrust that converts smoothly without losing integrity or efficiency. ... ver más
Revista: Aerospace

 
Max Käding and Steffen Marx    
Acoustic emission monitoring (AEM) has emerged as an effective technique for detecting wire breaks resulting from, e.g., stress corrosion cracking, and its application on prestressed concrete bridges is increasing. The success of this monitoring measure ... ver más
Revista: Applied Sciences

 
Tahsin Koroglu and Elanur Ekici    
In recent years, wind energy has become remarkably popular among renewable energy sources due to its low installation costs and easy maintenance. Having high energy potential is of great importance in the selection of regions where wind energy investment... ver más
Revista: Applied Sciences