Saudi Cultural Missions Theses & Dissertations
Permanent URI for this communityhttps://drepo.sdl.edu.sa/handle/20.500.14154/10
Browse
1 results
Search Results
Item Restricted Enhancing the Performance of Web Application Security Testing: An In-Depth Analysis and Optimization of Web Vulnerability Scanners(ProQuest, 2024-01-24) Alazmi, Suliman; de Leon, Daniel ConteWeb applications have become an indispensable part of our lives today. Meanwhile, hackers' exploitation of web application vulnerabilities is increasing, and the damages caused are devastating. Web application vulnerability scanners (WVS's) are tools have been considered to remediate this situation. However, these tools are different in their effectiveness and their quality of use. In this dissertation we provided four contributions: Firstly, we conducted a Systematic Literature Review (SLR) on the most frequently used WVS's. A total of 90 research papers were carefully evaluated. Thirty (30) WVS's were collected and reported, with only 12 having at least one quantitative assessment of effectiveness. These 12 WVS's were evaluated by 15 original evaluation studies. We found that these evaluations tested mostly only two of the Open Web Application Security Project (OWASP) Top Ten vulnerability types: SQL injection (SQLi) (13/15) and Cross-Site Scripting (XSS) (8/15). We also found that the reported detection rates were highly dissimilar between these 15 evaluations. Secondly, we evaluated the performance of four well known web vulnerability scanners (Burp Suite Pro, OWASP ZAP, Arachni and Wapiti) in detecting the OWASP Top Ten vulnerability types by running them against three benchmark web applications (Mutillidae, bWAPP, WebGoat). Our comparative results showed that web vulnerability scanners, were effective detecting only a very few of the OWASP Top Ten vulnerability types. Thirdly, we conducted a statistical study to measure the quality of use of four web vulnerability scanners. The quality of use was measured using the Software Usability Measurement Inventory (SUMI). The results suggested that OWASP ZAP and Burp Suite Pro were more positively perceived by the participants in terms of their Affect and Learnability, while Wapiti waFourthly, new scanning rules were proposed to improve OWASP ZAP's detection of SQL injection attacks. Testing on vulnerable web applications showed a significant improvement in detection capability.s less positively perceived by the participants in terms of their Efficiency, Affect and Controllability.59 0