Benchmarking of web application vulnerability scanners

Clicks: 1
ID: 286357
2022
Article Quality & Performance Metrics
Overall Quality
Not rated
Combines reader engagement with the AI quality analysis. This article has not been analysed, so there is no overall score — reader engagement is measured and shown alongside.
AI Quality Assessment
Not analyzed
Readership in this journal

Ranked #2,995 of 3,757 articles by views in Malay Journal

Most read Least read

Bar heights use a square-root scale. Only the 120 most-read articles are drawn; the journal has 3,757 in total.

Mint this article as an NFT
Not yet minted

Create a permanent, verifiable on-chain record of this article on the Scimatic Network. The NFT is held in your Journament account, and you can withdraw it to your own wallet at any time.

5 SUSD one-off · no wallet required
Abstract
As most organizations already rely on digitalization regardless of the purpose, web applications are indeed one of the digital components to reach their target audience. Due to this nature, Web Apps needed to be deployed on the public internet. Efficiency as it is, the risk of them being compromised is very high, that is why it is imperative to have this undergo security checks before deploying. Security testing during the early years was very costly as this was mostly done manually by professionals. Later on, vulnerability scanners were developed to lessen the workload of the testers. However, effective and easy-to-use vulnerability scanners are expensive while open-source scanners are very complex to use. Now, there were improvements seen in open-source scanners, they started to have Graphical User Interfaces (GUI), do automated scanning, and generate comprehensive reports which are the commercial Web Application Vulnerability Scanners’ (WAVS) selling points. Yet, there were no studies that compared the performance gap of these scanners. Thus, this research aimed to compare the accuracy and reporting capabilities of 2 commercial and 2 open-source WAVS. The evaluation was done thru Acunetix Acuart and OWASP Benchmark for accuracy and WIVET for its crawling URLs. The results implied that open-source vulnerability scanners are already competitive enough to match the detection capabilities of commercial ones as well as the visualization of their reports. On the other hand, we also discovered incompatibility of commercial WAVS on the OWASP benchmark which caused an absence of data for comparison. Lastly, it was noted that all WAVS were not able to crawl and detect all test cases by the benchmarking tools. Therefore, scanners still cannot be fully replaced the practice of penetration testing and human validation.
Reference Key
persistent_1760658332_68f1839c6d1dc Use this key to autocite in the manuscript while using SciMatic Manuscript Manager or Thesis Manager
Authors Dalmacio, John Ryan G.
Journal Malay Journal
Year 2022
DOI
DOI not found
URL
Keywords Keywords not found

Citations

No citations found. To add a citation, contact the admin at info@scimatic.org

No comments yet. Be the first to comment on this article.