首页> 外文会议>International Conference on Artificial Intelligence and Computer Science Technology >Evaluation of Web Application Vulnerability Scanner for Modern Web Application
【24h】

Evaluation of Web Application Vulnerability Scanner for Modern Web Application

机译:用于现代Web应用程序的Web应用程序漏洞扫描仪的评估

获取原文

摘要

Current needs and developments encourage the increasing use of digital-based applications. One of them is a web-based application that is easy to access and used by today’s society. Along with these developments, it is common for vulnerabilities to exist in web applications that the owners are unaware of. It creates the risk of data leakage or damage to the organization’s reputation as the application owner. In addition, the number of web applications owned by an organization or company leads to challenges in finding vulnerabilities in these applications. This happened due to time and resource constraints for conducting manual assessments. Therefore, there is necessary to use a web application vulnerability scanner, which performs vulnerability scanning automatically, to be able to help and streamline the search for vulnerabilities. There are many types of web application vulnerability scanners that can be used for free or commercially. This study evaluated the capabilities of WAVS (Web Application Vulnerability Scanners) tools such as OWASP ZAP, Wapiti, Arachni, and Burp Suite Professional with NodeJS-based benchmark targets, namely Damn Vulnerable NodeJS Application (DVNA) and NodeGoat. This study found that the four WAVS have an average f-measured value between 0.4-0.6. Burp Suite Professional had the best True Positive (TP) and Recall values, while Arachni for perfect Precision valued for both benchmark targets.
机译:当前的需求和发展鼓励不断使用基于数字的应用程序的使用。其中一个是基于网络的应用程序,易于访问和今天的社会使用。随着这些的发展,漏洞存在于业主不知道的Web应用程序中。它创造了数据泄漏的风险或对组织作为应用程序所有者的声誉的损害。此外,组织或公司拥有的Web应用程序的数量导致在这些应用程序中找到漏洞的挑战。这是由于进行手动评估的时间和资源限制因而发生这种情况。因此,有必要使用Web应用程序漏洞扫描仪自动执行漏洞扫描,以便能够帮助和简化搜索漏洞。有许多类型的Web应用程序漏洞扫描仪可用于自由或商业。本研究评估了WAVS(Web应用程序漏洞扫描仪)工具的功能,如OWASP ZAP,WAPITI,ARACHNI和Burp套件专业人员与基于NodeJS的基准目标,即该死的弱势Nodejs应用程序(DVNA)和leogoat。本研究发现,四个波的平均f测量值在0.4-0.6之间。 Burp Suite Professional具有最好的正面(TP)和召回值,而Arachni则为两个基准目标的完美精度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号