Evaluation of Information Security in Web Application Through Penetration Testing Techniques Using OWASP Risk Methodology


연구 분야: Strategies



학회: 2024 International Conference on Advances in Computing Research on Science Engineering and Technology (ACROSET)


초록

Web applications are indispensable to today's business operations. The emergence of e-commerce platforms, online finance, and social networking websites has significantly transformed our interactions, communication, and business practices. This increased dependence on web applications has increased the likelihood of cyber threats and attacks. Therefore, it is of the utmost importance to implement robust security measures to protect sensitive data and reduce intrusions. Incorporating evidence from penetration testing techniques, tools and OWASP risk methodology, this study demonstrates the inherent limitations of relying exclusively on a single scanning tool, as evidenced by the different results obtained when using several different techniques and tools. It argues that the most effective technique for identifying and remediating web application vulnerabilities is to implement a comprehensive testing technique that incorporates different kinds of vulnerability scanners and techniques. These concerns are especially evident when using grey box testing techniques along with manual and automated scanning tools such as Acunetix, Invicti, Burp Suite Professional, and OWASP ZAP to evaluate the different factors such as vulnerability coverage, scanning speed, vulnerability detection, and false positive rate. By adopting the method described, the security community can obtain reliable information that will help them make informed decisions when selecting penetration testing techniques and tools to effectively secure websites and applications information.


Author Profile
Chinekezi Chinyere Echefunna

Department of Cybersecurity and Networks Glasgow Caledonian University Glasgow UK

Andorra
Author Profile
Jude Osamor

School of Computer Science & Engineering University of Westminster London UK

정보 없음
Author Profile
Celestine Iwendi

School of Creative Technologies University of Bolton Bolton UK

정보 없음

📄 논문 정보

발행 연도 2024년
인용수 360
출판 국가 Andorra
사이트 IEEE
좋아요 수 0

연관 논문 목록 (188건)