A Quantitative Assessment of the Detection Performance of Web Vulnerability Scanners


연구 분야: Infrastructure



학회: ARES '22: Proceedings of the 17th International Conference on Availability, Reliability and Security


초록

Software developers use web application vulnerability scanners to automatically identify security weaknesses in their web applications. The scanners inspect source code or analyze the running application, and look for specific vulnerability types. While it can be expected that a scanner will not discover every vulnerability, no information is available on the expected efficacy of currently available vulnerability scanners for a given vulnerability type. We present an analysis of 24 web vulnerability scanners and determine their effectiveness on 11 vulnerability types. Our study offers insights into the trade-offs when selecting a specific type of scanner. We show that for some vulnerability types, most vulnerability scanners perform poorly.


Author Profile
Emma Lavens

imec - DistriNet KU Leuven Belgium

Belgium
Author Profile
Pieter Philippaerts

imec - DistriNet KU Leuven Belgium

Belgium
Author Profile
Wouter Joosen

imec - DistriNet KU Leuven Belgium

Belgium

📄 논문 정보

발행 연도 2022년
인용수 2
출판 국가 Belgium
사이트 ACM
좋아요 수 0

연관 논문 목록 (294건)