The approaches to quantify web application security scanners quality: a review

Lim Kah Seng, N. Ithnin, Syed Zainudeen Mohd Said
{"title":"The approaches to quantify web application security scanners quality: a review","authors":"Lim Kah Seng, N. Ithnin, Syed Zainudeen Mohd Said","doi":"10.19101/ijacr.2018.838012","DOIUrl":null,"url":null,"abstract":"The web application security scanner is a computer program that assessed web application security with penetration testing technique. The benefit of automated web application penetration testing is huge, which web application security scanner not only reduced the time, cost, and resource required for web application penetration testing but also eliminate test engineer reliance on human knowledge. Nevertheless, web application security scanners are possessing weaknesses of low test coverage, and the scanners are generating inaccurate test results. Consequently, experimentations are frequently held to quantitatively quantify web application security scanner's quality to investigate the web application security scanner's strengths and limitations. However, there is a discovery that neither a standard methodology nor criterion is available for quantifying the web application security scanner's quality. Hence, in this paper systematic review is conducted and analysed the methodology and criterion used for quantifying web application security scanners' quality. In this survey, the experiment methodologies and criterions that had been used to quantify web application security scanner's quality is classified and review using the preferred reporting items for systematic reviews and meta-analyses (PRISMA) protocol. The objectives are to provide practitioners with the understanding of methodologies and criterions that available for measuring web application security scanners’ test coverage, attack coverage, and vulnerability detection rate, while provides the critical hint for development of the next testing framework, model, methodology, or criterions, to measure web application security scanner quality.","PeriodicalId":273530,"journal":{"name":"International Journal of Advanced Computer Research","volume":"106 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-09-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"20","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Advanced Computer Research","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.19101/ijacr.2018.838012","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 20

Abstract

The web application security scanner is a computer program that assessed web application security with penetration testing technique. The benefit of automated web application penetration testing is huge, which web application security scanner not only reduced the time, cost, and resource required for web application penetration testing but also eliminate test engineer reliance on human knowledge. Nevertheless, web application security scanners are possessing weaknesses of low test coverage, and the scanners are generating inaccurate test results. Consequently, experimentations are frequently held to quantitatively quantify web application security scanner's quality to investigate the web application security scanner's strengths and limitations. However, there is a discovery that neither a standard methodology nor criterion is available for quantifying the web application security scanner's quality. Hence, in this paper systematic review is conducted and analysed the methodology and criterion used for quantifying web application security scanners' quality. In this survey, the experiment methodologies and criterions that had been used to quantify web application security scanner's quality is classified and review using the preferred reporting items for systematic reviews and meta-analyses (PRISMA) protocol. The objectives are to provide practitioners with the understanding of methodologies and criterions that available for measuring web application security scanners’ test coverage, attack coverage, and vulnerability detection rate, while provides the critical hint for development of the next testing framework, model, methodology, or criterions, to measure web application security scanner quality.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
量化web应用程序安全扫描器质量的方法:回顾
web应用程序安全扫描器是一种利用渗透测试技术评估web应用程序安全性的计算机程序。自动化web应用程序渗透测试的好处是巨大的,它不仅减少了web应用程序渗透测试所需的时间、成本和资源,而且消除了测试工程师对人类知识的依赖。然而,web应用程序安全扫描器具有低测试覆盖率的弱点,并且扫描器生成的测试结果不准确。因此,经常进行实验来定量量化web应用程序安全扫描程序的质量,以调查web应用程序安全扫描程序的优势和局限性。然而,人们发现既没有标准的方法也没有标准来量化web应用程序安全扫描程序的质量。因此,本文对web应用程序安全扫描器质量量化的方法和标准进行了系统的综述和分析。在这项调查中,实验方法和标准,已用于量化web应用程序安全扫描器的质量进行分类和审查使用首选报告项目的系统审查和荟萃分析(PRISMA)协议。本书的目标是让实践者了解测量web应用程序安全扫描器的测试覆盖率、攻击覆盖率和漏洞检测率的方法和标准,同时为开发下一个测试框架、模型、方法或标准提供关键提示,以测量web应用程序安全扫描器的质量。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Automatic urban boundary delineation in equatorial regions using SAR imagery: a comprehensive approach with decomposition, morphology, and statistical active contours The barriers and prospects related to big data analytics implementation in public institutions: a systematic review analysis Enhancing data analysis through k-means with foggy centroid selection Hybrid chaotic whale-shark optimization algorithm to improve artificial neural network: application to the skin neglected tropical diseases diagnosis A review and analysis for the text-based classification
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1