Measuring Vulnerability Assessment Tools’ Performance on the University Web Application

IF 0.6 Q3 MULTIDISCIPLINARY SCIENCES Pertanika Journal of Science and Technology Pub Date : 2023-10-03 DOI:10.47836/pjst.31.6.19
Pita Jarupunphol, Suppachochai Seatun, Wipawan Buathong
{"title":"Measuring Vulnerability Assessment Tools’ Performance on the University Web Application","authors":"Pita Jarupunphol, Suppachochai Seatun, Wipawan Buathong","doi":"10.47836/pjst.31.6.19","DOIUrl":null,"url":null,"abstract":"This research measured vulnerability assessment tools’ performance on a university web application, including Burp Suite and OWASP ZAP. There are three measurement criteria: (1) the number of vulnerabilities classified under risk and confidence metrics, (2) the number of vulnerability types and URL alerts classified under risk and confidence metrics, and (3) the number of vulnerabilities classified in the 2021 OWASP Top 10 vulnerabilities. Results showed that Burp Suite detected more vulnerabilities and alerts than OWASP ZAP, with a higher proportion of high-risk vulnerabilities. However, OWASP ZAP had a higher proportion of medium-confidence vulnerabilities. The comparison also revealed that the vulnerabilities identified by both tools were ranked differently within the OWASP Top 10, and there were variations in risk prioritisation between the tools. Despite these differences, the vulnerability assessment results obtained from these tools are still helpful for the university’s security analysts and administration, as mitigating cyber threats to the web application is paramount.","PeriodicalId":46234,"journal":{"name":"Pertanika Journal of Science and Technology","volume":"17 1","pages":"0"},"PeriodicalIF":0.6000,"publicationDate":"2023-10-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Pertanika Journal of Science and Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.47836/pjst.31.6.19","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"MULTIDISCIPLINARY SCIENCES","Score":null,"Total":0}
引用次数: 0

Abstract

This research measured vulnerability assessment tools’ performance on a university web application, including Burp Suite and OWASP ZAP. There are three measurement criteria: (1) the number of vulnerabilities classified under risk and confidence metrics, (2) the number of vulnerability types and URL alerts classified under risk and confidence metrics, and (3) the number of vulnerabilities classified in the 2021 OWASP Top 10 vulnerabilities. Results showed that Burp Suite detected more vulnerabilities and alerts than OWASP ZAP, with a higher proportion of high-risk vulnerabilities. However, OWASP ZAP had a higher proportion of medium-confidence vulnerabilities. The comparison also revealed that the vulnerabilities identified by both tools were ranked differently within the OWASP Top 10, and there were variations in risk prioritisation between the tools. Despite these differences, the vulnerability assessment results obtained from these tools are still helpful for the university’s security analysts and administration, as mitigating cyber threats to the web application is paramount.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
脆弱性评估工具在大学Web应用程序上的性能度量
本研究测量了漏洞评估工具在一个大学web应用程序上的性能,包括Burp Suite和OWASP ZAP。有三个衡量标准:(1)在风险和信心指标下分类的漏洞数量,(2)在风险和信心指标下分类的漏洞类型和URL警报数量,以及(3)在2021年OWASP十大漏洞中分类的漏洞数量。结果表明,与OWASP ZAP相比,Burp Suite检测到的漏洞和警报数量更多,高风险漏洞比例更高。然而,OWASP ZAP具有较高比例的中等置信度漏洞。比较还显示,两种工具识别的漏洞在OWASP前10名中的排名不同,并且工具之间的风险优先级存在差异。尽管存在这些差异,从这些工具中获得的漏洞评估结果仍然对大学的安全分析师和管理人员有帮助,因为减轻对web应用程序的网络威胁是至关重要的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
Pertanika Journal of Science and Technology
Pertanika Journal of Science and Technology MULTIDISCIPLINARY SCIENCES-
CiteScore
1.50
自引率
16.70%
发文量
178
期刊介绍: Pertanika Journal of Science and Technology aims to provide a forum for high quality research related to science and engineering research. Areas relevant to the scope of the journal include: bioinformatics, bioscience, biotechnology and bio-molecular sciences, chemistry, computer science, ecology, engineering, engineering design, environmental control and management, mathematics and statistics, medicine and health sciences, nanotechnology, physics, safety and emergency management, and related fields of study.
期刊最新文献
Estimation of Leachate Volume and Treatment Cost Avoidance Through Waste Segregation Programme in Malaysia Understanding the Degradation of Carbofuran in Agricultural Area: A Review of Fate, Metabolites, and Toxicity Phenolics-Enhancing Piper sarmentosum (Roxburgh) Extracts Pre-Treated with Supercritical Carbon Dioxide and its Correlation with Cytotoxicity and α-Glucosidase Inhibitory Activities Comparison Using Intelligent Systems for Data Prediction and Near Miss Detection Techniques Investigation of Blended Seaweed Waste Recycling Using Black Soldier Fly Larvae
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1