Please use this identifier to cite or link to this item:
http://dspace.univ-guelma.dz/jspui/handle/123456789/15028
Title: | A Meta-Scan based approach for the detection of injection vulnerabilities in Web applications |
Authors: | Oudjani, Seyyid Taqy Eddine |
Keywords: | Cybersecurity; injection vulnerabilities; penetration testing; meta-scan. |
Issue Date: | 2023 |
Publisher: | University of Guelma |
Abstract: | The constantly evolving web landscape presents a wide range of emerging threats that exploit vulnerabilities within web applications, exposing data, systems, and servers to significant risks such as data manipulation and theft, unauthorized access and de- nial of services. To tackle these challenges, the present research project explores the ability of dynamic analysis and penetration testing tools to effectively detect injec- tion vulnerabilities in web applications. Consequently, web developers with the help of security experts can take appropriate actions to safeguard vulnerable applications from cyberattacks. The study conducted in this project proposes a meta-scan-based system that leverages the capabilities of several open source and dynamic application security testing tools. The proposed system aims at detecting three specific injection vulnerabilities: cross-site scripting, SQL injections, and OS command injections. To enhance usability, the system incorporates a user-friendly graphical interface with various features. Through rigorous testing using four well-known vulnerable appli- cations, the system’s performance is assessed and compared with that of individual scanners. The results reveal promising outcomes, as the new system successfully re- duces false positives and negatives, validating its efficacy in bolstering web security. |
URI: | http://dspace.univ-guelma.dz/jspui/handle/123456789/15028 |
Appears in Collections: | Master |
Files in This Item:
File | Description | Size | Format | |
---|---|---|---|---|
OUDJANI_SEYYID TAQY EDDINE_F5.pdf | 2,84 MB | Adobe PDF | View/Open |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.