错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enabling Dynamic Vulnerability Assessment for Multi-web Application Using Executable Directed Acyclic Graph

  • Jakkarin Lapmoon,
  • Thunpisit Kosolsriwiwat,
  • Sirinyaporn Jiraporn,
  • Somchart Fugkeaw

摘要

Implementing vulnerability assessment (VA) and penetration testing is one of the crucial methods to evaluate the security of web applications. The VA and Pentest results can be used to assess the present vulnerability of the system to help improve effective and up-to-date controls. However, using such static results for vulnerability analysis may not reflect the real situation of the organization’s security policy. In addition, the integration of VA results and adaptive vulnerability calculation of vulnerabilities found in web applications are not provided by existing VA tools. Essentially, a dynamic, and interactive vulnerability assessment system for web applications is crucial due to the dynamic nature of modern web applications causing the possible new threat landscapes. In this paper, we introduce DyVAM (Dynamic Vulnerability Assessment for Multi-Web Applications), a system that integrates OWASP ZAP results and Directed Acyclic Graphs (DAGs) for supporting interactive vulnerability analysis. Our proposed system also incorporates organizational policies into the vulnerability calculation to enable a more actionable and pertinent vulnerability assessment result. Finally, we conducted the experiments to substantiate the efficiency and practicality of our proposed system. The results demonstrate that DyVAM, when implemented with our proposed multi-threading approach, significantly improves processing speed compared to traditional processing.