This paper develops and presents a methodology for automated vulnerability detection in web application development implemented on Folipro digital platform. It is investigated that securing web applications becomes critical as vulnerabilities can lead to data leaks and unauthorized access. The proposed methodology integrates state-of-the-art approaches including static application security analysis with Semgrep tool, dynamic analysis with ZAP, software composition analysis with depcheck and Trivy tools, and secret detection using TruffleHog and GitLeaks. Implemented the deployment of these tools in a continuous integration and deployment pipeline to automate the vulnerability discovery process. Found that the methodology reduced vulnerability discovery time from 8 h to 5 min and increased the number of vulnerabilities discovered from 49 to 110. It is determined that the methodology requires refinements to reduce false positives and missed vulnerabilities. It is found that the proposed technique significantly improves the speed, accuracy and efficiency of vulnerability detection and reduces labour costs, strengthening the security of web applications.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Practical Application of Automated Vulnerability Detection Methodology for Web Application Development on Folipro Digital Project Learning Support Platform

  • Vladislav Philippovich

摘要

This paper develops and presents a methodology for automated vulnerability detection in web application development implemented on Folipro digital platform. It is investigated that securing web applications becomes critical as vulnerabilities can lead to data leaks and unauthorized access. The proposed methodology integrates state-of-the-art approaches including static application security analysis with Semgrep tool, dynamic analysis with ZAP, software composition analysis with depcheck and Trivy tools, and secret detection using TruffleHog and GitLeaks. Implemented the deployment of these tools in a continuous integration and deployment pipeline to automate the vulnerability discovery process. Found that the methodology reduced vulnerability discovery time from 8 h to 5 min and increased the number of vulnerabilities discovered from 49 to 110. It is determined that the methodology requires refinements to reduce false positives and missed vulnerabilities. It is found that the proposed technique significantly improves the speed, accuracy and efficiency of vulnerability detection and reduces labour costs, strengthening the security of web applications.