Logo image
Evaluation Of Information Security in Web Application Through Penetration Testing Techniques Using OWASP Risk Methodology
Conference proceeding   Open access

Evaluation Of Information Security in Web Application Through Penetration Testing Techniques Using OWASP Risk Methodology

Chinekezi Chinyere Echefunna, Jude Osamor, Celestine Iwendi, Pius Owoh, Moses Ashawa and Anand Philip
2024 International Conference on Advances in Computing Research on Science Engineering and Technology (ACROSET)
International Conference on Advances in Computing Research on Science Engineering and Technology (ACROSET 2024) (Indore, India, 27/09/2024–28/09/2024)
12/11/2024

Abstract

Penetration testing techniques, Information security, OWASP, Web Application, Data Breach, Malicious, Scanning Cybersecurity
Web applications are indispensable to today's business operations. The emergence of e-commerce platforms, online finance, and social networking websites has significantly transformed our interactions, communication, and business practices. This increased dependence on web applications has increased the likelihood of cyber threats and attacks. Therefore, it is of the utmost importance to implement robust security measures to protect sensitive data and reduce intrusions. Incorporating evidence from penetration testing techniques, tools and OWASP risk methodology, this study demonstrates the inherent limitations of relying exclusively on a single scanning tool, as evidenced by the different results obtained when using several different techniques and tools. It argues that the most effective technique for identifying and remediating web application vulnerabilities is to implement a comprehensive testing technique that incorporates different kinds of vulnerability scanners and techniques. These concerns are especially evident when using grey box testing techniques along with manual and automated scanning tools such as Acunetix, Invicti, Burp Suite Professional, and OWASP ZAP to evaluate the different factors such as vulnerability coverage, scanning speed, vulnerability detection, and false positive rate. By adopting the method described, the security community can obtain reliable information that will help them make informed decisions when selecting penetration testing techniques and tools to effectively secure websites and applications information.
pdf
Evaluation of Information Security in Web Application Through Penetration Testing Techniques Using OWASP Risk Methodology2.17 MBDownloadView
AcceptedIn Copyright All Rights Reserved Open Access
url
Conference pageView
Event Website
url
Link to published versionView
Published (Version of record)Publisher sites may require subscription to read contentIn Copyright All Rights Reserved Restricted
url
https://researchonline.gcu.ac.uk/en/publications/7a34ed69-0939-47aa-8af7-3d66197c102fView
Open

Metrics

296 File views/ downloads
42 Record Views
2 Times Cited - Scopus

Details

Logo image

Usage Policy