Skip to main navigation Skip to search Skip to main content

Web Application Security Tools Analysis

  • Abdulrahman Alzahrani
  • , Ali Alqazzaz
  • , Ye Zhu
  • , Huirong Fu
  • , Nabil Almashfi
  • Department of Computer Science and Engineering, Oakland University
  • Cleveland State University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

23 Scopus citations

Abstract

Strong security in web applications is critical to the success of your online presence. Security importance has grown massively, especially among web applications. Dealing with web application or website security issues requires deep insight and planning, not only because of the many tools that are available but also because of the industry immaturity. Thus, finding the proper tools requires deep understanding and several steps, including analyzing the development environment, business needs, and the web applications' complexity. In this paper, we demonstrate the architecture of web applications then list and evaluate the widespread security vulnerabilities. Those vulnerabilities are: Insufficient Transport Layer Protection, Information Leakage, Cross-Site Scripting, and SQL Injection. In addition, this paper analyzes the tools that are used to scan for these widespread vulnerabilities in web applications. Finally, it evaluates tools due to security vulnerabilities and gives recommendations to the web applications' users and administrators aiming to educate them.
Original languageEnglish
Title of host publicationProceedings - 3rd IEEE International Conference on Big Data Security on Cloud, BigDataSecurity 2017, 3rd IEEE International Conference on High Performance and Smart Computing, HPSC 2017 and 2nd IEEE International Conference on Intelligent Data and Security, IDS 2017
EditorsMeikang Qiu
Place of Publicationusa
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages237-242
Number of pages6
ISBN (Electronic)9781509062959
DOIs
StatePublished - Jul 13 2017
Event3rd IEEE International Conference on Big Data Security on Cloud, BigDataSecurity 2017, 3rd IEEE International Conference on High Performance and Smart Computing, HPSC 2017 and 2nd IEEE International Conference on Intelligent Data and Security, IDS 2017 - Beijing, China
Duration: May 26 2017May 28 2017

Conference

Conference3rd IEEE International Conference on Big Data Security on Cloud, BigDataSecurity 2017, 3rd IEEE International Conference on High Performance and Smart Computing, HPSC 2017 and 2nd IEEE International Conference on Intelligent Data and Security, IDS 2017
Country/TerritoryChina
CityBeijing
Period05/26/1705/28/17

Keywords

  • Web application
  • web application security
  • web application vulnerabilities

Cite this