Artificial Intelligence and Dynamic Analysis-Based Web Application Vulnerability Scanner

Yükleniyor...
Küçük Resim

Tarih

Dergi Başlığı

Dergi ISSN

Cilt Başlığı

Yayıncı

Iranıan Soc Cryptology

Erişim Hakkı

info:eu-repo/semantics/openAccess

Özet

The widespread use of web applications and running on sensitive data has made them one of the most significant targets of cyber attackers. One of the most crucial security measures that can be taken is detecting and closing vulnerabilities on web applications before attackers. This study developed a web application vulnerability scanner based on dynamic analysis and artificial intelligence, which could test web applications using GET and POST methods and had test classes for 21 different vulnerability types. The developed vulnerability scanner was tested on a web application test laboratory, created within this study's scope and had 262 different web applications. A data set was created from the tests performed using the developed vulnerability scanner. In this study, web page classification was made using the mentioned data set as a first stage. The highest success rate in the page classification process was determined by 95.39% using the Random Forest Algorithm. The second operation performed using the dataset was the association analysis between vulnerabilities. The proposed model saved 21% more time than the standard scanning model. The page classification process was also used in crawling the web application in this study

Açıklama

Anahtar Kelimeler

Data Mining, Machine Learning, Web Application Penetration Tests, Web Application Vulnerabilities

Kaynak

Isecure-Isc International Journal of Information Security

WoS Q Değeri

Scopus Q Değeri

Cilt

16

Sayı

1

Künye

Yalçinkaya, M. A., & Küçüksille, E. U. (2024). Artificial Intelligence and Dynamic Analysis-Based Web Application Vulnerability Scanner. ISeCure, 16(1).

Onay

İnceleme

Ekleyen

Referans Veren