Baseline: Metrics for setting a baseline for web vulnerability scanners
نویسندگان
چکیده
As web scanners are becoming more popular because they are faster and cheaper than security consultants, the trend of relying on these scanners also brings a great hazard: users can choose a weak or outdated scanner and trust incomplete results. Therefore, benchmarks are created to both evaluate and compare the scanners. Unfortunately, most existing benchmarks suffer from various drawbacks, often by testing against inappropriate criteria that does not reflect the user’s needs. To deal with this problem, we present an approach called Baseline that coaches the user in picking the minimal set of weaknesses (i.e., a baseline) that a qualified scanner should be able to detect and also helps the user evaluate the effectiveness and efficiency of the scanner in detecting those chosen weaknesses. Baseline’s goal is not to serve as a generic ranking system for web vulnerability scanners, but instead to help users choose the most appropriate scanner for their specific needs.
منابع مشابه
Application of a New Approach in Optimizing the Operation of the Multi-Objective Reservoir
The application of optimization tools and techniques to operate the reservoir on a Multi-objective basis under the circumstances of climate change is unavoidable. The present study utilizes the Multi-Objective Farmland Fertility Optimization (MOFFA) algorithm to derive optimum rules on the operation of the Golestan Dam in Golestan province under circumstances of climate change. The two targets ...
متن کاملOptimization of Reservoir Operation using a Bioinspired Metaheuristic Based on the COVID-19 Propagation Model
Recently, global warming problems with rapid population growth and socio-economic development have intensified the demand for water and increased tensions on water supplies. This research evolves the Multi-Objective Coronavirus Optimization Algorithm (MOCVOA) to obtain operational optimum rules of Voshmgir Dam reservoir under the climate change conditions. The climatic variables downscaled and ...
متن کاملWeb Vulnerability Scanners: A Case Study
Cloud security is one of the biggest concerns for many companies. The growth in the number and size of websites increases the need for better securing those websites. Manual testing and detection of web vulnerabilities can be very time consuming. Automated Web Vulnerability Scanners (WVS) help with the detection of vulnerabilities in web applications. Acunetix is one of the widely used vulnerab...
متن کاملImproving the Adoption of Dynamic Web Security Vulnerability Scanners
Security vulnerabilities remain present in many web applications despite the improving knowledge base on vulnerabilities. Attackers can exploit such security vulnerabilities to extract critical data from web applications and their users. Many dynamic security vulnerability scanners exist that try to automatically find such security vulnerabilities. We studied the adoption of these tools and fou...
متن کاملEffective Learning to Rank Persian Web Content
Persian language is one of the most widely used languages in the Web environment. Hence, the Persian Web includes invaluable information that is required to be retrieved effectively. Similar to other languages, ranking algorithms for the Persian Web content, deal with different challenges, such as applicability issues in real-world situations as well as the lack of user modeling. CF-Rank, as a ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010