Open Source Web Vulnerability Scanners: The Cost Effective Choice?
Kinnaird McQuade · 2014
A plethora of tools are available to software testers so that software vulnerabilities can be mitigated before product deployment. However, some of these tools are less effective than others. In particular, open source dynamic web vulnerability scanners raise concerns including (1) total attack and input vector support, (2) scan coverage of different application protocols, and (3) rate of required manual detection versus automated detection. Additionally, what is often most attractive about proprietary scanners is vendor support and frequent software maintenance bundled with a paid licensing agreement. Indeed, the need for software support will ensure the longevity of proprietary dynamic web vulnerability scanners on the market. However, a low-cost alternative is available and recommended for web developers involved in agile development at small to medium sized development firms; it is the finding of this research that when a combination of certain open source tools are used in conjunction with a specific scanning strategy, there is a greater vulnerability detection accuracy than solely using a single proprietary scanner.