Using WASSEC to Analysis and Evaluate Open Source Web WASSEC to Analysis and Evaluate Open Source Web WASSEC to Analysis and Evaluate Open Source Web WASSEC to Analysis and Evaluate Open Source Web Application Security Scanners Application Security Scanners Application Security Scanners Application Security Scanners
Fakhreldeen Abbas Saeed · 2014
The web application security has currently become a very significant area of scholarship, the best way to deal with it is to use web application security scanner to discover the architectural weaknesses and vulnerabilities in the web application. The goal of this paper is to use The Web Application Security Scanner Evaluation Criteria (WASSEC) to compare and contrast the Open Source Web Application Security Scanners, and show the differences between them. We used six factors to do this compression (Protocol Support, Authentication, Session Management, Crawling, Parsing and Testing). The study shows that W3AF 1.2-rev509, arachniv0.4.0.3, IronWASP v0.9.1.0, Skipfish 2.07b and Zed Attack Proxy v1.4.0.1 are the most suitable ones because they have 0.554217, 0.385542, 0.385542, 0.349398 and 0.337349 averages respectively. As the result of this study and depend on the information about the Open Source Web Application Security Scanner we collected; the web developer can use W3AF with IronWASP to cover Parsing factor and arachniv0.4.0.3 or Zed Attack Proxy v1.4.0.1 to cover Authentication factor.