The approaches to quantify web application security scanners quality: a review

Lim Kah Seng, Norafida Ithnin, Syed Zainudeen Mohd Said · International Journal of Advanced Computer Research · 2018

Automated web application penetration testing is becoming ubiquitous with the development of computer programs that capable of simulating tester activities of web application penetration testing.Computer programs like HTTrack [1] or Maltego [2] were invented to aid penetration tester in intelligent information gathering.The invented web application security scanners like Acunetix [3] scanned web applications for vulnerability assessment.In the meanwhile, exploitation tools like Metasploit and WFuzz are created to compromise web application confidentiality, integrity, and availability.The web application penetration testing methodology of [4] showed web application security scanner always has a critical role in scanning the web application for vulnerability detection.

Read the paper · More papers on PaperTik