Performance Evaluation of Open Source Web Application Vulnerability Scanners based on OWASP Benchmark

Pious Akwasi Sarpong, Lawrence Larbi Sakyi, Daniel Paa Paa, Issah Bala Abdulai, Richard Amankwah, Akwasi Amponsah · International Journal of Computer Applications · 2021

The use of web application has become a critical component in our daily routine work due to its enormous benefits.Unfortunately, most of the web application deployed are not totally devoid of bugs which makes them vulnerable to attacks.Web application scanners are tools that detect security vulnerability in web application.Although there are several commercial and open-source web application vulnerability scanners proposed in literature, the performance of these scanners varies in relation to their detection capabilities.The aim of this paper is to assess and compare the vulnerability detection capabilities of five open-source web application vulnerability scanners (WAVS), namely, ZAP, Skipfish, Arachni, IronWASP and Vega by executing them against two vulnerable web applications, damn vulnerable web application (DVWA) and WebGoat.Furthermore, we evaluate the performance of the scanner results using the OWASP benchmark metric.The experimental results show that ZAP, Skipfish and Vega are very efficient for detecting the most common web vulnerabilities, such as Command Execution Cross-Site Scripting and SQL injection.The findings further show Skipfish obtained the highest Youden index of 0.7 and 0.6 in DVWA and WebGoat, which makes the scanner superior than all the studied tools.Based on our evaluation results, we make some valuable recommendations since software security is a very fast-growing domain.

Read the paper · More papers on PaperTik