OWASP-Based Assessment of Web Application Security
Aisha Khanum, Sana Qadir, Seema Jehan · 2023
Inadequate vulnerability assessment of web applications during the Software Development Life Cycle (SDLC) leads to security breaches posing a severe threat to digital transformation of businesses processes. Recently, Open Web Application Security Project (OWASP) augmented its list of common vulnerabilities found in web applications. In addition, they also provide Top 10 guidelines to help developers identify and eliminate these vulnerabilities. This study aims at evaluating the effectiveness of suggested guidelines in 70 web applications using the OWASP Zed Attack Proxy tool along with pre- and post-implementation analyses of cheat sheets on an enterprise-level web application. We observed that ranking categories in the Top 10 is not solely determined by frequency. Moreover, vulnerabilities in the Website X Division Head's portal reduced by 68.75% as a result of the cheat sheet analysis. In addition, the improvement was also significant in the Recruiter's portal (63.63%) whereas the reduction in the Candidates' portal's number of vulnerabilities was only 12.5%. The results suggest that cheat sheets can effectively address a number of web application vulnerabilities. However, additional measures such as S-SDLC and manual validation are needed for enhanced security of web applications.