Comparative Review of Vulnerability Analysis Tools
Isaac A. Odun-Ayo, Odede Blessing, Isaac Martins, Emmanuel Owoka, Timileyin Owoseni, Emmanuel Chibueze Omonedo · 2024
There are many vulnerabilities analysis tools available, ranging from free and open-source to paid and premium versions. Vulnerability test shows the correct behavior of a system’s security controls. The aim of this study is to evaluate the mostly used vulnerability analysis tools in penetration testing and to have a comparison done among these tools based on their usage, performance, type, and how they proffer solutions in a different environment. The method used in this study involved analyzing recommended literature with respect to defined inclusion and exclusion criteria and also based on the frequently discussed tools found in literature which can also be referred to as the widely used tools by industry practitioners. The result shows that, of the selected tools 20% could detect SQL injection, 24% can detect Cross-Site Scripting, 18% can detect Rogue Servers, 21% can detect Denial of service attack, while 14% can detect Remote Code Execution attacks. The result also shows that most of the tools run on Linux, followed by windows operating system. 24% are Open Source, 12% of the tools are free tools and licensed/subscription based respectively. This study concludes that there is no one perfect tool for vulnerability analysis and penetration test, and the best choice will depend on the aim and objectives of any given scenario. The study also looked to help achieve one of the 17 Sustainable Development Goals (SDG) – Decent Work and Economic Growth by helping organizations and nations protect their data and funds from attacks that can help boost the economy and provide employment and fair pay for citizens.