Performance-Based Comparative Assessment of Open Source Web Vulnerability Scanners

The widespread adoption of web vulnerability scanners and the differences in the functionality provided by these tool-based vulnerability detection approaches increase the demand for testing their detection effectiveness. Despite the advantages of dynamic testing approaches, the literature lacks stu...

Full description

Bibliographic Details
Main Authors: Mansour Alsaleh, Noura Alomar, Monirah Alshreef, Abdulrahman Alarifi, AbdulMalik Al-Salman
Format: Article
Language:English
Published: Hindawi-Wiley 2017-01-01
Series:Security and Communication Networks
Online Access:http://dx.doi.org/10.1155/2017/6158107
id doaj-a6538e4cf45844ffbea1ddb291e63a6e
record_format Article
spelling doaj-a6538e4cf45844ffbea1ddb291e63a6e2020-11-25T01:56:00ZengHindawi-WileySecurity and Communication Networks1939-01141939-01222017-01-01201710.1155/2017/61581076158107Performance-Based Comparative Assessment of Open Source Web Vulnerability ScannersMansour Alsaleh0Noura Alomar1Monirah Alshreef2Abdulrahman Alarifi3AbdulMalik Al-Salman4King Abdulaziz City for Science and Technology, Riyadh, Saudi ArabiaCollege of Computer and Information Sciences, King Saud University, Riyadh, Saudi ArabiaCollege of Computer and Information Sciences, King Saud University, Riyadh, Saudi ArabiaKing Abdulaziz City for Science and Technology, Riyadh, Saudi ArabiaCollege of Computer and Information Sciences, King Saud University, Riyadh, Saudi ArabiaThe widespread adoption of web vulnerability scanners and the differences in the functionality provided by these tool-based vulnerability detection approaches increase the demand for testing their detection effectiveness. Despite the advantages of dynamic testing approaches, the literature lacks studies that systematically evaluate the performance of open source web vulnerability scanners. The main objectives of this study are to assess the performance of open source scanners from multiple perspectives and to examine their detection capability. This paper presents the results of a comparative evaluation of the security features as well as the performance of four web vulnerability detection tools. We followed this comparative assessment with a case study in which we evaluate the level of agreement between the results reported by two open source web vulnerability scanners. Given that the results of our comparative evaluation did not show significant performance differences among the scanners while the results of the conducted case study revealed high level of disagreement between the reports generated by different scanners, we conclude that the inconsistencies between the reports generated by different scanners might not necessarily correlate with their performance properties. We also present some recommendations for helping developers of web vulnerabilities scanners to improve their tools’ capabilities.http://dx.doi.org/10.1155/2017/6158107
collection DOAJ
language English
format Article
sources DOAJ
author Mansour Alsaleh
Noura Alomar
Monirah Alshreef
Abdulrahman Alarifi
AbdulMalik Al-Salman
spellingShingle Mansour Alsaleh
Noura Alomar
Monirah Alshreef
Abdulrahman Alarifi
AbdulMalik Al-Salman
Performance-Based Comparative Assessment of Open Source Web Vulnerability Scanners
Security and Communication Networks
author_facet Mansour Alsaleh
Noura Alomar
Monirah Alshreef
Abdulrahman Alarifi
AbdulMalik Al-Salman
author_sort Mansour Alsaleh
title Performance-Based Comparative Assessment of Open Source Web Vulnerability Scanners
title_short Performance-Based Comparative Assessment of Open Source Web Vulnerability Scanners
title_full Performance-Based Comparative Assessment of Open Source Web Vulnerability Scanners
title_fullStr Performance-Based Comparative Assessment of Open Source Web Vulnerability Scanners
title_full_unstemmed Performance-Based Comparative Assessment of Open Source Web Vulnerability Scanners
title_sort performance-based comparative assessment of open source web vulnerability scanners
publisher Hindawi-Wiley
series Security and Communication Networks
issn 1939-0114
1939-0122
publishDate 2017-01-01
description The widespread adoption of web vulnerability scanners and the differences in the functionality provided by these tool-based vulnerability detection approaches increase the demand for testing their detection effectiveness. Despite the advantages of dynamic testing approaches, the literature lacks studies that systematically evaluate the performance of open source web vulnerability scanners. The main objectives of this study are to assess the performance of open source scanners from multiple perspectives and to examine their detection capability. This paper presents the results of a comparative evaluation of the security features as well as the performance of four web vulnerability detection tools. We followed this comparative assessment with a case study in which we evaluate the level of agreement between the results reported by two open source web vulnerability scanners. Given that the results of our comparative evaluation did not show significant performance differences among the scanners while the results of the conducted case study revealed high level of disagreement between the reports generated by different scanners, we conclude that the inconsistencies between the reports generated by different scanners might not necessarily correlate with their performance properties. We also present some recommendations for helping developers of web vulnerabilities scanners to improve their tools’ capabilities.
url http://dx.doi.org/10.1155/2017/6158107
work_keys_str_mv AT mansouralsaleh performancebasedcomparativeassessmentofopensourcewebvulnerabilityscanners
AT nouraalomar performancebasedcomparativeassessmentofopensourcewebvulnerabilityscanners
AT monirahalshreef performancebasedcomparativeassessmentofopensourcewebvulnerabilityscanners
AT abdulrahmanalarifi performancebasedcomparativeassessmentofopensourcewebvulnerabilityscanners
AT abdulmalikalsalman performancebasedcomparativeassessmentofopensourcewebvulnerabilityscanners
_version_ 1724982212965695488