Artificial Intelligence and Dynamic Analysis-Based Web Application Vulnerability Scanner

被引:0
|
作者
Yalcinkaya, Mehmet Ali [1 ]
Kucuksille, Ecir Ugur [2 ]
机构
[1] Kirsehir Ahi Evran Univ, Comp Engn Dept, Kirsehir, Turkiye
[2] Suleyman Demirel Univ, Comp Engn Dept, Isparta, Turkiye
关键词
Data Mining; Machine Learning; Web Application Penetration Tests; Web Application Vulnerabilities; FORMS;
D O I
10.22042/isecure.2023.367746.847
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The widespread use of web applications and running on sensitive data has made them one of the most significant targets of cyber attackers. One of the most crucial security measures that can be taken is detecting and closing vulnerabilities on web applications before attackers. This study developed a web application vulnerability scanner based on dynamic analysis and artificial intelligence, which could test web applications using GET and POST methods and had test classes for 21 different vulnerability types. The developed vulnerability scanner was tested on a web application test laboratory, created within this study's scope and had 262 different web applications. A data set was created from the tests performed using the developed vulnerability scanner. In this study, web page classification was made using the mentioned data set as a first stage. The highest success rate in the page classification process was determined by 95.39% using the Random Forest Algorithm. The second operation performed using the dataset was the association analysis between vulnerabilities. The proposed model saved 21% more time than the standard scanning model. The page classification process was also used in crawling the web application in this study. (c) 2024 ISC. All rights reserved.
引用
收藏
页码:55 / 77
页数:23
相关论文
共 50 条
  • [21] Research on artificial intelligence system based on web service
    Zhu, Qiang
    2007 International Symposium on Computer Science & Technology, Proceedings, 2007, : 595 - 598
  • [22] Dynamic Analysis of Emotions through Artificial Intelligence
    Mejia M, Susana
    Quintero M, Olga Lucia
    Castro M, Jaime
    AVANCES EN PSICOLOGIA LATINOAMERICANA, 2016, 34 (02): : 205 - 232
  • [23] ARTIFICIAL INTELLIGENCE IN ANALYSIS OF FAST DYNAMIC ACTIONS
    Stas, Ondrej
    Tolnay, Marian
    Magdolen, Lubos
    PROCEEDINGS OF THE ASME 10TH BIENNIAL CONFERENCE ON ENGINEERING SYSTEMS DESIGN AND ANALYSIS, 2010, VOL 3, 2010, : 885 - 889
  • [24] An Android Application Vulnerability Mining Method Based On Static and Dynamic Analysis
    Wang Chao
    Li Qun
    Wang XiaoHu
    Ren TianYu
    Dong JiaHan
    Guo GuangXin
    Shi EnJie
    PROCEEDINGS OF 2020 IEEE 5TH INFORMATION TECHNOLOGY AND MECHATRONICS ENGINEERING CONFERENCE (ITOEC 2020), 2020, : 599 - 603
  • [25] The Development of Artificial Intelligence-Based Web Application to Determine the Visibility Level of the Objects on the Road
    Kayakus, Mehmet
    Uncu, Ismail Serkan
    ARTIFICIAL INTELLIGENCE AND APPLIED MATHEMATICS IN ENGINEERING PROBLEMS, 2020, 43 : 502 - 508
  • [26] Evaluating AVDL descriptions for web application vulnerability analysis
    Le, Ha Thanh
    Loh, Peter Kok Keong
    ISI 2008: 2008 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, 2008, : 279 - +
  • [27] REALIZING WEB APPLICATION VULNERABILITY ANALYSIS VIA AVDL
    Le, Ha-Thanh
    Loh, Peter Kok Keong
    ICEIS 2008: PROCEEDINGS OF THE TENTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS, VOL ISAS-2: INFORMATION SYSTEMS ANALYSIS AND SPECIFICATION, VOL 2, 2008, : 259 - 265
  • [28] LUNG CLUSTERING ANALYSIS-BASED PHENOTYPES OF RHEUMATOID ARTHRITIS USING ARTIFICIAL INTELLIGENCE-BASED TECHNOLOGY FOR CHEST COMPUTED TOMOGRAPHY
    Nakayama, Y.
    Nakashima, R.
    Handa, T.
    Tanizawa, K.
    Onizawa, H.
    Fujii, T.
    Murata, K.
    Murakami, K.
    Onishi, A.
    Tanaka, M.
    Shirakashi, M.
    Hiwa, R.
    Tsuji, H.
    Kitagori, K.
    Akizuki, S.
    Yoshifuji, H.
    Morinobu, A.
    ANNALS OF THE RHEUMATIC DISEASES, 2023, 82 : 843 - 844
  • [29] MoSCAN: A Model-Based Vulnerability Scanner for Web Single Sign-On Services
    Wei, Hanlin
    Hassanshahi, Behnaz
    Bai, Guangdong
    Krishnan, Padmanabhan
    Vorobyov, Kostyantyn
    ISSTA '21: PROCEEDINGS OF THE 30TH ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, 2021, : 678 - 681
  • [30] Visual Analysis of The Application of Artificial Intelligence in Education
    Wang, Fei
    Tao Xinrong
    2018 INTERNATIONAL JOINT CONFERENCE ON INFORMATION, MEDIA AND ENGINEERING (ICIME), 2018, : 187 - 191