Reducing Attack Surface of a Web Application by Open Web Application Security Project Compliance

被引:3
|
作者
Goswami, Sumit [1 ]
Krishnan, Nabanita R. [1 ]
Mukesh [1 ]
Swarnkar, Saurabh [2 ]
Mahajan, Pallavi
机构
[1] DRDO, Directorate Management Informat Syst & Technol, New Delhi, India
[2] IAP Co Pvt Ltd, Gurgaon, India
关键词
Attack surface; DRDO Intranet; project management; open web application security project; security audit; security compliance; SOFTWARE;
D O I
10.14429/dsj.62.1291
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
The attack surface of a system is the amount of application area that is exposed to the adversaries. The overall vulnerability can be reduced by reducing the attack surface of a web application. In this paper, we have considered the web components of two versions of an in-house developed project management web application and the attack surface has been calculated prior and post open web application security project (OWASP) compliance based on a security audit to determine and then compare the security of this Project Management Application. OWASP is an open community to provide free tools and guidelines for application security. It was observed that the attack surface of the software reduced by 45 per cent once it was made OWASP compliant. The vulnerable surface exposed by the code even after OWASP compliance was due to the mandatory access points left in the software to ensure accessibility over a network.
引用
收藏
页码:324 / 330
页数:7
相关论文
共 50 条
  • [1] Security Qualitative Metrics for Open Web Application Security Project Compliance
    Sonmez, Ferda Ozdemir
    10TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT 2019) / THE 2ND INTERNATIONAL CONFERENCE ON EMERGING DATA AND INDUSTRY 4.0 (EDI40 2019) / AFFILIATED WORKSHOPS, 2019, 151 : 998 - 1003
  • [2] Open Web Application Security Project
    Dirk Fox
    Datenschutz und Datensicherheit - DuD, 2006, 30 (10) : 636 - 636
  • [3] Mitigation from SQL Injection Attacks on Web Server using Open Web Application Security Project Framework
    Fadlil, A.
    Riadi, I.
    Mu'min, M. A.
    INTERNATIONAL JOURNAL OF ENGINEERING, 2024, 37 (04): : 635 - 645
  • [4] Ontology for attack detection: An intelligent approach to web application security
    Razzaq, Abdul
    Anwar, Zahid
    Ahmad, H. Farooq
    Latif, Khalid
    Munir, Faisal
    COMPUTERS & SECURITY, 2014, 45 : 124 - 146
  • [5] Vulnerability Analysis of E-voting Application using Open Web Application Security Project (OWASP) Framework
    Sunardi, Sunardi
    Riadi, Imam
    Raharja, Pradana Ananda
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (11) : 135 - 143
  • [6] Open Source Web Application Security: A Static Analysis Approach
    Alenezi, Mamdouh
    Javed, Yasir
    2016 INTERNATIONAL CONFERENCE ON ENGINEERING & MIS (ICEMIS), 2016,
  • [7] Open source web application security: A static analysis approach
    College of Computer and Information Sciences, Prince Sultan University, Riyadh
    11586, Saudi Arabia
    Proc. - Int. Conf. Eng. MIS, ICEMIS,
  • [8] Web application security engineering
    Meier, J. D.
    IEEE SECURITY & PRIVACY, 2006, 4 (04) : 16 - 24
  • [9] Web application for project management based on open source solutions
    Wojtera, M.
    Sakowicz, B.
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE MIXED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2006, : 797 - +
  • [10] Web Application Security Education Platform Based on OWASP API Security Project
    Idris, Muhammad
    Syarif, Iwan
    Winarno, Idris
    EMITTER-INTERNATIONAL JOURNAL OF ENGINEERING TECHNOLOGY, 2022, 10 (02) : 246 - 261