Open Source Web Vulnerability Scanners: The Cost Effective Choice?

Open Source Web Vulnerability Scanners: The Cost Effective Choice?
复制标题

开源 Web 漏洞扫描器:经济高效的选择?

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
Kinnaird McQuade
Kinnaird McQuade
中科院分区:
--
文献类型:
--
作者:
Kinnaird McQuade

文献摘要

被引文献

相似文献

A plethora of tools are available to software testers so that software vulnerabilities can be mitigated before product deployment. However, some of these tools are less effective than others. In particular, open source dynamic web vulnerability scanners raise concerns including (1) total attack and input vector support, (2) scan coverage of different application protocols, and (3) rate of required manual detection versus automated detection. Additionally, what is often most attractive about proprietary scanners is vendor support and frequent software maintenance bundled with a paid licensing agreement. Indeed, the need for software support will ensure the longevity of proprietary dynamic web vulnerability scanners on the market. However, a low-cost alternative is available and recommended for web developers involved in agile development at small to medium sized development firms; it is the finding of this research that when a combination of certain open source tools are used in conjunction with a specific scanning strategy, there is a greater vulnerability detection accuracy than solely using a single proprietary scanner.