Journal & Conference Proceeding Publications



ID Code : CSC 0043
Title : A Survey on Conducting Vulnerability Assessment in Web-Based Application
Author/s :

Nor Fatimah Awang [UPNM];
Azizah Abd Manaf [UTM];
and Wan Shafiuddin Zainudin

Abstract : Many organizations have changed their traditional systems to web-based applications to make more profit and at the same time to increase the efficiency of their activities such as customer support services and data transactions. However web-based applications have become a major target for attackers due to some common vulnerability exists in the application. Assessing the level of information security in a web-based application is a serious challenge for many organizations. One of the important steps to ensure the security of web application is conducting vulnerability assessment periodically. Vulnerability assessment is a process to search for any potential loopholes or vulnerability contain in a system. Most of the current efforts in assessments are involve searching for known vulnerabilities that commonly exist in web-based application. The process of conducting vulnerability assessment can be improved by understanding the functionality of the application and characteristics of the nature vulnerabilities. In this paper, we perform an empirical study on how to do vulnerability assessment with the aim of understanding how the functionality, vulnerabilities and activities that would benefit for the assessment processes from the perspective of application security.
Publication :

Proceeding of the 2nd International Conference on Advanced Machine
Learning Technologies and Applications

Year Published : 2014|459- 471|Conference Proceeding
PDF / Official URL : http://link.springer.com/chapter/10.1007%2F978-3-319-13461-1_43