An Improving Way For Website Security Assessment
Abstract
Nowadays, the Internet plays a crucial role in our society. AmongInternet services, web-based services are very popular thatbecome the target of security attacks. Hence, securing websitesand connection to the users is important. If we own or manage awebsite, we certainly concern about how secure it is. Forassessing the security level of a website, we usually take someaction, including testing the website using security scanningtools. Unfortunately, most of scanning tools have limitations andneed to be updated frequently for new vulnerabilities. Using onlyone scanning tool is sometime not enough to determine securitylevel of a website. In this paper we propose a frameworksupporting website security assessment. The idea of thisframework is to integrate different scanning tools into theframework. We then write a program to implement thisframework with a real website. We guide the users how to add anew scanning tool to this framework, manage it and generate afinal report.
Published
2020-08-17
Section
Regular articles
An author's submission implies that the manuscript has not been published previously, and is not currently submitted for publication elsewhere. Submission also implies that the Corresponding Author has consent of all authors (the Authors). Upon acceptance for publication transfer of copyright will be made to the Publisher of REV-JEC, who guarantees that full content of the published article is freely distributed on the Journal's website. The copyright transfer gives the Publisher of REV-JEC full authority to resolve any complaints of misuse or abuse (such as infringement or plagiarism) of the published article. The Authors have the freedom to redistribute and reuse the published article in any medium or format for any purpose, provided the original published article is properly cited. An article submission implies author agreement with this policy.