A survey on vulnerability assessment tools and databases for cloud-based web applications
Author(s) -
Kyriakos Kritikos,
Kostas Magoutis,
Manos Papoutsakis,
Sotiris Ioannidis
Publication year - 2019
Publication title -
array
Language(s) - English
Resource type - Journals
ISSN - 2590-0056
DOI - 10.1016/j.array.2019.100011
Subject(s) - vulnerability (computing) , cloud computing , agile software development , provisioning , computer science , vulnerability assessment , vulnerability management , web application , database , computer security , data science , world wide web , software engineering , telecommunications , psychology , psychological resilience , psychotherapist , operating system
Due to its various offered benefits, an ever increasing number of applications are migrated to the cloud. However, such a migration should be carefully performed due to the cloud's public nature. Further, due to the agile development cycle that applications follow, their security level might not be the best possible, exhibiting various sorts of vulnerability. As such, to better support application migration and runtime provisioning, this article supplies three main contributions. First, it attempts to connect vulnerability management to the application lifecycle so as to highlight the exact moments where application vulnerability assessment must be performed. Second, it analyses the state-of-the-art open-source tools and databases so as to enable developers to make an informed decision about which ones to select. In this sense, discovering such vulnerabilities will enable to better secure applications before or after migrating them to the cloud. The analysis conducted is quite rich, covering various aspects and a rich sets of criteria. Third, it explores the claim that vulnerability scanning tools need to be orchestrated to reach the highest possible vulnerability coverage, both in terms of extend and breadth. Finally, this article concludes with some challenges that current vulnerability tools and databases need to face to increase their added-value and applicability level.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom