z-logo
Premium
An empirical comparison of commercial and open‐source web vulnerability scanners
Author(s) -
Amankwah Richard,
Chen Jinfu,
Kudjo Patrick Kwaku,
Towey Dave
Publication year - 2020
Publication title -
software: practice and experience
Language(s) - English
Resource type - Journals
SCImago Journal Rank - 0.437
H-Index - 70
eISSN - 1097-024X
pISSN - 0038-0644
DOI - 10.1002/spe.2870
Subject(s) - computer science , vulnerability (computing) , open source , vulnerability assessment , computer security , benchmark (surveying) , false positive paradox , source code , web application security , vulnerability management , web application , ibm , application security , world wide web , web service , software security assurance , information security , web development , software , operating system , artificial intelligence , geography , materials science , psychological resilience , psychotherapist , security service , psychology , geodesy , nanotechnology
Summary Web vulnerability scanners (WVSs) are tools that can detect security vulnerabilities in web services. Although both commercial and open‐source WVSs exist, their vulnerability detection capability and performance vary. In this article, we report on a comparative study to determine the vulnerability detection capabilities of eight WVSs (both open and commercial) using two vulnerable web applications: WebGoat and Damn vulnerable web application. The eight WVSs studied were: Acunetix; HP WebInspect; IBM AppScan; OWASP ZAP; Skipfish; Arachni; Vega; and Iron WASP. The performance was evaluated using multiple evaluation metrics: precision; recall; Youden index; OWASP web benchmark evaluation; and the web application security scanner evaluation criteria. The experimental results show that, while the commercial scanners are effective in detecting security vulnerabilities, some open‐source scanners (such as ZAP and Skipfish) can also be effective. In summary, this study recommends improving the vulnerability detection capabilities of both the open‐source and commercial scanners to enhance code coverage and the detection rate, and to reduce the number of false‐positives.

This content is not available in your region!

Continue researching here.

Having issues? You can contact us here