Proceedings of the XXth Conference of Open Innovations Association FRUCT (Nov 2023)

A Metamodel for Web Application Security Evaluation

  • Shao-Fang Wen

DOI
https://doi.org/10.23919/FRUCT60429.2023.10328176
Journal volume & issue
Vol. 34, no. 1
pp. 182 – https://youtu.be/VoG7qsK5UZw

Abstract

Read online

In the digital era, web applications have become a prevalent tool for businesses. As the number of web applications continues to grow, they become enticing targets for malicious actors seeking to exploit potential security vulnerabilities. Organizations face constant risks associated with vulnerabilities in their web-based software systems, which can result in data breaches, service disruptions, and a loss of trust. Consequently, organizations require an effective and efficient approach to assess and analyze the security of acquired web-based software, ensuring sufficient confidence in its utilization. This research aims to enhance the quantitative evaluation and analysis of web application security through a model-based approach. We focus on integrating the Open Web Application Security Project's (OWASP) Application Security Verification Standard (ASVS) into a structured and analyzable metamodel. This model aims to effectively assess the security levels of web applications while offering valuable insights into their strengths and weaknesses. By combining the ASVS with a comprehensive framework, we aim to provide a robust methodology for evaluating and analyzing web application security.

Keywords