This research study is built upon cybersecurity audits and investigates the optimization of an Open Web Application Security Project (OWASP) Top 10 algorithm for Web Applications (WA) security audits using Vulnerability Assessment and Penetration Testing (VAPT) processes. The study places particular emphasis on enhancing the VAPT process by optimizing the OWASP algorithm. To achieve this, the research utilizes desk documents to gain knowledge of WA cybersecurity audits and their associated tools. It also delves into archives to explore VAPT processes and identify techniques, methods, and tools for VAPT automation. Furthermore, the research proposes a prototype optimization that streamlines the two steps of VAPT using the OWASP Top 10 algorithm through an experimental procedure. The results are obtained within a virtual environment, which employs black box testing methods as the primary means of data acquisition and analysis. In this experimental setting, the OWASP algorithm demonstrates an impressive level of precision, achieving a precision rate exceeding 90%. It effectively covers all researched vulnerabilities, thus justifying its optimization. This research contributes significantly to the enhancement of the OWASP algorithm and benefits the offensive security community. It plays a crucial role in ensuring compliance processes for professionals and analysts in the security and software development fields.
翻译:本研究基于网络安全审计,探讨了利用漏洞评估与渗透测试(VAPT)流程优化开放式Web应用程序安全项目(OWASP)Top 10算法,用于Web应用程序(WA)安全审计。研究重点在于通过优化OWASP算法来增强VAPT流程。为此,研究利用桌面文档获取WA网络安全审计及其相关工具的知识,并深入档案资料探究VAPT流程,识别VAPT自动化的技术、方法和工具。进一步地,本研究提出了一种原型优化方案,通过实验程序利用OWASP Top 10算法简化VAPT的两个步骤。结果在虚拟环境中获得,该环境采用黑盒测试方法作为数据采集与分析的主要手段。在该实验设置下,OWASP算法展现出令人印象深刻的精确度,精确率达到90%以上。它有效覆盖了所有研究的漏洞,从而验证了其优化的合理性。本研究对OWASP算法的增强做出了重要贡献,并使进攻性安全社区受益。对于安全与软件开发领域的专业人员和分析师而言,它在确保合规流程方面发挥着关键作用。