Journal Article10.2352/ei.2024.36.3.mobmu-326
Vulnerability Management Using Open-Source Tools
Navaneeth Shivananjappa,Reiner Creutzburg +1 more
TL;DR: Vulnerability management using open-source tools enhances security posture by identifying and remediating vulnerabilities through asset discovery, vulnerability scanning, and remediation processes.
read more
Abstract: In today's cybersecurity landscape, protecting information systems is crucial due to the rising threat of cyber-attacks.This research focuses on vulnerability management using open-source tools for domain and subdomain enumeration, vulnerability scanning, and remediation.Open-source software offers costeffective and collaborative security solutions.Domain and subdomain enumeration tools play a vital role in mapping an organization's attack surface, providing insight into security posture.The analysis of vulnerability scanning tools highlights their effectiveness in identifying critical flaws in web applications and databases.Vulnerability remediation through patching, hardening, and exposure management processes closes security gaps.The research provides an empirical insight into using open-source tools for vulnerability management, listing their benefits and limitations empowering organizations to enhance their security posture.Recommendations for integrating these tools into existing security frameworks help combat cyber threats and protect valuable assets.1. To identify a variety open-source tools for asset discovery, to map out the attack surface of target organization by enumerating domains, subdomains and ASN's through passive means, their scope and limitations and a comparative analysis the result of their enumerations.2. To identify and test a range of open-source vulnerability scanners and conduct a comparative analysis of the scanners by testing them against test website http://testphp.vulnweb.com/,http://php.testsparker.com/and comparing the types of issues found and how we can use them to identify vulnerabilities in our assets.3.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
References
Testing and Comparing Web Vulnerability Scanning Tools for SQL Injection and XSS Attacks
José Fonseca,Marco Vieira,Henrique Madeira +2 more
- 17 Dec 2007
TL;DR: A method to evaluate and benchmark automatic web vulnerability scanners using software fault injection techniques, where the most common types of software faults are injected in the web application code which is then checked by the scanners.
189
Power-Performance Trade-Off of a Dependable Multicore Processor
Toshinori Sato,Toshimasa Funaki +1 more
- 17 Dec 2007
TL;DR: This paper investigates trade-off between power and performance of a dependable multicore processor, which is named multiple clustered core processor (MCCP), and proposes to hybrid thread- and instruction-level redundancy to achieve both large power efficiency and small performance loss.
135
Reducing Internet-based intrusions: Effective security patch management
B. Brykczynski,R.A. Small +1 more
TL;DR: The Software Productivity Consortium (the Consortium) has been investigating methods for improving and measuring four essential defenses against Internet-based threats: security patch management, system and application hardening, network reconnaissance and enumeration, and tools against malicious software as discussed by the authors.
49
Enterprise Vulnerability Management and Its Role in Information Security Management
TL;DR: An effective vulnerability management program will not only guard against hackers, but will also assure minimal impact from hybrid malcode that exploits known vulnerabilities.
40
A case study on web application vulnerability scanning tools
Nor Izyani Daud,Khairul Azmi Abu Bakar,Mohd Shafeq Md Hasan +2 more
- 09 Oct 2014
TL;DR: This paper attempts to share about the tools that were used to perform vulnerability analysis within the organization and result and finding from vulnerability scanning will be discussed in detail.
34
