Design and implementation of an integrated automated vulnerability scanning platform for web application security assessment

Loading...
Thumbnail Image

Date

item.page.thesis.degree.name

item.page.thesis.degree.level

item.page.thesis.degree.discipline

item.page.thesis.degree.department

item.page.thesis.degree.grantor

item.page.thesis.degree.advisor

item.page.thesis.degree.committeeMember

Journal Title

Journal ISSN

Volume Title

Publisher

Національний технічний університет "Харківський політехнічний інститут"

Abstract

Topicality. The rapid proliferation of web applications across enterprise ecosystems has intensified the demand for comprehensive, automated vulnerability detection mechanisms. Existing standalone scanning tools exhibit inherent limitations in coverage scope, reporting standardization, and CI/CD pipeline integration, necessitating the development of unified orchestration platforms. The subject of study in this article is the architectural design and implementation of a modular, Python-based integrated vulnerability scanner that consolidates multiple open-source security testing utilities into a cohesive automation framework. The purpose of the article is to develop and validate an extensible platform capable of orchestrating reconnaissance, dynamic application security testing (DAST), static configuration analysis, and information leak detection through unified command-line interface and consolidated HTML reporting.
Актуальність. Стрімке поширення веб-додатків у корпоративних екосистемах посилило потребу в комплексних автоматизованих механізмах виявлення вразливостей. Існуючі автономні інструменти сканування мають обмеження щодо охоплення, стандартизації звітності та інтеграції в CI/CD конвеєри, що потребує розробки уніфікованих платформ оркестрації.Предметом дослідженняу статті є архітектурне проєктування та реалізація модульного сканера вразливостей на базі Python, який консолідує кілька утиліт з відкритим кодом у єдину рамку автоматизації.Метою статтіє розробка та валідація розширюваної платформи, здатної оркеструва,ти розвідку, динамічне тестування безпеки додатків (DAST), статичний аналіз конфігурацій та виявлення витоків інформації через уніфікований інтерфейс командного рядка з консолідованою HTML-звітністю.

Description

Citation

Fediushyn O., Khivrenko H., Popova N., Stadnik V. Design and implementation of an integrated automated vulnerability scanning platform for web application security assessment. Територия безпеки. 2026. Т. 2. № 2. С. 78-85.

Related resource link

Endorsement

Review

Supplemented By

Referenced By