Development of a framework for assessing the technical security of WEB resources based on OWASP recommendations
Автор: Sokolov I.S., Shevchenko A.V.
Журнал: Сетевое научное издание «Системный анализ в науке и образовании» @journal-sanse
Рубрика: Моделирование и анализ данных
Статья в выпуске: 3, 2025 года.
Бесплатный доступ
The article describes the process of developing a modular framework for evaluating the technical security of web applications based on OWASP recommendations. The analysis of current threats is carried out, OWASP Top 10 techniques are considered, as well as existing scanning tools. The proposed architecture includes modules for data collection, vulnerability checking (SQL injection, XSS, API errors) and report generation using the language model. The developed solution provides automation of security audit processes and can be used for educational, research and practical purposes.
OWASP, framework, vulnerabilities, SQL injection, XSS, web application security, audit automation, information security
Короткий адрес: https://sciup.org/14134055
IDR: 14134055 | УДК: 004.056, 004.75