<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Recommended Practices for the Analysis of Web Application Vulnerabilities</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vitali V. Varenitca</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alexey S. Markov</string-name>
          <email>a.markov@bmstu.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vladislav V. Savchenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Certification Department NPO Echelon</institution>
          ,
          <addr-line>JTC Moscow</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Information Security Department Bauman Moscow State Technical University Moscow</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>75</fpage>
      <lpage>78</lpage>
      <abstract>
        <p>The paper is dedicated to information security of web applications. It discusses main classes of web application vulnerabilities and topic-related regulatory documents. An original procedure for the analysis of web application vulnerabilities is suggested. Conformity of the suggested procedure with modern standards is demonstrated. The paper highlights some issues of concern associated with the analysis of vulnerabilities and identification of existing web application vulnerabilities, and suggests a few ways of how to solve them. The effectiveness and efficiency of this technique has been proved by the vulnerability statistics in the course of software certification for compliance with information security requirements.</p>
      </abstract>
      <kwd-group>
        <kwd>- assessment of web application security</kwd>
        <kwd>vulnerability assessment</kwd>
        <kwd>vulnerability analysis technique</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>I. INTRODUCTION</title>
      <p>
        Timely identification of vulnerabilities is one of the most
crucial tasks of web application testing [
        <xref ref-type="bibr" rid="ref1 ref2 ref4 ref5 ref6">1-6</xref>
        ]. The importance of
this problem is attributed to a number of reasons, including the
key ones [
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref13 ref14 ref15 ref7 ref8 ref9">7-15</xref>
        ]:
      </p>
      <p>— Existing vulnerabilities imply poor security of data
processed by web applications.</p>
      <p>— It is difficult to identify various classes of web application
vulnerabilities using static analyzers.</p>
      <p>— Constantly growing complexity of modern web
applications, the number of problems to be solved and the level
of integration with other software and hardware make the
problem of software code analysis insolvable due to limited
resources allocated for testing.</p>
      <p>— Certain classes of web application vulnerabilities cannot
be identified using automation tools without a comprehensive
vulnerability analysis.</p>
      <p>— Regular vulnerability analysis helps minimize the risks
associated with eventual intrusion and violation of the integrity,
availability, and confidentiality of data processed by the web
application.</p>
      <p>
        Existing vulnerabilities mean web application vulnerabilities
that are confirmed by the developer or those for which an
exploitation scenario exists [
        <xref ref-type="bibr" rid="ref16 ref17">16, 17</xref>
        ].
      </p>
      <p>We have analyzed information available in open information
sources (OIS) in order to identify the causes of web application
vulnerabilities and vulnerability exploits. To date, the open
project of web application security assurance, Open
WebApplication Security Project (OWASP), is one of the most
comprehensive open information sources. OWASP regularly
publishes information on existing web application attack
techniques as well as the rating of attacks based on their
implementation complexity, frequency, and criticality.
Vulners (https://vulners.com/), CVE (https://cve.mitre.org/),
NIST (https://www.nist.gov) databases, databank of security
threats of the Federal Service for Technical and Export Control
(https://bdu.fstec.ru) can also be useful.</p>
      <p>II. METHODOLOGICAL APPROACH TO WEB APPLICATION</p>
      <p>VULNERABILITY ANALYSIS</p>
      <p>To make the web application vulnerability analysis more
effective, a vulnerability analysis technique based on web
application vulnerability analysis has been developed using the
information available in open sources.</p>
      <p>At first, developer’s software documents, including the
source code need to be obtained. In addition to the software
documents, the expert can obtain a set of tests the developer
carries out during the routine analysis of the product
vulnerabilities and other types of tests. The developer can also
provide a test bench to enable familiarization with the product
and ad hoc testing.</p>
      <p>At this stage, the expert should study the public information
sources to improve his/her awareness of the goals and tasks the
tested product solves, the product purpose and its main
functional features. The information should be sought for in the
following publicly available sources:</p>
    </sec>
    <sec id="sec-2">
      <title>Software developer’s website.</title>
      <p>- OWASP Foundation – the free and open software
security community (https://www.owasp.org).</p>
      <p>- Other sources that contain information about the tested
software and the information about similar software.</p>
      <p>Sought for information required to expand the initial data
should be based on following criteria:</p>
    </sec>
    <sec id="sec-3">
      <title>Product name and version. Name of similar software. testing.</title>
      <p>- Names of products which have the architecture similar to
that of the tested product</p>
      <p>- expert’s propositions about the technologies used in the
tested product based on expert’s experience and qualification
The next stage includes ad hoc testing of the product.</p>
      <p>During the exploratory testing, the expert shall perform ad
hoc testing of the product.</p>
      <p>The expert shall use a bench with the product installed and
configured as required by the documents to prepare for ad hoc
testing. To complete this step, the expert can:</p>
      <p>Use the bench prepared by the developer for ad hoc
- Install and configure the product as required by the
documents on his/her own.</p>
      <p>- Use the product installed as part of the existing information
system.</p>
    </sec>
    <sec id="sec-4">
      <title>During this step, the expert shall:</title>
      <p>View the product.</p>
      <p>operation</p>
      <p>- Test the product trying to disrupt the software operation or
make it stop as soon as possible.</p>
      <p>- Define the list of tools the expert is planning to use to
identify defects in the code or product configuration.</p>
    </sec>
    <sec id="sec-5">
      <title>A product can be tested by:</title>
      <p>- Changing the configuration of the product and tools the
product interacts with during the operation
- Using different variations of input data</p>
      <p>Using the product to process data known to be incorrect
Making intentional attempts to put the product out of
- Studying the responses to specially formulated requests
to the product</p>
      <p>At the end of ad hoc testing, the following shall be
documented:</p>
      <p>- Potential weaknesses of the software which, in expert’s
opinion, may be the evidence of defects in the software code
- Name of potentially vulnerable technologies used to
implement functional features of the product
- List of potentially unsafe product configurations</p>
      <p>Then the expert shall carry out exploratory testing. At this
stage, the expert shall perform the tests using the steps listed
below.</p>
      <p>The expert shall prepare for the exploratory testing. The
expert shall obtain a bench with the product installed and
configured as required by the documents to prepare for
exploratory testing. The expert shall install and configure the
product on his/her own. The bench shall allow for all types of
product researches in all operation modes defined in the
documents or tests required by the customer.</p>
      <p>When preparing the test bench the expert shall perform the
steps listed below.</p>
      <p>III. CONFIGURATION OF THE SOFTWARE OPERATIONAL</p>
      <p>ENVIRONMENTS</p>
      <p>Software installation and configuration in compliance with
the operating documentation.</p>
      <p>Development and implementation of security measures
required for software research.</p>
      <p>Preparation of the test bench shall include the deployment
and configuration of all operational environments in which the
product can operate according to the operating documentation or
which are specified by the customer, and identification of the
tools required to perform the tests. The operational
environments shall be installed, configured and adjusted in
compliance with the relevant operating documentation. In case
of any conflict between the requirements specified in the
environment documents and the requirements for the
environments in the software documents, the expert shall use the
requirements defined in the environment documents and record
the conflict. The expert shall analyze the conflict during the
analysis of the product configuration when making further steps
of this technique.</p>
      <p>The expert shall analyze the available product documents
and open information sources to obtain complete information
about the product. The expert should examine the product
documents and data provided in open information sources to
obtain the following information:
- Identification characteristics of the product tested
- Identification characteristics of the software in which
environment the test product operates
- Identification characteristics of the borrowed software
- Identification characteristics of the technologies used in the
test product</p>
      <p>After the identification characteristics are defined, the expert
shall analyze the documents for the test product and perform a
direct analysis of the product in order to define the set of the
product input interfaces, to understand how these interfaces
process the data, and to identify any additional potential
vulnerabilities of the product.</p>
      <p>During this step, the expert shall use expert analysis,
documentation analysis and automated tools to identify the input
interfaces of the test product, which make it possible to influence
on the product. The analysis shall result in a set of entry points
the expert can use to produce a direct impact on the product.</p>
      <p>After identification of all input interfaces of the product, the
researcher shall get an idea of the structure and the type of data
that can be sent to the identified interface. Then the expert shall
define the input interfaces that affect the operation of the product
security mechanisms.</p>
      <p>After identification of the input interfaces of the product, the
expert shall analyze the open sources for information on existing
vulnerabilities of the product, its operational environment or
technologies used to design the product. The expert shall
document the analysis findings.</p>
      <p>In order to complete this step, the expert shall use the unique
characteristics identified previously. The expert shall search for
the known (confirmed) vulnerabilities of the product using the
following publicly available information sources:</p>
      <p>- Databank of security threats of the Federal Service for
Technical and Export Control of Russia (http://bdu.fstec.ru);
- Software vulnerabilities database Common
Vulnerabilities and Exposures (CVE) (https://cve.mitre.org/);
vulnerabilities
database</p>
      <p>Vulners
- Software
(https://vulners.com);</p>
      <p>- National Vulnerability
(https://nvd.nist.gov/vuln/search);</p>
      <p>- OWASP Foundation – the free and open software
security community (https://www.owasp.org);</p>
      <p>- Websites of the product developer and manufacturer
and developers of borrowed components;</p>
    </sec>
    <sec id="sec-6">
      <title>Other open information sources. Based on the analysis of the open sources, the expert shall supplement the previously identified potential weaknesses of the product.</title>
      <p>Having identified the potential vulnerabilities described in
the open information sources, the expert shall study the product
documents to define the list of potentially unsafe product
configurations. At this step, the expert shall read the documents
for the test product to identify all possible ways of the software
reconfiguration and define those configurations which can
compromise the information integrity, availability, and
confidentiality. At the end of this step, the expert shall correct
the findings obtained earlier during the study of the product
documents and in the course of ad hoc testing. The expert shall
supplement the information about unsafe configurations of the
test product by potentially dangerous configurations defined
during this step and remove the potentially dangerous
configurations for which the documents describe the techniques
of how to neutralize threats caused by such configurations.</p>
      <p>Identification of unsafe configurations shall be followed by
a static analysis of the product code to identify potential
vulnerabilities of the test software code.</p>
      <p>At this step, the expert shall use static analysis tools to
perform an expert assessment of the product source code. The
number of false positive results can be minimized by using static
Database
(NVD)
analyzers which are based on symbolic execution methods and
other state-of-the-art methods of false positive minimization
during the static code analysis. The expert shall identify the
responses which cannot be well-defined as false by the
automated analysis tools as potential vulnerabilities of the
product code and document them as an attachment to the
vulnerability analysis certificate. The expert shall expand the
information on the potential product weaknesses identified
earlier with the information obtained during this step.</p>
      <p>
        After the static analysis [
        <xref ref-type="bibr" rid="ref18 ref6">3, 6, 18</xref>
        ], the expert shall scan the
test product using a security network scanner. The expert shall
use the findings of the security scanner to identify the vulnerable
components of the test product, unsafe configurations and other
types of errors.
      </p>
      <p>During this step, the expert shall use network scanning tools
to assess the configured product in its real operating mode. If
any potential configuration vulnerabilities or potentially unsafe
components are identified, the expert shall correct the previous
results.</p>
      <p>
        On the completion of the product analysis with a network
scanner [
        <xref ref-type="bibr" rid="ref14 ref18">14, 18</xref>
        ], the expert shall assess the security mechanisms
of the test product for correct operation.
      </p>
      <p>The expert shall examine the security mechanisms of the
software under study, assess the correctness of their operation
and make attempts to disrupt the claimed logic of the security
mechanisms. If the expert can disrupt the normal operation of
the product security mechanisms, or identify potential defects of
the program using any of the methods, the expert shall add these
findings to the identification results of the product potential
weaknesses.</p>
      <p>
        The exploratory testing shall result in a list of potential
weaknesses of the product. The dynamic code analysis and
fuzzing test shall be performed in relation to the potential
software weaknesses identified. At the end of the completed
analysis, the expert shall obtain [
        <xref ref-type="bibr" rid="ref4 ref5">4, 5</xref>
        ]:
      </p>
    </sec>
    <sec id="sec-7">
      <title>The list of errors in the product operation</title>
      <p>- Fragments of data that lead to errors in the product
operation.</p>
      <p>- Sample scenarios of work with the product components
whose execution causes a product behavior different from that
described in the product documents.</p>
      <p>
        The expert shall develop penetration tests based on the data
obtained during the exploratory testing, dynamic analysis and
fuzzing test, and carry out the penetration test [
        <xref ref-type="bibr" rid="ref19 ref20">19, 20</xref>
        ].
      </p>
    </sec>
    <sec id="sec-8">
      <title>IV. CONCLUSIONS</title>
      <p>The paper suggests a general technique and
recommendations on identification of web application
vulnerabilities. This technique has an applied scientific nature as
it was formulated based on the findings of information security
certification tests of software systems performed over many
years.</p>
      <p>Using this technique will turn the web application security
assessment into a problem-oriented process, which will enable a
more complete check of web resources in very a short time. This
technique complies with the state-of-the-art web application
security assessment standards.</p>
      <p>
        The available statistical data confirm the reliability,
effectiveness and efficiency of the suggested technique [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ].
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Gaskova</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Massel</surname>
            <given-names>A</given-names>
          </string-name>
          .
          <article-title>Intelligent System for Risk Identification of Cybersecurity Violations in Energy Facility”</article-title>
          ,
          <source>In: Proceedings of the:2018 3rd Russian-Pacific Conference on Computer Technology and Applications (Vladivostok, Russia, August 18-25</source>
          ,
          <year>2018</year>
          ), RPC, IEEE,
          <year>2018</year>
          , pp
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          . DOI:
          <volume>10</volume>
          .1109/RPC.
          <year>2018</year>
          .
          <volume>8482229</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Kharzhevskaya</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lomako</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S. Representing</given-names>
          </string-name>
          <article-title>Programs with Similarity Invariants for Monitoring Tampering with Calculations</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <year>2017</year>
          .
          <volume>No2</volume>
          (
          <volume>20</volume>
          ). P. 9-
          <fpage>20</fpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2017-2-9-20.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <given-names>Markov A.S.</given-names>
            ,
            <surname>Fadin</surname>
          </string-name>
          <string-name>
            <given-names>A.A.</given-names>
            ,
            <surname>Tsirlov</surname>
          </string-name>
          <string-name>
            <surname>V.L. Multilevel</surname>
          </string-name>
          <article-title>Metamodel for Heuristic Search of Vulnerabilities in the Software Source Code</article-title>
          ,
          <source>International Journal of Control Theory and Applications</source>
          ,
          <year>2016</year>
          , vol.
          <volume>9</volume>
          , No 30, pp.
          <fpage>313</fpage>
          -
          <lpage>320</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Pechenkin</surname>
            ,
            <given-names>A.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lavrova</surname>
            ,
            <given-names>D.S. Modeling</given-names>
          </string-name>
          <article-title>the search for vulnerabilities via the fuzzing method using an automation representation of network protocols. (2015) Automatic Control</article-title>
          and
          <source>Computer Sciences</source>
          ,
          <volume>49</volume>
          (
          <issue>8</issue>
          ), pp.
          <fpage>826</fpage>
          -
          <lpage>833</lpage>
          . DOI:
          <volume>10</volume>
          .3103/S0146411615080325.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Reber</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Malmquist</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shcherbakov</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <year>2014</year>
          .
          <article-title>Mapping the Application Security Terrain</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2014. N 1</source>
          (
          <issue>2</issue>
          ). P.
          <volume>36</volume>
          -
          <fpage>39</fpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2014-2-
          <fpage>36</fpage>
          -39.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Zegzhda</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zegzhda</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pavlenko</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dremov</surname>
            ,
            <given-names>A. Detecting</given-names>
          </string-name>
          <article-title>Android application malicious behaviors based on the analysis of control flows and data flows (</article-title>
          <year>2017</year>
          ) ACM International Conference Proceeding Series, pp.
          <fpage>280</fpage>
          -
          <lpage>286</lpage>
          . DOI:
          <volume>10</volume>
          .1145/3136825.3140583.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L.</given-names>
          </string-name>
          <string-name>
            <surname>Information Security Controls Against</surname>
          </string-name>
          Cross-Site
          <source>Request Forgery Attacks on Software Application of Automated Systems. Journal of Physics: Conference Series</source>
          .
          <year>2018</year>
          . V. 1015. P. 042034. DOI :
          <volume>10</volume>
          .1088/
          <fpage>1742</fpage>
          - 6596/1015/4/04203
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Calzavara</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Focardi</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nemec</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rabitti</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Squarcina</surname>
            <given-names>M.</given-names>
          </string-name>
          <article-title>Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web Ecosystem</article-title>
          .
          <source>In: 2019 IEEE Symposium on Security and Privacy (SP)</source>
          , IEEE,
          <year>2019</year>
          , 8995551, DOI: 10.1109/SP.
          <year>2019</year>
          .00053
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Calzavara</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Focardi</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Squarcina</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tempesta</surname>
            <given-names>M. Surviving</given-names>
          </string-name>
          <article-title>the Web: A Journey into Web Session Security</article-title>
          , ACM Comput. Surv.,
          <year>2017</year>
          , vol.
          <volume>50</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>34</lpage>
          , DOI: 10.1145/3038923.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Nirmal</surname>
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Janet</surname>
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kumar</surname>
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Web Application Vulnerabilities - The Hacker's Treasure</surname>
          </string-name>
          .
          <source>In: 2018 International Conference on Inventive Research in Computing Applications (ICIRCA)</source>
          , IEEE,
          <year>2018</year>
          , 18358073, DOI: 10.1109/ICIRCA.
          <year>2018</year>
          .
          <volume>8597221</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Petrenko</surname>
            ,
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            ,
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Makoveichuk</surname>
            ,
            <given-names>K.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chetyrbok</surname>
            ,
            <given-names>P.V.</given-names>
          </string-name>
          :
          <article-title>Protection Model of PCS of Subway from Attacks Type «Wanna cry», «Petya» and «Bad rabbit» IoT</article-title>
          .
          <source>In: Proceedings of the 2018 IEEE Conference of Russian Young Researchers in Electrical and Electronic Engineering (ElConRus</source>
          <year>2018</year>
          ). IEEE, pp.
          <fpage>945</fpage>
          -
          <lpage>949</lpage>
          (
          <year>2018</year>
          ). DOI:
          <volume>10</volume>
          .1109/EIConRus.
          <year>2018</year>
          .
          <volume>8317245</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Priya</surname>
            <given-names>R. L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lifna</surname>
            <given-names>C. S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dhanamma</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Anooja</surname>
            <given-names>J</given-names>
          </string-name>
          .
          <article-title>Rational Unified Treatment for Web application Vulnerability Assessment</article-title>
          .
          <source>In: 2014 International Conference on Circuits, Systems, Communication and Information Technology Applications (CSCITA)</source>
          , IEEE,
          <year>2014</year>
          , 14395120. DOI:
          <volume>10</volume>
          .1109/CSCITA.
          <year>2014</year>
          .
          <volume>6839283</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Rafique</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Humayun</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Gul Z.</given-names>
            ,
            <surname>Abbas</surname>
          </string-name>
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Javed</surname>
          </string-name>
          <string-name>
            <surname>H</surname>
          </string-name>
          .
          <article-title>Systematic Review of Web Application Security Vulnerabilities Detection Methods</article-title>
          ,
          <source>Journal of Computer and Communications</source>
          ,
          <year>2015</year>
          . V.
          <volume>3</volume>
          , No 9, pp.
          <fpage>28</fpage>
          -
          <lpage>40</lpage>
          . DOI:
          <volume>10</volume>
          .4236/jcc.
          <year>2015</year>
          .
          <volume>39004</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Wang</surname>
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liu</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Li</surname>
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhang</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chen</surname>
            <given-names>T.</given-names>
          </string-name>
          ,
          <source>Zou Z. Research on Web Application Security Vulnerability Scanning Technology. In: 2019 IEEE 4th Advanced Information Technology, Electronic and Automation Control Conference (IAEAC)</source>
          , IEEE,
          <year>2019</year>
          , 19359942, DOI: 10.1109/IAEAC47372.
          <year>2019</year>
          .
          <volume>8997964</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Yadav</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gupta</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Singh</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kumar</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sharma</surname>
            <given-names>U</given-names>
          </string-name>
          .
          <article-title>Vulnerabilities and Security of Web Applications</article-title>
          .
          <source>In: 2018 4th International Conference on Computing Communication and Automation (ICCCA)</source>
          , IEEE,
          <year>2018</year>
          , 18868543. DOI:
          <volume>10</volume>
          .1109/CCAA.
          <year>2018</year>
          .
          <volume>8777558</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L. Methodological</given-names>
          </string-name>
          <article-title>Framework for Analysis and Synthesis of a Set of Secure Software Development Controls</article-title>
          ,
          <source>Journal of Theoretical and Applied Information Technology</source>
          ,
          <year>2016</year>
          , vol.
          <volume>88</volume>
          , No 1, pp.
          <fpage>77</fpage>
          -
          <lpage>88</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Howard</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lipner</surname>
            <given-names>S.</given-names>
          </string-name>
          <article-title>The Security Development Lifecycle: A Process for Developing Demonstrably More Secure Software</article-title>
          . Microsoft Press,
          <year>2006</year>
          . 352 p.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Dorofeev</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rautkin</surname>
            <given-names>Y.V.</given-names>
          </string-name>
          <string-name>
            <surname>Ethical Hacking</surname>
          </string-name>
          <article-title>Training</article-title>
          .
          <source>In: CEUR Workshop Proceedings</source>
          ,
          <year>2019</year>
          , Vol-
          <volume>2522</volume>
          , pp.
          <fpage>47</fpage>
          -
          <lpage>56</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Markov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V</given-names>
          </string-name>
          .
          <article-title>Models for Testing Modifiable Systems</article-title>
          . In Book:
          <article-title>Probabilistic Modeling in System Engineering</article-title>
          , by ed.
          <source>A.Kostogryzov. IntechOpen</source>
          ,
          <year>2018</year>
          , Chapter
          <issue>7</issue>
          , pp.
          <fpage>147</fpage>
          -
          <lpage>168</lpage>
          . DOI:
          <volume>10</volume>
          .5772/intechopen.75126.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Poltavtseva</surname>
            ,
            <given-names>M.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pechenkin</surname>
            ,
            <given-names>A.I.</given-names>
          </string-name>
          <article-title>Intelligent data analysis in decision support systems for penetration tests</article-title>
          . In: (
          <year>2017</year>
          )
          <article-title>Automatic Control</article-title>
          and
          <source>Computer Sciences</source>
          ,
          <volume>51</volume>
          (
          <issue>8</issue>
          ), pp.
          <fpage>985</fpage>
          -
          <lpage>991</lpage>
          . DOI:
          <volume>10</volume>
          .3103/S014641161708017X.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L.</given-names>
          </string-name>
          <article-title>Statistics of Software Vulnerability Detection in Certification Testing</article-title>
          .
          <source>Journal of Physics: Conference Series</source>
          .
          <year>2018</year>
          . V. 1015. P. 042033. DOI :
          <volume>10</volume>
          .1088/
          <fpage>1742</fpage>
          - 6596/1015/4/042033.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>