An effective new penetration test approach to detect web attacks on web applications
| dc.contributor.author | Kaya, Muhammed Onur | |
| dc.contributor.author | Dagdogen, Huseyin Alperen | |
| dc.contributor.author | Ozdem, Mehmet | |
| dc.contributor.author | Das, Resul | |
| dc.date.accessioned | 2026-08-12T17:42:36Z | |
| dc.date.issued | 2026 | |
| dc.department | Fırat Üniversitesi | |
| dc.description.abstract | As web applications increasingly involve sensitive transactions such as e-commerce, online banking, and public services, they have become primary targets for cyberattacks. Therefore, web application penetration testing is vital for discovering and protecting against vulnerabilities in web-based systems. This study introduces an automated penetration testing tool that systematically applies comprehensive penetration testing methodologies to effectively identify and mitigate web application vulnerabilities. The proposed tool uses a hybrid approach that includes automated and manual testing phases for multiple attacks, including SQL Injection, Cross-Site Scripting, and Cross-Site Request Forgery. System diversity is increased, and the penetration testing process is enriched using Python scripts and APIs. The tool provides an effective mechanism for uncovering critical vulnerabilities by simulating real-world attacker behavior. Practical evaluations on various web applications demonstrate the tool's ability to identify vulnerabilities and increase system resilience. This research will help developers and security engineers apply this automated, specialized approach to security as our digital environment becomes more connected. | |
| dc.identifier.doi | 10.1016/j.eswa.2025.129623 | |
| dc.identifier.issn | 0957-4174 | |
| dc.identifier.issn | 1873-6793 | |
| dc.identifier.orcid | 0009-0004-6313-2278 | |
| dc.identifier.orcid | 0000-0002-2901-2342 | |
| dc.identifier.orcid | 0000-0003-2862-8257 | |
| dc.identifier.orcid | 0000-0002-6113-4649 | |
| dc.identifier.scopus | 2-s2.0-105020574890 | |
| dc.identifier.scopusquality | Q1 | |
| dc.identifier.uri | https://doi.org/10.1016/j.eswa.2025.129623 | |
| dc.identifier.uri | https://hdl.handle.net/11508/59808 | |
| dc.identifier.volume | 298 | |
| dc.identifier.wos | WOS:001592550900002 | |
| dc.identifier.wosquality | Q1 | |
| dc.indekslendigikaynak | Web of Science | |
| dc.indekslendigikaynak | Scopus | |
| dc.language.iso | en | |
| dc.publisher | Pergamon-Elsevier Science Ltd | |
| dc.relation.ispartof | Expert Systems with Applications | |
| dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı | |
| dc.rights | info:eu-repo/semantics/closedAccess | |
| dc.snmz | KA_WoS_20260511 | |
| dc.subject | Web application security | |
| dc.subject | Penetration test | |
| dc.subject | Cyber security | |
| dc.subject | Automated penetration testing tool | |
| dc.title | An effective new penetration test approach to detect web attacks on web applications | |
| dc.type | Article |







