An effective new penetration test approach to detect web attacks on web applications

dc.contributor.authorKaya, Muhammed Onur
dc.contributor.authorDagdogen, Huseyin Alperen
dc.contributor.authorOzdem, Mehmet
dc.contributor.authorDas, Resul
dc.date.accessioned2026-08-12T17:42:36Z
dc.date.issued2026
dc.departmentFırat Üniversitesi
dc.description.abstractAs web applications increasingly involve sensitive transactions such as e-commerce, online banking, and public services, they have become primary targets for cyberattacks. Therefore, web application penetration testing is vital for discovering and protecting against vulnerabilities in web-based systems. This study introduces an automated penetration testing tool that systematically applies comprehensive penetration testing methodologies to effectively identify and mitigate web application vulnerabilities. The proposed tool uses a hybrid approach that includes automated and manual testing phases for multiple attacks, including SQL Injection, Cross-Site Scripting, and Cross-Site Request Forgery. System diversity is increased, and the penetration testing process is enriched using Python scripts and APIs. The tool provides an effective mechanism for uncovering critical vulnerabilities by simulating real-world attacker behavior. Practical evaluations on various web applications demonstrate the tool's ability to identify vulnerabilities and increase system resilience. This research will help developers and security engineers apply this automated, specialized approach to security as our digital environment becomes more connected.
dc.identifier.doi10.1016/j.eswa.2025.129623
dc.identifier.issn0957-4174
dc.identifier.issn1873-6793
dc.identifier.orcid0009-0004-6313-2278
dc.identifier.orcid0000-0002-2901-2342
dc.identifier.orcid0000-0003-2862-8257
dc.identifier.orcid0000-0002-6113-4649
dc.identifier.scopus2-s2.0-105020574890
dc.identifier.scopusqualityQ1
dc.identifier.urihttps://doi.org/10.1016/j.eswa.2025.129623
dc.identifier.urihttps://hdl.handle.net/11508/59808
dc.identifier.volume298
dc.identifier.wosWOS:001592550900002
dc.identifier.wosqualityQ1
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherPergamon-Elsevier Science Ltd
dc.relation.ispartofExpert Systems with Applications
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.snmzKA_WoS_20260511
dc.subjectWeb application security
dc.subjectPenetration test
dc.subjectCyber security
dc.subjectAutomated penetration testing tool
dc.titleAn effective new penetration test approach to detect web attacks on web applications
dc.typeArticle

Dosyalar