METHODOLOGY FOR ASSESSING WEB-SERVICE VULNERABILITIES USING AUTOMATED SCANNERS

Authors

DOI:

https://doi.org/10.31673/2409-7292.2026.032815

Abstract

The article proposes a comprehensive methodology for assessing web-service vulnerabilities that combines
automated scanning with manual expert verification. The methodology comprises eight consecutive stages: planning,
passive reconnaissance, active mapping and fuzzing, infrastructure and configuration analysis, dynamic testing and
business-logic assessment, specialized testing, result filtering, and reporting. The capabilities of SAST, DAST, IAST, and
SCA approaches, as well as Burp Suite, Nessus, Nuclei, and specialized fuzzers, are considered. Experimental comparison
with conventional use of a commercial DAST scanner demonstrated an increase in detection precision from 0.26 to 0.80,
growth in identified entry points from 18 to 64, and an increase in confirmed critical vulnerabilities from 2 to 6. The
proposed approach reduces false positives, broadens attack-surface coverage, and supports risk prioritization using CVSS
metrics.
Keywords: cybersecurity, web services, vulnerability assessment, automated scanners, penetration testing, DAST,
CVSS.

References
1. Андрусяк І., Севериненко Д. Методи та засоби моніторингу функціонування веб-сервісів. Herald of
Khmelnytskyi National University. Technical sciences. 2025. № 347(1). С. 11-19.
2. Методи та моделі проєктування системи автоматизованого пошуку вразливостей у web-додатках /
Івануса А. І. та ін. Вісник Львівського державного університету безпеки життєдіяльності. 2024. № 30. С. 110–122.
3. Семенець О., Тецький А. Аналіз методів та засобів вибору та комплексування сканерів вразливостей
для тестування на проникнення інтернет систем. Measuring and computing devices in technological processes. 2024.
№ 2. С. 336-347.
4. Максимович М. В. Використання методів штучного інтелекту для виявлення вразливостей нульового
дня. Сучасний захист інформації. 2025. № 4. С. 123-132.
5. Alhamed M., Rahman M. H. A systematic literature review on penetration testing in networks: future research
directions. Applied Sciences. 2023. Vol. 13, № 12. 6986.
6. Morhul D. M., Nariezhnii O. P., Hrinenko T. O. Модель порушника та модель загроз для веб-сервісу
QRNG. Radiotekhnika. 2025. № 221. С. 31-38.
7. Design and development of a large language model-based tool for vulnerability detection / Zhuravchak A. et
al. Eastern-European Journal of Enterprise Technologies. 2025. Vol. 2, № 2 (134). С. 75-83.
8. Експрес-аудит як інструмент оцінки вразливостей в системах обробки даних: підходи, методики та
рекомендації / Сиропятов О. А. та ін. Informatics & Mathematical Methods in Simulation. 2024. Vol. 14, № 4.
9. SQLI-ScanEval: A framework for design and evaluation of SQLI detection using vulnerability and penetration
testing scanners / Bashir H. et al. Engineering Reports. 2026. Vol. 8, № 1.

Published

2026-09-15

Issue

Section

Articles