Attack graph modeling for web application vulnerability representation and analysis

DSpace/Manakin Repository

Show simple item record

dc.contributor.advisor Focardi, Riccardo it_IT Serani, Hernest <1998> it_IT 2023-06-19 it_IT 2023-11-08T14:55:48Z 2023-07-21 it_IT
dc.description.abstract Web application vulnerabilities pose a high risk for both end-users and sensitive data. In this thesis, we propose the use of graph theory notions as a tool to model web applications and their associated vulnerabilities as an attack graph. By representing web applications as attack graphs, we can gain a comprehensive understanding of their components and related vulnerabilities, which can be crucial in developing effective defensive and offensive strategies. To construct the attack graph, we suggest various techniques, including crawlers, vulnerability assessment tools, and manual penetration testing. We also introduce the use of graph algorithms to analyze the web application attack graph and provide a quantitative assessment of the likelihood and severity of various vulnerabilities. This information can be invaluable in making informed decisions about the prioritization of security measures from the point of view of the defensive team, or optimize the finding of attack paths for the offensive team. In addition, we apply mathematical frameworks for different analysis. To facilitate the practical application of our theoretical model, we propose the use of graph databases to efficiently query large graphs, generate useful insights and identify potential attack paths for exploitation. The goal is to leverage graph theory in order to improve the security of web applications. it_IT
dc.language.iso en it_IT
dc.publisher Università Ca' Foscari Venezia it_IT
dc.rights © Hernest Serani, 2023 it_IT
dc.title Attack graph modeling for web application vulnerability representation and analysis it_IT
dc.title.alternative Attack graph modeling for web application vulnerability representation and analysis it_IT
dc.type Master's Degree Thesis it_IT Informatica - computer science it_IT Laurea magistrale it_IT Dipartimento di Scienze Ambientali, Informatica e Statistica it_IT
dc.description.academicyear 2022/2023_sessione estiva_10-luglio-23 it_IT
dc.rights.accessrights closedAccess it_IT
dc.thesis.matricno 877028 it_IT
dc.subject.miur INF/01 INFORMATICA it_IT
dc.description.note it_IT it_IT it_IT 10000-01-01
dc.provenance.upload Hernest Serani (, 2023-06-19 it_IT
dc.provenance.plagiarycheck Riccardo Focardi (, 2023-07-10 it_IT

Files in this item

This item appears in the following Collection(s)

Show simple item record