Comprehensive secure code review analysis of web application security vulnerabilities

Azlinda Abdul Aziz, Nur Razia Mohd Suradi, Rahayu Handan, Mohd Noor Rizal Arbain

Abstract


A secure code review is a process of software development involves systematic examination of application code. However, web applications evolving of cyber threats makes it challenging to conduct adequate security. Therefore, this paper conducts a comprehensive secure code review analysis to protect any crucial aspect of web security from potential threats and vulnerabilities. The application code is scanned for security issues during the real review and the results are classified according to the areas of vulnerability. As a result, the application code risk level and list of risk categories were defined. This result assists in prioritizing issues for resolution, beginning with the most critical problems to lower risk levels. Next, list of risk categories that give the most significant security vulnerabilities affect to application codes are defined. SQL injection, weak password handling, insecure direct object reference, information exposure, improper session management, missing input validation, deprecated functions, and lack of comments are defined as a risk category. Moreover, the result of application code weakness in the security of the application code is determined based on the level of risk and categories. Thus, analysis result offers the developers a clear perspective on protects the web applications from threats and vulnerabilities.

Keywords


Cyber thread; Risk; Secure code; Security; Vulnerabilities; Web application

Full Text:

PDF


DOI: http://doi.org/10.11591/ijeecs.v39.i3.pp1807-1814

Refbacks

  • There are currently no refbacks.


Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

Indonesian Journal of Electrical Engineering and Computer Science (IJEECS)
p-ISSN: 2502-4752, e-ISSN: 2502-4760
This journal is published by the Institute of Advanced Engineering and Science (IAES).

shopify stats IJEECS visitor statistics