Security Engineering of Open Web Application Security Project-Based Automated System for Web Vulnerability Detection and Mitigation

Open

Irawan Afrianto, Ismayani Setyaningrum, Sufa Atin, Eddy Prasetyo Nugroho, Girindro Pringgo Digdo

2025 International Journal of Safety and Security Engineering Vol. 15 Issue 12 Article Cited by 0 SDG 9SDG 17 Quartile

Abstract

Web application vulnerabilities present escalating security risks to organizational data integrity, particularly within public sector infrastructure, where legacy systems often lack robust defense mechanisms. To address this challenge, this study engineers an automated web vulnerability monitoring system that seamlessly integrates the Open Web Application Security Project Zed Attack Proxy Application Programming Interface (OWASP ZAP API) within a Model-View-Controller (MVC) architecture. Adopting an Iterative Development Life Cycle (IDLC), the system was rigorously validated through Black-box, White-box, and User Acceptance Testing (UAT) to ensure functional reliability. The system's practical efficacy was evaluated via a comparative analysis against the standard OWASP ZAP desktop interface using "Laplakgar2022," an active government performance reporting application, as a real-world test subject. The empirical results demonstrate that the proposed system achieves a 20% reduction in scanning duration by optimizing scanning policies, while simultaneously maintaining a 100% detection rate for critical High and Medium-risk vulnerabilities, specifically Structure Query Language (SQL) Injection and Cross-Site Scripting (XSS). Furthermore, UAT results indicate a high usability score of approximately 80%, confirming that the system effectively mitigates alert fatigue and assists development teams in prioritizing remediation. Future research will focus on integrating Artificial Intelligence (AI) for predictive threat modeling and expanding validation to distributed cloud environments. © 2025 The authors. This article is published by IIETA and is licensed under the CC BY 4.0 license (http://creativecommons.org/licenses/by/4.0/).

Affiliations

Department of Informatics Engineering, Universitas Komputer Indonesia, Bandung, 40132, Indonesia; Department of Computer Science, Universitas Pendidikan Indonesia, Bandung, 40154, Indonesia; CyberArmyID – PT Global Inovasi Siber Indonesia, Bandung, 40164, Indonesia

Research at a Glance

Premium content — register to unlock

Research at a Glance

Register to unlock

Topics & SDG Alignment

Premium content — register to unlock

Topics & SDG Alignment

Register to unlock

Collaboration

Premium content — register to unlock

Collaboration

Register to unlock

Author Profile (Selected)

Premium content — register to unlock

Author Profile (Selected)

Register to unlock

References Overview

Premium content — register to unlock

References Overview

Register to unlock

Journal & Source

Premium content — register to unlock

Journal & Source

Register to unlock

Metadata & Integrity

Premium content — register to unlock

Metadata & Integrity

Register to unlock