Open Access Peer Reviewed Monthly Est. 2014

British International Journal of Education and Social Sciences

(BIJESS)
ISSN (Print): 4519-6511 | ISSN (Online): 3342-543X
9.82
Impact Factor
13
H-Index
893+
Articles
HomeBIJESS Vol. 13, No. 3 QUANTITATIVE SECURITY EVALUATION OF WEB APPS USIN…
📄 Research Article BIJESS Vol. 13, No. 3 (2025)

QUANTITATIVE SECURITY EVALUATION OF WEB APPS USING STATIC ANALYSIS TOOLS

Andrii Oleksandrovych Bondarenko-Melnyk
Department of Information and Cyber Security, State University of Information and Communication Technologies, Kyiv, Ukraine
British International Journal of Education and Social Sciences, Vol. 13, No. 3 (2025), pp. 41-52 | DOI: https://doi.org/10.5281/zenodo.20157367
Open Access Peer Reviewed Research Article

Abstract

This paper presents a study on Static Application Security Testing (SAST) with a focus on the Snyk Code tool. SAST enables early detection and remediation of security vulnerabilities during software development, improving overall system security. The research introduces the General Application Vulnerability Rate (GAVR) model, which quantifies vulnerability risks based on the CVSS 3.1 framework. A case study using Snyk Code demonstrates the identification and assessment of security flaws, such as XSS and certificate validation issues. The study highlights the need for an integrated approach to security testing, emphasizing automation and structured vulnerability assessment to enhance software security. The GAVR model enhances traditional security evaluations by incorporating exploitability probabilities, offering a more dynamic risk assessment. The findings suggest that integrating SAST within the software development lifecycle significantly reduces security risks and improves remediation efficiency. By leveraging automation and systematic vulnerability quantification, this study underscores the importance of proactive security strategies to safeguard web applications against evolving threats.
Keywords: ["SAST","web application vulnerabilities","CVSS v.3.1","general application vulnerability score","cyber security"]
📑 How to Cite This Article
APA 7th Edition:
Andrii Oleksandrovych Bondarenko-Melnyk (2025). QUANTITATIVE SECURITY EVALUATION OF WEB APPS USING STATIC ANALYSIS TOOLS. British International Journal of Education and Social Sciences, 13(3), 41-52. https://doi.org/https://doi.org/10.5281/zenodo.20157367
Vancouver Style:
Andrii Oleksandrovych Bondarenko-Melnyk. QUANTITATIVE SECURITY EVALUATION OF WEB APPS USING STATIC ANALYSIS TOOLS. Br. Int. J. Educ. Soc. Sci.. 2025;13(3):41-52. DOI: https://doi.org/10.5281/zenodo.20157367
🔗 Other Articles in This Issue