📄 Research Article
BIJESS Vol. 13, No. 3 (2025)
QUANTITATIVE SECURITY EVALUATION OF WEB APPS USING STATIC ANALYSIS TOOLS
Andrii Oleksandrovych Bondarenko-Melnyk
Department of Information and Cyber Security, State University of Information and Communication Technologies, Kyiv, Ukraine
British International Journal of Education and Social Sciences,
Vol. 13, No. 3 (2025),
pp. 41-52 |
DOI: https://doi.org/10.5281/zenodo.20157367
Open Access
Peer Reviewed
Research Article
Abstract
This paper presents a study on Static Application Security Testing (SAST) with a focus on the Snyk Code tool. SAST enables early detection and remediation of security vulnerabilities during software development, improving overall system security. The research introduces the General Application Vulnerability Rate (GAVR) model, which quantifies vulnerability risks based on the CVSS 3.1 framework. A case study using Snyk Code demonstrates the identification and assessment of security flaws, such as XSS and certificate validation issues. The study highlights the need for an integrated approach to security testing, emphasizing automation and structured vulnerability assessment to enhance software security. The GAVR model enhances traditional security evaluations by incorporating exploitability probabilities, offering a more dynamic risk assessment. The findings suggest that integrating SAST within the software development lifecycle significantly reduces security risks and improves remediation efficiency. By leveraging automation and systematic vulnerability quantification, this study underscores the importance of proactive security strategies to safeguard web applications against evolving threats.
Keywords:
["SAST","web application vulnerabilities","CVSS v.3.1","general application vulnerability score","cyber security"]
📑 How to Cite This Article
APA 7th Edition:
Andrii Oleksandrovych Bondarenko-Melnyk (2025). QUANTITATIVE SECURITY EVALUATION OF WEB APPS USING STATIC ANALYSIS TOOLS. British International Journal of Education and Social Sciences, 13(3), 41-52. https://doi.org/https://doi.org/10.5281/zenodo.20157367
Andrii Oleksandrovych Bondarenko-Melnyk (2025). QUANTITATIVE SECURITY EVALUATION OF WEB APPS USING STATIC ANALYSIS TOOLS. British International Journal of Education and Social Sciences, 13(3), 41-52. https://doi.org/https://doi.org/10.5281/zenodo.20157367
Vancouver Style:
Andrii Oleksandrovych Bondarenko-Melnyk. QUANTITATIVE SECURITY EVALUATION OF WEB APPS USING STATIC ANALYSIS TOOLS. Br. Int. J. Educ. Soc. Sci.. 2025;13(3):41-52. DOI: https://doi.org/10.5281/zenodo.20157367
Andrii Oleksandrovych Bondarenko-Melnyk. QUANTITATIVE SECURITY EVALUATION OF WEB APPS USING STATIC ANALYSIS TOOLS. Br. Int. J. Educ. Soc. Sci.. 2025;13(3):41-52. DOI: https://doi.org/10.5281/zenodo.20157367
🔗 Other Articles in This Issue