WASC Announcement: 2008 Web Application Security Statistics Published | Linux Today

WASC Announcement: 2008 Web Application Security Statistics Published

Written By
Web Webster
Web Webster
Oct 16, 2009

[ Thanks to WASC for this link.
]

“As a result, we now have 4 data sets:

“Overall statistics by all kinds of activities;
Automatic scanning statistics;
Black box method security assessment statistics;
White box method security assessment statistics.

“Automatic scanning data is collected in fully automated
scanning process without any preliminary settings (with standard
profile) of hosting provider sites. Remember that not all the sites
include interactive elements, and additional settings made by an
expert considering certain Web application, allows to greatly
improve the efficiency of vulnerability detection.

“Black box method security assessment statistics includes the
results of manual and automated Web application analysis without
any preliminary known data about the application. As a rule, this
includes scanning with standard settings and manual search of
vulnerabilities unavailable for automatic scanners.

“White box method security assessment statistics includes the
results of the deep Web application analysis which contains
application analysis done as an authorized user. It also includes
static source code and binary analysis. Detected vulnerabilities
are classified according to Web Application Security Consortium Web
Security Threat Classification (WASC WSTCv2) early draft.
Vulnerability risk level is determined by contributors or assessed
according to CVSSv2 (Common Vulnerability Scoring System version
2). Then the level was brought to PCI DSS (Payment Card Industry
Data Security Standard) risk levels as described in the methodology
(see appendix 1).”


Complete Story

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.