EVALUATION OF MOST VISITED WEB SITES IN TURKEY IN ASPECTS OF STRUCTURE AND SECURITY
Abstract
Applications on World Wide Web have made our daily lives easier with their basic and fast access, neglecting time and place, they have become indispensable. It made Web applications a popular target for malevolent users and increased web security risk. In this study web penetration test which is indispensable for web security and threating risks for web security are mentioned. In Turkey, 60 of the most visited sites were identified in five different categories scanned as an ordinary user to consider a safety assessment of the general situation of the websites. For the review, large sites in news sites, e-commerce, government, universities and other categories have been selected that are thought to have strong security infrastructure. The knowledge about these sites such as used technologies and infrastructure which considers as vulnerability of sites and can be obtained by the ordinal person who uses penetration tests has been investigated in this study. As a result of the research, operating system information and web server information from 62% and 87% of the reviewed sites were identified respectively. Medium and low degree vulnerabilities were found in all scanned websites. With the vulnerability screening tests, weakness map revealed and information about the most identified weaknesses was given.
Keywords
Kaynakça
- Anonymous, 2016, https://www.symantec.com/content/dam/ symantec /docs/reports/istr-21-2016-en.pdf, 2016.
- Anonymous, 2017, https://www.owasp.org/index.php/Top_ 10_2017-Top_10,
- Arsoy, S., 2014, “e-Devlet Web Sitelerinin Kullanılabilirlik Yönünden Standartlara ve Rehberlere Göre Değerlendirilmesi,” M.S. thesis, Fen Bilimleri Enstitüsü, Yıldız Teknik Üniversitesi, İstanbul
- Barbara, S., 2014, Advanced Automated Web Application Vulnerability Analysis, Ph.D. Dissertation, University of California.
- Boşal, S., 2017, Kamuda Bilgi Güvenliği ve Iller Bankasi A.Ş. Örneği, Uzmanlık Tezi, İller Bankasi Anonim Şirketi Ankara.
- Canbek, G., Sağıroğlu Ş., 2006, “Bilgi, Bilgi Güvenliği ve Süreçleri Üzerine Bir İnceleme,” Politeknik Dergisi, Vol 9(3), pp. 165-174.
- Çetinkaya, M., 2008, Bilgi Güvenliği Yönetim Sistemi Altyapisinin Değerlendirilmesi Için Bir Test Araci Geliştirilmesi, M.S. Thesis, İstanbul Kültür Üniversitesi, İstanbul.
- Doğan, S., 2013, Web Application Testing: A Systematic Literature Review, M.S. Thesis, The Middle East Technical University, Ankara.
Ayrıntılar
Birincil Dil
İngilizce
Konular
Mühendislik
Bölüm
Araştırma Makalesi
Yayımlanma Tarihi
1 Aralık 2018
Gönderilme Tarihi
25 Ağustos 2017
Kabul Tarihi
9 Nisan 2018
Yayımlandığı Sayı
Yıl 2018 Cilt: 6 Sayı: 4