Automating web application vulnerability detection: a generative AI and security tool based penetration testing framework

dc.contributor.advisorHossain, Muhammad Iqbal
dc.contributor.advisorAhmed, Md Faisal
dc.contributor.authorSanjeena, Sariha
dc.contributor.authorGomes, Dip Gourab Isaac
dc.contributor.authorRahman, Sanjida
dc.contributor.authorTazwar, Mahdi
dc.contributor.authorRafsan, Asif Arman
dc.date.accessioned2026-01-12T06:15:32Z
dc.date.available2026-01-12T06:15:32Z
dc.date.issued2025-10
dc.descriptionCataloged from PDF version of thesis.
dc.descriptionIncludes bibliographical references (pages 88-94).
dc.descriptionThis thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2025.
dc.description.abstractIn the current age of interconnected computer networks, web applications have emerged as one of the most prominent mediums for information interchange, sensitive data sharing and even critical transactions. Therefore, ensuring the security of these web applications is one of the most important aspects of web security. Despite this, a significant number of web applications fail to implement basic security measures, making them vulnerable to cyber attacks orchestrated by malicious actors, also known as “black hat” attacks. Detecting these vulnerabilities is essential to safeguard both user and organizational data. One of the most effective methods for identifying security flaws in web application systems is penetration testing. However, traditional penetration testing is time consuming and prone to human error due to its dependence on manual processes. As the complexity of modern web applications rises, relying solely on manual methods is no longer sufficient for ensuring effective security coverage. To address this challenge, this paper aims to implement automation systems for these methods of detection to accelerate the process of penetration testing tenfold. In our approach, we have utilized a combination of different open-source tools and Generative AI-driven analysis to enhance the efficiency of detecting web application vulnerability in the process of penetration testing. This approach represents a crucial advancement in overcoming the limitations of manual testing, addressing the need for faster and more adaptive security solutions.
dc.identifier.otherID 21201158
dc.identifier.otherID 21201169
dc.identifier.otherID 21301568
dc.identifier.otherID 21301237
dc.identifier.otherID 21201155
dc.identifier.otherhttps://dspace.bracu.ac.bd/server/api/core/items/a49eb451-632e-4462-8866-ad65b9da6c9a
dc.identifier.urihttp://hdl.handle.net/10361/27423
dc.language.isoen
dc.publisherBRAC University
dc.sourceBRAC University Institutional Repository
dc.subjectPenetration testing
dc.subjectWeb applications
dc.subjectVulnerability detection
dc.subjectAI
dc.subjectRetrieval-augmented generation
dc.subjectGenerative AI
dc.subjectWeb security
dc.titleAutomating web application vulnerability detection: a generative AI and security tool based penetration testing framework
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Thumbnail Image
Name:
21201158, 21201169, 21301568, 21301237, 21201155_CSE.pdf
Size:
3.99 MB
Format:
Adobe Portable Document Format