Behind the firewall: A study on structured vulnerability assessment of the websites of the tertiary educational institutes of Bangladesh focusing on intuitive attack vectors to realize the cybersecurity practices in web design of academia
Loading...
Date
Publisher
BRAC University
Authors
Citation
Abstract
The rapid expansion of web-based services in higher education has significantly increased
the exposure of university websites to cyber threats. In Bangladesh, many academic
institutions rely on publicly accessible web applications for administrative, academic,
and informational purposes, making them potential targets for website infections and
exploitation. This research examines the security posture of selected public and private
university websites in Bangladesh by identifying, analyzing, and comparing prevalent web
application vulnerabilities.
The study adopts a structured vulnerability assessment methodology grounded in the
OWASP framework, focusing on common attack vectors such as SQL Injection (SQLi),
Cross-Site Scripting (XSS), authentication weaknesses, insecure configurations, and improper
input validation. Controlled and non-destructive testing techniques were employed
using industry-standard tools in a safe and ethical virtual environment, Kali Linux. Data
collected from the assessments were systematically analyzed using statistical methods to
evaluate vulnerability frequency, severity, and distribution across institutional categories.
The results reveal discernible differences between public and private universities, with
variations in defensive practices, exposure levels, and maintenance strategies. Several
recurring vulnerabilities indicate gaps in secure coding practices, patch management,
and security awareness. The findings highlight the need for inclusive and proactive
cybersecurity strategies, regular vulnerability assessments, and alignment with established
web security standards.
This research contributes to the understanding of website infection risks within academic
institutions in developing regions and provides practical insights and recommendations to
strengthen web application security, improve resilience against cyberattacks, and promote
responsible cybersecurity practices in higher education.
Description
This thesis is submitted in partial fulfillment of the requirements for the degree of Master of Science in Computer Science and Engineering, 2026.
Cataloged from PDF version of thesis.
Includes bibliographical references (pages 38-42).
Cataloged from PDF version of thesis.
Includes bibliographical references (pages 38-42).
Publisher Link
Type
Thesis
Creative Commons license

Except where otherwise noted, this item's license is described as
Attribution-NonCommercial-NoDerivatives 4.0 International