Behind the firewall: A study on structured vulnerability assessment of the websites of the tertiary educational institutes of Bangladesh focusing on intuitive attack vectors to realize the cybersecurity practices in web design of academia

bracu.degree.levelPostgraduate
bracu.type.groupStudent Works
datacite.rightsOpen Access
dc.contributor.advisorAlam, Md. Golam Rabiul
dc.contributor.authorKhan, Rafia Tabassum
dc.contributor.departmentDepartment of Computer Science and Engineering
dc.date.accessioned2026-07-28T08:48:59Z
dc.date.available2026-07-28T08:48:59Z
dc.date.copyright2026
dc.date.issued2026-03
dc.descriptionThis thesis is submitted in partial fulfillment of the requirements for the degree of Master of Science in Computer Science and Engineering, 2026.
dc.descriptionCataloged from PDF version of thesis.
dc.descriptionIncludes bibliographical references (pages 38-42).
dc.description.abstractThe rapid expansion of web-based services in higher education has significantly increased the exposure of university websites to cyber threats. In Bangladesh, many academic institutions rely on publicly accessible web applications for administrative, academic, and informational purposes, making them potential targets for website infections and exploitation. This research examines the security posture of selected public and private university websites in Bangladesh by identifying, analyzing, and comparing prevalent web application vulnerabilities. The study adopts a structured vulnerability assessment methodology grounded in the OWASP framework, focusing on common attack vectors such as SQL Injection (SQLi), Cross-Site Scripting (XSS), authentication weaknesses, insecure configurations, and improper input validation. Controlled and non-destructive testing techniques were employed using industry-standard tools in a safe and ethical virtual environment, Kali Linux. Data collected from the assessments were systematically analyzed using statistical methods to evaluate vulnerability frequency, severity, and distribution across institutional categories. The results reveal discernible differences between public and private universities, with variations in defensive practices, exposure levels, and maintenance strategies. Several recurring vulnerabilities indicate gaps in secure coding practices, patch management, and security awareness. The findings highlight the need for inclusive and proactive cybersecurity strategies, regular vulnerability assessments, and alignment with established web security standards. This research contributes to the understanding of website infection risks within academic institutions in developing regions and provides practical insights and recommendations to strengthen web application security, improve resilience against cyberattacks, and promote responsible cybersecurity practices in higher education.
dc.description.degreeMaster of Science in Computer Science and Engineering
dc.description.statementofresponsibilityRafia Tabassum Khan
dc.format.extent81 pages
dc.identifier.otherID 22366025
dc.identifier.urihttps://hdl.handle.net/10361/28664
dc.language.isoen_US
dc.publisherBRAC University
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internationalen
dc.rightsBRAC University theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission.
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectWeb security
dc.subjectVulnerability assessment
dc.subjectCybersecurity
dc.subjectAcademic institutions
dc.subjectWeb applications
dc.subjectStatistical analysis
dc.subjectFirewall
dc.subjectEducational institutes
dc.subject.lcshWeb sites--Security measures.
dc.subject.lcshComputers--Access control--Evaluation--Congresses.
dc.subject.lcshComputer security--Risk management.
dc.subject.lcshPenetration testing (Computer security).
dc.subject.lcshUniversities and colleges--Computer networks--Security measures.
dc.titleBehind the firewall: A study on structured vulnerability assessment of the websites of the tertiary educational institutes of Bangladesh focusing on intuitive attack vectors to realize the cybersecurity practices in web design of academia
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
22366025_CSE.pdf
Size:
778.93 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: