Behind the firewall: A study on structured vulnerability assessment of the websites of the tertiary educational institutes of Bangladesh focusing on intuitive attack vectors to realize the cybersecurity practices in web design of academia
| bracu.degree.level | Postgraduate | |
| bracu.type.group | Student Works | |
| datacite.rights | Open Access | |
| dc.contributor.advisor | Alam, Md. Golam Rabiul | |
| dc.contributor.author | Khan, Rafia Tabassum | |
| dc.contributor.department | Department of Computer Science and Engineering | |
| dc.date.accessioned | 2026-07-28T08:48:59Z | |
| dc.date.available | 2026-07-28T08:48:59Z | |
| dc.date.copyright | 2026 | |
| dc.date.issued | 2026-03 | |
| dc.description | This thesis is submitted in partial fulfillment of the requirements for the degree of Master of Science in Computer Science and Engineering, 2026. | |
| dc.description | Cataloged from PDF version of thesis. | |
| dc.description | Includes bibliographical references (pages 38-42). | |
| dc.description.abstract | The rapid expansion of web-based services in higher education has significantly increased the exposure of university websites to cyber threats. In Bangladesh, many academic institutions rely on publicly accessible web applications for administrative, academic, and informational purposes, making them potential targets for website infections and exploitation. This research examines the security posture of selected public and private university websites in Bangladesh by identifying, analyzing, and comparing prevalent web application vulnerabilities. The study adopts a structured vulnerability assessment methodology grounded in the OWASP framework, focusing on common attack vectors such as SQL Injection (SQLi), Cross-Site Scripting (XSS), authentication weaknesses, insecure configurations, and improper input validation. Controlled and non-destructive testing techniques were employed using industry-standard tools in a safe and ethical virtual environment, Kali Linux. Data collected from the assessments were systematically analyzed using statistical methods to evaluate vulnerability frequency, severity, and distribution across institutional categories. The results reveal discernible differences between public and private universities, with variations in defensive practices, exposure levels, and maintenance strategies. Several recurring vulnerabilities indicate gaps in secure coding practices, patch management, and security awareness. The findings highlight the need for inclusive and proactive cybersecurity strategies, regular vulnerability assessments, and alignment with established web security standards. This research contributes to the understanding of website infection risks within academic institutions in developing regions and provides practical insights and recommendations to strengthen web application security, improve resilience against cyberattacks, and promote responsible cybersecurity practices in higher education. | |
| dc.description.degree | Master of Science in Computer Science and Engineering | |
| dc.description.statementofresponsibility | Rafia Tabassum Khan | |
| dc.format.extent | 81 pages | |
| dc.identifier.other | ID 22366025 | |
| dc.identifier.uri | https://hdl.handle.net/10361/28664 | |
| dc.language.iso | en_US | |
| dc.publisher | BRAC University | |
| dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 International | en |
| dc.rights | BRAC University theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. | |
| dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/4.0/ | |
| dc.subject | Web security | |
| dc.subject | Vulnerability assessment | |
| dc.subject | Cybersecurity | |
| dc.subject | Academic institutions | |
| dc.subject | Web applications | |
| dc.subject | Statistical analysis | |
| dc.subject | Firewall | |
| dc.subject | Educational institutes | |
| dc.subject.lcsh | Web sites--Security measures. | |
| dc.subject.lcsh | Computers--Access control--Evaluation--Congresses. | |
| dc.subject.lcsh | Computer security--Risk management. | |
| dc.subject.lcsh | Penetration testing (Computer security). | |
| dc.subject.lcsh | Universities and colleges--Computer networks--Security measures. | |
| dc.title | Behind the firewall: A study on structured vulnerability assessment of the websites of the tertiary educational institutes of Bangladesh focusing on intuitive attack vectors to realize the cybersecurity practices in web design of academia | |
| dc.type | Thesis |