Automating web application vulnerability detection: a generative AI and security tool based penetration testing framework

bracu.degree.levelUndergraduate
bracu.type.groupStudent Works
datacite.rightsOpen Access
dc.contributor.advisorHossain, Muhammad Iqbal
dc.contributor.advisorAhmed, Md Faisal
dc.contributor.authorSanjeena, Sariha
dc.contributor.authorGomes, Dip Gourab Isaac
dc.contributor.authorRahman, Sanjida
dc.contributor.authorTazwar, Mahdi
dc.contributor.authorRafsan, Asif Arman
dc.contributor.departmentDepartment of Computer Science and Engineering
dc.date.accessioned2026-01-12T06:15:32Z
dc.date.available2026-01-12T06:15:32Z
dc.date.copyright2025
dc.date.issued2025-10
dc.descriptionCataloged from PDF version of thesis.
dc.descriptionIncludes bibliographical references (pages 88-94).
dc.descriptionThis thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2025.en_US
dc.description.abstractIn the current age of interconnected computer networks, web applications have emerged as one of the most prominent mediums for information interchange, sensitive data sharing and even critical transactions. Therefore, ensuring the security of these web applications is one of the most important aspects of web security. Despite this, a significant number of web applications fail to implement basic security measures, making them vulnerable to cyber attacks orchestrated by malicious actors, also known as “black hat” attacks. Detecting these vulnerabilities is essential to safeguard both user and organizational data. One of the most effective methods for identifying security flaws in web application systems is penetration testing. However, traditional penetration testing is time consuming and prone to human error due to its dependence on manual processes. As the complexity of modern web applications rises, relying solely on manual methods is no longer sufficient for ensuring effective security coverage. To address this challenge, this paper aims to implement automation systems for these methods of detection to accelerate the process of penetration testing tenfold. In our approach, we have utilized a combination of different open-source tools and Generative AI-driven analysis to enhance the efficiency of detecting web application vulnerability in the process of penetration testing. This approach represents a crucial advancement in overcoming the limitations of manual testing, addressing the need for faster and more adaptive security solutions.en_US
dc.description.degreeBachelor of Science in Computer Science
dc.description.statementofresponsibilitySariha Sanjeena
dc.description.statementofresponsibilityDip Gourab Isaac Gomes
dc.description.statementofresponsibilitySanjida Rahman
dc.description.statementofresponsibilityMahdi Tazwar
dc.description.statementofresponsibilityAsif Arman Rafsan
dc.format.extent132 pages
dc.identifier.otherID 21201158
dc.identifier.otherID 21201169
dc.identifier.otherID 21301568
dc.identifier.otherID 21301237
dc.identifier.otherID 21201155
dc.identifier.urihttp://hdl.handle.net/10361/27423
dc.language.isoenen_US
dc.publisherBRAC Universityen_US
dc.rightsBRAC University theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission.
dc.subjectPenetration testingen_US
dc.subjectWeb applicationsen_US
dc.subjectVulnerability detectionen_US
dc.subjectAIen_US
dc.subjectRetrieval-augmented generationen_US
dc.subjectGenerative AIen_US
dc.subjectWeb securityen_US
dc.subject.lcshPenetration testing (Computer security).
dc.subject.lcshWeb applications--Security measures--Automation.
dc.subject.lcshGenerative artificial intelligence.
dc.titleAutomating web application vulnerability detection: a generative AI and security tool based penetration testing frameworken_US
dc.typeThesisen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
21201158, 21201169, 21301568, 21301237, 21201155_CSE.pdf
Size:
3.99 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: