Enhancing Web Application Security Through Active and Passive Reconnaissance Methods: A Comparative Framework Study Against Single-Method Approaches

relationships.isAuthorOf

Journal Title

Journal ISSN

Volume Title

Publisher

Abstract

Web application security assessment depends on effective reconnaissance to identify externally exposed assets, services, and vulnerabilities. Current reconnaissance practice relies on fragmented command-line tools that operate in isolation, produce unstructured outputs requiring substantial manual correlation, and apply context-independent vulnerability scoring that cannot reflect deployment-specific risk. The Common Vulnerability Scoring System provides no mechanism for automatically adjusting severity based on whether an affected service is internet-accessible or whether the host carries elevated asset value. These limitations reduce coverage, slow analyst workflows, and lead to systematic mis prioritization of remediation effort. This research investigates whether integrating passive and active reconnaissance within a unified pipeline, combined with cross-module analytical models, can produce security insights that isolated tools cannot generate, and whether a visualization-driven interface can deliver measurable workflow improvements over command-line operations. Following a Design Science Research methodology, this thesis presents a three-module reconnaissance framework combining subdomain enumeration, port scanning, and vulnerability identification within a unified pipeline. Four original analytical algorithms are introduced: Shannon Entropy anomaly detection for identifying algorithmically generated subdomains, the Service Exposure Classification engine for quantifying port-level exposure risk, the Contextual Vulnerability Priority Score for context-aware vulnerability re-prioritization using cross-module deployment data, and the Attack Surface Risk Score for synthesizing a composite risk metric from all three scanning phases. Each algorithm is presented with theoretical justification, mathematical specification, and an explicit statement of originality. The framework is integrated with a graphical user interface providing single-action scan execution, real-time progress feedback, and structured result visualization. Experimental evaluation demonstrates that the combined approach improves asset discovery coverage and reduces false negatives compared to passive-only methods, while the visualization-driven interface enhances analyst efficiency. Furthermore, the integration of context-aware models enables more precise vulnerability prioritization. Overall, this research presents a comprehensive and scalable solution that advances the effectiveness of web application reconnaissance. This thesis contributes four original analytical algorithms that produce qualitatively new categories of security insight requiring data from all three scanning phases simultaneously, demonstrating that integrated, context-aware reconnaissance surfaces actionable findings that fragmented tools systematically miss.

Description

Thesis (Master's)--University of Washington, 2026

Citation

DOI