Enhancing Web Application Security Through Active and Passive Reconnaissance Methods: A Comparative Framework Study Against Single-Method Approaches

dc.contributor.advisorChen, Min
dc.contributor.authorKshirsagar, Shlok Amit
dc.date.accessioned2026-08-11T19:18:28Z
dc.date.issued2026-08-11
dc.date.submitted2026
dc.descriptionThesis (Master's)--University of Washington, 2026
dc.description.abstractWeb application security assessment depends on effective reconnaissance to identify externally exposed assets, services, and vulnerabilities. Current reconnaissance practice relies on fragmented command-line tools that operate in isolation, produce unstructured outputs requiring substantial manual correlation, and apply context-independent vulnerability scoring that cannot reflect deployment-specific risk. The Common Vulnerability Scoring System provides no mechanism for automatically adjusting severity based on whether an affected service is internet-accessible or whether the host carries elevated asset value. These limitations reduce coverage, slow analyst workflows, and lead to systematic mis prioritization of remediation effort. This research investigates whether integrating passive and active reconnaissance within a unified pipeline, combined with cross-module analytical models, can produce security insights that isolated tools cannot generate, and whether a visualization-driven interface can deliver measurable workflow improvements over command-line operations. Following a Design Science Research methodology, this thesis presents a three-module reconnaissance framework combining subdomain enumeration, port scanning, and vulnerability identification within a unified pipeline. Four original analytical algorithms are introduced: Shannon Entropy anomaly detection for identifying algorithmically generated subdomains, the Service Exposure Classification engine for quantifying port-level exposure risk, the Contextual Vulnerability Priority Score for context-aware vulnerability re-prioritization using cross-module deployment data, and the Attack Surface Risk Score for synthesizing a composite risk metric from all three scanning phases. Each algorithm is presented with theoretical justification, mathematical specification, and an explicit statement of originality. The framework is integrated with a graphical user interface providing single-action scan execution, real-time progress feedback, and structured result visualization. Experimental evaluation demonstrates that the combined approach improves asset discovery coverage and reduces false negatives compared to passive-only methods, while the visualization-driven interface enhances analyst efficiency. Furthermore, the integration of context-aware models enables more precise vulnerability prioritization. Overall, this research presents a comprehensive and scalable solution that advances the effectiveness of web application reconnaissance. This thesis contributes four original analytical algorithms that produce qualitatively new categories of security insight requiring data from all three scanning phases simultaneously, demonstrating that integrated, context-aware reconnaissance surfaces actionable findings that fragmented tools systematically miss.
dc.embargo.termsOpen Access
dc.format.mimetypeapplication/pdf
dc.identifier.otherKshirsagar_washington_0250O_29679.pdf
dc.identifier.urihttps://hdl.handle.net/1773/56984
dc.language.isoen_US
dc.rightsnone
dc.subjectActive-Passive Scanning
dc.subjectAttack Surface Measurement
dc.subjectCross-Module Security Analysis
dc.subjectDesign Science Research
dc.subjectWeb Application Reconnaissance
dc.subjectComputer science
dc.subjectInformation technology
dc.subject.otherComputing and software systems
dc.titleEnhancing Web Application Security Through Active and Passive Reconnaissance Methods: A Comparative Framework Study Against Single-Method Approaches
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Kshirsagar_washington_0250O_29679.pdf
Size:
1.16 MB
Format:
Adobe Portable Document Format