Methods for Testing, Assessment and Analysis of the Security of University Information Systems

Authors

  • Assist. Prof. Dr Venko Andonov Department of Informatics, Faculty of Applied Informatics and Statistics, UNWE Author

DOI:

https://doi.org/https://doi.org/10.37075/RP.2023.5.05

Keywords:

Software, Information security, Security testing, Vulnerabilities, Cybersecurity
I23, M15

Abstract

The methods for testing, evaluating and analyzing the security of university information systems aim to build a unified framework that leads to an increase in information security in this type of institution, which is characterized by the administration of a huge volume of sensitive information of a diverse nature. Security testing is a multifaceted process involving steps to ensure the safety of systems in their entirety. The proposed methods have been tested with three systems of the University of National and World Economy, and one of them is presented here; and conclusions are drawn to increase security and include the described procedures as a permanent practice.

References

Brian Myers (2025). Software Composition Analysis: Overview and Tooling Guide. DOI: https://www.stackhawk.com/blog/software-composition-analysis-sca-overview-and-tooling-guide

Christey, S. (2008). CWE -

A Comparison of the CWE Development and Research Views. DOI: https://cwe.mitre.org/documents/views/view-comparison.html

WGJ Halfond, J Viegas, A Orso (2006). A classification of SQL injection attacks and countermeasures. Proceedings of the IEEE International Symposium on Secure Software Engineering (Ed. NA). URL: https://apps.dtic.mil/sti/pdfs/ADA483186.pdf#page=57

A Barth, C Jackson, JC Mitchell - … of the 15th ACM conference on …, 2008 (2008). Robust defenses for cross-site request forgery. Proceedings of the 15th ACM conference on Computer and communications security (Ed. NA). URL: https://dl.acm.org/doi/abs/10.1145/1455770.1455782

Published

2024-01-26

Issue

Section

Articles

How to Cite

Andonov, V. (2024). Methods for Testing, Assessment and Analysis of the Security of University Information Systems. Research Papers, 5, 137-151. https://doi.org/https://doi.org/10.37075/RP.2023.5.05