MARATTO

review · Information Security Journal A Global Perspective

A systematic review and taxonomy of web applications threats

202033 citations

In plain language

Web application security represents an escalating challenge within information technology, driven by a continuous rise in sophisticated cyber attacks. These attacks stem from diverse motivations and predominantly target data linked to economic activities, creating substantial disruption to information systems. While numerous threat classifications exist in academic literature, each possesses distinct strengths and constraints. An evaluation of these established frameworks highlights their respective advantages and disadvantages to establish a unified perspective. Building on these existing structures, a comprehensive taxonomy classifies both client-side and server-side attacks into an integrated system. This consolidated classification aims to provide researchers with a structured, detailed overview of threats confronting modern web applications, facilitating clearer analysis and understanding across diverse threat vectors.

Key takeaways

  • Web-related attacks are increasingly sophisticated and primarily target economic data, causing severe disruption to information systems.
  • Existing web application threat taxonomies offer specific strengths but also present clear limitations.
  • A new integrated taxonomy combines the advantages of prior frameworks to classify both client-side and server-side attacks.
  • The unified classification provides researchers with a detailed and structured framework to analyse web application threats.

Why it matters

Web applications underpin vital economic activities and everyday digital services, making their security crucial. As online attacks grow more varied and complex, standardising how threats are classified enables security professionals and researchers to systematically identify vulnerabilities across both server and client environments. A shared classification framework helps guide effective defence strategies against emerging cyber risks.

Commercialisation angle

This work offers a theoretical classification rather than a deployable software tool, placing it at an early conceptual stage. The integrated taxonomy could eventually inform the design criteria for vulnerability assessment frameworks, intrusion detection systems, or threat intelligence platforms used by cybersecurity analysts and software engineers. However, the abstract indicates no direct commercial validation or testing, focusing instead on aiding security researchers.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

Nowadays, web application security is one of the relevant issues in the IT security domain due to the continued growth in the number of web-related attacks. As a result, attacks, with various and varied motivations, have developed and become increasingly sophisticated. They mainly target data related to economic activities. Thus, they cause significant damage to the overall functioning of information systems. To address the various threats, several robust taxonomies exist in the literature. Each taxonomy and classification has advantages and limitations. We first define the different threat classifications related to the context of Web applications. The objective of this analysis is to provide a synthesis of the advantages and disadvantages of each classification. The current work analyses different taxonomies for web applications threats, in order to propose our proper taxonomy. The proposed taxonomy takes advantage of the benefits of existing taxonomies and provides an integrated approach for classifying both client-side and server-side attacks. The finding will help researchers to find a clear and detailed taxonomy of the different threats related to web applications.

Research topics

  • Network Security and Intrusion Detection
  • Web Application Security Vulnerabilities
  • Advanced Malware Detection Techniques

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1080/19393555.2020.1853855

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.