Análise de cobertura e precisão em ferramentas DAST: um comparativo técnico entre Owasp Zap e Nuclei utilizando o Damn Vulnerable Web App (DVWA)

dc.contributor.advisor1 Santana, Fernando Castelo Branco Gonçalves
dc.contributor.advisor1Lattes http://lattes.cnpq.br/7801051159658130pt_BR
dc.contributor.referee1 Leal, Aline Montenegro
dc.contributor.referee1Lattes http://lattes.cnpq.br/3340016700432290pt_BR
dc.contributor.referee2 Ramos, Ricardo Martins
dc.contributor.referee2Lattes http://lattes.cnpq.br/1163294951081965pt_BR
dc.creator Marques, Felipe Gabriel Freitas
dc.creator.Lattes http://lattes.cnpq.br/1692810246934562pt_BR
dc.date.accessioned 2026-07-21T14:07:33Z
dc.date.available 2026-07-21T14:07:33Z
dc.date.issued 2026
dc.description.abstract The accelerated growth of web applications and the migration of critical services to the digital environment have expanded the attack surface and the frequency of cyber incidents, making early vulnerability detection a mandatory requirement for data protection. In this scenario, Dynamic Application Security Testing (DAST) tools emerge as essential solutions for automating audits, although they present significant variations in effectiveness depending on their architecture and search engine. This article presents a comparative analysis of coverage and accuracy between the OWASP ZAP and Nuclei tools in identifying flaws based on the global consensus of the OWASP Top 10. The methodology adopted consisted of experimental research in a virtualized and isolated environment, using the intentionally vulnerable application Damn Vulnerable Web App (DVWA) configurated at the “Low” and “Medium” security levels. The results demonstrate the technical distinctions between ZAP’s proxy-based active scanning approach and Nuclei’s fast template-oriented model, revealing how each tool behaves in the face of basic security filters and distinct attack surfaces. It is concluded that the effectiveness of automation is dependent on the context of the target application, highlighting the need for hybrid testing strategies to ensure the robustness and technical compliance of contemporary web systems.pt_BR
dc.description.resumo O crescimento acelerado das aplicações web e a migração de serviços críticos para o ambiente digital ampliaram a superfície de ataque e a frequência de incidentes cibernéticos, tornando a detecção precoce de vulnerabilidades um requisito mandatório para a proteção de dados. Neste cenário, as ferramentas de Teste Dinâmico de Segurança de Aplicações (DAST) surgem como soluções essenciais para a automação de auditorias, embora apresentem variações significativas de eficácia conforme sua arquitetura e motor de busca. Este artigo apresenta uma análise comparativa de cobertura e precisão entre as ferramentas OWASP ZAP e Nuclei na identificação de falhas baseadas no consenso global do OWASP Top 10. A metodologia adotada consistiu em uma pesquisa experimental em ambiente virtualizado e isolado, utilizando a aplicação intencionalmente vulnerável Damn Vulnerable Web App (DVWA) configurada nos níveis de segurança “Low” e “Medium”. Os resultados obtidos demonstram as distinções técnicas entre a abordagem de varredura ativa baseada em proxy do ZAP e o modelo veloz orientado a templates do Nuclei, revelando como cada ferramenta se comporta diante de filtros de segurança básicos e superfícies de ataque distintas. Conclui-se que a eficácia da automação é dependente do contexto da aplicação alvo, evidenciando a necessidade de estratégias de testes híbridas para garantir a robustez e a conformidade técnica dos sistemas web contemporâneos.pt_BR
dc.description.sponsorship Agência 1pt_BR
dc.description.sponsorship Agência 2pt_BR
dc.identifier.citation MARQUES, Felipe Gabriel Freitas.Análise de cobertura e precisão em ferramentas DAST: um comparativo técnico entre Owasp Zap e Nuclei utilizando o Damn Vulnerable Web App (DVWA). Orientador: Fernando Castelo Branco Gonçalves Santana. 2026. 13 f. Trabalho de Conclusão de Curso (Tecnologia em Análise e Desenvolvimento de Sistemas) - Instituto Federal do Piauí, Campus Teresina Central, Teresina, 2026pt_BR
dc.identifier.uri https://bia.ifpi.edu.br/jspui/handle/123456789/5696
dc.language porpt_BR
dc.publisher Instituto Federal de Educação, Ciência e Tecnologia do Piauípt_BR
dc.publisher.country Brasilpt_BR
dc.publisher.department Campus Teresina Centralpt_BR
dc.publisher.initials IFPIpt_BR
dc.rights Acesso Abertopt_BR
dc.subject Cybersecuritypt_BR
dc.subject OWASP ZAP - ferramenta de testept_BR
dc.subject Nuclei - escannerpt_BR
dc.subject Teste Dinâmico de Segurança de Aplicações (DAST)pt_BR
dc.subject Damn Vulnerable Web App (DVWA)pt_BR
dc.subject.cnpq CNPQ::CIENCIAS EXATAS E DA TERRApt_BR
dc.title Análise de cobertura e precisão em ferramentas DAST: um comparativo técnico entre Owasp Zap e Nuclei utilizando o Damn Vulnerable Web App (DVWA)pt_BR
dc.title.alternative Analysis of coverage and accuracy in DAST tools: a technical comparison between OWASP ZAP and Nuclei using the Damn Vulnerable Web App (DVWA)pt_BR
dc.type Trabalho de Conclusão de Cursopt_BR

Files

Original bundle

Now showing 1 - 2 of 2
Loading...
Thumbnail Image
Name:
2026_termo_fgfmarques.pdf
Size:
205.93 KB
Format:
Description:
Loading...
Thumbnail Image
Name:
2026_tcc_fgfmarques.pdf
Size:
643.87 KB
Format:
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.82 KB
Format:
Item-specific license agreed upon to submission
Description: