Skip to content
Review Open access

An AI-Driven Integrated Framework for Automated Web Application Penetration Testing Using Multi-Tool Vulnerability Assessment

2026 · Journal of Cybersecurity and Intelligent Systems · 0 citations

TL;DR

An AI-driven integrated framework for automated web application penetration testing that combines multiple industry-recognized security tools, including OWASP ZAP, Burp Suite Professional, FOCA, and Vega, within a unified graphical interface developed using Python is presented.

Abstract

The rapid growth of web-based applications and cloud computing has significantly increased organizations' exposure to sophisticated cyber threats. Conventional penetration testing methods often require extensive manual effort, specialized expertise, and considerable time to identify security vulnerabilities, making them less suitable for continuously evolving digital infrastructures. Recent advancements in artificial intelligence (AI) and intelligent automation provide an opportunity to enhance vulnerability assessment by improving detection accuracy, reducing human intervention, and accelerating security analysis. This paper presents an AI-driven integrated framework for automated web application penetration testing that combines multiple industry-recognized security tools, including OWASP ZAP, Burp Suite Professional, FOCA, and Vega, within a unified graphical interface developed using Python. The proposed framework automates reconnaissance, vulnerability scanning, analysis, report generation, and remediation recommendation while maintaining flexibility for security professionals to customize scanning parameters. Multithreading and multiprocessing techniques are employed to improve scanning efficiency and enable the simultaneous execution of multiple security assessments. The framework also incorporates intelligent vulnerability prioritization based on severity levels and integrates structured reporting mechanisms to support organizational compliance and risk management activities. A comprehensive literature review and gap analysis identify the limitations of existing automated penetration testing solutions and motivate the development of the proposed architecture. Experimental analysis demonstrates the effectiveness of integrating multiple vulnerability scanners to improve the detection of common web application vulnerabilities such as SQL injection, cross-site scripting, broken authentication, cross-site request forgery, XML external entity attacks, insecure configurations, and API-related security flaws. Comparative analysis reveals that the integrated framework provides broader vulnerability coverage, improved usability, enhanced reporting capabilities, and greater operational efficiency than standalone scanning tools do. The proposed framework contributes to intelligent cybersecurity automation by providing a scalable, extensible, and user-friendly solution capable of supporting modern web application security assessments while reducing the complexity and cost associated with traditional penetration testing methods.

Read PDF

Similar papers

#software testing Open access Aug 2026

HawkEye: Web Vulnerability Analysis and Security Audit Tool

HawkEye is introduced, a modular, web-based vulnerability auditing platform designed to streamline security analysis by integrating multiple scanning tools within a unified dashboard and illustrates how consolidated reporting improves vulnerability prioritization for development teams.

D. R. Patil, Varad Salgare, Devaj Arya et al. · 0 citations
Open access Sep 2026

Automated Quality Assurance in Web Applications Using Model-Based Testing and Cypress with AI-Assisted Test Generation

An automated quality assurance framework that combines Model-Based Testing (MBT), a modeling approach to designing and generating test cases based on system models with AI-assisted test generation strategies using the Cypress testing platform is outlined.

Bhuvan Chandra Kasarapu · 0 citations
Open access Aug 2026

Static Code Analysis Framework for Automated Security Vulnerability Detection

Experimental results show that AST-based structural features substantially improve recall compared with the TF-IDF baseline, while the combined TF-IDF and AST representation maintains this improved performance.

Vani Pasupula, M. N. V. Manikanth, Nagaraju Vassey · 0 citations
Open access Aug 2026

ZeroProbe: An Intelligent Web-Based Vulnerability Scanner Integrating Automated Detection and AI-Based Analysis

The findings confirm that an accessible, accurate, and AI-augmented vulnerability scanner can be constructed for educational and entry-level use within a deliberately bounded scope, lowering the expertise barrier for web application security assessment.

Dah Berrou, Zaenal Alamsyah, Nugraha Nugraha · 0 citations
Conference Aug 2026

Cloud-Native Modernization of Legacy Enterprise Systems Using AI and DevSecOps

Legacy enterprise systems continue to support critical business operations, but many of these systems are monolithic, tightly coupled, difficult to scale, and vulnerable to security risks. These limitations reduce their ability to adapt to modern digital environments that require flexibility, reliability, faster deploy...

Shandilya Avadhanam Venkat Krishna Sastry, Pasuluri Bindu Swetha, S. Kishore et al. · 0 citations
Open access Sep 2026

On-Premise CodeBERT-Driven Model for Vulnerability Detection in Source Code

An on premise Artificial Intelligence (AI)-based model for vulnerability detection in source code, designed to ensure there is efficiency in identifying potential weaknesses, and deployed locally within a Dockerized environment.

D. Sako · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.