15.11.2012 Views

icegov2012 proceedings

icegov2012 proceedings

icegov2012 proceedings

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Categories<br />

Only XSS<br />

(%)<br />

Table 2: Distribution of vulnerability in each category.<br />

XSS and SQLi Analysis CM &<br />

Only SQLi XSS &<br />

XSS None<br />

UP<br />

(%)<br />

SQLi (%) or SQLi(%) (%)<br />

(%)<br />

Agencies (n=10) 20 (2) 0 (0) 20 (2) 40 (4) 60 (6) 30 (3) 70 (7)<br />

Judiciary (n=8) 25 (2) 12.5 (1) 25 (2) 62.5 (5) 37.5 (3) 37.5 (3) 50 (4)<br />

Law Enf./Def (n=5) 20 (1) 0 (0) 40 (2) 60 (3) 40 (2) 40 (2) 80 (4)<br />

Media (n=2) 0 (0) 50 (1) 0 (0) 50 (1) 50 (1) 0 (0) 100 (2)<br />

Ministries (n=6) 16.7 (1) 16.7 (1) 33.3 (2) 66.7 (4) 33.3 (2) 33.3 (2) 66.7 (4)<br />

Others (n=7) 42.9 (3) 0 (0) 28.6 (2) 71.4 (5) 28.6 (2) 28.6 (2) 85.7 (6)<br />

Parastatals (n=13) 23.1 (3) 15.4 (2) 15.4 (2) 53.8 (7) 46.1 (6) 46.2 (6) 76.9 (10)<br />

States (n=13) 15.4 (2) 15.4 (2) 7.7 (1) 38.5 (5) 61.5 (8) 46.2 (6) 61.5 (8)<br />

* Please note that the values in parenthesis represent the actual number of the vulnerability found.<br />

XSS- Cross Site Scripting, SQLi- Structure Query Language injection,<br />

CM- Cookie Manipulation, UP- Unencrypted Password, BL- Broken Links<br />

Table 3: Type and magnitude of website vulnerabilities across categories<br />

Level of Severity/<br />

Category<br />

Highly Severe Less Severe<br />

XSS SQLi CM/UP BL<br />

Agencies 14.8 10.5 12 15.6<br />

Judiciary 14.8 10.5 12 8.9<br />

Law Enf./Def 11.1 10.5 8 8.9<br />

Media 0.0 5.3 4 4.4<br />

Ministries 11.1 15.8 8 8.9<br />

Others 18.5 10.5 8 13.3<br />

Parastatals 18.5 21.1 24 22.2<br />

States 11.1 15.8 24 17.8<br />

25.0<br />

20.0<br />

15.0<br />

10.0<br />

5.0<br />

0.0<br />

Figure 1: Pictorial representation of vulnerabilities across sectors<br />

239<br />

XSS<br />

SQLi<br />

CM/UP<br />

BL<br />

BL<br />

(%)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!