Cybersecurity vulnerabilities and solutions in Ethiopian university websites

被引:2
|
作者
Eshetu, Ali Yimam [1 ]
Mohammed, Endris Abdu [1 ]
Salau, Ayodeji Olalekan [2 ,3 ]
机构
[1] Woldia Univ, Inst Technol, Sch Elect & Comp Engn, Woldia, Ethiopia
[2] Afe Babalola Univ, Dept Elect Elect & Comp Engn, Ado Ekiti, Nigeria
[3] Saveetha Inst Med & Tech Sci, Saveetha Sch Engn, Chennai, Tamil Nadu, India
关键词
Cybersecurity in higher education; Information security standards; Nessus; Nmap; VAPT; Vega; SECURITY;
D O I
10.1186/s40537-024-00980-z
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This study investigates the causes and countermeasures of cybercrime vulnerabilities, specifically focusing on selected 16 Ethiopian university websites. This study uses a cybersecurity awareness survey, and automated vulnerability assessment and penetration testing (VAPT) technique tools, namely, Nmap, Nessus, and Vega, to identify potential security threats and vulnerabilities. The assessment was performed according to the ISO/IEC 27001 series of standards, ensuring a comprehensive and globally recognized approach to information security. The results of this study provide valuable insights into the current state of cybersecurity in Ethiopian universities and reveals a range of issues, from outdated software and poor password management to a lack of encryption and inadequate access control. Vega vulnerability assessment reports 11,286 total findings, and Nessus identified a total of 1749 vulnerabilities across all the websites of the institutions examined. Based on these findings, the study proposes counteractive measures tailored to the specific needs of each identified defect. These recommendations aim to strengthen the security posture of the university websites, thereby protecting sensitive data and maintaining the trust of students, staff, and other stakeholders. The study emphasizes the need for proactive cybersecurity measures in the realm of higher education and presents a strategic plan for universities to improve their digital security. The study investigates the causes of cybersecurity vulnerabilities in university websites, with a focus on Ethiopian Universities.The evaluation was based on ISO/IEC 27001 series standards and utilized three different automatic VAPT evaluation tools: Nmap, NESSUS, and VEGA.The research identified a range of issues contributing to cybersecurity vulnerabilities, including outdated software, poor password management, a lack of encryption, and inadequate access control.The study underscores the importance of proactive cybersecurity practices in the higher education sector and provides a roadmap for universities to enhance their digital security.
引用
收藏
页数:35
相关论文
共 50 条
  • [21] Legal protection for the search and notification of cybersecurity vulnerabilities in Chile
    Alvarez-Valenzuela, Daniel
    Hevia Angulo, Alejandro
    REVISTA CHILENA DE DERECHO Y TECNOLOGIA, 2020, 9 (02): : 1 - 4
  • [22] Addressing the cybersecurity vulnerabilities of advanced nanogrids: A practical framework
    Jose Hueros-Barrios, Pablo
    Rodriguez Sanchez, Francisco Javier
    Martin, Pedro
    Jimenez, Carlos
    Fernandez, Ignacio
    INTERNET OF THINGS, 2022, 20
  • [23] Educators' Cybersecurity Vulnerabilities in Marginalised Schools in South Africa
    Magunje, Caroline
    Chigona, Wallace
    SOUTH AFRICAN COMPUTER SCIENCE AND INFORMATION SYSTEMS RESEARCH TRENDS, SAICSIT 2024, 2024, 2159 : 347 - 360
  • [24] Vulnerabilities and Strategies of Cybersecurity in Smart Grid - Evaluation and Review
    Mohammed, Amira
    George, Gibin
    3RD INTERNATIONAL CONFERENCE ON SMART GRID AND RENEWABLE ENERGY (SGRE), 2022,
  • [25] CYBERSECURITY VULNERABILITIES AND THREATS OF SCADA SYSTEMS IN CRITICAL INFRASTRUCTURES
    Savin, Vlad Daniel
    Serban, Costel
    PROCEEDINGS OF THE 13TH INTERNATIONAL MANAGEMENT CONFERENCE: MANAGEMENT STRATEGIES FOR HIGH PERFORMANCE (IMC 2019), 2019, : 234 - 237
  • [26] Efficient Assessment and Evaluation for Websites Vulnerabilities Using SNORT
    Dabbour, Mohammad
    Alsmadi, Izzat
    Alsukhni, Emad
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (01): : 7 - 16
  • [27] VULNERABILITIES OF SCHOOL WEBSITES IN V4 COUNTRIES
    Svoboda, Jaroslav
    Georgiev, Jiri
    DIGITALIZED ECONOMY, SOCIETY AND INFORMATION MANAGEMENT (IDIMT-2020), 2020, 49 : 333 - 340
  • [28] Efficient assessment and evaluation for websites vulnerabilities using SNORT
    Yarmouk University, Jordan
    Int. J. Secur. Appl., 1 (7-16):
  • [29] Assessments Sqli and Xss vulnerability in Several Organizational Websites of North khorasan in Iran and Offer Solutions to Fix these Vulnerabilities
    Pirvadlu, Fatemeh Talebzadeh
    Sepidnam, Ghodrat
    2017 3RD INTERNATIONAL CONFERENCE ON WEB RESEARCH (ICWR), 2017, : 44 - 47
  • [30] Identification of system vulnerabilities in the Ethiopian electric power system
    Moges Alemu Tikuneh
    Getachew Biru Worku
    Global Energy Interconnection, 2018, 1 (03) : 358 - 365