Cybersecurity vulnerabilities and solutions in Ethiopian university websites

被引:2
|
作者
Eshetu, Ali Yimam [1 ]
Mohammed, Endris Abdu [1 ]
Salau, Ayodeji Olalekan [2 ,3 ]
机构
[1] Woldia Univ, Inst Technol, Sch Elect & Comp Engn, Woldia, Ethiopia
[2] Afe Babalola Univ, Dept Elect Elect & Comp Engn, Ado Ekiti, Nigeria
[3] Saveetha Inst Med & Tech Sci, Saveetha Sch Engn, Chennai, Tamil Nadu, India
关键词
Cybersecurity in higher education; Information security standards; Nessus; Nmap; VAPT; Vega; SECURITY;
D O I
10.1186/s40537-024-00980-z
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This study investigates the causes and countermeasures of cybercrime vulnerabilities, specifically focusing on selected 16 Ethiopian university websites. This study uses a cybersecurity awareness survey, and automated vulnerability assessment and penetration testing (VAPT) technique tools, namely, Nmap, Nessus, and Vega, to identify potential security threats and vulnerabilities. The assessment was performed according to the ISO/IEC 27001 series of standards, ensuring a comprehensive and globally recognized approach to information security. The results of this study provide valuable insights into the current state of cybersecurity in Ethiopian universities and reveals a range of issues, from outdated software and poor password management to a lack of encryption and inadequate access control. Vega vulnerability assessment reports 11,286 total findings, and Nessus identified a total of 1749 vulnerabilities across all the websites of the institutions examined. Based on these findings, the study proposes counteractive measures tailored to the specific needs of each identified defect. These recommendations aim to strengthen the security posture of the university websites, thereby protecting sensitive data and maintaining the trust of students, staff, and other stakeholders. The study emphasizes the need for proactive cybersecurity measures in the realm of higher education and presents a strategic plan for universities to improve their digital security. The study investigates the causes of cybersecurity vulnerabilities in university websites, with a focus on Ethiopian Universities.The evaluation was based on ISO/IEC 27001 series standards and utilized three different automatic VAPT evaluation tools: Nmap, NESSUS, and VEGA.The research identified a range of issues contributing to cybersecurity vulnerabilities, including outdated software, poor password management, a lack of encryption, and inadequate access control.The study underscores the importance of proactive cybersecurity practices in the higher education sector and provides a roadmap for universities to enhance their digital security.
引用
收藏
页数:35
相关论文
共 50 条
  • [31] New Solutions for Cybersecurity
    De Paoli, Stefano
    TECNOSCIENZA-ITALIAN JOURNAL OF SCIENCE & TECHNOLOGY STUDIES, 2020, 11 (01): : 101 - 105
  • [32] Cybersecurity vulnerabilities in medical devices: a complex environment and multifaceted problem
    Williams, Patricia A. H.
    Woodward, Andrew J.
    MEDICAL DEVICES-EVIDENCE AND RESEARCH, 2015, 8 (305-316): : 305 - 315
  • [33] Apply transfer learning to cybersecurity: Predicting exploitability of vulnerabilities by description
    Yin, Jiao
    Tang, MingJian
    Cao, Jinli
    Wang, Hua
    KNOWLEDGE-BASED SYSTEMS, 2020, 210
  • [34] FRAPE: A Framework for Risk Assessment, Prioritization and Explainability of vulnerabilities in cybersecurity
    Parente, F. R.
    Rodrigues, Emanuel B.
    Mattos, Cesar L. C.
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2025, 89
  • [35] The CAN Bus in the Maritime Environment - Technical Overview and Cybersecurity Vulnerabilities
    Kessler, Gary C.
    TRANSNAV-INTERNATIONAL JOURNAL ON MARINE NAVIGATION AND SAFETY OF SEA TRANSPORTATION, 2021, 15 (03) : 531 - 540
  • [36] CyberTwitter: Using Twitter to generate alerts for Cybersecurity Threats and Vulnerabilities
    Mittal, Sudip
    Das, Prajit Kumar
    Mulwad, Varish
    Joshi, Anupam
    Finin, Tim
    PROCEEDINGS OF THE 2016 IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING ASONAM 2016, 2016, : 860 - 867
  • [37] Cybersecurity Vulnerabilities of Smart Inverters and Their Impacts on Power System Operation
    Ustun, Taha Selim
    2019 INTERNATIONAL CONFERENCE ON POWER ELECTRONICS, CONTROL AND AUTOMATION (ICPECA-2019), 2019, : 1 - 4
  • [38] Cybersecurity Vulnerabilities in Mobile Fare Payment Applications: A Case Study
    Dennis, Kevin
    Alibayev, Maxat
    Barbeau, Sean J.
    Ligatti, Jay
    TRANSPORTATION RESEARCH RECORD, 2020, 2674 (11) : 616 - 624
  • [39] Autonomous Vehicles: The Cybersecurity Vulnerabilities and Countermeasures for Big Data Communication
    Algarni, Abdullah
    Thayananthan, Vijey
    SYMMETRY-BASEL, 2022, 14 (12):
  • [40] Vulnerabilities of Government Websites in a Developing Country - the Case of Burkina Faso
    Bissyande, Tegawende F.
    Ouoba, Jonathan
    Ahmat, Daouda
    Ouedraogo, Frederic
    Bere, Cedric
    Bikienga, Moustapha
    Sere, Abdoulaye
    Dandjinou, Mesmin
    Sie, Oumarou
    E-INFRASTRUCTURE AND E-SERVICES, 2016, 171 : 123 - 135