Cybersecurity vulnerabilities and solutions in Ethiopian university websites

被引:2
|
作者
Eshetu, Ali Yimam [1 ]
Mohammed, Endris Abdu [1 ]
Salau, Ayodeji Olalekan [2 ,3 ]
机构
[1] Woldia Univ, Inst Technol, Sch Elect & Comp Engn, Woldia, Ethiopia
[2] Afe Babalola Univ, Dept Elect Elect & Comp Engn, Ado Ekiti, Nigeria
[3] Saveetha Inst Med & Tech Sci, Saveetha Sch Engn, Chennai, Tamil Nadu, India
关键词
Cybersecurity in higher education; Information security standards; Nessus; Nmap; VAPT; Vega; SECURITY;
D O I
10.1186/s40537-024-00980-z
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This study investigates the causes and countermeasures of cybercrime vulnerabilities, specifically focusing on selected 16 Ethiopian university websites. This study uses a cybersecurity awareness survey, and automated vulnerability assessment and penetration testing (VAPT) technique tools, namely, Nmap, Nessus, and Vega, to identify potential security threats and vulnerabilities. The assessment was performed according to the ISO/IEC 27001 series of standards, ensuring a comprehensive and globally recognized approach to information security. The results of this study provide valuable insights into the current state of cybersecurity in Ethiopian universities and reveals a range of issues, from outdated software and poor password management to a lack of encryption and inadequate access control. Vega vulnerability assessment reports 11,286 total findings, and Nessus identified a total of 1749 vulnerabilities across all the websites of the institutions examined. Based on these findings, the study proposes counteractive measures tailored to the specific needs of each identified defect. These recommendations aim to strengthen the security posture of the university websites, thereby protecting sensitive data and maintaining the trust of students, staff, and other stakeholders. The study emphasizes the need for proactive cybersecurity measures in the realm of higher education and presents a strategic plan for universities to improve their digital security. The study investigates the causes of cybersecurity vulnerabilities in university websites, with a focus on Ethiopian Universities.The evaluation was based on ISO/IEC 27001 series standards and utilized three different automatic VAPT evaluation tools: Nmap, NESSUS, and VEGA.The research identified a range of issues contributing to cybersecurity vulnerabilities, including outdated software, poor password management, a lack of encryption, and inadequate access control.The study underscores the importance of proactive cybersecurity practices in the higher education sector and provides a roadmap for universities to enhance their digital security.
引用
收藏
页数:35
相关论文
共 50 条
  • [41] Marketing and Culture in University Websites
    Simin, Shahla
    Tavangar, Manoochehr
    Pinna, Antonio
    CLCWEB-COMPARATIVE LITERATURE AND CULTURE, 2011, 13 (04):
  • [42] Cybersecurity Resiliency of Marine Renewable Energy Systems-Part 1: Identifying Cybersecurity Vulnerabilities and Determining Risk
    de Peralta, Fleurdeliza A.
    Gorton, Alicia M.
    Watson, Mark D.
    Bays, Ryan M.
    Boles, Joshua R.
    Gorton, Brandon T.
    Castleberry, Jerry E.
    Powers, Ford E.
    MARINE TECHNOLOGY SOCIETY JOURNAL, 2020, 54 (06) : 97 - 107
  • [43] Advances in Cybersecurity: Challenges and Solutions
    Trim, Peter R. J.
    Lee, Yang-Im
    APPLIED SCIENCES-BASEL, 2024, 14 (10):
  • [44] An intelligent cybersecurity system for detecting fake news in social media websites
    Mughaid, Ala
    Al-Zu'bi, Shadi
    Al Arjan, Ahmed
    AL-Amrat, Rula
    Alajmi, Rathaa
    Abu Zitar, Raed
    Abualigah, Laith
    SOFT COMPUTING, 2022, 26 (12) : 5577 - 5591
  • [45] Measures to Mitigate Cybersecurity Risks and Vulnerabilities in Service-Oriented Architecture
    Cirnu, Carmen Elena
    Rotuna, Carmen Ionela
    Vevera, Adrian Victor
    Boncea, Radu
    STUDIES IN INFORMATICS AND CONTROL, 2018, 27 (03): : 359 - 368
  • [46] Review of Electric Vehicle Charger Cybersecurity Vulnerabilities, Potential Impacts, and Defenses
    Johnson, Jay
    Berg, Timothy
    Anderson, Benjamin
    Wright, Brian
    ENERGIES, 2022, 15 (11)
  • [47] An intelligent cybersecurity system for detecting fake news in social media websites
    Ala Mughaid
    Shadi Al-Zu’bi
    Ahmed AL Arjan
    Rula AL-Amrat
    Rathaa Alajmi
    Raed Abu Zitar
    Laith Abualigah
    Soft Computing, 2022, 26 : 5577 - 5591
  • [48] Distributed Energy Resources Cybersecurity Outlook: Vulnerabilities, Attacks, Impacts, and Mitigations
    Zografopoulos, Ioannis
    Hatziargyriou, Nikos D.
    Konstantinou, Charalambos
    IEEE SYSTEMS JOURNAL, 2023, 17 (04): : 6695 - 6709
  • [49] Social Engineering in Cybersecurity: Effect Mechanisms, Human Vulnerabilities and Attack Methods
    Wang, Zuoguang
    Zhu, Hongsong
    Sun, Limin
    IEEE ACCESS, 2021, 9 : 11895 - 11910
  • [50] ARTIFICIAL INTELLIGENCE AND CYBERSECURITY, UNIVERSITY KLAGENFURT
    University Klagenfurt, Austria
    Electron. Device Fail. Anal., 2023, 2 (33):