Skip to main navigation Skip to search Skip to main content

A Comprehensive Analysis of Cybersecurity Infrastructure in Academic Environments

Research output: Contribution to journalArticle

Abstract

This paper addresses a comprehensive analysis of cybersecurity systems in academic environments taking as a case study the domains: “www. ups. edu. ec”, “cas. ups. edu. ec”, “virtual. ups. edu. ec” y “dspace. ups. edu. ec”, of the Salesian Polytechnic University, using specialized tools such as Kali Linux and Nessus. Through these technologies, critical aspects of the system’s security are evaluated: its ability to resist attacks, how effective its defense mechanisms are, and its capacity to identify exploitable weak points. A novel methodology is applied to evaluate the security of the system, using emerging technologies and innovative techniques. During the research, several vulnerabilities were identified covering the four studied domains. These were classified using the CVSS (Common Vulnerability Scoring System) rating protocol, which allowed the most critical ones to be prioritized and addressed first. In addition, a scan of open ports was performed to recognize possible unauthorized access points. As part of the security testing, a simulation of an email phishing attack was carried out by cloning the Salesian University access website, in order to assess users’ susceptibility to this threat. Domain security analysis revealed critical vulnerabilities, including an outdated version of PHP and possible remote code execution (CVSS 9.8-10) in “virtual. ups. edu. ec”. SSL/TLS security issues were also detected, such as the use of weak ciphers and outdated versions of TLS (CVSS up to 7.5). In addition, medium risks related to lack of HSTS and vulnerabilities in PHP and jQuery were found, along with weaker SSH configurations of lesser impact (CVSS 2.6-3.7). These results show the need for security updates and improvements.
Translated title of the contributionUn Análisis Integral de la Infraestructura de Ciberseguridad en Entornos Académicos
Original languageEnglish (US)
Pages (from-to)11-23
Number of pages13
JournalRevista Ingeniería
Volume35
Issue number35
DOIs
StatePublished - 14 Oct 2024

Keywords

  • Cybersecurity
  • Kali linux
  • Nessus
  • Phishing
  • Vulnerabilities

CACES Knowledge Areas

  • 8417A Telecommunications

Fingerprint

Dive into the research topics of 'A Comprehensive Analysis of Cybersecurity Infrastructure in Academic Environments'. Together they form a unique fingerprint.
  • Electricity Generation Through the Internet of Things Integration of Mini Generators Connected to a House's Drinking Water Pipes (Mini Turbines & IOT)

    Santillan Carranza, H. J. (PI), Colcha Chacon, L. I. (Student), Mejia Orellana, J. A. (Student), Peregrina Wong Wong, M. A. (External), Alcivar Alvarado, K. J. (Student), Alcivar Sanchez, A. S. (Student), Bohorquez Reyes, L. E. (Student), Chacon Garcia, P. M. (Student), Feijoo Roman, C. M. (Student), Larrea Onofre, A. A. (Student), Martinez Cedeño, M. L. (Student), Mendoza Bernal, C. E. (Student), Mora Madrid, M. A. (Student), Muñoz Herrera, W. I. (Student), Nieto Zambrano, N. A. (Student), Ochoa Ayala, J. D. (Student), Ordoñez Guzman, J. A. (Student), Pesantez Carcelen, J. P. (Student), Quezada Funes, K. Y. (Student), Quiñonez Santos, N. D. (Student), Ramirez Carrera, R. S. (Student), Ramos Mendez, A. F. (Student), Sanchez Piza, P. J. (Student) & Vargas Vinueza, A. E. (Student)

    4/08/21 → …

    Project: Research and Development

Cite this