Cloud-Native Serverless Web Security Assessment: Coverage, Agreement, and Score Sensitivity

Preprint, Version 1.0. BRAVO6 is an Azure-hosted serverless system for externally observable web security assessment. This study presents an auditable reanalysis of an archived 864-domain experiment, distinguishing execution success, observation coverage, and measurement validity. The archive contains 848 result documents, including 508 representative-page responses and 497 module-complete representative results. Evidence-backed sensitivity analysis shows that removing unsupported TLS assertions and one incorrect advisory-version match changes the mean score of the representative cohort from 16.93 to 24.78 under the original scoring rubric. The study also identifies substantial observation gaps for HSTS and dependency analysis and evaluates saved cross-tool verdict agreement under explicit small-sample limitations. This manuscript is a preprint and has not yet undergone peer review.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-25
DOI
https://doi.org/10.5281/zenodo.22958201
Primary Topic
Web Application Security Vulnerabilities
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Cloud-Native Serverless Web Security Assessment: Coverage, Agreement, and Score Sensitivity

Amr Medhat Amer
Zenodo (CERN European Organization for Nuclear Research)
Web Application Security Vulnerabilities
preprint

Cloud-Native Serverless Web Security Assessment: Coverage, Agreement, and Score Sensitivity

Amr Medhat Amer
preprint en

Abstract

Preprint, Version 1.0. BRAVO6 is an Azure-hosted serverless system for externally observable web security assessment. This study presents an auditable reanalysis of an archived 864-domain experiment, distinguishing execution success, observation coverage, and measurement validity. The archive contains 848 result documents, including 508 representative-page responses and 497 module-complete representative results. Evidence-backed sensitivity analysis shows that removing unsupported TLS assertions and one incorrect advisory-version match changes the mean score of the representative cohort from 16.93 to 24.78 under the original scoring rubric. The study also identifies substantial observation gaps for HSTS and dependency analysis and evaluates saved cross-tool verdict agreement under explicit small-sample limitations. This manuscript is a preprint and has not yet undergone peer review.

Zenodo (CERN European Organization for Nuclear Research)
Alexandria University (EG)
Peace, Justice and strong institutions
Web Application Security Vulnerabilities
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.