Research project / 2026

Hendra: context-aware black-box DAST

A context-aware DAST scanner I designed and developed at ITMO University, combining attack-surface mapping, selective testing, request deduplication and evidence-based finding verification.

Fig. 01

Hendra · DAST

Hendra — the DAST scanner I designed and built.

For my completed doctoral research at ITMO University, I developed Hendra’s architecture, scan planning, request deduplication, finding verification and evaluation framework. Application context guides which checks the scanner runs.

ITMO
Hendra
Role
Architecture, implementation and evaluation
Explore Hendra’s architecture and results
Hendra vs. Burp Suite Pro · DVWA, low security · controlled run
Burp Suite ProF1 0.929

40,131

HendraF1 0.966

686

58.5×Fewer requests

Recorded in my project research: DVWA at low security, under the tested tool configurations. F1 combines precision and recall. These figures describe this experiment, not a universal ranking or a production performance guarantee.

Overview

I designed and developed Hendra for my completed doctoral research project at ITMO University. The work spans the core scanner architecture, technology fingerprinting, scan planning, request deduplication and memoization, finding adjudication, and the DASTestBed evaluation framework.

DAST examines a running application. Hendra works through its exposed interfaces without reading the source code. My research asks how the context observed through those interfaces can guide useful tests, reduce redundant traffic and support findings with evidence.

The engineering goal is selective, measurable testing: build a useful model of the application, choose checks from that context, control request dispatch and evaluate the evidence. Each part addresses a specific limitation in automated scanning.

How I engineered the scanner

  1. Map the application

    An instrumented crawler builds an Attack Surface Graph of endpoints, parameters, observed technologies and response characteristics. Passive checks enrich that model from responses already collected.

  2. Choose relevant checks

    Technology identification and the graph guide scan planning, payload selection and relevant Nuclei templates. The scanner combines its own generic probes with technology-specific workflows.

  3. Control every request

    A shared dispatch layer applies feature-equivalence deduplication and memoization across scanner modules. Reuse depends on request context and validity checks, so similar URLs alone do not establish equivalence.

  4. Review the evidence

    Candidate findings pass through an evidence-based adjudication layer, with LLM assistance, before reporting. Detection is evaluated against explicit ground truth; the verification layer itself must also be evaluated.

What the controlled experiment showed

In the recorded DVWA low-security run, Hendra detected 14 of 15 ground-truth vulnerability instances with no false positives; Burp Suite Pro detected 13 of 15 with no false positives. Hendra missed one XSS instance because its crawler did not exercise the affected parameter. Request volume and F1 make the detection outcome and traffic cost visible together.

Hendra vs. Burp Suite Pro · DVWA, low security · controlled run
ScannerRequests dispatchedF1
Hendra6860.966
Burp Suite Pro40,1310.929
Recorded in my project research: DVWA at low security, under the tested tool configurations. F1 combines precision and recall. These figures describe this experiment, not a universal ranking or a production performance guarantee.

What these results establish

This run demonstrates a compact request set with strong detection on the chosen target and configuration. It does not establish universal superiority, lower elapsed time, complete coverage or the same result on a client application. The remaining miss also shows why crawl coverage belongs in the evaluation. A new comparison needs explicit targets, access, ground truth where available and repeatable tool profiles.

Research supporting the engineering

These publications address specific parts of the research. The DVWA comparison above comes from my project research record; it is not presented as a result published in all three papers.

  • Web technology identification

    Behavioral features, weak supervision and rule-assisted machine learning help establish application context. The published study evaluates 122 technologies across 8,594 websites.

  • Request deduplication and memoization

    A formal model for request equivalence, safe reuse, concurrent dispatch and complexity bounds provides a basis for controlling redundant scanner traffic.

  • DASTestBed evaluation framework

    Containerized targets, explicit vulnerability records and normalized scanner findings make evaluation conditions and detection costs inspectable.

What this means for your project

If you build a security product or need a custom analysis tool, we can scope work on architecture, detection logic, scanner extensions or evaluation. Hendra provides a concrete example of my DAST engineering. SAST development is a separate capability, with the language, analysis approach and deliverables agreed for your project.

Discuss security tool development

Key facts

Research project
2026
Institution
ITMO University
Topics
DAST · Hendra · Context-aware scanning · Attack Surface Graph

Related work

08Contact

Let’s solve the next hard problem.

Tell me what you’re building, what is at stake and when you need a result. I’ll discuss the fit and propose a defined scope, deliverables and price.