A context-aware DAST scanner I designed and developed at ITMO University, combining attack-surface mapping, selective testing, request deduplication and evidence-based finding verification.
Fig. 01
Hendra · DAST
Hendra — the DAST scanner I designed and built.
For my completed doctoral research at ITMO University, I developed Hendra’s architecture, scan planning, request deduplication, finding verification and evaluation framework. Application context guides which checks the scanner runs.
Hendra vs. Burp Suite Pro · DVWA, low security · controlled run
Burp Suite ProF1 0.929
40,131
HendraF1 0.966
686
58.5×Fewer requests
Recorded in my project research: DVWA at low security, under the tested tool configurations. F1 combines precision and recall. These figures describe this experiment, not a universal ranking or a production performance guarantee.
Overview
I designed and developed Hendra for my completed doctoral research project at ITMO University. The work spans the core scanner architecture, technology fingerprinting, scan planning, request deduplication and memoization, finding adjudication, and the DASTestBed evaluation framework.
DAST examines a running application. Hendra works through its exposed interfaces without reading the source code. My research asks how the context observed through those interfaces can guide useful tests, reduce redundant traffic and support findings with evidence.
The engineering goal is selective, measurable testing: build a useful model of the application, choose checks from that context, control request dispatch and evaluate the evidence. Each part addresses a specific limitation in automated scanning.
How I engineered the scanner
01
Map the application
An instrumented crawler builds an Attack Surface Graph of endpoints, parameters, observed technologies and response characteristics. Passive checks enrich that model from responses already collected.
02
Choose relevant checks
Technology identification and the graph guide scan planning, payload selection and relevant Nuclei templates. The scanner combines its own generic probes with technology-specific workflows.
03
Control every request
A shared dispatch layer applies feature-equivalence deduplication and memoization across scanner modules. Reuse depends on request context and validity checks, so similar URLs alone do not establish equivalence.
04
Review the evidence
Candidate findings pass through an evidence-based adjudication layer, with LLM assistance, before reporting. Detection is evaluated against explicit ground truth; the verification layer itself must also be evaluated.
What the controlled experiment showed
In the recorded DVWA low-security run, Hendra detected 14 of 15 ground-truth vulnerability instances with no false positives; Burp Suite Pro detected 13 of 15 with no false positives. Hendra missed one XSS instance because its crawler did not exercise the affected parameter. Request volume and F1 make the detection outcome and traffic cost visible together.
Hendra vs. Burp Suite Pro · DVWA, low security · controlled run
Scanner
Requests dispatched
F1
Hendra
686
0.966
Burp Suite Pro
40,131
0.929
Recorded in my project research: DVWA at low security, under the tested tool configurations. F1 combines precision and recall. These figures describe this experiment, not a universal ranking or a production performance guarantee.
What these results establish
This run demonstrates a compact request set with strong detection on the chosen target and configuration. It does not establish universal superiority, lower elapsed time, complete coverage or the same result on a client application. The remaining miss also shows why crawl coverage belongs in the evaluation. A new comparison needs explicit targets, access, ground truth where available and repeatable tool profiles.
Research supporting the engineering
These publications address specific parts of the research. The DVWA comparison above comes from my project research record; it is not presented as a result published in all three papers.
Behavioral features, weak supervision and rule-assisted machine learning help establish application context. The published study evaluates 122 technologies across 8,594 websites.
A formal model for request equivalence, safe reuse, concurrent dispatch and complexity bounds provides a basis for controlling redundant scanner traffic.
Containerized targets, explicit vulnerability records and normalized scanner findings make evaluation conditions and detection costs inspectable.
What this means for your project
If you build a security product or need a custom analysis tool, we can scope work on architecture, detection logic, scanner extensions or evaluation. Hendra provides a concrete example of my DAST engineering. SAST development is a separate capability, with the language, analysis approach and deliverables agreed for your project.