RESEARCH OF METHODS FOR DETECTING VULNERABILITIES IN SOFTWARE AND INFORMATION AND COMMUNICATION SYSTEMS BASED ON THE WINDOWS OPERATING SYSTEM WITH THE DEVELOPMENT OF AUTOMATED ANALYSIS SOFTWARE

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1302

Keywords:

operating systems, cybersecurity, cyber threats, software security, programming, Windows, information and communication systems, Python

Abstract

The article investigates modern methods of detecting vulnerabilities in software and information and communication systems, and also develops a software tool for automated analysis of potential threats based on the Windows operating system. A comparative analysis of the main approaches to detecting vulnerabilities, in particular static and dynamic analysis, is carried out, their advantages, disadvantages and areas of practical application are determined. Based on the research, a software tool in Python has been developed that automates the process of analyzing the source code, operating system parameters and network configuration in order to identify potential vulnerabilities. The implemented algorithm provides analysis of the program code for the use of potentially dangerous structures, the MD5 hashing algorithm and cases of hard coding of passwords. In addition to software analysis, the parameters of the Windows operating system are checked, as well as analysis of open network ports and configuration of network interfaces. Based on the analysis results, the software tool generates text and HTML reports that contain a list of detected potential vulnerabilities, a risk assessment, statistical information on the analysis results and recommendations for eliminating the identified shortcomings. The proposed approach makes it possible to automate the process of initial security auditing of software and information and communication systems, and to increase the efficiency of identifying potential threats.

Downloads

Download data is not yet available.

References

Baca, D., Carlsson, B., Petersen, K., & Lundberg, L. (2019). Benchmarking static code analyzers. Information and Software Technology, 112, 68-85.

Grossman, J., Hansen, R., Petkov, P., Rager, A., & Fogie, S. (2007). XSS attacks: Cross site scripting exploits and defense. Syngress.

Kubiuk, Y., & Kyselov, G. (2021). Comparative analysis of approaches to source code vulnerability detection based on deep learning methods. Technology Audit and Production Reserves, 3(2[59]), 19-23. https://doi.org/10.15587/2706-5448.2021.233534

Lu, G., Ju, X., Chen, X., Pei, W., & Cai, Z. (2024). GRACE: Empowering LLM-based software vulnerability detection with graph structure and in-context learning. Journal of Systems and Software, 212, Article 112031. https://doi.org/10.1016/j.jss.2024.112031

MITRE Corporation. (n.d.). Common Weakness Enumeration (CWE). https://cwe.mitre.org/

National Institute of Standards and Technology. (2022). Secure Software Development Framework (SSDF) version 1.1: Recommendations for mitigating the risk of software vulnerabilities (NIST Special Publication 800-218). https://doi.org/10.6028/NIST.SP.800-218

OWASP Foundation. (2023). OWASP Web Security Testing Guide (WSTG) (Version 4.2).

Static analysis techniques for embedded, cyber-physical, and electronic software systems: A comprehensive survey. (2025). Electronics, 15(5).

Youn, D., Lee, S., & Ryu, S. (2023). Declarative static analysis for multilingual programs using CodeQL. Software: Practice and Experience, 53(7), 1472-1495. https://doi.org/10.1002/spe.3199

Hapon, A. O., Fedorchenko, V. M., & Sievierinov, O. V. (2023). Methods and tools for static and dynamic code analysis. Radioelectronics, 212, 7-13. https://doi.org/10.30837/rt.2023.1.212.01

Horiuk, N. V., & Lavrovskyi, I. M. (2021). Static analysis of software source code using Fortify Static Code Analyzer. Modern Information Security, 2. https://doi.org/10.31673/2409-7292.2021.020910

Drozd, A., & Mykuliak, D. (2026). Intelligent computer system for automatic detection of web application vulnerabilities and threat classification. Measuring and Computing Devices in Technological Processes, 1, 368-376. https://doi.org/10.31891/2219-9365-2026-85-45

Diachenko, O. O., & Hrabovskyi, O. V. (2025). Software code quality assessment using static analysis. Collection of Scientific Works of the Odesa State Academy of Technical Regulation and Quality, 1, 129–135. https://doi.org/10.32684/2412-5288-2025-1-26-129-135

Kuievda, Yu. V., Tatarin, Ye. O., & Selin, Yu. M. (2025). A system for assessing the quality of object-oriented program code based on static analysis and metric visualization. Applied Issues of Mathematical Modelling, 8(2), 154-165. https://doi.org/10.32782/mathematical-modelling/2025-8-2-16

Polotai, O. I. (2023). The use of computer forensics to ensure effective investigation of information and cybersecurity incidents. Bulletin of Lviv State University of Life Safety, 28, 73–80. https://doi.org/10.32447/20784643.28.2023.07

Polotai, O. I., Kukharska, N. P., Tkachenko, A. M., Siedin, Ye. O., & Nikolaichuk, M. I. (2026). Methods for automating cybersecurity incident investigations based on Windows operating system logs using Python to support information security management. Cybersecurity: Education, Science, Technique, 33(1), 414-426. https://doi.org/10.28925/2663-4023.2026.33.1219

Spys, D. V., & Ilienko, A. V. (2025). Systematization and classification of modern methods for static analysis of web applications. Cybersecurity: Education, Science, Technique, 2(30), 157-179. https://doi.org/10.28925/2663-4023.2025.30.957

Downloads


Abstract views: 12

Published

2026-09-24

How to Cite

Polotai, O., Kukharska, N., Maslova, N., Siedin , I., & Nykolaichuk , M. (2026). RESEARCH OF METHODS FOR DETECTING VULNERABILITIES IN SOFTWARE AND INFORMATION AND COMMUNICATION SYSTEMS BASED ON THE WINDOWS OPERATING SYSTEM WITH THE DEVELOPMENT OF AUTOMATED ANALYSIS SOFTWARE. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 129–140. https://doi.org/10.28925/2663-4023.2026.34.1302

Most read articles by the same author(s)