IJCOPE Journal

UGC Logo DOI / ISO Logo

International Journal of Creative and Open Research in Engineering and Management

A Peer-Reviewed, Open-Access International Journal Supporting Multidisciplinary Research, Digital Publishing Standards, DOI Registration, and Academic Indexing.
Journal Information
ISSN: 3108-1754 (Online)
Crossref DOI: Available
ISO Certification: 9001:2015
Publication Fee: 599/- INR
Compliance: UGC Journal Norms
License: CC BY 4.0
Peer Review: Double Blind
Volume 02, Issue 9

Published on: September 2026

SECUREXON: DESIGN, ARCHITECTURE, AND EVALUATION METHODOLOGY FOR AN AI-AUGMENTED WEB RECONNAISSANCE AND CYBERSECURITY THREAT-INTELLIGENCE PLATFORM

Sahil Bagde Swapnil Meshram Harish Dange Mansi Mate Prof. Komal Tiwari

Dr. Sushama Telrandhe

Department of  Computer Science and Engineering, Guru Nanak Institute of Engineering and Technology, Nagpur, India

Article Status

Plagiarism Passed Peer Reviewed Open Access

Available Documents

Abstract

The rapid expansion of internet-facing web applications has widened the attack surface available to automated scanners, botnets and malicious actors, while common weaknesses such as misconfigured servers, unpatched software, obsolete transport-layer encryption and missing HTTP security headers continue to be exploited at scale. Commercial vulnerability scanners are costly and largely opaque, whereas open-source command-line utilities operate independently of one another and demand specialised expertise, offering little contextual or remediation guidance. This paper presents the design of SecureXon , a modular, full-stack security reconnaissance and threat-intelligence platform built around a Python/Flask backend that consolidates fifteen asynchronous reconnaissance modules with a large-language-model-driven Security Operations Center (SOC) assistant for false-positive vulnerability filtering and remediation guidance. A dedicated Zero-Trust defensive subsystem, the SSRF Guard, validates every outbound network request against loopback, private, link-local, multicast and encoded IP representations before it is dispatched. A companion log-analysis engine maps detected attack signatures in Nginx/Apache traffic to the MITRE ATT&CK knowledge base. Beyond the system design, this paper contributes a normalised risk-scoring formulation, an architecture and workflow specification, a structured SSRF bypass test-vector suite, and a precision/recall/F1-based evaluation protocol for the AI-assisted CVE triage stage. As the platform is currently at the design-and-development stage, the paper specifies evaluation protocols for quantitative validation rather than reporting unmeasured performance results.

Index Terms— Web reconnaissance, vulnerability assessment, artificial intelligence in security operations, Server-Side Request Forgery, CVE triage, MITRE ATT&CK, SSL/TLS auditing, log analysis, asynchronous scanning.

How to Cite this Paper

Bagde, S., Meshram, S., Dange, H., Mate, M. & Tiwari, K. (2026). SecureXon: Design, Architecture, and Evaluation Methodology for an AI-Augmented Web Reconnaissance and Cybersecurity Threat-Intelligence Platform. International Journal of Creative and Open Research in Engineering and Management, <i>02</i>(9), 1-9. https://doi.org/10.55041/ijcope.v2i9.004

Bagde, Sahil, et al.. "SecureXon: Design, Architecture, and Evaluation Methodology for an AI-Augmented Web Reconnaissance and Cybersecurity Threat-Intelligence Platform." International Journal of Creative and Open Research in Engineering and Management, vol. 02, no. 9, 2026, pp. 1-9. doi:https://doi.org/10.55041/ijcope.v2i9.004.

Bagde, Sahil,Swapnil Meshram,Harish Dange,Mansi Mate, and Komal Tiwari. "SecureXon: Design, Architecture, and Evaluation Methodology for an AI-Augmented Web Reconnaissance and Cybersecurity Threat-Intelligence Platform." International Journal of Creative and Open Research in Engineering and Management 02, no. 9 (2026): 1-9. https://doi.org/https://doi.org/10.55041/ijcope.v2i9.004.

Search & Index

References

[1] M. E. Whitman and H. J. Mattord, Principles of Information Security, 6th ed. Boston, MA, USA: Cengage Learning, 2018.

[2] OWASP Foundation, "OWASP Top 10:2021 - The Ten Most Critical Web Application Security Risks," 2021.

[3] MITRE Corporation, "MITRE ATT&CK Enterprise Matrix," 2023.

[4] National Institute of Standards and Technology, "National Vulnerability Database API v2 Specification," NIST NVD, 2023.

[5] Google DeepMind, "Gemini 2.0 Flash Model Card and API Reference," Google AI, 2024.

[6] G. F. Lyon, Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning. Sunnyvale, CA, USA: Insecure.Com LLC, 2009.

[7] M. Grinberg, Flask Web Development: Developing Web Applications with Python, 2nd ed. Sebastopol, CA, USA: O'Reilly Media, 2018.

[8] E. Rescorla, "The Transport Layer Security (TLS) Protocol Version 1.3," IETF RFC 8446, Aug. 2018.

[9] R. Fielding et al., "Hypertext Transfer Protocol (HTTP/1.1): Message Syntax and Routing," IETF RFC 7230, Jun. 2014.

[10] Y. Rekhter, B. Moskowitz, D. Karrenberg, G. J. de Groot, and E. Lear, "Address Allocation for Private Internets," IETF RFC 1918, Feb. 1996.

[11] S. Kitterman, "Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1," IETF RFC 7208, Apr. 2014.

[12] M. Kucherawy and E. Zwicky, "Domain-based Message Authentication, Reporting, and Conformance (DMARC)," IETF RFC 7489, Mar. 2015.

[13] M. J. Torkamani, J. Ng, N. Mehrotra, M. Chandramohan, P. Krishnan, and R. Purandare, "Streamlining Security Vulnerability Triage with Large Language Models," arXiv preprint arXiv:2501.18908, 2025.

[14] PortSwigger Research, "Introducing the URL Validation Bypass Cheat Sheet," PortSwigger Ltd., 2024. [Online]. Available: https://portswigger.net/research/introducing-the-url-validation-bypass-cheat-sheet

[15] Shodan.io, "Shodan REST API Developer Documentation," 2023.

Ethical Compliance & Review Process

  • All submissions are screened under plagiarism detection.
  • Review follows editorial policy.
  • Authors retain copyright.
  • Peer Review Type: Double-Blind Peer Review
  • Published on: Sep 08 2026
CCBYNC

This article is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License. You are free to share and adapt this work for non-commercial purposes with proper attribution.

View License
Scroll to Top