The maritime-logistics sector is a fundamental component of smart cities and is increasingly exposed to cyber threats because of progressive digitalization. This paper presents a reproducible, low-intrusion method for measuring the publicly observable web attack surface of organizations in a port community. The workflow identifies official domains, captures traffic generated by ordinary browsing, applies OWASP ZAP passive rules, exports alert severity, confidence, and occurrence counts, and aggregates them into site- and group-level comparative exposure indexes. A case study of 109 websites in the Port of Livorno ecosystem reveals marked heterogeneity: eleven alert types account for approximately 90% of detections, three sites exceed an illustrative exposure threshold of 4, and group averages range from 0.26 for shippers to 1.48 for terminal operators. The index is an alert-prioritization proxy rather than a measure of cyber risk because it excludes exploitability, likelihood, asset criticality, business impact, internal infrastructure, and cascading effects. The method supports ecosystem-level triage and repeatable monitoring but requires independent validation before risk claims can be made.
A Data-Driven Assessment of the Web Cyberattack Surface: The case study of the Livorno Maritime-Logistic Ecosystem
Gianluca Dini
Primo
Writing – Review & Editing
;Sergio Vittorio ZambelliSecondo
Data Curation
;Martina NeriPenultimo
Membro del Collaboration Group
;Federico NiccoliniUltimo
Membro del Collaboration Group
2026-01-01
Abstract
The maritime-logistics sector is a fundamental component of smart cities and is increasingly exposed to cyber threats because of progressive digitalization. This paper presents a reproducible, low-intrusion method for measuring the publicly observable web attack surface of organizations in a port community. The workflow identifies official domains, captures traffic generated by ordinary browsing, applies OWASP ZAP passive rules, exports alert severity, confidence, and occurrence counts, and aggregates them into site- and group-level comparative exposure indexes. A case study of 109 websites in the Port of Livorno ecosystem reveals marked heterogeneity: eleven alert types account for approximately 90% of detections, three sites exceed an illustrative exposure threshold of 4, and group averages range from 0.26 for shippers to 1.48 for terminal operators. The index is an alert-prioritization proxy rather than a measure of cyber risk because it excludes exploitability, likelihood, asset criticality, business impact, internal infrastructure, and cascading effects. The method supports ecosystem-level triage and repeatable monitoring but requires independent validation before risk claims can be made.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


