The maritime-logistics sector is a fundamental component of smart cities and is increasingly exposed to cyber threats because of progressive digitalization. This paper presents a reproducible, low-intrusion method for measuring the publicly observable web attack surface of organizations in a port community. The workflow identifies official domains, captures traffic generated by ordinary browsing, applies OWASP ZAP passive rules, exports alert severity, confidence, and occurrence counts, and aggregates them into site- and group-level comparative exposure indexes. A case study of 109 websites in the Port of Livorno ecosystem reveals marked heterogeneity: eleven alert types account for approximately 90% of detections, three sites exceed an illustrative exposure threshold of 4, and group averages range from 0.26 for shippers to 1.48 for terminal operators. The index is an alert-prioritization proxy rather than a measure of cyber risk because it excludes exploitability, likelihood, asset criticality, business impact, internal infrastructure, and cascading effects. The method supports ecosystem-level triage and repeatable monitoring but requires independent validation before risk claims can be made.

A Data-Driven Assessment of the Web Cyberattack Surface: The case study of the Livorno Maritime-Logistic Ecosystem

Gianluca Dini
Primo
Writing – Review & Editing
;
Sergio Vittorio Zambelli
Secondo
Data Curation
;
Martina Neri
Penultimo
Membro del Collaboration Group
;
Federico Niccolini
Ultimo
Membro del Collaboration Group
2026-01-01

Abstract

The maritime-logistics sector is a fundamental component of smart cities and is increasingly exposed to cyber threats because of progressive digitalization. This paper presents a reproducible, low-intrusion method for measuring the publicly observable web attack surface of organizations in a port community. The workflow identifies official domains, captures traffic generated by ordinary browsing, applies OWASP ZAP passive rules, exports alert severity, confidence, and occurrence counts, and aggregates them into site- and group-level comparative exposure indexes. A case study of 109 websites in the Port of Livorno ecosystem reveals marked heterogeneity: eleven alert types account for approximately 90% of detections, three sites exceed an illustrative exposure threshold of 4, and group averages range from 0.26 for shippers to 1.48 for terminal operators. The index is an alert-prioritization proxy rather than a measure of cyber risk because it excludes exploitability, likelihood, asset criticality, business impact, internal infrastructure, and cascading effects. The method supports ecosystem-level triage and repeatable monitoring but requires independent validation before risk claims can be made.
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11568/1370568
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact