Document Generation Security Assessment - A DocOrigin Case Study

dc.contributor.authorTamminen, Leo
dc.contributor.departmentfi=Tietotekniikan laitos|en=Department of Computing|
dc.contributor.facultyfi=Teknillinen tiedekunta|en=Faculty of Technology|
dc.contributor.studysubjectfi=Tietotekniikka|en=Information and Communication Technology|
dc.date.accessioned2026-05-18T19:31:44Z
dc.date.issued2026-05-11
dc.description.abstractEnterprise document generation systems are widely used in modern organizations toautomatically generate large volumes of business-critical documents such as invoices,payslips, and official communications. These systems process sensitive data and areoften deeply integrated into enterprise backend environments, making their securitya critical concern. Despite their importance, document production platformsare frequently treated as supporting systems, and their architecture-level securityaspects may receive limited attention. This thesis evaluates the security of a real-world ERP-to-DocOrigin document productionpipeline using two industry-recognized standards: OWASP Application SecurityVerification Standard (ASVS) v5.0.0 and the AS&D Security Technical ImplementationGuide (STIG) Version 6, Release 4.The evaluation combines a systematic literature review of document pipeline securityrisks with a practical case study based on a production environment running theDocOrigin document generation platform. The application was evaluated againstthe OWASP ASVS at the application level and against AS&D STIG at the environmentlevel.The results show that DocOrigin operates as a component-style engine that delegatessecurity entirely to its surrounding environment, a pattern termed the dumb enginehypothesis in this study. Proven vulnerabilities include input validation failures, asuccessful Billion Laughs denial-of-service attack, plain-text credential storage, anda total absence of drive encryption in the reference environment. Nineteen out oftwenty-three high severity STIG findings were confirmed as active. The findings areapplicable to organizations deploying similar document generation systems, particularlyin regulated or defense-sector contexts.
dc.format.extent102
dc.identifier.urihttps://www.utupub.fi/handle/11111/60785
dc.identifier.urnURN:NBN:fi-fe2026051847874
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.rights.accessrightsavoin
dc.subjectOWASP ASVS
dc.subjectSTIG
dc.subjectcyber security
dc.subjectdocument generation
dc.subjectdocument pipeline security
dc.subjectERP integration
dc.subjectCCM
dc.subjectpenetration testing
dc.subjectsecurity hardening
dc.subjectDocOrigin
dc.titleDocument Generation Security Assessment - A DocOrigin Case Study
dc.type.ontasotfi=Diplomityö|en=Master's thesis|

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
Tamminen_Thesis.pdf
Size:
688.43 KB
Format:
Adobe Portable Document Format