Comparative evaluation of approaches & tools for effective security testing of Web applications

Sana Qadir1, Eman Waheed1, Aisha Khanum1

  • 1Faculty of Computing, National University of Sciences & Technology, Islamabad, Pakistan.

PubMed
Summary

Dynamic and static application security testing (SAST and DAST) effectiveness varies by vulnerability type. DAST excels in certain OWASP categories, while SAST is crucial for high-severity flaws, with specific tools showing superior performance.

Related Concept Videos

Multiple Comparison Tests01:13

Multiple Comparison Tests

Multiple comparison test, abbreviated as MCT, is a post hoc analysis generally performed after comparing multiple samples with one or more tests. An MCT will help identify a significantly different sample among multiple samples or a factor among multiple factors.
It would be easy to compare two samples using a significance alpha level of 0.05. In other words, there is only one sample pair to be compared. However, it would be difficult to identify a significantly different sample if the number...
4.0K
Reliability and Validity01:29

Reliability and Validity

Reliability and validity are two important considerations that must be made with any type of data collection. Reliability refers to the ability to consistently produce a given result. In the context of psychological research, this would mean that any instruments or tools used to collect data do so in consistent, reproducible ways.
13.2K
Quality Assurance01:19

Quality Assurance

Quality assurance is the overarching term used to describe the activities employed to ensure the proper performance of a system. These activities can be classified into three categories: quality control, quality assessment, and internal corrective measures. Typically, these activities work cyclically: quality control is performed before and during the analysis, while quality assessment occurs during and after the investigation. Internal corrective measures are implemented based on the findings...
208
Non-destructive Tests for Concrete Strength01:12

Non-destructive Tests for Concrete Strength

The rebound hammer test, also known as the Schmidt hammer test, is a non-destructive technique for evaluating the hardness of concrete and, indirectly, the strength of concrete. It operates on the principle that the rebound of a spring-driven mass from a concrete surface correlates to the surface's hardness. The device comprises a mass within a tubular housing, a spring mechanism, and a plunger that strikes the concrete. Upon release, the energy imparted to the mass by the spring causes it...
195
Testing Water Quality01:14

Testing Water Quality

When the quality of water for concrete preparation is uncertain, its impact on the setting time of cement and compressive strength of mortar is assessed by comparison with de-ionized or distilled water benchmarks. American Society for Testing and Materials (ASTM) C1602 requires the setting times to be within 90 minutes of the control, British Standard (BS) 3146:1980 allows a 30-minute variance in the initial setting, while British Standards European Norm (BS EN) 1008 specifies initial setting...
191
Development of Analytical Methods01:21

Development of Analytical Methods

An analytical methodology can be divided into four sequential steps: technique, method, procedure, and protocol. A technique is a scientific principle that rationalizes a specific phenomenon through chemical measurements. Adapting a technique for analyzing a sample of interest is termed a method. The procedure outlines the directions for performing the analysis via an analytical method. The protocol is the detailed guidelines on the procedure, which should be strictly followed to obtain the...
731