Тёмный

SAST vs DAST vs IAST vs RASP vs SCA | App Security | Comparison between SAST, DAST, IAST, RASP, SCA 

CyberPlatter
Подписаться 12 тыс.
Просмотров 4 тыс.
50% 1

This video provides a comparison between the following application security practices:
SAST - Static Application Security Testing
DAST - Dynamic Application Security Testing
IAST - Interactive Application Security Testing
RASP - Realtime Application Self Protection
SCA - Software Composition Testing
Software Composition Analysis (SCA): • Software Composition A...
Cyber Security Interview Questions and Answers Playlist: • CyberSecurity Intervie...
Subscribe here: / @cyberplatter8980
CyberPlatter Discord Channel: / discord
Application Security Testing

Опубликовано:

 

12 дек 2023

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 7   
@arnaudfrancktaptuekuate5367
@arnaudfrancktaptuekuate5367 3 месяца назад
Nice thank you for this video
@erikklein7352
@erikklein7352 Месяц назад
Your brief summary is very helpful for introducing these approaches to people. I used it for upleveling my team's knowledge today. Your SCA description easily and accurately describes scan-based SCA solutions. Your IAST description does a good job of describing Active IAST (DAST invoked). Your RASP description is quite accurate and can additionally be used to describe Passive IAST (normal functional usage invoked). Certain vendors (e.g. Dynatrace) have Runtime SCA, Passive IAST, and RASP implementations that are made for production usage with less than 1% overhead ... Runtime SCA reduces Scan-based SCA false positives by up to 85% and reprioritizes the remaining 15% based on the manner in which the vulnerable part of the library code executes and is reachable ... when used in production, Passive IAST reduces false negatives significantly over pre-production Passive and Active IAST ... and RASP that alerts only when a well-formed attack reaches a vulnerable line of code reduces false positive alarms by over 99.9%. Happy to chat more if you wish. www.linkedin.com/in/eriknklein/
@sarfarazmahmood2158
@sarfarazmahmood2158 2 месяца назад
Thanks for the informative video
@cyberplatter8980
@cyberplatter8980 2 месяца назад
Glad it was helpful!
@Yogi-dc4nw
@Yogi-dc4nw 6 месяцев назад
Good👍👍👍
@cyberplatter8980
@cyberplatter8980 6 месяцев назад
Thank you!
@sakshatbhardwaj8041
@sakshatbhardwaj8041 11 дней назад
There is no link for SAST or DAST ?
Далее
What is DevSecOps?
10:48
Просмотров 22 тыс.
SAST, DAST, IAST, RASP Explained
10:09
Просмотров 6 тыс.
What is SAST? | AppSec 101
22:51
Просмотров 4,1 тыс.
98% Cloud Cost Saved By Writing Our Own Database
21:45
Просмотров 315 тыс.
Contrast Security Demo & Overview
59:41
Просмотров 10 тыс.
2017 OWASP Top 10: Broken Access Control
9:58
Просмотров 83 тыс.