Jump to content

Interactive application security testing

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by Aostyen (talk | contribs) at 11:28, 8 November 2022. The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Interactive application security testing (IAST for short) is a security testing method that detects software vulnerabilities by interaction with the program coupled with observation and sensors.[1][2] It is distinct from static application security testing, which does not interact with the program, and dynamic application security testing, which considers the program as a black box. It may be considered a mix of both.[3]

References

  1. ^ "OWASP DevSecOps Guideline - v-0.2 | OWASP Foundation". Owasp.org.
  2. ^ "What is IAST: Interactive Application Security Testing". www.softwaretestinghelp.com.
  3. ^ Aaron Walker (August 14, 2019). "SAST vs. DAST: Application Security Testing Explained". www.g2.com. Archived from the original on 2022-07-20.