#[[Security]] #[[Testing]]

DAST

Dynamic Application Security Testing

#Security #Testing

稼働中のアプリケーションに対して外部から攻撃シミュレーションを行い、セキュリティ脆弱性を検出するテスト手法

  • DevSecOpsの継続的セキュリティテストを担い、認証、セッション管理、入力検証などランタイムの脆弱性を検出する
  • 検出結果を SARIF 形式で出力するツールも多い

owasp.org https://owasp.org/www-project-devsecops-guideline/latest/02b-Dynamic-Application-Security-Testing

neighbourhood

DevSecOps DevSecOps SARIF SARIF Aikido Security/Platform Platform DAST

backlinks · 2

links · 2