Application security, DevSecOps, Vulnerability Management
How to tune out AppSec noise through DAST

Credit: Getty Images
Application security testing can create a huge number of false-positive alerts, but is there a way for development teams to avoid these distractions? There are indeed methods for making the process of testing applications less "noisy" without compromising security.Modern approaches to dynamic application security testing (DAST) have made significant improvements over the first generation of DAST tools, as well as over the static application security testing (SAST) tools still in use. In this breakdown, we’ll be covering areas of weakness in SAST and in older DAST tools — and how newer solutions can separate the signal from the noise in application security testing.
How false positives during app testing create extra work. Credit: InvictiMore significantly, 68% of respondents said they ignored potential vulnerabilities flagged during testing at least once a week, while 97% said that at least once a month, they dismissed false positives that later turned out to be real vulnerabilities.This highlights a real problem: The volume of false positives generated by SAST and legacy DAST tools could undermine app security testing altogether."As developers and testers lose confidence in a vulnerability scanner that generates mostly false alarms, they might start routinely ignoring whole classes of issues from this tool," said a recent Invicti white paper. "Sooner or later, someone will start ticking boxes just to make the errors go away."
True vulnerabilities may require less work than false positives. Credit: InvictiNot every flagged vulnerability can be tested by the DAST tool, so developers and app testers will still have to chase some down. But proof-based scanning greatly cuts down the number of false positives, reducing the noise around app testing and letting security staffers focus on the real threats.Invicti's DAST tool, which performs proof-based scanning, incorporates IAST so that apps can be tested from the "inside out" as they run, giving DevSecOps teams more insight and accuracy. Invicti's tool can also run 24/7 and runtime-test bits of code earlier in the software development life cycle."When you have a DAST platform that actually does what it says on the tin and delivers on the promises of speed, accuracy, and integration," said Invicti's Banach, "you can automate the testing process to launch full or partial scans when you want and how you want."
An In-Depth Guide to Application Security
Get essential knowledge and practical strategies to fortify your applications.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds