The article analyzes modern methods and tools used for security testing of web applications. The prevalence of security violations of web applications and the importance of their prevention made security testing an integral part of the software development life cycle (SDLC), which should detect vulnerabilities associated with providing a holistic approach to protecting the program from hacker attacks, viruses, unauthorized access to confidential data. To identify security vulnerabilities, there are various security testing tools, among which the popular ones are: static and dynamic application security testing (SAST and DAST), interactive application security testing (IAST), software composition analysis (SCA), runtime application self-protection (RASP), web application firewalls (WAF), cloud security posture management (CSPM). Analysis of modern security testing tools showed that they all have their advantages and disadvantages due to the specifics of their organization. Combining and using the advantages of each of them can ensure a high level of security for a web software product. Possible issues related to the web testing aspect of security are cracked or untrusted passwords,
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً