Products
Features
YouTube Video Summarizer
Summarize YouTube videos
Web & PDF Highlighter
Highlight web pages & PDFs
Chat with PDF
Ask any PDF questions with AI
Ask AI Clone
Chat with your highlights & memories
Audio Transcriber
Transcribe audio files to text
Glasp Reader
Read and highlight articles
Kindle Highlight Export
Export your Kindle highlights
Idea Hatch
Hatch ideas from your highlights
Integrations
Obsidian Plugin
Notion Integration
Pocket Integration
Instapaper Integration
Medium Integration
Readwise Integration
Snipd Integration
Hypothesis Integration
Apps & Extensions
Chrome Extension
Safari Extension
Edge Add-ons
Firefox Add-ons
iOS App
Android App
Discover
Discover
Ideas
Discover new ideas and insights
Articles
Curated articles and insights
Books
Book recommendations by great minds
Posts
Essays and notes from readers
Quotes
Inspiring quotes collection
Videos
Curated videos and summaries
Explore Glasp
Glasp Newsletter
Weekly insights and updates
Glasp Talk
Interview series with great minds
Glasp Blog
Latest news and articles
Glasp Use Cases
Learn how others use Glasp
Build & Support
Glasp API
Access Glasp's API for developers
MCP Connector
Connect Glasp to Claude & ChatGPT
Community
Glasp Reddit Community
Students
Student discount and benefits
FAQs
Frequently Asked Questions
AboutPricing
DashboardLog inSign up

How to select between SAST, DAST, IAST, RASP, and AST Abraham Kang

5.1K views
•
November 4, 2021
by
OWASP Foundation
YouTube video player
How to select between SAST, DAST, IAST, RASP, and AST Abraham Kang

TL;DR

Understand the importance of evaluating scanning tools based on supported languages, frameworks, and architectures, as well as their integration with the CI/CD pipeline and developer/QA buy-in.

Transcript

arcsan is now digital.ai join us at our booth in the virtual expo hall to learn how our app protection white box cryptography and threat analytics solutions can help you stay ahead of the evolving threat landscape welcome today i'm going to help you navigate this alphabet soup of scanning tools sas das isd rasp and asd first i want to start by than... Read More

Key Insights

  • 🗯️ Understanding the specific languages, frameworks, and architectures being scanned is crucial for selecting the right scanning tool and optimizing vulnerability detection.
  • 😀 Involving developers and QA staff in the tool selection process enhances buy-in, integration, and overall app security.
  • 👨‍💻 Different scanning tools have various strengths and weaknesses, such as false positives, false negatives, language and framework support, and code coverage capabilities.
  • 🐛 Integrating scanning tools with the CI/CD pipeline and bug tracking systems streamlines the security process and enables early vulnerability identification and remediation.
  • 👨‍💼 Custom rules and manual code review may be necessary for niche languages, frameworks, or specific business logic vulnerabilities.
  • 🥳 Software composition analysis tools focus on identifying vulnerabilities in third-party libraries but may generate false positives without examining usage in the code.
  • 🧑‍🏭 When evaluating scanning tool vendors, consider factors such as true and false positives and negatives, integration capabilities, vulnerability explanations, and business logic support.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why is it important to understand the specific languages and frameworks being scanned?

Each scanning tool has different capabilities and limitations when it comes to scanning different languages and frameworks, so understanding compatibility ensures accurate vulnerability detection and prevention.

Q: How does involving developers and QA staff in the selection process benefit app security?

Involving developers and QA staff ensures their buy-in and comfort with the selected tool, leading to higher confidence in the results and greater willingness to address reported vulnerabilities.

Q: What are the advantages and disadvantages of static analysis tools?

Static analysis tools can provide decent results for supported languages with all the source code, but they struggle with scanning through binaries, have a high number of false positives, and depend heavily on rule coverage and language support.

Q: How does dynamic application security testing (DAST) differ from other scanning tools?

DAST can detect vulnerabilities across the entire server pipeline, making it effective for finding vulnerabilities that other tools may miss. However, it may result in false positives and has limitations in correctly identifying vulnerabilities.

Key Insights:

  • Understanding the specific languages, frameworks, and architectures being scanned is crucial for selecting the right scanning tool and optimizing vulnerability detection.
  • Involving developers and QA staff in the tool selection process enhances buy-in, integration, and overall app security.
  • Different scanning tools have various strengths and weaknesses, such as false positives, false negatives, language and framework support, and code coverage capabilities.
  • Integrating scanning tools with the CI/CD pipeline and bug tracking systems streamlines the security process and enables early vulnerability identification and remediation.
  • Custom rules and manual code review may be necessary for niche languages, frameworks, or specific business logic vulnerabilities.
  • Software composition analysis tools focus on identifying vulnerabilities in third-party libraries but may generate false positives without examining usage in the code.
  • When evaluating scanning tool vendors, consider factors such as true and false positives and negatives, integration capabilities, vulnerability explanations, and business logic support.
  • Calculating return on investment involves weighing the tool's effectiveness, developer/QA trust, integration capabilities, and standardized handling of business logic vulnerabilities.

Summary & Key Takeaways

  • Evaluating scanning tools requires understanding the specific languages, frameworks, and architectures being scanned, as different tools have varying limitations and capabilities.

  • Consider common characteristics of scanning tools, such as the number of rules, the type of vulnerabilities covered, and the level of language and framework support.

  • Integration with the CI/CD pipeline and involving developers and QA staff in the tool selection process enhances security and ensures efficiency in finding and fixing vulnerabilities.


Read in Other Languages (beta)

English

Share This Summary 📚

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator

Apps & Extensions

  • Chrome Extension
  • Safari Extension
  • Edge Add-ons
  • Firefox Add-ons
  • iOS App
  • Android App

Key Features

  • YouTube Video Summarizer
  • Web & PDF Summarizer
  • Web & PDF Highlighter
  • Chat with PDF
  • Ask AI Clone
  • Audio Transcriber
  • Glasp Reader
  • Kindle Highlight Export
  • Idea Hatch

Integrations

  • Obsidian Plugin
  • Notion Integration
  • Pocket Integration
  • Instapaper Integration
  • Medium Integration
  • Readwise Integration
  • Snipd Integration
  • Hypothesis Integration

More Features

  • APIs
  • MCP Connector
  • Blog & Post
  • Embed Links
  • Image Highlight
  • Personality Test
  • Quote Shots

Company

  • About us
  • Blog
  • Community
  • FAQs
  • Job Board
  • Newsletter
  • Pricing
Terms

•

Privacy

•

Guidelines

© 2026 Glasp Inc. All rights reserved.