Slide 30
Slide 30 text
Analysis Tools
Static app security testing (SAST)
Dynamic app security testing (DAST)
− White-box testing evaluating static inputs
− documentation
− source code
− 3rd party dependencies
− Integrated into CI/CD pipelines
− SonarQube, Fortify, Veracode, MobSF,…
− Black-box approach (no knowledge of software)
− Input/output analysis on running app
− Frida, Charles, mitmproxy,…