Application Security Testing - A New Approach
Old & New - Buildings & Security

Application Security Testing - A New Approach

My fourth and most significant e-Book has been published by EuroSTAR Testing Conferences. If you have any interest in security or DevOps I urge you to read this: EuroSTAR e-Book on a new approach to Application Security

Application Security is a broad and deep topic that few Testers or Developers ever master. Static and dynamic analysis vulnerability detection tools are proven to be appallingly inaccurate. Specialised hands-on security testing tools require intensive effort by skilled experts who remain in short supply.

Thoroughly security testing a web application presents extreme challenges to the delivery date and to the scope of test coverage. The shift to Agile and DevOps can exacerbate the conflict between security and timely delivery if conventional tools and techniques are retained from sequential project development methodologies.

A new approach to Application Security has arrived that turns our traditional testing model inside-out. Now we can integrate security tools with the code and components inside applications. Instead of scanning and probing an application from the outside, we can make security attributes report out to us from inside the application itself. Security becomes part of the code and operates in continuous real-time.

The results in terms of speed and accuracy astonished my team and I in 2016 when we implemented the first UK real-time security instrumentation.  Read the free EuroSTAR e-Book here.

Daragh Murphy

Senior Engineer, Product Marketing

8 年

You can read about Declan's new approach to Application Security Testing Here - https://huddle.eurostarsoftwaretesting.com/download-application-security-testing-new-approach/

回复

要查看或添加评论,请登录

Declan O'Riordan的更多文章

  • SPEED!

    SPEED!

    Bitcoin is now creating and testing potential solutions to complicated problems beyond 74,548,542,000,000,000 times per…

    3 条评论
  • Risk - an introduction to advanced assessment, and the Top-Ten mistakes.

    Risk - an introduction to advanced assessment, and the Top-Ten mistakes.

    For every difficult risk assessment, there is an answer which is clear, concise, and wrong. The Root of the word Risk…

  • The Assertive Tester

    The Assertive Tester

    Recently I realised the Assertive Tester e-book I wrote for the BCS SIGiST and EuroSTAR Testing conference in 2014 was…

    4 条评论
  • The 22nd Testing Retreat

    The 22nd Testing Retreat

    The Testing Retreat is an opportunity for a dozen or so notable Testers to spend time together from Friday until Monday…

    1 条评论
  • BA - What just happened?

    BA - What just happened?

    From the IT rumour mill: Allegedly, staff at the data centre were told to apply some security fixes to the BA…

    11 条评论
  • WannaCrypt, some details

    WannaCrypt, some details

    The WannaCrypt / Wcry attackers obtained a set of stolen NSA tools from a dump by 'The Shadow Brokers' a group with a…

    7 条评论
  • Ransomware at a glance

    Ransomware at a glance

    Ransomware is a towering giant among crime-ware incidents, but crime-ware is still a minnow when it comes to data…

    1 条评论
  • UKSTAR is now accepting proposals!

    UKSTAR is now accepting proposals!

    EuroSTAR has invited Dot Graham, James Lyndsay, and myself to host a premier Testing conference at County Hall in…

  • My 3rd eBook: Application Security Testing - What Testers Can Do!

    My 3rd eBook: Application Security Testing - What Testers Can Do!

    Don't stand back and watch Rome burn, click the EuroSTAR Test Huddle link and save society! Test Huddle Book

    1 条评论
  • My 2nd e-book: The Assertive Tester

    My 2nd e-book: The Assertive Tester

    Published by EuroSTAR today: https://testhuddle.com/resource/the-assertive-tester/ Passive behaviour is a factor leading…

    2 条评论

社区洞察

其他会员也浏览了