पाठ 22 / 25

Security Testing

SAST, DAST, SCA and pentests.

Layers of automated and manual testing

SAST (static analysis, such as Semgrep or CodeQL) finds risky code patterns before running it. SCA finds vulnerable dependencies. DAST (dynamic testing, such as OWASP ZAP) probes a running application for issues like missing headers and injection. Secret scanning catches leaked credentials. Automated tests for authorisation rules catch access control regressions. Periodic penetration tests and bug bounty programmes find business-logic flaws automation misses. Test only systems you own or are authorised to test.

Security as a habit

Testing, review, error handling and a checklist make security part of everyday engineering.

Four ideas: security testing, exceptional conditions, code review, checklist.
Figure 8.1 — Testing, error handling, review and checklist.

Security checks in a pipeline

An example stage list.

on every pull request:
  - SAST (Semgrep / CodeQL) on changed code
  - dependency scan (npm audit / pip-audit / Trivy)
  - secret scan (gitleaks)
  - unit + authorisation tests (user A cannot read user B's data)
nightly / pre-release:
  - DAST baseline scan (OWASP ZAP) against staging
  - container image scan; IaC scan
periodically:
  - penetration test; threat model review for new features

Triage findings, do not just collect them

Assign owners and deadlines by severity; a growing pile of ignored findings is a risk in itself.

त्वरित जाँच: What does DAST test?

  • Only passwords
  • Source code without running it
  • Only dependencies
  • A running application, from the outside
Answer

A running application, from the outside — Dynamic application security testing.