22 July 2012

Web Application Security Scanner Comparison

Testing for vulnerabilities is just one part of a wider secure software development life cycle. While manual testing has great value, the use of automated tools is necessary to assist with anything but the smallest of applications. But which tools should you use?

Images from the DAST comparison showing the ticks and crosses in a feature chart on the website sectoolmarket.com

The results of a comparison of dynamic web application vulnerability scanners has just been published by Shay Chen. 2012 Web Application Scanner Benchmark updates a similar study undertaken in 2011 and compares ten different aspects of the tools.

The analysis examined 11 commercial tools and a slightly larger number of maintained free/open source tools and provides a superb reference for anyone undertaking a selection process. The results are presented in a dozen web pages at http://sectoolmarket.com/.

Of course what matters is the coverage, false negative rate, false positive rate and the features you need for your own style of applications.

See also the comparative studies in the other papers referenced, but especially Analyzing the Accuracy and Time Costs of Web Application Security Scanners, Larry Suto, February 2010 (and discussion/responses) and the SAMATE bibliography.

Posted on: 22 July 2012 at 15:06 hrs

Comments Comments (2) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

It's good to go one step beyond simply comparing security scanners and actually making sure you don't become overly dependent on automatic scanners. Relying too much on automatic scanners can be potentially damaging to your app's security as you may miss vital clues: http://blog.port80software.com/2012/08/09/heavily-...
1 Added by Port80 Software Posted on 13 August 2012 at 18:56 hrs
The paper "Why Johnny Can't Pentest", referred to in the blog post (linked in the above comment) is from 2009, and is available at http://www.cs.ucsb.edu/~adoupe/static/black-box-sc...
2 Added by Clerkendweller Posted on 13 August 2012 at 20:45 hrs
Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Web Application Security Scanner Comparison
http://www.clerkendweller.com/2012/7/22/Web-Application-Security-Scanner-Comparison
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2012/7/22/Web-Application-Security-Scanner-Comparison
Requested by 184.72.91.94 on Friday, 24 May 2013 at 00:09 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2012-2013 clerkendweller.com