Skip to main content

Reimagining DAST: Integrating ZAProxy into Web Testing

25-minute Talk

This combination of DAST and web testing will empower testing teams to perform strong, dynamyc security analysis easily. Follow this talk to make your products under test safe!

Deep Dive session

Timetable

11:45 a.m. – 12:30 p.m. Wednesday 26th

Room

Room D5 - Track 8: Security Testing Deep Dive

Continuous Integration/Continuous Delivery (CI/CD) Security Testing Test Automation

Audience

Tester, Manager, Developer, DevOps..

Key-Learnings

  • DAST (Dynamic Application Security Testing)
  • Cybersecurity
  • SSDCL (Secure Software Development Life Cycle)

One of the most challenging phases within the Secure Software Development Life Cycle (SSDLC) is the implementation of Dynamic Application Security Testing (DAST). In this talk, we propose a new vision to address this critical phase, transforming it into a more efficient and accessible process by integrating it directly with the web tests developed by software quality teams.

The need for a robust dynamic security testing process that can be easily adopted by software quality teams has been the driving force behind this research. For this purpose, two key concepts are merged: automated web testing and the dynamic security testing tool ZAProxy. Typically, the configuration process of dynamic analysis tools requires prior analysis of URLs to be attacked and configuration of authentication processes, among other things.

However, in this talk we propose a different approach allowing ZAProxy to connect directly to the browser where the tests are executed. This approach has several advantages like analysis by functionality, simplicity, prevention.

Finally, in the last part of the talk, we will compare the results obtained using the traditional approach (spidering URLs with the tool) with the results obtained by running web tests with Selenium and ZAProxy, both in passive and active analysis. The goal is to consolidate all the proposed concepts and demonstrate that an alternative approach to dynamic security testing is not only feasible, but also more efficient and practical.

Related Sessions

Deep Dive session
Wed, Nov 26 • 11:45 a.m. – 12:30 p.m.
Room D1+D2 - Track 6: Test Automation Deep Dive

25-minute Talk

Test Automation

Virtual Pass session
Thu, Nov 27 • 4:00 p.m. – 4:45 p.m.
Room F1 - Track 1: Talks

25-minute Talk

Coding for Testers Collaboration & Communication Test Automation

Mon, Nov 24 • 8:30 a.m. – 4:30 p.m.
F-,E- & D-Rooms

Full-Day Tutorial (6 hours)

Testability Test Automation

Deep Dive session
Tue, Nov 25 • 2:45 p.m. – 4:45 p.m.
Room D5 - Track 8: Security Testing Deep Dive

120-minute Workshop

Security Testing