Interactive Application Security Testing (IAST): Bridging the Gap Between SAST and DAST
Keywords:
IAST, SAST, DAST, application security, vulnerability detection, software testing, real-time analysis, security automationAbstract
With the increasing threats in the digital landscape, securing software applications is a critical requirement for organizations. Traditional security testing methods such as Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) have been used for identifying vulnerabilities in applications, but they each have their limitations. Interactive Application Security Testing (IAST) is a new approach that combines the strengths of both SAST and DAST, providing real-time insights into vulnerabilities during runtime without the need for a full application scan. This manuscript explores IAST as a bridge between SAST and DAST, addressing their individual shortcomings while enhancing the accuracy and speed of application security testing. We analyze the methodology, implementation, statistical analysis, results, and the future potential of IAST in the realm of software security.




