Interactive application security testing
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
top
Interactive application security testing (abbreviated as IAST)cite-ref-1[1] is a security testing method that detects software vulnerabilities by interaction with the program coupled with observation and sensors.cite-ref-2[2]cite-ref-3[3] The tool was launched by several application security companies.cite-ref-janca2020-4-0[4] It is distinct from static application security testing, which does not interact with the program, and dynamic application security testing, which considers the program as a black box. It may be considered a mix of both.cite-ref-5[5]
References
cite-note-22. ↑ "OWASP DevSecOps Guideline - v-0.2 | OWASP Foundation". Owasp.org.
cite-note-33. ↑ "What is IAST: Interactive Application Security Testing". www.softwaretestinghelp.com.
cite-note-55. ↑ citerefaaron-walker2019Aaron Walker (August 14, 2019). "SAST vs. DAST: Application Security Testing Explained". www.g2.com. Archived from the original on 2022-07-20.