SlideShare a Scribd company logo
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.1
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.2
Market Overview – Application Security
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.3
The CA Veracode Portfolio
Code Commit Build Test Release Deploy Operate
CA Veracode Greenlight CA Veracode Static Analysis
CA Veracode Dynamic Analysis
CA Veracode Software Composition Analysis
Developer Training
Application Security Consulting
Security Program Management
CA Veracode Manual Penetration Testing
CA Veracode Discovery
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.4
What is DAST?
Crawls
Audits
Reports
A Dynamic Application Security Testing (DAST)
solution will crawl the web app and inventory a
series of links
DAST then audits each link found by the
automated crawler.
If the audit phase identifies a vulnerability, it is
reported to the Veracode Platform for
verification/scrubbing.
Crawling and auditing occur at the same time.
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.5
What does DAST find?
• Dynamic Analysis has the ability to capture exploitable
issues at run-time such as certification issues, server
configuration, deployment issues, etc. which Static
Analysis is not able to capture.
• These run-time issues can include vulnerabilities that
may only be found because the web interface interacts
with a web service and the dynamic link between these
two software layers results in a vulnerability when
analyzed as one entity.
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.6
Survey Demographics – DAST Use Cases
• How do you use your DAST
solution today?
Years in AppSec Count Percent
Occasional scans in a pre-
production environment
8 27.6%
Regular scans in a pre-
production environment
19 65.6%
To discover all websites owned
by my organization
4 13.8%
Occasional scans in a
production environment
8 27.6%
Regular scans in a production
environment
10 34.5%
0.0%
10.0%
20.0%
30.0%
40.0%
50.0%
60.0%
70.0%
Occasional
scans in a pre-
production
environment
Regular scans
in a pre-
production
environment
To discover all
websites
owned by my
organization
Occasional
scans in a
production
environment
Regular scans
in a production
environment
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.7
CA Veracode Web Application Scanning
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.8
CA Veracode Dynamic Analysis
Automation Easy to Onboard & Scale Quality of Results
• Scheduling Automation
Recurring Scanning
• IT Maintenance Window
Automation – Automated
Pause & Resume
• Scan Stop
• Time Savings – less time
managing
• All you need is a URL
• Batch Upload Configuration
• Batch Scanning
• Concurrent Scanning
• Security Program
Management
• Time Savings – less time
spent configuring
• Broad Coverage of Apps
incl. Single Page Apps
• Breadth of CWEs
• Low FP Rate
• Actionable Results
• Remediation Consultation
• Time Savings – faster
remediation
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.9
Automate Your Scans
• Scheduling Automation
Recurring Scanning
• IT Maintenance Window
Automation – Automated
Pause & Resume
• Scan Stop
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.10
Easy to Onboard & Scale
• All you need is a URL
• Batch Upload Configuration
• Batch Scanning
• Concurrent Scanning
• Security Program
Management
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.11
High Quality of Results
• Broad Coverage of Apps
incl. Single Page Apps
• Breadth of CWEs
• Low FP Rate
• Actionable Results
• Remediation Consultation
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.12
• Remediation Consultation – Provide guidance in understanding
the results
• Security Program Management – Setup and help manage an
AppSec program
• Operational Assistance
– Login Script Assistance
– False Positive Removal
Dynamic Analysis Services
SERVICES
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.13
Closing Thoughts
• DAST Scanning is an integral part of a well rounded
Application Security program and covers applications in
pre-prod and production (runtime) environments.
• DAST Scanning helps ensure the continued security of your
applications and finds exploitable vulnerabilities that static
testing alone cannot find.
• DAST solutions should provide users with automation, ease of
onboarding, scalability, speed, and coverage.
© 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.14
LEARN MORE
KEEP THE CONVERSATION GOING!
Join the Veracode Community
https://community.veracode.com
Web Application (Dynamic) Scanning Group

More Related Content

PDF
Deploy + Destroy Complete Test Environments
PDF
8 Patterns For Continuous Code Security by Veracode CTO Chris Wysopal
PDF
Automating OWASP Tests in your CI/CD
PDF
Addressing the Challenges of Mobile Test Automation
PPTX
Succeeding-Marriage-Cybersecurity-DevOps final
PDF
Scale DevSecOps with your Continuous Integration Pipeline
PDF
Running a High-Efficiency, High-Visibility Application Security Program with...
PDF
The DevOps Challenge: Open Source Security at Scale
Deploy + Destroy Complete Test Environments
8 Patterns For Continuous Code Security by Veracode CTO Chris Wysopal
Automating OWASP Tests in your CI/CD
Addressing the Challenges of Mobile Test Automation
Succeeding-Marriage-Cybersecurity-DevOps final
Scale DevSecOps with your Continuous Integration Pipeline
Running a High-Efficiency, High-Visibility Application Security Program with...
The DevOps Challenge: Open Source Security at Scale

What's hot (20)

PPTX
Continuous Delivery Pipeline in the Cloud – How to Achieve Continous Everything
PPTX
DevSecOps-OWASP Indonesia Day 2017
PDF
Evolving from Automated to Continous Testing for Agile and DevOps
PDF
Embrace DevSecOps and Enjoy a Significant Competitive Advantage!
PDF
ThreadFix and SD Elements Unifying Security Requirements and Vulnerability Ma...
PDF
Rx for FDA Software Compliance
PDF
DevSecOps - Building continuous security into it and app infrastructures
PPTX
Accelerate Web and Mobile Testing for Continuous Integration and Delivery
PDF
SecDevOps: afaste-se dos ciberataques sem complicar o dia a dia dos desenvolv...
PDF
Veracode - Overview
PDF
Practical appsec lessons learned in the age of agile and DevOps
PDF
EuroSPI 2016 - Software Safety and Security Through Standards
PPTX
O'Reilly Webcast: How Nordstrom Prepares Its Site for Holidays and Major Events
PDF
Synopsys Security Event Israel Presentation: Making AppSec Testing Work in CI/CD
PDF
2021 Open Source Governance: Top Ten Trends and Predictions
PDF
Scale DevSecOps with your Continuous Integration Pipeline
PDF
AppSec Fast and Slow: Your DevSecOps CI/CD Pipeline Isn’t an SSA Program
PDF
From rogue one to rebel alliance by Peter Chestna
PDF
Driving Risks Out of Embedded Automotive Software
PDF
Devops: Security's big opportunity by Peter Chestna
Continuous Delivery Pipeline in the Cloud – How to Achieve Continous Everything
DevSecOps-OWASP Indonesia Day 2017
Evolving from Automated to Continous Testing for Agile and DevOps
Embrace DevSecOps and Enjoy a Significant Competitive Advantage!
ThreadFix and SD Elements Unifying Security Requirements and Vulnerability Ma...
Rx for FDA Software Compliance
DevSecOps - Building continuous security into it and app infrastructures
Accelerate Web and Mobile Testing for Continuous Integration and Delivery
SecDevOps: afaste-se dos ciberataques sem complicar o dia a dia dos desenvolv...
Veracode - Overview
Practical appsec lessons learned in the age of agile and DevOps
EuroSPI 2016 - Software Safety and Security Through Standards
O'Reilly Webcast: How Nordstrom Prepares Its Site for Holidays and Major Events
Synopsys Security Event Israel Presentation: Making AppSec Testing Work in CI/CD
2021 Open Source Governance: Top Ten Trends and Predictions
Scale DevSecOps with your Continuous Integration Pipeline
AppSec Fast and Slow: Your DevSecOps CI/CD Pipeline Isn’t an SSA Program
From rogue one to rebel alliance by Peter Chestna
Driving Risks Out of Embedded Automotive Software
Devops: Security's big opportunity by Peter Chestna
Ad

Similar to Shifting Left…AND Right to Ensure Full Application Security Coverage (20)

PPTX
Veracode - Inglês
PPTX
The Dynamic Application Security Testing Process A Step-by-Step Guide.pptx
PPTX
The Dynamic Application Security Testing Process: A Step-by-Step Guide
PPTX
Secure Code review - Veracode SaaS Platform - Saudi Green Method
PDF
Veracode Corporate Overview - Print
PDF
Efficient Security Development and Testing Using Dynamic and Static Code Anal...
PPTX
[OPD 2019] AST Platform and the importance of multi-layered application secu...
PDF
SAST vs. DAST: What’s the Best Method For Application Security Testing?
PDF
How to Integrate AppSec Testing into your DevOps Program
PDF
Web Application Security Testing (1).pptx.pdf
PDF
The CA Technologies | Veracode Platform: A 360-Degree View of Your Applicatio...
PPTX
Leverage DevOps & Agile Development to Transform Your Application Testing Pro...
PDF
Leverage DevOps & Agile Development to Transform Your Application Testing Pro...
PPTX
Leverage DevOps & Agile Development to Transform Your Application Testing Pro...
PDF
Automated Pentesting vs Dynamic Application Security Testing
PDF
Automated pentesting vs dynamic application security testing (dast) (2)
PPTX
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
PPTX
Overcoming Challenges in Dynamic Application Security Testing (DAST)
PDF
Positive Technologies Application Inspector
PDF
Ast in CI/CD by Ofer Maor
Veracode - Inglês
The Dynamic Application Security Testing Process A Step-by-Step Guide.pptx
The Dynamic Application Security Testing Process: A Step-by-Step Guide
Secure Code review - Veracode SaaS Platform - Saudi Green Method
Veracode Corporate Overview - Print
Efficient Security Development and Testing Using Dynamic and Static Code Anal...
[OPD 2019] AST Platform and the importance of multi-layered application secu...
SAST vs. DAST: What’s the Best Method For Application Security Testing?
How to Integrate AppSec Testing into your DevOps Program
Web Application Security Testing (1).pptx.pdf
The CA Technologies | Veracode Platform: A 360-Degree View of Your Applicatio...
Leverage DevOps & Agile Development to Transform Your Application Testing Pro...
Leverage DevOps & Agile Development to Transform Your Application Testing Pro...
Leverage DevOps & Agile Development to Transform Your Application Testing Pro...
Automated Pentesting vs Dynamic Application Security Testing
Automated pentesting vs dynamic application security testing (dast) (2)
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
Overcoming Challenges in Dynamic Application Security Testing (DAST)
Positive Technologies Application Inspector
Ast in CI/CD by Ofer Maor
Ad

More from DevOps.com (20)

PDF
Modernizing on IBM Z Made Easier With Open Source Software
PPTX
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
PPTX
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
PDF
Next Generation Vulnerability Assessment Using Datadog and Snyk
PPTX
Vulnerability Discovery in the Cloud
PDF
A New Year’s Ransomware Resolution
PPTX
Getting Started with Runtime Security on Azure Kubernetes Service (AKS)
PDF
Don't Panic! Effective Incident Response
PDF
Creating a Culture of Chaos: Chaos Engineering Is Not Just Tools, It's Culture
PDF
Role Based Access Controls (RBAC) for SSH and Kubernetes Access with Teleport
PDF
Monitoring Serverless Applications with Datadog
PDF
Deliver your App Anywhere … Publicly or Privately
PPTX
Securing medical apps in the age of covid final
PDF
How to Build a Healthy On-Call Culture
PPTX
The Evolving Role of the Developer in 2021
PDF
Service Mesh: Two Big Words But Do You Need It?
PPTX
Secure Data Sharing in OpenShift Environments
PPTX
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
PDF
Elevate Your Enterprise Python and R AI, ML Software Strategy with Anaconda T...
PDF
Hotels, Hookups and Video Conferencing: A Top 10 Countdown to 2020's Worst Da...
Modernizing on IBM Z Made Easier With Open Source Software
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
Next Generation Vulnerability Assessment Using Datadog and Snyk
Vulnerability Discovery in the Cloud
A New Year’s Ransomware Resolution
Getting Started with Runtime Security on Azure Kubernetes Service (AKS)
Don't Panic! Effective Incident Response
Creating a Culture of Chaos: Chaos Engineering Is Not Just Tools, It's Culture
Role Based Access Controls (RBAC) for SSH and Kubernetes Access with Teleport
Monitoring Serverless Applications with Datadog
Deliver your App Anywhere … Publicly or Privately
Securing medical apps in the age of covid final
How to Build a Healthy On-Call Culture
The Evolving Role of the Developer in 2021
Service Mesh: Two Big Words But Do You Need It?
Secure Data Sharing in OpenShift Environments
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
Elevate Your Enterprise Python and R AI, ML Software Strategy with Anaconda T...
Hotels, Hookups and Video Conferencing: A Top 10 Countdown to 2020's Worst Da...

Recently uploaded (20)

PDF
Encapsulation theory and applications.pdf
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
A Presentation on Artificial Intelligence
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
Machine Learning_overview_presentation.pptx
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Machine learning based COVID-19 study performance prediction
PDF
A comparative analysis of optical character recognition models for extracting...
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Encapsulation theory and applications.pdf
NewMind AI Weekly Chronicles - August'25-Week II
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
A Presentation on Artificial Intelligence
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
The Rise and Fall of 3GPP – Time for a Sabbatical?
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Machine Learning_overview_presentation.pptx
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
The AUB Centre for AI in Media Proposal.docx
Unlocking AI with Model Context Protocol (MCP)
Machine learning based COVID-19 study performance prediction
A comparative analysis of optical character recognition models for extracting...
“AI and Expert System Decision Support & Business Intelligence Systems”
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Encapsulation_ Review paper, used for researhc scholars
Chapter 3 Spatial Domain Image Processing.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx

Shifting Left…AND Right to Ensure Full Application Security Coverage

  • 1. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.1
  • 2. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.2 Market Overview – Application Security
  • 3. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.3 The CA Veracode Portfolio Code Commit Build Test Release Deploy Operate CA Veracode Greenlight CA Veracode Static Analysis CA Veracode Dynamic Analysis CA Veracode Software Composition Analysis Developer Training Application Security Consulting Security Program Management CA Veracode Manual Penetration Testing CA Veracode Discovery
  • 4. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.4 What is DAST? Crawls Audits Reports A Dynamic Application Security Testing (DAST) solution will crawl the web app and inventory a series of links DAST then audits each link found by the automated crawler. If the audit phase identifies a vulnerability, it is reported to the Veracode Platform for verification/scrubbing. Crawling and auditing occur at the same time.
  • 5. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.5 What does DAST find? • Dynamic Analysis has the ability to capture exploitable issues at run-time such as certification issues, server configuration, deployment issues, etc. which Static Analysis is not able to capture. • These run-time issues can include vulnerabilities that may only be found because the web interface interacts with a web service and the dynamic link between these two software layers results in a vulnerability when analyzed as one entity.
  • 6. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.6 Survey Demographics – DAST Use Cases • How do you use your DAST solution today? Years in AppSec Count Percent Occasional scans in a pre- production environment 8 27.6% Regular scans in a pre- production environment 19 65.6% To discover all websites owned by my organization 4 13.8% Occasional scans in a production environment 8 27.6% Regular scans in a production environment 10 34.5% 0.0% 10.0% 20.0% 30.0% 40.0% 50.0% 60.0% 70.0% Occasional scans in a pre- production environment Regular scans in a pre- production environment To discover all websites owned by my organization Occasional scans in a production environment Regular scans in a production environment
  • 7. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.7 CA Veracode Web Application Scanning
  • 8. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.8 CA Veracode Dynamic Analysis Automation Easy to Onboard & Scale Quality of Results • Scheduling Automation Recurring Scanning • IT Maintenance Window Automation – Automated Pause & Resume • Scan Stop • Time Savings – less time managing • All you need is a URL • Batch Upload Configuration • Batch Scanning • Concurrent Scanning • Security Program Management • Time Savings – less time spent configuring • Broad Coverage of Apps incl. Single Page Apps • Breadth of CWEs • Low FP Rate • Actionable Results • Remediation Consultation • Time Savings – faster remediation
  • 9. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.9 Automate Your Scans • Scheduling Automation Recurring Scanning • IT Maintenance Window Automation – Automated Pause & Resume • Scan Stop
  • 10. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.10 Easy to Onboard & Scale • All you need is a URL • Batch Upload Configuration • Batch Scanning • Concurrent Scanning • Security Program Management
  • 11. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.11 High Quality of Results • Broad Coverage of Apps incl. Single Page Apps • Breadth of CWEs • Low FP Rate • Actionable Results • Remediation Consultation
  • 12. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.12 • Remediation Consultation – Provide guidance in understanding the results • Security Program Management – Setup and help manage an AppSec program • Operational Assistance – Login Script Assistance – False Positive Removal Dynamic Analysis Services SERVICES
  • 13. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.13 Closing Thoughts • DAST Scanning is an integral part of a well rounded Application Security program and covers applications in pre-prod and production (runtime) environments. • DAST Scanning helps ensure the continued security of your applications and finds exploitable vulnerabilities that static testing alone cannot find. • DAST solutions should provide users with automation, ease of onboarding, scalability, speed, and coverage.
  • 14. © 2017 VERACODE INC. A BUSINESS UNIT OF CA TECHNOLOGIES.14 LEARN MORE KEEP THE CONVERSATION GOING! Join the Veracode Community https://community.veracode.com Web Application (Dynamic) Scanning Group