SAST vs DAST vs IAST vs RASP vs SCA | App Security | Comparison between SAST, DAST, IAST, RASP, SCA — Transcript
Full transcript
- 0:00hey guys welcome back to cyber platter
- 0:02today we'll learn the difference between
- 0:04sast D iast rasp and sem if you want to
- 0:08know about these individual topics and
- 0:10we have different videos where I talk in
- 0:13detail about these testing methodologies
- 0:16I will link that in the description box
- 0:18you can go through them tast stands for
- 0:21static application security testing Das
- 0:25is dynamic application security testing
- 0:29iast is is interactive application
- 0:32security testing rasp is runtime
- 0:35application self- protection sea is
- 0:40software composition analysis all of
- 0:43these are different approaches to
- 0:45identifying and mitigating security
- 0:48vulnerabilities in software applications
- 0:51let's see the comparison now the first
- 0:54aspect of comparison is testing stage
- 0:57sast is static analysis and it is done
- 1:01pre- run time that is it analyzes the
- 1:04source code or binaries before the
- 1:07application is executed next is Das Das
- 1:11is dynamic analysis and it is done at
- 1:14runtime that is a test the application
- 1:17in a running State typically after the
- 1:20development and during the testing phase
- 1:24iast is hybrid approach that is it
- 1:27combines elements of both static that is
- 1:30pre- runtime and dynamic that is runtime
- 1:33testing rasp testing stage is at the
- 1:35runtime it operates during the
- 1:38application run time that is it operates
- 1:41during the application run time
- 1:43monitoring and protecting the
- 1:45application as it runs SCA is pre-run
- 1:49time that is it identifies
- 1:51vulnerabilities in third-party
- 1:53components before they are integrated
- 1:55into the code base next aspect of
- 1:58comparison is analysis is type sast is
- 2:01white box testing as it has full access
- 2:05to the applications code sast is Black
- 2:08Box testing as it examines the
- 2:10application externally like a hacker
- 2:13would iast is gray box testing it
- 2:17combines aspects of both white box and
- 2:19black box testing rasp it depends on the
- 2:23implementation that is it can be white
- 2:26box or Black Box depending on its
- 2:28implementation it can inspect code and
- 2:31respond to runtime threats sea is wibx
- 2:35testing it analyzes the third party
- 2:38component dependencies next aspect of
- 2:41comparison is scope sast examines the
- 2:45application source code or binaries Das
- 2:50tests the running application focusing
- 2:53on how it behaves externally iast
- 2:56examines code and runtime data providing
- 3:00insights into both of them rasp protects
- 3:04applications when it is running by
- 3:06actively monitoring and intervening SCA
- 3:10analyzes thirdparty libraries and
- 3:13components for any known
- 3:15vulnerabilities next aspect of
- 3:17comparison is false positives sast May
- 3:21generate some false positives as it
- 3:25analyzes code static statically Das
- 3:28tends to have fewer false positives as
- 3:31it tests the applications dynamically is
- 3:35typically has fewer false positives
- 3:38compared to sast due to its combination
- 3:41of static and dynamic analysis Ras May
- 3:45generate POS false positives depending
- 3:47on its configured rules sea May report
- 3:51issues that aren't vulnerabilities
- 3:54depending on the quality of
- 3:56vulnerability databases next aspect of
- 4:00comparison is deployment SAS is
- 4:03integrated into the cicd pipelines for
- 4:07early buged identification dast is
- 4:10usually used post development and
- 4:14pre-production iast is integrated into
- 4:18cicd pipelines providing continuous
- 4:21security feedback rasp is deployed in
- 4:24the production environment to protect
- 4:27against runtime attacks SCA is
- 4:30integrated into development and build
- 4:33processes to assess third-party
- 4:36components next aspect of comparison is
- 4:40ease of use SAS may require setup and
- 4:43tuning to understand the application's
- 4:46codebase and coding standards tast is
- 4:49easier to set up as it interacts with
- 4:52the application externally iast is
- 4:55easier to set up than sast due to its
- 4:59hybrid nature rasp requires integration
- 5:03and configuration but can be relatively
- 5:07straightforward SCA is generally easy to
- 5:10set up and integrate into the
- 5:12development process next aspect of
- 5:15comparison is vulnerability types tast
- 5:19identifies code level vulnerabilities
- 5:22such as injection flaws insecure coding
- 5:25practices and code smells dast
- 5:28identifies run
- 5:30vulnerabilities including configuration
- 5:32issues and non vulnerabilities is
- 5:35detects vulnerabilities in both code and
- 5:38data including runtime data related
- 5:42issues Ras monitors and mitigates
- 5:46various threats at runtime offering
- 5:49broader protection sea identifies known
- 5:52security issues in thirdparty libraries
- 5:56and components next aspect of comparison
- 5:59is performance impact SAS typically has
- 6:03a low performance impact since it
- 6:06analyzes code statically that is when
- 6:09the application is not running Das can
- 6:12impact application performance as it
- 6:15interacts with the running application
- 6:18iast has moderate impact on the
- 6:21performance due to its combination of
- 6:23static and dynamic analysis rasp has
- 6:27minimal impact on application
- 6:29performance sea has a negligible impact
- 6:33on performance as it primarily scans
- 6:36metadata and dependency information next
- 6:40aspect of comparison is realtime
- 6:43protection sast T and I do not provide
- 6:48realtime protection they are primarily
- 6:50testing or analysis tools Ras provides
- 6:54realtime protection by actively
- 6:56monitoring and responding to threats due
- 6:59during application execution sea does
- 7:02not provide realtime protection but
- 7:05helps in identifying and managing
- 7:07vulnerabilities and third party
- 7:09components before integration next
- 7:11aspect of comparison is common use cases
- 7:16SAS is used for early bug identification
- 7:20and code quality improvement during
- 7:24development dast is used for testing web
- 7:28apps and and apis in a postd development
- 7:32phase iast provides continuous security
- 7:36monitoring during the development life
- 7:38cycle rasp is used for realtime
- 7:42protection against attacks in a
- 7:44production environment sea is used to
- 7:47identify and manage opsource
- 7:50vulnerabilities in thirdparty components
- 7:54next aspect of comparison is tools for
- 7:57sass you can use tools like fortify
- 8:00check marks and verac code for das you
- 8:04can use tools like oos zap burp suite
- 8:09and nesses for I you can use tools like
- 8:13contrast security and EDD for rasp you
- 8:17can use tools like impera app spider and
- 8:22F5 ASM for sea you can use tools like
- 8:26sonar Cube black duck and l so this is
- 8:30the comparison between the five Concepts
- 8:33so to summarize sass is used for
- 8:37identifying code level vulnerabilities
- 8:39and security issues in the applications
- 8:42source code or binaries Das is employed
- 8:46to test running applications and
- 8:48discover runtime vulnerabilities
- 8:51misconfigurations and known security
- 8:53issues I combines static and dynamic
- 8:56analysis to detect vulnerabilities in
- 8:59both code and runtime data rasp is
- 9:02designed for realtime protection of
- 9:05applications during runtime actively
- 9:08monitoring and mitigating security
- 9:10threats sea focuses on identifying nonn
- 9:14vulnerabilities in third party
- 9:16components libraries and dependencies so
- 9:19that's it for today guys I hope this
- 9:21video helped you understand the
- 9:24differences or provide you a comparison
- 9:27between these techniques I don't know if
- 9:29you can take a screenshot of it so that
- 9:32it's helpful thank you so much for
- 9:34watching I will see you in another video
- 9:36with another topic until then take care
- 9:39of yourselves bye-bye
About this transcript
This page contains the full transcript of SAST vs DAST vs IAST vs RASP vs SCA | App Security | Comparison between SAST, DAST, IAST, RASP, SCA by CyberPlatter, generated from the public captions YouTube serves with the video. The transcript has 1,091 words across 186 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.