YouTube2Text

SAST vs DAST vs IAST vs RASP vs SCA | App Security | Comparison between SAST, DAST, IAST, RASP, SCA — Transcript

by CyberPlatter · 1,091 words · 186 segments · language en · Watch on YouTube

Full transcript

  1. 0:00hey guys welcome back to cyber platter
  2. 0:02today we'll learn the difference between
  3. 0:04sast D iast rasp and sem if you want to
  4. 0:08know about these individual topics and
  5. 0:10we have different videos where I talk in
  6. 0:13detail about these testing methodologies
  7. 0:16I will link that in the description box
  8. 0:18you can go through them tast stands for
  9. 0:21static application security testing Das
  10. 0:25is dynamic application security testing
  11. 0:29iast is is interactive application
  12. 0:32security testing rasp is runtime
  13. 0:35application self- protection sea is
  14. 0:40software composition analysis all of
  15. 0:43these are different approaches to
  16. 0:45identifying and mitigating security
  17. 0:48vulnerabilities in software applications
  18. 0:51let's see the comparison now the first
  19. 0:54aspect of comparison is testing stage
  20. 0:57sast is static analysis and it is done
  21. 1:01pre- run time that is it analyzes the
  22. 1:04source code or binaries before the
  23. 1:07application is executed next is Das Das
  24. 1:11is dynamic analysis and it is done at
  25. 1:14runtime that is a test the application
  26. 1:17in a running State typically after the
  27. 1:20development and during the testing phase
  28. 1:24iast is hybrid approach that is it
  29. 1:27combines elements of both static that is
  30. 1:30pre- runtime and dynamic that is runtime
  31. 1:33testing rasp testing stage is at the
  32. 1:35runtime it operates during the
  33. 1:38application run time that is it operates
  34. 1:41during the application run time
  35. 1:43monitoring and protecting the
  36. 1:45application as it runs SCA is pre-run
  37. 1:49time that is it identifies
  38. 1:51vulnerabilities in third-party
  39. 1:53components before they are integrated
  40. 1:55into the code base next aspect of
  41. 1:58comparison is analysis is type sast is
  42. 2:01white box testing as it has full access
  43. 2:05to the applications code sast is Black
  44. 2:08Box testing as it examines the
  45. 2:10application externally like a hacker
  46. 2:13would iast is gray box testing it
  47. 2:17combines aspects of both white box and
  48. 2:19black box testing rasp it depends on the
  49. 2:23implementation that is it can be white
  50. 2:26box or Black Box depending on its
  51. 2:28implementation it can inspect code and
  52. 2:31respond to runtime threats sea is wibx
  53. 2:35testing it analyzes the third party
  54. 2:38component dependencies next aspect of
  55. 2:41comparison is scope sast examines the
  56. 2:45application source code or binaries Das
  57. 2:50tests the running application focusing
  58. 2:53on how it behaves externally iast
  59. 2:56examines code and runtime data providing
  60. 3:00insights into both of them rasp protects
  61. 3:04applications when it is running by
  62. 3:06actively monitoring and intervening SCA
  63. 3:10analyzes thirdparty libraries and
  64. 3:13components for any known
  65. 3:15vulnerabilities next aspect of
  66. 3:17comparison is false positives sast May
  67. 3:21generate some false positives as it
  68. 3:25analyzes code static statically Das
  69. 3:28tends to have fewer false positives as
  70. 3:31it tests the applications dynamically is
  71. 3:35typically has fewer false positives
  72. 3:38compared to sast due to its combination
  73. 3:41of static and dynamic analysis Ras May
  74. 3:45generate POS false positives depending
  75. 3:47on its configured rules sea May report
  76. 3:51issues that aren't vulnerabilities
  77. 3:54depending on the quality of
  78. 3:56vulnerability databases next aspect of
  79. 4:00comparison is deployment SAS is
  80. 4:03integrated into the cicd pipelines for
  81. 4:07early buged identification dast is
  82. 4:10usually used post development and
  83. 4:14pre-production iast is integrated into
  84. 4:18cicd pipelines providing continuous
  85. 4:21security feedback rasp is deployed in
  86. 4:24the production environment to protect
  87. 4:27against runtime attacks SCA is
  88. 4:30integrated into development and build
  89. 4:33processes to assess third-party
  90. 4:36components next aspect of comparison is
  91. 4:40ease of use SAS may require setup and
  92. 4:43tuning to understand the application's
  93. 4:46codebase and coding standards tast is
  94. 4:49easier to set up as it interacts with
  95. 4:52the application externally iast is
  96. 4:55easier to set up than sast due to its
  97. 4:59hybrid nature rasp requires integration
  98. 5:03and configuration but can be relatively
  99. 5:07straightforward SCA is generally easy to
  100. 5:10set up and integrate into the
  101. 5:12development process next aspect of
  102. 5:15comparison is vulnerability types tast
  103. 5:19identifies code level vulnerabilities
  104. 5:22such as injection flaws insecure coding
  105. 5:25practices and code smells dast
  106. 5:28identifies run
  107. 5:30vulnerabilities including configuration
  108. 5:32issues and non vulnerabilities is
  109. 5:35detects vulnerabilities in both code and
  110. 5:38data including runtime data related
  111. 5:42issues Ras monitors and mitigates
  112. 5:46various threats at runtime offering
  113. 5:49broader protection sea identifies known
  114. 5:52security issues in thirdparty libraries
  115. 5:56and components next aspect of comparison
  116. 5:59is performance impact SAS typically has
  117. 6:03a low performance impact since it
  118. 6:06analyzes code statically that is when
  119. 6:09the application is not running Das can
  120. 6:12impact application performance as it
  121. 6:15interacts with the running application
  122. 6:18iast has moderate impact on the
  123. 6:21performance due to its combination of
  124. 6:23static and dynamic analysis rasp has
  125. 6:27minimal impact on application
  126. 6:29performance sea has a negligible impact
  127. 6:33on performance as it primarily scans
  128. 6:36metadata and dependency information next
  129. 6:40aspect of comparison is realtime
  130. 6:43protection sast T and I do not provide
  131. 6:48realtime protection they are primarily
  132. 6:50testing or analysis tools Ras provides
  133. 6:54realtime protection by actively
  134. 6:56monitoring and responding to threats due
  135. 6:59during application execution sea does
  136. 7:02not provide realtime protection but
  137. 7:05helps in identifying and managing
  138. 7:07vulnerabilities and third party
  139. 7:09components before integration next
  140. 7:11aspect of comparison is common use cases
  141. 7:16SAS is used for early bug identification
  142. 7:20and code quality improvement during
  143. 7:24development dast is used for testing web
  144. 7:28apps and and apis in a postd development
  145. 7:32phase iast provides continuous security
  146. 7:36monitoring during the development life
  147. 7:38cycle rasp is used for realtime
  148. 7:42protection against attacks in a
  149. 7:44production environment sea is used to
  150. 7:47identify and manage opsource
  151. 7:50vulnerabilities in thirdparty components
  152. 7:54next aspect of comparison is tools for
  153. 7:57sass you can use tools like fortify
  154. 8:00check marks and verac code for das you
  155. 8:04can use tools like oos zap burp suite
  156. 8:09and nesses for I you can use tools like
  157. 8:13contrast security and EDD for rasp you
  158. 8:17can use tools like impera app spider and
  159. 8:22F5 ASM for sea you can use tools like
  160. 8:26sonar Cube black duck and l so this is
  161. 8:30the comparison between the five Concepts
  162. 8:33so to summarize sass is used for
  163. 8:37identifying code level vulnerabilities
  164. 8:39and security issues in the applications
  165. 8:42source code or binaries Das is employed
  166. 8:46to test running applications and
  167. 8:48discover runtime vulnerabilities
  168. 8:51misconfigurations and known security
  169. 8:53issues I combines static and dynamic
  170. 8:56analysis to detect vulnerabilities in
  171. 8:59both code and runtime data rasp is
  172. 9:02designed for realtime protection of
  173. 9:05applications during runtime actively
  174. 9:08monitoring and mitigating security
  175. 9:10threats sea focuses on identifying nonn
  176. 9:14vulnerabilities in third party
  177. 9:16components libraries and dependencies so
  178. 9:19that's it for today guys I hope this
  179. 9:21video helped you understand the
  180. 9:24differences or provide you a comparison
  181. 9:27between these techniques I don't know if
  182. 9:29you can take a screenshot of it so that
  183. 9:32it's helpful thank you so much for
  184. 9:34watching I will see you in another video
  185. 9:36with another topic until then take care
  186. 9:39of yourselves bye-bye

About this transcript

This page contains the full transcript of SAST vs DAST vs IAST vs RASP vs SCA | App Security | Comparison between SAST, DAST, IAST, RASP, SCA by CyberPlatter, generated from the public captions YouTube serves with the video. The transcript has 1,091 words across 186 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.