Application Security Testing and Vulnerability Assessment
Keywords:
Static Application Security Testing (SAST),, Dynamic Application Security Testing (DAST),, ommon Vulnerability Scoring System (CVSS),, DevSecOps, Threat Modeling,, AI/ML in Cybersecurity,, Compliance Standards (GDPR, PCI-DSS).Abstract
Application Security Testing (AST) and Vulnerability Assessment (VA) are critical pillars in
safeguarding modern software systems against cyber threats. This paper explores the
methodologies, tools, and frameworks underpinning AST and VA, emphasizing their
integration into the Software Development Lifecycle (SDLC) and DevSecOps pipelines. It
evaluates static, dynamic, and interactive testing techniques, vulnerability scoring systems
(e.g., CVSS), and emerging trends such as AI-driven vulnerability detection and cloud-native
security challenges. The study synthesizes data from industry reports (2020–2023) and
academic research to highlight best practices, compliance requirements, and future directions,
including quantum-resistant cryptography and zero-trust architectures.