Hi Members,
I am a novice in web application security field. I am asked to write a white paper on "Next Generation Vulnerability Scanner".
As per my understanding, the current assessment methods are as follows
1. Black box testing: - This is performed in the following ways
a. Automated vulnerability scanning
b. Manual Penetration testing
c. Manual vulnerability assessment
2. Gray box testing:- This is similar to Black box testing. In addition, the analyst use to have some information about the application (e.g. credentials, technology, architecture etc. )
3. White Box Testing:- Analyst use to have maximum information about the application. Analyst reviews the code base of the application.
Now the question I have are
1. Are the current methodologies sufficient for the current generation technologies or is there a gap, if there is, then what is it and has there been any work going on to fill it in?
2. Here I am assuming the current methodologies are sufficient for current generation web App. But question is, will these methodologies be able to assess the next generation web applications ( developed in technologies like SAP, Oracle, IBM or more advanced ones )? If no, then what approach is going to be followed for such web Apps?
I would really appreciate your effort in answering these questions.
Thanks in advance
Jyoti
This thread was automatically locked due to age.