Talk:Static application security testing

Latest comment: 2 months ago by Ericbodden in topic IAST

IAST

edit

This article states "interactive application security testing (IAST), a combination of the two", i.e., a combination of static and dynamic analysis, and cites [6] as a source. However, [6] makes no such statement. And more generally, I do not think that IAST commonly uses static analysis. I think it is usually a purely dynamic approach. Are there other sources to back up this claim? Ericbodden (talk) 13:08, 29 August 2024 (UTC)Reply