Practitioner Perspectives of DAST Integration in Agile Development Workflows: An Experience Report
Modern web development relies on Agile frameworks and Continuous Integration and Continuous Delivery (CI/CD) pipelines to accelerate software delivery, yet the rising number of vulnerabilities underscores the need to better integrate security testing into these workflows. We present an experience report for a large software organization in the United States, investigating practitioners’ perceptions of Dynamic Application Security Testing (DAST) integration within their development workflow. Through semi-structured interviews with 10 practitioners on the team, we outline perceptions of adoption challenges, workflow impacts, and opportunities for improvement. Based on these findings, we provide practical recommendations for integrating security testing into modern development processes.
Tue 7 JulDisplayed time zone: Eastern Time (US & Canada) change
11:00 - 12:30 | Security 1Tool Demonstrations / Industry Papers / Ideas, Visions and Reflections / Research Papers at MB 3.445 Chair(s): Ezekiel Soremekun Singapore University of Technology and Design | ||
11:00 10mTalk | IDSLab: A Low-Code Platform for End-to-End IDS Dataset Construction and Experimentation Tool Demonstrations Reda Morsli École de Technologie Supérieure, Nadjia Kara École de Technologie Supérieure, Hakima Ould-Slimane University of Quebec at Trois-Rivieres, Laaziz Lahlou Ecole de Technologie Superieure | ||
11:10 20mTalk | JDetect: A Fine-Grained Detecting Method for Java Source SCA by Fusing Behavioral and Code Features Industry Papers Guisheng Fan East China University of Science and Technology, Shulin Liu East China University of Science and Technology, Wentao Chen East China University of Science and Technology, Huiqun Yu East China University of Science and Technology; Shanghai Engineering Research Center of Smart Energy, Huan Wang Orient Securities Company Limited, Diwen Shi East China University of Science and Technology | ||
11:30 10mTalk | AST-PAC: AST-guided Membership Inference for Code Ideas, Visions and Reflections Roham Koohestani JetBrains Research & Delft University of Technology, Ali Al-Kaswan Delft University of Technology, Netherlands, Jonathan Katzy Delft University of Technology, Mali Izadi Google & TU Delft | ||
11:40 20mTalk | Cerberus: Robust Endpoint Threat Detection in Practice Industry Papers Zhiwei Xu Tsinghua University, Tian Qiu Tsinghua University, Haohao Gao China Central Depository & Clearing Co., Ltd., Wei Jiao China Central Depository & Clearing Co., Ltd., Qichen Ma China Central Depository & Clearing Co., Ltd., Jingli Wang China Central Depository & Clearing Co., Ltd., Jiaxiang Zhao China Central Depository & Clearing Co., Ltd., Jiabao Gao Tsinghua University, Hai Wan Tsinghua University, Xibin Zhao Tsinghua University | ||
12:00 20mTalk | JSProtect: A Scalable Obfuscation Framework for Mini-Games in WeChat Industry Papers Zhihao Li Tencent Inc., Chaozheng Wang The Chinese University of Hong Kong, Li Zongjie Hong Kong University of Science and Technology, Xinyong Peng Tencent Inc., Zelin Su Tencent Inc., Qun Xia Tencent Inc., Haochuan Lu Tencent, Ting Xiong Tencent Inc., Man Ho Lam The Chinese University of Hong Kong, Shuzheng Gao Chinese University of Hong Kong, Yuchong Xie Hong Kong University of Science and Technology, Cuiyun Gao Harbin Institute of Technology, Shenzhen, Shuai Wang Hong Kong University of Science and Technology, Yuetang Deng Tencent, Huafeng Ma Tencent Inc. | ||
12:20 10mTalk | Practitioner Perspectives of DAST Integration in Agile Development Workflows: An Experience Report Industry Papers | ||