Like the web itself, security scanners are advancing at a fast pace. Here are the top 5 technologies that leading security professionals are applying to stay ahead of the curve:

5. XSS Analyzer

The “classic” black box approach for detecting XSS relies on sending a bulk of tests based on a “cheat sheet” of around a hundred different payloads. This is a reasonable approach for an automated tool, but it isn’t very sophisticated.

Mimicking a human attacker, XSS Analyzer is a learning system that follows a disciplined step-by-step approach. XSS Analyzer learns the defense patterns of an application, and finds ways to defeat those defenses. This allows XSS Analyzer to find vulnerabilities that could never be found automatically before, with higher accuracy and less time.

 4. JSA

Black box scanners are great for testing server-side logic, but what about client-side? 40% of Fortune 500 websites are vulnerable to DOM-based XSS or other JavaScript security risks, which are notoriously difficult to find with traditional approaches. This is where JavaScript Security Analyzer (JSA) comes into play.

In JSA, the black-box scanner fetches HTML and JavaScript content, and passes them on to be statically analyzed. With DAST and SAST working together as part of the same scan, the result is a powerful hybrid analysis that is able to detect a wide range of security issues in JavaScript.

3. F4F

When applying static analysis to modern applications, which are built with frameworks and XML configurations, it is insufficient to have great data-flow and control-flow analysis. There are framework-specific constructs that require customizations to the analysis, without which many issues go undetected.

This is where Framework for Frameworks (F4F) comes into the picture. With F4F, the analysis can take into consideration framework-specific configuration and invocations, converting those into synthetically-generated code. This results in accurately and automatically finding more issues than ever before. That’s what it’s all about, isn’t it?

2. Glass box

An exciting and emerging technology, glass box is all about giving black box scanners visibility into the internals of a running application, usually through instrumentation (also called IAST by Gartner). Agents running on the server side send information to the black box scanner, which helps the scanner provide dramatically improved results.

We believe glass box is the future of dynamic analysis. Watch this short demo to learn more.

1. String Analysis

Imagine a scanner that is able to track individual string values and patterns across your entire program – now that’s smart! The possibilities are endless, from automatically detecting the parts in your code that perform input validation, to eliminating false positives in cases where exploit is not possible.

It takes some serious technology to be able to do that. Luckily, IBM researchers have been working hard to make this technology a reality. String Analysis is probably the most advanced kind of static analysis in existence today, and being used across AppScan products extensively.


What do you think? Are you excited as we are about these innovations? What other capabilities would you like to see in future versions of security scanners? Leave us a comment!

more from Application Security

Controlling the Source: Abusing Source Code Management Systems

For full details on this research, see the X-Force Red whitepaper “Controlling the Source: Abusing Source Code Management Systems”. This material is also being presented at Black Hat USA 2022. Source Code Management (SCM) systems play a vital role within organizations and have been an afterthought in terms of defenses compared to other critical enterprise systems such as Active Directory.…

Black Hat 2022 Sneak Peek: How to Build a Threat Hunting Program

You may recall my previous blog post about how our X-Force veteran threat hunter Neil Wyler (a.k.a “Grifter”) discovered nation-state attackers exfiltrating unencrypted, personally identifiable information (PII) from a company’s network, unbeknownst to the security team. The post highlighted why threat hunting should be a baseline activity in any environment. Before you can embark on a threat hunting exercise, however,…