Static Security Testing Models in Inefficiency Reduction Identification of SQL Injection in Web Applications

Authors

  • Armando Tipacti Garcia Facultad de Ingeniería de Sistemas e Informática, Unidad de Postgrado, Universidad Nacional Mayor de San Marcos, Lima, Perú

DOI:

https://doi.org/10.26423/rctu.v11i2.800

Keywords:

Static application security testing, Secure software development, DevSecOps, SQL Inyection

Abstract

Early detection of vulnerabilities is crucial in software development to ensure the security of web applications, especially against SQL injection attacks. Static Application Security Testing (SAST) allows for the identification of vulnerabilities from the early stages of the development lifecycle. This article systematically reviews the literature to identify and analyze the most effective SAST models in reducing inefficiencies in detecting SQL injections. Following PRISMA 2020 guidelines and Kitchenham’s approach, exhaustive searches were conducted in databases like EBSCO and Scopus. The results show that early integration of SAST and the use of artificial intelligence significantly improve vulnerability detection, reducing false positives and negatives. The implementation of advanced SAST models is essential for enhancing the security of web applications, with future research suggested to explore more integrated methodologies and new tools.

Downloads

Download data is not yet available.

Published

2024-12-19

How to Cite

Static Security Testing Models in Inefficiency Reduction Identification of SQL Injection in Web Applications. (2024). UPSE Scientific and Technological Magazine, 11(2), 130-144. https://doi.org/10.26423/rctu.v11i2.800